A Six-Figure Fine for What Inspectors Found in a Bathroom
Ireland's Data Protection Commission announced its final decision against the Health Service Executive on September 2, 2026, following a decision dated August 25, 2026. The total fine reached 645,000 euro, but the number is less striking than what inspectors describe finding: patient documents "damaged or destroyed by mould, contaminated by animal droppings, covered in rubble or detritus, rotting due to storage environment or water damaged," in the words of Deputy Commissioner Graham Doyle.
The records themselves turned up in places no hospital archive should be: disused bathrooms and toilet cubicles, a shipping container inside a turf shed, rooms with no functioning lighting or heating, and derelict buildings. This was not a hacking incident or a lost laptop. It was years of physical storage neglect, only surfaced when a formal inquiry went looking.
How the 645,000 Euro Fine Breaks Down
The DPC split the penalty across four separate GDPR articles rather than issuing one lump sum, and the breakdown shows where the Commission judged the failure to be worst.
| GDPR Article | Fine |
|---|---|
| Art. 5(1)(f) + Art. 32(1) - security of processing | EUR 300,000 |
| Art. 5(1)(e) - storage limitation | EUR 300,000 |
| Art. 33(1) - breach notification to the DPC | EUR 30,000 |
| Art. 34(1) - notification to data subjects | EUR 15,000 |
The two largest shares, for security of processing and storage limitation, together account for 600,000 of the 645,000 euro total, making clear that the core offence was not the eventual breach notification delay but the years-long neglect that made a breach inevitable.
The Breach That Started It: St. Loman's and St. Conal's
The inquiry traces back to breaches first notified to the DPC in October and November 2023, involving records at St. Loman's Hospital in Mullingar, County Westmeath, and St. Conal's site. Those initial notifications were narrow incidents; the DPC's subsequent inquiry expanded into a systemic review of how the HSE stores paper records across its estate.
Nearly three years passed between the first notified breach and the final decision, a timeline that itself says something about how long a physical-records failure can stay invisible compared with a digital breach, which usually forces faster disclosure once discovered.
The HSE's Response and the Corrective Orders
The DPC's corrective orders require the HSE to conduct a full audit of every storage facility it uses, implement a proper system for tracking and managing records, destroy documents it no longer needs to keep, and remove any records currently held in unsuitable facilities. The HSE said it accepts the findings and will comply.
Joe Ryan, the HSE's chief risk officer, apologised on behalf of the organisation for failing to manage patient records appropriately, and the HSE says it has already started a Records Management Steering Committee and a National Records Management Programme to address the issues.
The Compliance Blind Spot This Case Exposes
Most GDPR enforcement actions that make headlines involve a cyberattack, a misconfigured database, or an employee sending the wrong email. This case shows the DPC applying the same severity to a completely different failure mode: an organisation simply failing to manage where its paper records physically live over time.
For any EU or UK business with an offsite archive, a decommissioned office, or a records-retention policy nobody has checked in years, the lesson is concrete: a GDPR compliance audit that stops at firewalls and access logs is incomplete. The HSE's fine is evidence that a national data protection authority will treat a mouldy filing cabinet with the same seriousness as a breached server.
Read next: Automated Firings Just Cost Uber 825 Million Euros | The Met Police Breach Every Business Could Repeat



