DPC fines the HSE €645,000 over paper records: storage limitation is now an enforcement risk
The Data Protection Commission's final decision, notified to the HSE on 25 August and announced on 2 September, imposes fines totalling €645,000, a reprimand and corrective orders after 12 nationwide site inspections found medical records rotting in derelict buildings, shipping containers and disused bathrooms. Two of the four fines are the headline: €300,000 for security failings under Articles 5(1)(f) and 32(1), and an equal €300,000 purely for keeping records longer than necessary under Article 5(1)(e). The DPC has now priced storage limitation at the same level as a security breach, which is the point deployers should take back to their own retention schedules — including the training sets, prompt logs and model inputs that quietly accumulate around an AI deployment. Smaller fines for late breach notification (Article 33) and for failing to tell the affected patients (Article 34) round out a decision aggravated by the HSE's prior record on paper files.
Unsure which of these developments applies to your AI systems?
Begin in writing →This briefing is general information, not legal advice, and does not create an advisor–client relationship. Summaries are original; follow source links for the full record. Adesanya AI Advisory — Abdulwahab B. Adesanya, Barrister-at-Law (Nigeria).