
A Data Protection Impact Assessment can identify serious privacy and security risks. It can assign actions, recommend safeguards and document management decisions. What it cannot do is protect a single record while it remains unfinished or its actions remain unimplemented.
That is the clearest practical lesson from the Irish Data Protection Commission's decision concerning Children's Health Ireland at Tallaght University Hospital.
The case involved paper healthcare records and confidential waste containing sensitive information about children. However, its significance extends well beyond hospitals and physical documents. It demonstrates the difference between documenting risk and controlling it, a distinction that matters to every privacy, information security and compliance programme.
On 1 October 2026, the Data Protection Commission (DPC) announced its final decision following an inquiry into the physical safety and security of children's healthcare records at a Children's Health Ireland facility in Tallaght University Hospital.
The DPC carried out an unannounced inspection on 16 July 2025, following protected disclosures received in June and July 2025. When it opened the formal inquiry on 14 August 2025, the DPC also cited a breach notification submitted by CHI itself.
According to the DPC's published summary, documents containing sensitive and special-category personal data relating to children had been overflowing from a confidential-waste bin and were subsequently removed from it. The circumstances raised concerns about the confidentiality, management and control of paper records retained in an office used by non-consultant hospital doctors (NCHDs) and placed in confidential waste. CHI has also acknowledged that patient records were stored in an unlocked room at the facility.
The DPC found that CHI at Tallaght had infringed:
The regulator issued a reprimand and ordered CHI to bring the processing into compliance.
The corrective orders are particularly instructive. CHI was required to:
Alongside the orders, the DPC recommended that CHI implement and embed the action items and Standard Operating Procedures identified in the DPIAs.
The DPC has stated that it will publish its full decision in due course. Until then, organisations should avoid extending the announcement beyond its actual findings.
In particular, the published summary identifies infringements of Articles 5(1)(f) and 32(1). It does not announce a separate infringement of Article 35, the GDPR provision governing DPIAs. The importance of the DPIAs arises from the corrective orders and what they reveal about the relationship between risk assessment and operational security.
The GDPR requires a DPIA before processing that is likely to result in a high risk to people's rights and freedoms. This is especially relevant when processing special-category data at scale or information relating to vulnerable individuals.
The Irish DPC's DPIA guidance explains that the process should:
The guidance also describes integrating the selected privacy solutions into the project as a key element of a successful DPIA.
This final point is frequently overlooked. Completing the assessment is not the desired outcome. Reducing the risk is.
A DPIA should therefore be treated as a controlled risk-management workflow rather than a document produced solely for an approval meeting or audit folder. Its recommendations need owners, resources, deadlines, evidence and follow-up. If the processing changes, new risks emerge or measures prove ineffective, the assessment must be revisited.
There are legitimate reasons why a DPIA may begin as a draft. Projects evolve, information may be incomplete and consultation may still be taking place. The danger arises when draft status becomes permanent while the processing continues.
An indefinitely open DPIA can create several problems:
Adding "draft" to the filename does not suspend the real-world consequences of the processing. If personal data is already being collected, stored, accessed or disposed of, the risk exists regardless of the document's status.
The DPC did not stop at ordering CHI to complete the DPIAs. It ordered the identified measures to be implemented, and recommended that the action items and SOPs be embedded in practice.
This is a vital distinction. A procedure is not effective merely because it has been approved and published. It must be understood, followed and supported by the working environment.
For confidential waste, this could include:
Effectiveness must then be tested through workplace inspections, sampling, staff interviews, incident data and contractor assurance. A signed procedure cannot compensate for an overflowing bin.
Cybersecurity and privacy programmes often concentrate on digital systems. Paper records, printers, meeting rooms, temporary storage areas and waste processes can consequently receive less scrutiny.
GDPR Article 32 is technology-neutral. Appropriate security applies to personal data regardless of whether it is held in a database, printed in a file or waiting for secure destruction.
CHI is not an isolated case. One month earlier, on 2 September 2026, the DPC fined the HSE €645,000 over paper records held in external storage facilities, after unauthorised access to records at two disused hospital sites. Two decisions in as many months make the regulator's focus on physical records hard to miss.
The CHI decision reinforces the need to include physical information throughout the control lifecycle:
It also shows why security assurance cannot rely exclusively on document review. The DPC's inspection was unannounced, allowing the regulator to observe actual conditions rather than a prepared demonstration.
The decision is directly relevant to organisations operating an ISO/IEC 27001 Information Security Management System or an ISO/IEC 27701 Privacy Information Management System.
Relevant ISO/IEC 27001:2022 considerations include:
For more on turning risk treatment into implemented controls, see ISO 27001 Roadmap Part 7: Risk Treatment, Statement of Applicability and Continuous Improvement.
ISO/IEC 27701:2025 adds privacy-specific accountability, risk assessment and operational expectations for organisations acting as PII controllers or processors.
The practical message is the same across these frameworks: risk treatment must move from intention to implementation, and implementation must produce evidence.
An auditor or regulator may reasonably ask:
If the only answer is the DPIA itself, the organisation has evidence of analysis, not necessarily evidence of control.
1. Inventory unfinished DPIAs. Identify assessments recorded as draft, awaiting approval or pending consultation. Confirm whether the relevant processing has already commenced and whether interim safeguards are operating.
2. Separate document completion from risk treatment. Closing the DPIA document and closing its actions are different milestones. Track both.
3. Give every action an owner and deadline. Recommendations such as "improve access controls" are too vague. Define the required outcome, accountable owner, target date, priority and evidence needed for closure.
4. Connect DPIAs to the risk and corrective-action registers. High-risk actions should not disappear inside a privacy document. Integrate them with the organisation's wider governance and escalation mechanisms.
5. Verify implementation physically and technically. Inspect workplaces, test workflows, sample records and interview users. Do not rely solely on a policy owner confirming that a control exists.
6. Review confidential-waste arrangements. Assess containers, locations, access, capacity, collection schedules, supplier responsibilities, destruction evidence and exception handling.
7. Train everyone in the process. Privacy and records security are not only responsibilities for the DPO or IT team. Include operational, clinical, administrative, facilities, cleaning and contractor personnel where relevant.
8. Report effectiveness to management. Useful measures could include overdue DPIA actions, time to implement high-risk treatments, failed physical inspections, waste-management exceptions and repeat findings.
The CHI decision does not suggest that DPIAs lack value. It demonstrates why they matter.
A good DPIA makes risk visible and helps an organisation choose proportionate safeguards. Its value is realised only when those safeguards are implemented, embedded in normal operations and tested for effectiveness.
The same principle applies to policies, procedures, risk registers and audit findings. Documentation supports accountability, but documentation alone does not protect personal data.
The real security control is what people, processes and technology consistently do after the document has been written.
Cycubix supports organisations in connecting privacy assessments with practical information-security controls. This includes DPIA and risk-treatment reviews, ISO 27001 and ISO 27701 implementation, physical information-security assessments, supplier assurance and scenario-based training.
Contact Cycubix to discuss how your organisation can turn privacy and security assessments into controls that operate effectively in practice.