Ireland Ireland

Health Service Executive (HSE)

645,000 €

GDPR enforcement action by Data Protection Commission (DPC) on 2026-08-25.

Rank · Sector
#14
of 286 in Health Care
Rank · Ireland
#15
of 40
Rank · All fines
#224
of 3,170

Case details

Authority
Data Protection Commission (DPC)
Date
2026-08-25
Controller / Processor
Health Service Executive (HSE)
Sector
Health Care
Quoted Articles
Art. 5 (1) e) GDPR, Art. 5 (1) f) GDPR, Art. 32 (1) GDPR, Art. 33 (1) GDPR, Art. 34 (1) GDPR
Type of violation
Insufficient technical and organisational measures to ensure information security

Summary

The Irish DPA has imposed a fine of EUR 645,000 on the Health Service Executive (HSE). Following the breach notifications the authority opened its investigation in May 2024. The first notification on 1 October 2023 related to intruders accessing paper documents from a disused psychiatric hospital contaminated with asbestos. The second notification on 1 November 2023 related to access to physical records in a disused psychiatric hospital severely affected by mould. In April 2024 the authority found further evidence of access to the first institution's records on social media. The authority investigated 12 sites and found that medical records were stored in mouldy, wet, disorganised and unsafe conditions with no security measures in place. The records were held beyond the maximum retention period and data subjects were not informed about the breaches.

Open original source Links to the regulator's original publication or another source.

Related fines