Records management: It’s all fine
The Irish Data Protection Commission has fined the Irish Health Service Executive €645,000 (64.5% of the statutory maximum) for problems in their handling of physical paper records. I’m unsurprised. Because physical records management has become the blind spot in data strategies and data governance frameworks of organisations after iterations of digital and data transformation (and the rise of AI). But it’s impossible to have a robust data strategy and data culture if you are not managing all media holding data with appropriate care and intentionality.
The background to the fine
The background is simple. Some TikTok-ing ‘urban explorers’ broke into two HSE locations (by the devious means of pushing open an unlocked door) and recorded what they saw. What they saw was a shambles of unstructured data storage. By which I mean the structured documents (all documents have structure) containing data where essentially thrown in corners. The DPC got wind of this and commenced an investigation that looked at the two locations in the videos but also looked at ten more locations.
“The DPC discovered storage areas in such profound disarray and neglect that the records contained within them could not be deemed to be filed in any organised or accessible manner“, according to the DPC. This is not a security issue. This is a metadata, records management, and data governance issue. And at the heart of it is a series of decisions made by people, working under pressure, within the constraints imposed on them. Those constraints and those decisions resulted in “records stored in disused bathrooms and cubicles, a shipping container in a turf shed, rooms without functioning lighting or heating, as well as derelict buildings at a number of disparate locations“. In other words: not exactly conditions conducive to the physical preservation of the records, the physical security of the records, or the ability of staff to safely search for and find records.
Look at my surprised face
It’s not a surprise to me. A family member worked in administration in a busy south Dublin hospital over twenty years ago. Their description of the overflowing and cluttered file room where it was impossible to quickly find things and there was an ever present risk of literally being crushed by toppling files. When working with clients my team often find physical records jammed into packing cases and thrown in basements. Sometimes those files are subject to National Archives legislation. Sometimes they have historically important information. Usually they have personal data in them. And, inevitably, there’s no budget to actually handle those files properly and no time resource or people resource to go through them and archive them correctly.
The HSE statement in response to the decision assures us that they are taking measures to improve the security at the affected locations. They also say that the development of a “national, consistent and standardised approach to archiving and disposal of records is a key priority”. But this rings a little hollow when among the aggravating factors cited by the DPC as the reason for the fine include the fact that they have made previous findings that “the HSE had committed similar previous infringements concerning the lack of appropriate security measures and loss of control over personal data held in paper healthcare records“.
That’s all fine and dandy, but..
Right now all we have to go on is the DPC’s press release about the decision. Until the period for any appeal passes and the fine is approved by the courts the full decision remains out of reach. But that press release gives us some details to understand what the issues identified were that drove the fine. And, as often happens with DPC decisions, the findings that drive the fines are often burying the lede about the root causes. So, what’s at the heart of what happened?
The answer is boring stuff. Stuff that is not sexy. It’s organisational processes, training, procedures, and controls to make sure that physical records were properly handled. The DPC links this to an Article 32(1) infringement and bundles it as a security breach. However, it’s actually an Article 24 infringement as well because before we get to the security issue we have the fundamental question of whether the data in the files was being processed in line with the HSE’s obligations under GDPR. The security finding is a finding of the symptom. The data governance and records management failure is the precipitating cause.
Fixing the Issues
The DPC’s required remedial actions for the HSE include auditing their records management processes, auditing all locations where physical records are stored, implementing “a robust and appropriately designed management system for the purposes of tracking and tracing the location of all paper records” and ensuring the testing of that system and also the storage locations used. This is in addition to ensuring retention periods are applied, records are appropriately disposed of when no longer needed, and that these processes are tested as well. These are all actions to remedy broken governance and missing management of data and instil intentionality into what had become mindless handling of data and records.
To actually address this in any new “national, consistent, and standardised approach to archiving and disposal of records” the HSE will also need to address the people, culture, process, resources, and budget constraints imposed from the centre that affected and constrained the choices of local management in the wider organisation. The purpose of the system is what it does, and without investment to fix the system the HSE will continue to operate as a system for the collection and inappropriate storage of physical records containing special category personal data. On a day to day basis, people in the HSE are trying to do their best with the knowledge, skills, time, facilities, and budgets they have. Improving stewardship and governance of data and records in a sustainable and resilient manner means tackling those factors that lead to inevitable poor choices and worse outcomes.
Different media, same message
And while this decision deals with physical records management, my experience of working with client’s electronic data, whether it is in documents in SharePoint, spreadsheets in a file share, or content in a CRM system, consistently highlights the fundamental need to think about data and information as an asset distinct from and separate to the medium it is being stored or processed in.
Fundamental concepts of knowing what data lives where, what it is called, how it is defined, how the container it is stored in is structured are often overlooked in the IT department’s rush to install the system or migrate to the Cloud. Development of file plans and information asset registers and definition of associated metadata helps encourage the business stakeholders to think about what they are capturing, recording, and storing. Done well it is done as a technology neutral process that asks what do you have, what does it mean, where does it live, and when does it expire.
Properly structuring SharePoint or file folders, applying sensible metadata tags, automating retention schedules, and ensuring role-based and rule-based access to data and records is another example of appropriate organisational and technical measures to ensure appropriate processing of data whether it’s digital or paper based. This requires a culture of stewardship of data and records that has intentionality in how things are planned and executed and that ensures appropriate knowledge, skills, time, and budgets to actually implement and manage the transition from current state to required state.
Mind the legislative gap
A worrying signal of the tone-at-the-top in the culture of stewardship of data and data governance in respect of health records is the fact that the Health Information Act 2026, as currently enacted, doesn’t include any of the governance and oversight aspects required under the EU Health Data Spaces Regulation, the EU law that the Health Information Act is intended to implement domestically. Hopefully when the amending legislation that must implement those parts of the Regulation is being drafted the opportunity will be taken to address governance independent of medium and format.
But until then the tone at the top seems to be that governance isn’t a priority
How Castlebridge can help
The HSE’s physical records problem is one experienced by many organisations. But data is data. Some data lives in physical documents, some data lives in digital documents and spreadsheets, some data lives in electronic databases. Castlebridge can help organisations navigate the regulatory, cultural, people, process, and technology aspects of getting a holistic approach to your data and records. Through our experienced consultants and our network of Associates and partner service providers we can guide you to actionable and sustainable governance and stewardship of your data.
Related Insights
Playing All the Right Notes: What Stafford Beer Can Teach Us About Data Governance
Daragh O Brien July 3, 2026