The Data Protection Commission’s fine was increased due to “aggravating factors”
The Data Protection Commission (DPC) has fined the HSE €645,000 for storing documents and records in rotting, pest-infested quarters.
According to the regulator, in some cases, documents and records were stored in disused bathrooms a cubicles, derelict buildings, shipping containers and turf sheds.
“During the site inspections, the DPC observed significant issues with documents damaged or effectively destroyed by mould, contaminated by animal droppings, covered in rubble or detritus, rotting due to the storage environment or water damaged,” said Graham Doyle, the DPC’s deputy commissioner.
“The DPC discovered storage areas in such profound disarray and neglect that the records contained within them could not be deemed to be filed in any organised or accessible manner. ”
The DPC also said that the fine was higher than usual, citing the “aggravating factor that the HSE committed similar previous infringements concerning the lack of appropriate security measures and the loss of control over personal data contained in paper healthcare records”.
“The retention of records by the HSE in an insecure manner beyond the period where they should be retained gives rise to an ongoing significant risk of unauthorised access to and disclosure of sensitive medical information by third parties. There is also the risk of records not being available for other medical care or other legal or regulatory reasons,” said Doyle.
The DPC’s inquiry began in May of 2024 as a result of two personal data breaches, in St Loman’s Mullingar and St Conal’s Letterkenny, which were notified to the DPC the previous year, the regulator said.
Videos uploaded to social media by intruders highlighted that medical records were stored and retained in both facilities, the watchdog said.
The DPC found that the HSE had breached GDPR rules by “failing to ensure appropriate security of the personal data contained in paper records stored and retained by the HSE in its external facilities” as well as “failing to implement appropriate technical and organisational measures, including proper records management processes, mechanisms and controls, to ensure a level of security appropriate to the risk”.
It also found that the HSE failed “to retain personal data contained in paper records in a form which permits identification of data subjects for no longer than is necessary”.
And it found that the HSE left those affected by the data breaches in the dark by not communicating with them about it.
As part of the investigation, 12 sites were inspected by the DPC. They were: St Lomans, Mulligar; St Peters, Castlepollard; Clonskeagh HSE campus, Dublin; Blindcraft storage facility, Dublin; St Canice’s, Kilkenny; St Luke’s, Clonmel; St Joseph’s, Limerick; St Finbar’s, Cork; St Raphael’s, Youghal; Primary Care Centre, Buncrana; St Conal’s and LGH, Letterkenny and St Joseph’s, Stranloar.

