The Irish Data Protection Commission has fined the Health Service Executive (HSE) €645,000 after finding serious weaknesses in the storage and protection of paper medical records. The decision is a useful reminder for every organisation handling sensitive information: physical security is part of GDPR security, even when the data never enters a database.
The DPC national announcement was published on 3 September 2026. The final decision was dated 28 August 2026 and followed two personal-data breaches notified in October and November 2023. The EDPB case summary records the publication date, legal references and outcome; the DPC announcement is the primary source for the regulator’s findings.
The case involved two former hospitals
The records were stored and retained in external facilities at St Loman’s Hospital in Mullingar, County Westmeath, and St Conal’s Hospital in Letterkenny, County Donegal. Both sites were former disused psychiatric hospitals. Unauthorised individuals accessed paper records at both locations, and videos uploaded to social media drew attention to the exposure.
The issue was therefore broader than a single misplaced file. The DPC identified failings in the physical conditions of the storage facilities and in the integrity of the documents held there. For healthcare providers, employers and other organisations handling special-category data, that distinction matters: a retention room, archive or off-site warehouse remains part of the processing environment.
How the €645,000 fine was split
- €300,000 for infringements of GDPR Articles 5(1)(f) and 32, concerning integrity and confidentiality and security of processing.
- €300,000 for an infringement of Article 5(1)(e), the storage-limitation principle.
- €30,000 for an infringement of Article 33, concerning notification of a personal-data breach to the supervisory authority.
- €15,000 for an infringement of Article 34, concerning communication of a personal-data breach to affected people.
The DPC also issued a reprimand and made corrective orders. The decision links day-to-day controls to the GDPR principles: organisations must protect information against unauthorised access, keep it only as long as necessary, and respond properly when a breach occurs.
What compliance leads should take from the decision
Map paper records as data assets
Include paper files in records of processing, information-asset registers and risk assessments. Record what is held, where it is held, who can access it, how it is moved and when it should be destroyed. A storage provider or facilities team may support the process, but accountability does not disappear when records leave the main office.
Test the physical environment
Check doors, locks, alarms, visitor controls, lighting, water and fire risks, environmental conditions, shelving and evidence of intrusion. Inspections should be documented, risk-ranked and repeated. A policy that says records are secure is not a substitute for checking the room where they are stored.
Make retention operational
Retention schedules need owners, review dates and a practical destruction process. If a file has reached the end of its retention period, leaving it in an archive creates continuing exposure. Destruction should be secure, authorised and evidenced.
Exercise the breach plan
Teams should know how to escalate a suspected physical breach, preserve evidence, assess risk and record decisions. The GDPR’s breach rules can require notification to the supervisory authority and communication to affected people. A tabletop exercise can expose gaps in contact lists, decision rights and response times before a real incident does.
Why this matters beyond healthcare
Medical records make the risk especially visible, but the control lesson applies to HR files, safeguarding records, customer applications, legal documents and printed exports. The medium changes the control, not the organisation’s responsibility to protect personal data.
For a UK or US compliance lead, the practical question is simple: could the organisation show where sensitive paper records are, why they are still needed, and what prevents unauthorised access? If the answer depends on informal knowledge, this decision is a prompt to strengthen the control environment. Our coverage of a previous HSE breach shows how the same accountability questions arise when the records are digital.
Questions to ask about paper-record security
- Have all off-site paper stores been identified and risk-assessed?
- Are access rights, visitors and incidents recorded?
- Is there a documented retention and secure-destruction schedule?
- Can staff recognise and escalate a physical data breach?
- When was the last documented inspection or exercise?
For a practical grounding in the core requirements, see our GDPR Essentials course.
