October 6, 2026

A Draft DPIA Is Not a Security Control: Lessons from the CHI Decision

A Draft DPIA Is Not a Security Control: Lessons from the CHI Decision
By Fabio Cerullo - Managing Director - Cycubix

The Irish DPC's decision concerning Children's Health Ireland is a reminder that identifying privacy risks is only the beginning. Organisations must finish their DPIAs, implement the resulting measures and verify that procedures work in practice.

A Data Protection Impact Assessment can identify serious privacy and security risks. It can assign actions, recommend safeguards and document management decisions. What it cannot do is protect a single record while it remains unfinished or its actions remain unimplemented.

That is the clearest practical lesson from the Irish Data Protection Commission's decision concerning Children's Health Ireland at Tallaght University Hospital.

The case involved paper healthcare records and confidential waste containing sensitive information about children. However, its significance extends well beyond hospitals and physical documents. It demonstrates the difference between documenting risk and controlling it, a distinction that matters to every privacy, information security and compliance programme.

‍

What happened at Children's Health Ireland?

On 1 October 2026, the Data Protection Commission (DPC) announced its final decision following an inquiry into the physical safety and security of children's healthcare records at a Children's Health Ireland facility in Tallaght University Hospital.

The DPC carried out an unannounced inspection on 16 July 2025, following protected disclosures received in June and July 2025. When it opened the formal inquiry on 14 August 2025, the DPC also cited a breach notification submitted by CHI itself.

According to the DPC's published summary, documents containing sensitive and special-category personal data relating to children had been overflowing from a confidential-waste bin and were subsequently removed from it. The circumstances raised concerns about the confidentiality, management and control of paper records retained in an office used by non-consultant hospital doctors (NCHDs) and placed in confidential waste. CHI has also acknowledged that patient records were stored in an unlocked room at the facility.

The DPC found that CHI at Tallaght had infringed:

  • Article 5(1)(f) GDPR, which requires personal data to be processed with appropriate security, integrity and confidentiality; and
  • Article 32(1) GDPR, which requires controllers and processors to implement appropriate technical and organisational security measures.

The regulator issued a reprimand and ordered CHI to bring the processing into compliance.

‍

What the DPC ordered CHI to do

The corrective orders are particularly instructive. CHI was required to:

  • complete and finalise its draft DPIA covering the processing of healthcare records in the NCHD office, taking into account the DPC's views and findings;
  • complete and finalise a separate draft DPIA covering confidential-waste management, again taking into account the DPC's views and findings;
  • fully implement the technical and organisational measures identified in the final DPIAs; and
  • provide copies of the finalised DPIAs to the DPC within four weeks of the decision, to facilitate a consultation process with the regulator.

Alongside the orders, the DPC recommended that CHI implement and embed the action items and Standard Operating Procedures identified in the DPIAs.

The DPC has stated that it will publish its full decision in due course. Until then, organisations should avoid extending the announcement beyond its actual findings.

In particular, the published summary identifies infringements of Articles 5(1)(f) and 32(1). It does not announce a separate infringement of Article 35, the GDPR provision governing DPIAs. The importance of the DPIAs arises from the corrective orders and what they reveal about the relationship between risk assessment and operational security.

‍

A DPIA is a process, not a completed template

The GDPR requires a DPIA before processing that is likely to result in a high risk to people's rights and freedoms. This is especially relevant when processing special-category data at scale or information relating to vulnerable individuals.

The Irish DPC's DPIA guidance explains that the process should:

  • describe the proposed processing and its purposes;
  • assess whether the processing is necessary and proportionate;
  • identify risks to individuals; and
  • identify measures that address those risks and demonstrate compliance.

The guidance also describes integrating the selected privacy solutions into the project as a key element of a successful DPIA.

This final point is frequently overlooked. Completing the assessment is not the desired outcome. Reducing the risk is.

A DPIA should therefore be treated as a controlled risk-management workflow rather than a document produced solely for an approval meeting or audit folder. Its recommendations need owners, resources, deadlines, evidence and follow-up. If the processing changes, new risks emerge or measures prove ineffective, the assessment must be revisited.

‍

Why "draft" can become a dangerous status

There are legitimate reasons why a DPIA may begin as a draft. Projects evolve, information may be incomplete and consultation may still be taking place. The danger arises when draft status becomes permanent while the processing continues.

An indefinitely open DPIA can create several problems:

  • material risks may have been identified but never formally accepted or treated;
  • proposed controls may lack owners, funding or implementation dates;
  • business teams may assume that privacy approval has already been obtained;
  • changes to suppliers, data flows or retention practices may not be reflected;
  • unresolved high residual risks may never be escalated for prior consultation with the DPC under Article 36; and
  • the organisation may be unable to demonstrate who made the risk decision and on what evidence.

Adding "draft" to the filename does not suspend the real-world consequences of the processing. If personal data is already being collected, stored, accessed or disposed of, the risk exists regardless of the document's status.

‍

Written procedures must be embedded in daily work

The DPC did not stop at ordering CHI to complete the DPIAs. It ordered the identified measures to be implemented, and recommended that the action items and SOPs be embedded in practice.

This is a vital distinction. A procedure is not effective merely because it has been approved and published. It must be understood, followed and supported by the working environment.

For confidential waste, this could include:

  • selecting appropriate locked containers;
  • positioning them where unauthorised people cannot access their contents;
  • ensuring capacity and collection frequency match actual use;
  • preventing documents from being left beside or protruding from containers;
  • controlling access by staff, cleaners and waste contractors;
  • documenting collection and destruction;
  • addressing missed collections or damaged containers; and
  • training staff on what belongs in confidential waste and how to report problems.

Effectiveness must then be tested through workplace inspections, sampling, staff interviews, incident data and contractor assurance. A signed procedure cannot compensate for an overflowing bin.

‍

Physical information is part of the security environment

Cybersecurity and privacy programmes often concentrate on digital systems. Paper records, printers, meeting rooms, temporary storage areas and waste processes can consequently receive less scrutiny.

GDPR Article 32 is technology-neutral. Appropriate security applies to personal data regardless of whether it is held in a database, printed in a file or waiting for secure destruction.

CHI is not an isolated case. One month earlier, on 2 September 2026, the DPC fined the HSE €645,000 over paper records held in external storage facilities, after unauthorised access to records at two disused hospital sites. Two decisions in as many months make the regulator's focus on physical records hard to miss.

The CHI decision reinforces the need to include physical information throughout the control lifecycle:

  • information and processing inventories;
  • privacy and security risk assessments;
  • retention and disposal schedules;
  • access-control reviews;
  • supplier due diligence;
  • incident and breach procedures;
  • internal audits; and
  • security and privacy training.

It also shows why security assurance cannot rely exclusively on document review. The DPC's inspection was unannounced, allowing the regulator to observe actual conditions rather than a prepared demonstration.

‍

What this means for ISO 27001 and ISO 27701 programmes

The decision is directly relevant to organisations operating an ISO/IEC 27001 Information Security Management System or an ISO/IEC 27701 Privacy Information Management System.

Relevant ISO/IEC 27001:2022 considerations include:

  • Clause 6.1, requiring organisations to determine information-security risks and plan treatment actions;
  • Clause 8.1, requiring planned processes to be implemented and controlled;
  • Clause 8.3, requiring the information-security risk treatment plan to be implemented;
  • Clause 9.1, requiring the organisation to evaluate control performance and effectiveness;
  • Annex A control 5.33 on the protection of records;
  • Annex A control 5.34 on privacy and protection of personally identifiable information;
  • Annex A control 7.3 on securing offices, rooms and facilities;
  • Annex A control 7.7 on clear-desk and clear-screen practices; and
  • Annex A control 7.10 on managing storage media through its lifecycle.

For more on turning risk treatment into implemented controls, see ISO 27001 Roadmap Part 7: Risk Treatment, Statement of Applicability and Continuous Improvement.

ISO/IEC 27701:2025 adds privacy-specific accountability, risk assessment and operational expectations for organisations acting as PII controllers or processors.

The practical message is the same across these frameworks: risk treatment must move from intention to implementation, and implementation must produce evidence.

An auditor or regulator may reasonably ask:

  • Which DPIA actions remain open?
  • Who accepted any residual risk?
  • How was the control implemented?
  • Were affected employees and suppliers trained?
  • How does management know the procedure works?
  • What happened when the control failed or circumstances changed?

If the only answer is the DPIA itself, the organisation has evidence of analysis, not necessarily evidence of control.

‍

Eight actions organisations should take now

1. Inventory unfinished DPIAs. Identify assessments recorded as draft, awaiting approval or pending consultation. Confirm whether the relevant processing has already commenced and whether interim safeguards are operating.

2. Separate document completion from risk treatment. Closing the DPIA document and closing its actions are different milestones. Track both.

3. Give every action an owner and deadline. Recommendations such as "improve access controls" are too vague. Define the required outcome, accountable owner, target date, priority and evidence needed for closure.

4. Connect DPIAs to the risk and corrective-action registers. High-risk actions should not disappear inside a privacy document. Integrate them with the organisation's wider governance and escalation mechanisms.

5. Verify implementation physically and technically. Inspect workplaces, test workflows, sample records and interview users. Do not rely solely on a policy owner confirming that a control exists.

6. Review confidential-waste arrangements. Assess containers, locations, access, capacity, collection schedules, supplier responsibilities, destruction evidence and exception handling.

7. Train everyone in the process. Privacy and records security are not only responsibilities for the DPO or IT team. Include operational, clinical, administrative, facilities, cleaning and contractor personnel where relevant.

8. Report effectiveness to management. Useful measures could include overdue DPIA actions, time to implement high-risk treatments, failed physical inspections, waste-management exceptions and repeat findings.

‍

The key lesson

The CHI decision does not suggest that DPIAs lack value. It demonstrates why they matter.

A good DPIA makes risk visible and helps an organisation choose proportionate safeguards. Its value is realised only when those safeguards are implemented, embedded in normal operations and tested for effectiveness.

The same principle applies to policies, procedures, risk registers and audit findings. Documentation supports accountability, but documentation alone does not protect personal data.

The real security control is what people, processes and technology consistently do after the document has been written.

‍

How Cycubix can help

Cycubix supports organisations in connecting privacy assessments with practical information-security controls. This includes DPIA and risk-treatment reviews, ISO 27001 and ISO 27701 implementation, physical information-security assessments, supplier assurance and scenario-based training.

Contact Cycubix to discuss how your organisation can turn privacy and security assessments into controls that operate effectively in practice.

‍

Sources and further reading

‍

} } } }) } }