# Health Service Executive (HSE): Insufficient technical and organisational measures to ensure information security

- Type: Enforcement
- Source: Data Protection Commission (DPC)
- Date: 2026-08-25
- Original: https://www.enforcementtracker.com/ETid-3302
- Canonical: https://overview.legal/posts/593144
- Topics: Personal Data, Data Breaches, Notification Obligation, Security, Supervision, Notified Body Reporting and Notification Obligations, Article 19 GDPR - Notification of Rectification, Erasure or Restriction

## Summary

The Irish Data Protection Commission (DPC) fined the Health Service Executive (HSE) €645,000 for failing to implement sufficient technical and organizational measures to ensure information security. The enforcement action cited violations of GDPR Articles 5(1)(e), 5(1)(f), 32(1), 33(1), and 34(1), concerning failures related to integrity, confidentiality, security of processing, and breach notification obligations. The case arose in the health care sector and reflects deficiencies in the HSE's safeguards for protecting personal data.

## Full text

Data Protection Commission (DPC) fined Health Service Executive (HSE) €645,000 on 2026-08-25 for: Insufficient technical and organisational measures to ensure information security.
GDPR Articles: Art. 5 (1) e) GDPR, Art. 5 (1) f) GDPR, Art. 32 (1) GDPR, Art. 33 (1) GDPR, Art. 34 (1) GDPR
Sector: Health Care
Country: Ireland
Source: https://www.dataprotection.ie/en/news-media/latest-news/data-protection-commission-announces-final-decision-following-inquiry-health-service-executive-hse

---
Generated by overview.legal · https://overview.legal/posts/593144 · 2026-10-08
