Skip to content

Regulatory Pulse

DPC orders paper-record and confidential-waste controls after children’s health data inquiry

A final DPC decision finds GDPR security failures in the physical handling of children’s paper health records and orders completed DPIAs, implemented controls and regulator consultation.

Ireland / European Union
GDPR security, children’s health data, paper records, confidential waste and privacy operations
Guidance
Official source reviewed

PrivacyBuilt Editorial · Source published Final GDPR enforcement decision · Reviewed 3 October 2026 · 9 min read

The 60-second summary

On 1 October 2026, the Data Protection Commission announced a final decision concerning the physical security and control of children’s paper health records at one Children’s Health Ireland facility. Following protected disclosures, an unannounced inspection and an inquiry, the DPC found infringements of the GDPR security and confidentiality principle in Article 5(1)(f) and the security obligation in Article 32(1). The decision addresses records stored in a clinical office and sensitive documents placed in confidential-waste bins. The DPC issued a reprimand and ordered completion of two DPIAs, implementation of the identified measures and procedures, and delivery of the final DPIAs to the regulator within four weeks of the decision. The full decision is not yet public, so the announcement is the current authoritative account.

Timeline that matters

  1. June–July 2025

    Protected disclosures

    The DPC received protected disclosures concerning the handling of children’s records.

  2. 16 July 2025

    Unannounced inspection

    The regulator inspected the relevant facility.

  3. 11 August 2025

    Inquiry opened

    The DPC launched its formal inquiry.

  4. 10 September 2026

    Decision notified

    The final decision was notified to the organisation.

  5. Within four weeks of the decision

    DPIAs due to the DPC

    Copies of the finalised DPIAs must be provided for consultation; the full decision should be checked for the precise calculation.

  6. 1 October 2026

    Decision announced

    The DPC published its summary and said the full decision would follow.

What changed

The final decision turns physical-record weaknesses into specific GDPR findings and corrective actions. The DPC found that records in the clinical office and documents placed in confidential-waste bins were not managed with appropriate security, confidentiality and control. The organisation must finalise DPIAs covering healthcare-record processing and confidential-waste management, implement the technical and organisational measures and action items identified in those DPIAs, embed the relevant standard operating procedures, and provide the completed DPIAs to the DPC for consultation. The announcement does not report an administrative fine. The full decision will be published later.

Who should pay attention?

Privacy and DPO teams

Ensure DPIAs address real storage, handling and disposal practices and that regulator-facing deadlines are controlled.

Records and facilities teams

Map paper-record locations, access, overflow, temporary storage, transport and destruction.

Healthcare and safeguarding leaders

Treat children’s records and special-category data as requiring heightened, demonstrable protection.

Security and internal audit

Test physical controls, exception handling and evidence rather than relying on written procedures alone.

Vendors and procurement

Verify confidential-waste, storage, cleaning and destruction providers through contracts and operational assurance.

What the guidance clarifies

A final regulatory decision
The decision was notified on 10 September 2026 and announced on 1 October 2026.
Paper records remain fully in scope
The findings concern physical records and confidential-waste handling, not a cyber incident.
Two GDPR infringements
The DPC identified infringements of Articles 5(1)(f) and 32(1).
Corrective orders, not only a reprimand
The organisation must finalise DPIAs, implement resulting measures and procedures, and submit the DPIAs to the DPC.
No fine reported
The announcement lists a reprimand and corrective orders but does not state an administrative fine.
Full decision pending
Detailed reasoning, scope and exact order wording should be checked when the DPC publishes the full decision.

Global relevance — physical records need the same assurance discipline as digital systems

Why this matters for global organisations.

Sensitive information can be exposed through ordinary workplace conditions: crowded rooms, overflowing disposal containers, unclear ownership and procedures that are not embedded in practice. Strong governance connects inventories, physical access, disposal chains, DPIAs, vendor assurance and testing.

  • Include paper and hybrid workflows in data inventories, risk assessments and incident exercises.
  • Treat confidential disposal as a controlled processing chain with capacity, custody and verification.
  • Convert risk-assessment findings into owned actions with measurable completion evidence.
  • Test physical controls through observation and sampling, including during busy operating periods.
  • Align facilities, privacy, security, operations and suppliers around a single evidence register.

15 actions to start now

  1. Inventory every location where paper records containing personal or special-category data are created, stored, reviewed, transported or destroyed.
  2. Assign accountable owners for clinical or operational workspaces, records rooms, temporary holding areas and confidential-waste streams.
  3. Inspect physical storage for unlocked cabinets, exposed files, overflow, unattended trolleys and records left in shared spaces.
  4. Restrict and document access to sensitive-record areas using role-based physical controls.
  5. Review confidential-waste bin placement, capacity, locking, collection frequency and chain of custody.
  6. Create escalation rules for full bins, damaged containers, misplaced records and unapproved temporary storage.
  7. Complete or refresh DPIAs for paper-record handling and confidential-waste management.
  8. Translate every DPIA action into an owner, due date, acceptance criterion and retained completion record.
  9. Embed standard operating procedures in daily workflows and verify that staff can follow them under peak demand.
  10. Train clinical, administrative, facilities, cleaning and contractor personnel on physical-record security.
  11. Test controls through unannounced walkthroughs, sampling and exception reviews.
  12. Review vendor contracts for secure collection, transport, storage, destruction, incident reporting and audit evidence.
  13. Document near misses and protected disclosures, investigate root causes and track remediation.
  14. Set management reporting for overdue DPIA actions, recurring exceptions and vendor failures.
  15. Monitor publication of the full decision and update the control interpretation if its detailed reasoning changes the assessment.

Suggested next steps

  • Review the full decision when published and revise this briefing if its detailed reasoning or order wording materially changes the operational interpretation.

Evidence worth retaining

  • Current paper-record location and lifecycle inventory.
  • Physical access lists, key or badge records and periodic access reviews.
  • Inspection photographs, walkthrough reports and remediation tickets.
  • Confidential-waste bin specifications, placement map and collection schedule.
  • Waste chain-of-custody logs and certificates of destruction.
  • Final DPIAs, action registers, approvals and implementation evidence.
  • Version-controlled standard operating procedures and staff acknowledgements.
  • Training attendance, contractor briefings and competence checks.
  • Internal-audit samples, exception logs, near-miss reports and root-cause analyses.
  • Vendor contracts, assurance reports, incident notices and corrective-action records.

Questions to take to counsel or your conformity team

These are discussion prompts, not legal advice or conclusions.

  • Where can sensitive paper records accumulate outside approved storage?
  • Who owns security for each physical location and each handoff?
  • Can confidential-waste capacity cope with peak activity without overflow?
  • Are bins locked, appropriately placed and protected from unauthorised removal?
  • Do DPIAs reflect production reality, including workarounds and temporary storage?
  • How are DPIA actions verified and closed rather than merely recorded?
  • Can the organisation reconstruct the chain of custody from creation to destruction?
  • Do cleaners, contractors and temporary staff receive role-specific instructions?
  • What triggers an incident, near-miss or protected-disclosure escalation?
  • What additional detail must be incorporated when the full decision is published?

Official sources

PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.

PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.