Understanding the Source of These Questions
Recently, Ireland's Data Protection Commission fined the Health Service Executive €645,000 for failing to secure paper medical records in two disused psychiatric hospitals. Intruders accessed St. Loman's Hospital in Mullingar and St Conal's Hospital in Letterkenny, filmed themselves with patient files, and shared the footage online.
This incident raised a critical question for privacy teams: "Are we liable for paper records too?" The answer is yes. Here are the key questions compliance managers have been asking since this decision.
Q1: Do GDPR Requirements Apply to Physical Records Like They Do to Databases?
Yes, they do. Article 2(1) of the GDPR covers "the processing of personal data wholly or partly by automated means and to the processing other than by automated means of personal data which form part of a filing system." This includes file cabinets, archive boxes, and off-site storage.
The HSE case shows that regulators enforce this. The DPC examined "the physical conditions of HSE document storage facilities and the integrity of the documents held within those facilities" to ensure compliance with Article 5(1)(f), which mandates "appropriate security of the personal data, including protection against unauthorized or unlawful processing."
If you've been ignoring your paper archives while focusing on digital compliance, you're exposing yourself to significant risk.
Q2: What Constitutes "Appropriate Security" for Off-Site Storage Facilities?
Article 32 requires "appropriate technical and organizational measures." For physical storage, this means:
Access controls: Who has keys? Who can authorize entry? The HSE facilities failed here, allowing unauthorized access and filming of medical records.
Environmental protection: Are documents safe from water damage, fire, pests, and deterioration? The DPC noted concerns about "the physical conditions" of storage facilities.
Inventory and tracking: Can you account for what records you hold, their locations, and access history? If someone requests erasure under Article 17, you need to know where their paper file is.
Regular inspection: Conditions can change. Schedule regular site visits to ensure security measures are effective.
The goal isn't perfection but a demonstrable effort proportionate to the risk. Medical records need more protection than old marketing materials.
Q3: How Can We Audit Legacy Storage When Some Boxes Haven't Been Touched in Years?
Implement a phased inventory project. Don't try to catalog everything at once.
Phase one: Identify all physical storage locations, including off-site facilities, basement archives, and file rooms in satellite offices. The HSE case involved two separate disused sites, suggesting incomplete visibility into storage.
Phase two: Assess security at each location. Can unauthorized people access it? What environmental risks exist? Document conditions with photos and notes.
Phase three: Categorize by sensitivity and retention requirements. Medical records, HR files, and financial documents need different handling than general correspondence.
Phase four: Create a retention schedule aligned with Article 5(1)(e)'s storage limitation principle. If there's no legal basis to keep records, they shouldn't be stored.
Act now. The HSE inquiry began after intruders posted videos online. Your first audit might be prompted by something worse.
Q4: What If We Find Records We Should've Destroyed Years Ago?
Document the discovery, assess the risk, and act immediately. Under Article 5(1)(e), you can't keep personal data longer than necessary. Finding old records doesn't make you compliant, but your response is crucial.
Secure the records, determine the appropriate retention period, and if that period has passed, destroy them securely. Use shredding or incineration for paper; degaussing or physical destruction for electronic media.
If the records contain special category data under Article 9, prioritize remediation. The DPC's investigation into the HSE stemmed from breaches involving medical records, which face higher scrutiny.
Q5: Does Using a Vendor for Off-Site Storage Shift Liability?
No. Article 28 governs processor relationships, making you responsible for choosing processors "which provide sufficient guarantees to implement appropriate technical and organizational measures." You must have a contract specifying the processor's obligations.
When outsourcing physical storage, audit the vendor as you would a cloud provider. Visit the facility, review security protocols, verify insurance, and check references.
If they fail and personal data is compromised, you're the controller who chose an inadequate processor. The DPC fined the HSE, not the contractor managing the facilities.
Q6: Can We Go Paperless by Scanning Everything and Shredding Originals?
Only if you have a legal basis to retain the information and secure the digital copies per Article 32. Digitization is format conversion, not destruction. You're still processing personal data.
Consider retention requirements carefully. Some records must remain in original form for legal or regulatory reasons. Consult your legal team before destroying originals.
When shredding, document the destruction. Keep a log with dates, record categories, and methods used. If someone later exercises their rights under Article 15 (access) or Article 17 (erasure), you need to show what happened to their data.
Next Steps
The DPC's full decision on the HSE inquiry is available at dataprotection.ie. Review it to understand what the regulator examined and why the organization failed.
Check out EDPB Guidelines 4/2019 on Article 25 Data Protection by Design and by Default. These principles apply to physical infrastructure as well. Security is a requirement from the start.
For managing legacy records, consult the National Archives or your jurisdiction's equivalent for retention schedules and practices. Compliance intersects with records management and sector-specific regulations.
Start your audit now. The intruders in the Irish hospitals didn't need technical skills or sophisticated tools. They just needed an unlocked door and a camera phone.





