Compliance · · 3 min read

DPC finds CHI breached security rules over children’s paper records

The Data Protection Commission says a Children’s Health Ireland facility at Tallaght University Hospital failed to protect children’s health records and confidential waste.

The Data Protection Commission has concluded that a Children’s Health Ireland facility at Tallaght University Hospital breached data-protection requirements governing the security and confidentiality of children’s health records.

The decision concerns the physical handling and protection of paper records at the CHI facility, rather than Children’s Health Ireland as a whole. According to the account published by the DPC, the inquiry focused on one location within Tallaght University Hospital and on records kept in the office used by non-consultant hospital doctors.

The regulator’s final decision was notified to CHI at Tallaght on 10 September 2026. The DPC published its decision on 1 October 2026, following an inquiry that began after protected disclosures were made to the commission in June and July 2025.

Inspection followed protected disclosures

The DPC carried out an unannounced inspection of the CHI facility on 16 July 2025. The inspection took place after the disclosures raised concerns about how children’s personal information was being stored, retained and controlled.

During the protected-disclosure process, the commission also learned that documents containing sensitive information about children had overflowed from a confidential-waste bin. The material was later removed. The bin was positioned beside the entrance to the office used by non-consultant hospital doctors at the CHI facility.

The documents were described as containing both sensitive data and special-category data relating to children. Their location and removal formed part of wider concerns about whether confidential records were being properly managed and protected from unauthorised access or exposure.

The inspection and information received through the disclosures brought together concerns about two connected aspects of record handling. One was the security of paper files kept within the doctors’ office. The other was the management of documents intended for confidential disposal. Taken together, the issues led the DPC to examine the arrangements used to control children’s health information at the facility.

The commission opened its formal inquiry on 11 August 2025, several weeks after the unannounced visit. Its investigation subsequently produced the final decision now issued to CHI at Tallaght.

Findings under the GDPR

The DPC found that CHI at Tallaght had infringed the security and confidentiality principle in Article 5(1)(f) of the General Data Protection Regulation. It also found an infringement of Article 32(1), the GDPR provision identified in the decision in relation to data security.

Those findings relate to the physical safety and security of children’s health records at the specific CHI facility examined by the commission. The concerns included the continued storage and retention of paper records in the non-consultant doctors’ office and the systems used to manage and control those records.

The issue is significant because the material involved children’s personal information and health records. The DPC’s account says the documents included sensitive and special-category data, making the handling of the records a particular focus of the inquiry. The placement of an overflowing confidential-waste bin beside an office door was also relevant to the regulator’s assessment of how the information was being protected.

The decision therefore links the physical environment in which records were held with the broader requirement for confidentiality. It does not concern only the contents of individual files. It also addresses the procedures and controls surrounding paper records while they were being kept and when documents were being discarded.

The published account identifies the two GDPR infringements and sets out the events that prompted the inquiry. It does not, in the material provided here, give further details of sanctions, corrective measures or a timetable for changes at the facility. The confirmed finding is that the Tallaght CHI facility failed to meet the security and confidentiality standards cited by the DPC in relation to children’s records.

The case began with disclosures to the regulator, proceeded through an unannounced inspection and formal inquiry, and ended with the final decision notified to CHI in September 2026. Its publication records the DPC’s conclusion that the handling and control of paper health information at the facility did not comply with the GDPR provisions named in the decision.

data protectionchildren’s healthgdprhealth recordstallaght university hospitalchildren’s health irelandprivacy

Continue reading

Read this in another language