Health Service Executive - August and September 2020

Year2020
Date18 August 2020
SectionDecisions made under data protection act 2018
Note on this document
This document contains two statutory decisions issued by the Data Protection Commission concerning
the HSE. Decision IN-19-9-1 was issued in August 2020 and Decision IN-19-9-2 was issued in
September 2020. These decisions should be read in conjunction with one another in circumstances
where they concern the same processing operations, undertaken by the same controller, and concern
the same time period. The first decision (IN-19-9-1) imposed a fine, reprimanded the HSE, and
ordered the HSE to bring its processing into compliance. There were no further additional corrective
powers exercised in the second decision (IN-19-9-2) in light of how the first decision addressed
the circumstances of the same infringements as were subsequently also identified in the second
decision.
1
In the matter of the General Data Protection Regulation
DPC Case Reference: IN-19-9-1
In the matter of The Health Service Executive (HSE South)
Decision of the Data Protection Commission made pursuant to Section 111 of the Data Protection Act
2018
Further to an own-volition inquiry commenced pursuant to Section 110 of the Data Protection Act 2018
DECISION
Decision-Maker for the Commission:
18 August 2020
Helen Dixon
Commissioner for Data Protection
Data Protection Commission
2 Fitzwilliam Square South
Dublin 2, Ireland
2
Contents
1. Introduction .................................................................................................................................... 3
2. Legal Framework for the Inquiry and the Decision ......................................................................... 3
i. Legal Basis for the Inquiry ........................................................................................................... 3
ii. Data Controller ............................................................................................................................ 4
iii. Legal Basis for the Decision ......................................................................................................... 4
3. Factual Background ......................................................................................................................... 4
4. Scope of the Inquiry and the Application of the GDPR ................................................................... 6
5. Analysis and Findings ...................................................................................................................... 8
i. Assessing Risk .............................................................................................................................. 9
ii. Security Measures Implemented by the HSE ............................................................................ 12
iii. The Appropriate Level of Security............................................................................................. 15
iv. Finding ....................................................................................................................................... 18
6. Corrective Powers ......................................................................................................................... 18
A. Order to Bring Processing into Compliance .............................................................................. 18
B. Reprimand ................................................................................................................................. 19
C. Administrative Fine ................................................................................................................... 20
i. Decision to Impose an Administrative Fine .......................................................................... 20
ii. The Same or Linked Processing Operations .......................................................................... 26
iii. The Permitted Range ............................................................................................................ 26
iv. Calculating the Administrative Fine ...................................................................................... 28
7. Right of Appeal .............................................................................................................................. 29
Appendix: Schedule of Materials Considered for the Purposes of this Decision ............................... 30

To continue reading

Request your trial

VLEX uses login cookies to provide you with a better browsing experience. If you click on 'Accept' or continue browsing this site we consider that you accept our cookie policy. ACCEPT