Inquiry into Midlands Regional Hospital Tullamore

On the 10 June 2026 the Data Protection Commission adopted its final decision following an inquiry into a ransomware attack on the laboratory information system in Midlands Regional Hospital Tullamore, County Offaly. The breach was detected on 14 November 2018. The attackers gained access to computers that stored and processed laboratory results of patients’ diagnostic tests, and used that access to encrypt patients’ personal data. 

The DPC’s inquiry examined the HSE’s technical and organisational measures for ensuring the security of processing personal data on the systems that were attacked. It also examined the HSE’s compliance with the GDPR in relation to its contracts with service providers such as third-party data processors, its record of processing activities, and the requirement to notify persons who are affected by high-risk breaches. 

The DPC’s decision, which was notified to the HSE on 11 June 2026, finds that the HSE:

  • infringed the principle of integrity and confidentiality of Article 5(1)(f) GDPR by failing to ensure appropriate security of the personal data related to the processing of patients’ personal data using appropriate technical and organisational measures;
  • infringed Article 28 GDPR by not ensuring that agreements with third parties that processed personal data on its behalf included sufficient safeguards to ensure that processing was fully compliant with the GDPR and that the rights of data subjects were protected;
  • Infringed Article 30 GDPR by failing to have a complete and compliant record of processing activity at the time of the breach;
  • infringed Article 32(1) GDPR by failing to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk presented by its processing of personal data on the systems affected by the ransomware attack; and
  • infringed Article 34 GDPR by its failure to provide to persons affected by the breach all information required by that Article.

In light of the infringements identified above, the DPC has:

  • reprimanded the HSE;
  • fined the HSE €300,000 for the infringements of Articles 5(1)(f) and 32(1) GDPR; and
  • ordered the HSE to implement specified policies and procedures intended to ensure appropriate security of processing of personal data.

You can download the full decision at this link: Inquiry concerning Midlands Regional Hospital Tullamore - June 2026 (PDF, 1.3MB)

FAQs

FAQs

FAQs

Inquiry into Permanent TSB (PTSB)

The inquiry commenced following Permanent TSB’s (‘PTSB’) notification to the DPC of a series of three data breaches relating to PTSB’s ‘Open 24 Contact Centre’. Each of the data breach notifications concerned malicious actors, in possession of certain PTSB client information, contacting PTSB’s Open24 Contact Centre in order to gain access to client accounts.

The decision considered whether PTSB had complied with Articles 5(1)(f), 32(1) and 33(1) GDPR. In particular the DPC considered whether PTSB had implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risks associated with its processing of personal data via the Open 24 Contact Centre, and also whether PTSB had reported the breaches to DPC within the required time periods under the GDPR. 

The DPC’s decision found that PTSB:

  • infringed the principle of integrity and confidentiality of Article 5(1)(f) GDPR by failing to ensure appropriate security of the personal data related to customer accounts by implementing appropriate technical and organisational measures;
  • infringed Article 32(1) GDPR by failing to implement appropriate technical and organisational measures to ensure a level of security appropriate to the risk presented by its processing of personal data within the Open24 Contact Centre; and
  • infringed Article 33(1) GDPR by its failure to notify the DPC without undue delay and within 72 hours of becoming aware of the breaches.

Corrective Powers Exercised:

  1. The Decision issued PTSB with a reprimand in respect of the infringements of Articles PTSB;
  2. The Decision imposed an administrative fine on PTSB in the amount €250,000 in respect of the infringements of Articles 5(1)(f) and 32(1) GDPR; and
  3. The Decision imposed an administrative fine on €27,500 for the infringement of Article 33(1) GDPR

 

You can download the full decision at this link: Permanent TSB (PTSB) - April 2026 (PDF, 898KB).

Inquiry into Microsoft Ireland Operations Limited

On 1 September 2025, following an inquiry concerning a complaint received against Microsoft Ireland Operations Limited (Microsoft), the Data Protection Commission (DPC) adopted a decision.

The DPC commenced this inquiry on 16 May 2023, on foot of a complaint that Microsoft failed to comply with an access request submitted by the complainant in August 2020.

The scope of the inquiry concerned an examination and assessment of the following:

  1. Whether the Controller complied with Article 12(4) of the GDPR after the Complainant made an access request on 17 August 2020; 

     

  2. Whether the Controller’s reliance on Article 15(4) to withhold all of the Complainant’s data was justified; and 

 

  1. Whether the Controller was in compliance with Article 5(1)(a) in deleting the Complainant’s personal data (i.e. any personal data contained in the relevant OneDrive account).

As the processing under examination constituted 'cross border' processing, the DPC’s decision was subject to the cooperation and consistency mechanism outlined in Article 60 of the GDPR and pursuant to Article 60(3) of the GDPR, the DPC submitted its draft decision to the supervisory authorities concerned for their opinion.

The DPC received one relevant and reasoned objection to the draft decision from the supervisory authorities concerned within the statutory period and therefore issued a revised draft decision. As the DPC did not receive any relevant and reasoned objections to the revised draft decision, the supervisory authorities concerned were deemed to be in agreement with the revised draft decision of the DPC and are bound by it in accordance with Article 60(6) of the GDPR.

The DPC adopted its decision in respect of this complaint in accordance with Article 60(7) of the GDPR. The decision, which was adopted on 1 September 2025, records findings of infringement as follows:

  • Article 12(4) of the GDPR

The DPC finds that Microsoft infringed Article 12(4) of the GDPR in respect of the access request when it failed to inform the complainant of the possibility to lodge a complaint with a supervisory authority and to seek a judicial remedy following the complainant’s access request.

  • Article 5(1)(a) of the GDPR

The DPC finds that, the specific circumstances of the complaint, Microsoft infringed the lawfulness, fairness and transparency principle under Article 5(1)(a) of the GDPR in its handling of the access request and in its decision to delete the complainant’s data.

Corrective Powers Exercised:

  • A reprimand to Microsoft Ireland Operations Limited pursuant to Article 58(2)(b) of the GDPR in light of the infringements found.
  • In light of the infringement of Article 5(1)(a) of the GDPR, and in accordance with Article 58(2)(d) of the GDPR, an order for Microsoft to revise its policies and procedures so that 
    1. the data retention policies for data associated with accounts terminated by Microsoft for violations of the Microsoft Services Agreement are clarified in its user-facing policies; 
    2. the circumstances when Microsoft permanently deletes such data are clarified and;
    3. the appeals processes available to the account holder where Microsoft has terminated the service for an alleged infringement of the Terms of Service are outlined.

 

The full decision is now available to view (PDF, 1MB)

Data Protection Commission Publishes Annual Report for 2025 and Results of “Sharenting” Survey

30th June 2026

The Data Protection Commission (DPC) published its Annual Report for 2025 today. At a press conference at the DPC’s offices, Commissioners for Data Protection, Dr Des Hogan (Chairperson), Mr Dale Sunderland and Ms Niamh Sweeney detailed the significant work of the office throughout the year.  ...