Skip to content

Regulatory Pulse

Irish DPC fines HSE €645,000 over paper-record security, retention and breach response

The DPC’s €645,000 HSE decision links paper-record security, excessive retention, physical storage and breach response to concrete GDPR enforcement.

Ireland and European Union
GDPR, paper records, retention and breach response
Guidance
Official source reviewed

PrivacyBuilt Editorial · Source published Final GDPR enforcement decision — full decision to follow · Reviewed 4 September 2026 · 8 min read

The 60-second summary

On 2 September 2026, Ireland’s Data Protection Commission announced a final GDPR decision concerning sensitive paper records held by the Health Service Executive in external storage facilities. The inquiry followed two 2023 breach notifications and expanded through 12 site inspections. The DPC found infringements of storage limitation, integrity and confidentiality, security of processing, breach notification and communication duties. It imposed a reprimand, corrective orders and fines totalling €645,000. The orders require complete storage audits, traceable records-management systems, safe destruction of unnecessary records, removal from unsuitable facilities and regular testing of retention and storage controls. The full decision will be published later.

Timeline that matters

  1. October and November 2023

    Breaches notified

    Two incidents involved unauthorised access to medical paper records at disused facilities.

  2. April 2024

    Further records discovered

    The controller informed the DPC of another unauthorised-access incident involving old mental-health records.

  3. 24 May 2024

    Inquiry commenced

    The DPC opened an inquiry and later conducted 12 site inspections.

  4. 25 August 2026

    Final decision notified

    The DPC notified the HSE of its findings, orders, reprimand and fines.

  5. 2 September 2026

    Decision announced

    The regulator published its enforcement summary and said the full decision would follow.

  6. 11 September 2026

    Next editorial review

    Check whether the full decision has been published and whether it adds deadlines or scope details.

What changed

The decision turns paper-record governance into a concrete enforcement benchmark. The DPC linked physical conditions, disorganised storage, excessive retention, loss of control, delayed notification and failure to inform affected people. It required not only remediation of the breached sites but a complete audit of all relevant storage facilities and an operating system for locating, tracing, reviewing and securely destroying records.

Who should pay attention?

Records and information managers

Create a complete, locatable inventory of physical files, owners, retention rules and disposal status.

Facilities and security teams

Assess environmental conditions, access control, structural risks, monitoring and incident escalation for every storage site.

Privacy and legal teams

Connect retention, security, availability and breach-notification decisions to documented GDPR assessments.

Archive and destruction vendors

Provide chain-of-custody, storage-condition, access, retrieval and certified-destruction evidence.

Incident-response teams

Ensure physical-record incidents enter the same detection, assessment, notification and communication workflow as cyber incidents.

What the guidance clarifies

This concerns paper records
The failures involved physical archives and external storage facilities, showing that security of processing and breach response are not limited to digital systems.
The decision is final at regulator level
The DPC says it notified the final decision on 25 August 2026 and announced it on 2 September. The full decision is still to be published.
The inquiry expanded beyond two incidents
Authorised officers inspected 12 sites to determine whether the storage and retention weaknesses were isolated or systemic.
Retention and security were linked
Keeping records beyond necessity in unsuitable and untraceable conditions increased risks of unauthorised access, destruction and unavailability.
Corrective orders require operating controls
The DPC required complete audits, traceability, safe destruction, fit-for-purpose storage and regular testing—not merely revised policies.

Paper archives remain part of the sensitive-data estate

Why this matters for global organisations

Physical records can outlive systems, teams and buildings while remaining subject to retention, security, availability and incident-response duties. A defensible programme combines discovery, site inspection, traceability, environmental controls, tested retrieval, approved destruction and evidence that policies operate in practice.

  • Include physical archives in enterprise data inventories and risk assessments.
  • Test whether every record can be located, retrieved and securely destroyed.
  • Assess storage conditions and access controls at owned and outsourced sites.
  • Route physical-record incidents through formal breach-response procedures.

12 actions to start now

  1. Create a complete register of owned and outsourced locations holding physical personal-data records.
  2. Assign a business owner, facilities owner and records custodian for every storage location.
  3. Inventory record series, sensitivity, approximate volumes, date ranges, purpose and applicable retention rule.
  4. Inspect each location for access control, water, mould, pests, fire, structural, lighting, temperature and handling risks.
  5. Test whether representative files can be located and retrieved within the required operational timeframe.
  6. Quarantine and relocate records from unsuitable facilities using documented chain-of-custody controls.
  7. Identify records beyond approved retention and obtain authorised destruction decisions.
  8. Use secure destruction vendors and retain certificates tied to specific batches and approvals.
  9. Reconcile retention schedules with legal holds, care requirements, limitation periods and regulatory duties.
  10. Integrate physical intrusions, missing files and environmental damage into incident detection and breach assessment.
  11. Test the 72-hour notification workflow and the decision process for communicating high-risk breaches to affected people.
  12. Repeat site and control assessments on a defined schedule and track remediation to closure.

Suggested next steps

  • Identify unmanaged physical-storage locations and schedule a risk-based audit. Validate retention, notification and remediation decisions with qualified specialists. Recheck the official source when the full decision is published.

Evidence worth retaining

  • Master register of storage sites, custodians, vendors and record series.
  • Site inspection reports, photographs, environmental readings and remediation tickets.
  • Access-control lists, visitor logs, key records, alarm and monitoring evidence.
  • Retention schedule, legal-hold register and approved disposition decisions.
  • File-location index and sample retrieval-test results.
  • Relocation plans, inventories and signed chain-of-custody records.
  • Destruction approvals, vendor certificates and batch reconciliation.
  • Vendor due diligence, contracts, service levels, audit rights and incident obligations.
  • Incident records, awareness timestamps, risk assessments and notification decisions.
  • Communications to affected people and delivery evidence where required.
  • Training records, management reviews and recurring-control test results.

Questions to take to counsel or your conformity team

These are discussion prompts, not legal advice or conclusions.

  • Where are all physical records containing personal data stored, including inherited and temporary locations?
  • Can the organisation locate and retrieve each record series reliably?
  • Which records have exceeded their purpose-based retention period?
  • Are any legal holds or sector-specific requirements preventing destruction?
  • Are all facilities fit for purpose for confidentiality, integrity and availability?
  • Do archive vendors provide sufficient chain-of-custody and environmental-control evidence?
  • What event starts the clock for breach awareness when physical records are accessed or lost?
  • When would an incident require notification to the authority or communication to affected people?
  • How are damaged, contaminated or inaccessible records handled without exposing staff or personal data?
  • Which findings require specialist records-management, health, safety, legal or engineering advice?

Official sources

PrivacyBuilt / PrivacyBuilt is an independent educational publisher. It is not affiliated with, or endorsed by, any regulator or the European Union.

PrivacyBuilt publishes educational and technical guidance. Nothing on this site constitutes legal advice, and it should not be relied on as a legal determination for your organisation.