Skip to content
Enforcement · Data Protection Authority of Ireland EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Irish Departement of Health: Non-compliance with general data processing principles

The Irish DPA (DPC) has fined the Irish Department of Health EUR 22,500.

€22,500 Fine
Irish Departement of Health
IRELAND
Art. 5 GDPR Art. 6 GDPR Art. 9 GDPR

Full text

The Irish DPA (DPC) has fined the Irish Department of Health EUR 22,500. The DPA launched an investigation into the department following public allegations that the department unlawfully processed personal data from claimants and their families in the context of litigation over special educational needs. The DPC found that the departement had obtained information from the Health Service Executive (HSE) about services that the plaintiffs and their families had received. They had also been asked broad questions that led to the disclosure of sensitive private information. The data was collected to determine whether a settlement could be pursued with the plaintiff. The DPC concluded that the collection of information about the social services provided was lawful. However, the questions that led to the disclosure of the sensitive information were excessive and, according to the DPC, not necessary for the purposes of the litigation. According to the DPC, this violated the principle of data minimization.

Industry: Health Care

How it connects

C-205/21 Criminal proceedings against V.S In Case C-205/21, the Court of Justice of the European Union (Fifth Chamber) issued a preliminary ruling responding to a request from the Spetsializiran nakazatelen sad… CJEU ·Fifth Chamber Jan 26, 2023 Types of Special Categories of Personal Data Personal Data Retention Period
C-252/21 Meta Platforms v noyb C-252/21 (Meta Platforms (noyb)) CJEU Jan 12, 2023 Supervisory Authorities IP Address Supervision
W292 2292202-1 The data subject is in the military The unit he is employed at (controller) and the data subject are involved in a multitude of legal disputes concerning his employment, disciplinary proceedings, data protection… BVwG - W292 2292202-1 ·Federal Administrative Court Jun 30, 2026 Health Data Legitimate Interest Healthcare