WIRE 10.09.2026Commission opens formal AI Act proceedings against two model providersECB digital euro pilot names first Belgian banksAgeas, AXA, Allianz sign joint letter on cloud exit clausesBelgium's NIS2 transposition enters force 18 October
All wire
Hosaka Seven

Tech, policy and power. For the people who have to sign off on it.

Policy

Article 83(7) let every Member State decide whether the state can be fined at all. Ireland said yes, capped it at a million, and has now spent most of that twice.

The health service decision landed on 2 September with a reprimand, €645,000 and a set of orders. The money is the part that moves between two accounts of the same exchequer.

One stone government building. A cheque passes out of a ground-floor window on a tray and back in through another window four metres along the same wall. Beside that second window is a locked door with a dated notice, and a queue of people waiting at it.

Draft, not yet edited. Written by Marine Lefebvre, and not yet through the desk: nothing here has been checked against the sources listed at the foot of the page. Do not act on it.

The Data Protection Commission announced a final decision against the Health Service Executive on 2 September. It had been notified to the HSE ten days earlier. A reprimand, a set of corrective orders, and fines totalling €645,000 — and the subject is paper.

Not a cloud misconfiguration and not a third-country transfer. Files in external storage facilities, including a store at St Loman's Hospital in Mullingar, which people who should not have been in it got into. The DPC opened the inquiry on 24 May 2024 after two breach notifications, in October and November 2023. It found the HSE had failed to secure personal data in paper records and had no records management controls at a level appropriate to the risk.

In calculating the fine it treated as an aggravating factor that the HSE had infringed in a similar way before, on the same subject: loss of control over personal data in paper healthcare records.The DPC has exercised corrective powers against the HSE previously, and an earlier decision on the same broad subject sits on its own decisions page. We have not read it for this piece.

Fifteen months earlier the same regulator fined another arm of the same state €550,000.

The most it could have fined either of them is one million euro. That figure is not in the GDPR.

The one sentence that hands the decision back

Article 83(7) reads, in full: "Without prejudice to the corrective powers of supervisory authorities pursuant to Article 58(2), each Member State may lay down the rules on whether and to what extent administrative fines may be imposed on public authorities and bodies established in that Member State."

Read the operative words twice. Not how much. Whether.

Ireland took the option and used it to cap rather than to exclude. Section 141 of the Data Protection Act 2018 lets the Commission fine a public authority or public body up to one million euro, and lifts the cap where the body is acting as an undertaking within the meaning of the Competition Act 2002. We have not had section 141 open for this piece — the statute book refused the request — and its effect is described here from secondary material. The number is load-bearing. If it is wrong, so is the headline.

Other Member States answered the same question differently. Luxembourg's 2018 law largely excludes the State and the municipalities except where they operate on a competitive market. Denmark routes the penalty through the criminal courts rather than the supervisory authority. We have not built the map of twenty-seven answers and will not imply that we have. What is established is that the same facts, in the same kind of body, produce a fine in Dublin, a prosecution in Copenhagen, and somewhere else a letter.

Social ProtectionHealth Service Executive
Announced12 June 20252 September 2026
Inquiry openedJuly 202124 May 2024
Subjectfacial templates, SAFE 2paper records in external stores
Fine€550,000€645,000
Reprimandyesyes
Ordercease within nine monthscorrective orders
Prior counted against itnoyes
Ceiling available€1m€1m

An Irish public authority or public body

€1,000,000

Fixed by section 141 of the Data Protection Act 2018, whatever the body is and whatever it did. Both fines above were imposed under this ceiling.

A private controller, same infringement

€20,000,000, or 4% of worldwide annual turnover, whichever is higher

Article 83(5) GDPR. For a controller of any size the second limb is the operative one, and the bar does not end where this drawing does.

Same category of infringement, two ceilings. The Irish public body's is a number in an Act. The private controller's is a share of its own turnover, so it rises with the controller and has no top.Section 141, Data Protection Act 2018. Article 83(5) GDPR.

The money moves between two accounts of the same state

Ten corrective powers sit in Article 58(2), lettered (a) to (j). A warning, a reprimand, orders to comply, an order to tell the people affected, a limitation on processing, orders to rectify or erase, withdrawal of a certification, a fine, a suspension of transfers. The fine is one of ten. It is also the one every account of these decisions leads on, including this one, four paragraphs ago.

And it is the least likely to change anything. A department pays out of money the Oireachtas appropriated to it, and the payment lands back in the exchequer. We could not establish from this desk how either fine was actually accounted for, and neither decision says. Article 83(1) asks that a fine be effective, proportionate and dissuasive, which is a test drafted with a controller that has shareholders in mind.

A fine on a government department is a transfer between two accounts of the same state. The order is the only part of the decision a citizen would ever notice.

The part of the Department of Social Protection decision that is visible from outside the building is the order. The DPC found the Department had no valid lawful basis for collecting biometric facial templates during SAFE 2 registration, had retained them without justification, had not told people in the terms the transparency provisions require, and had left required elements out of its impact assessment. In 2021 it held facial templates for around seventy per cent of the population of the State.That is the DPC's figure and it is for 2021. What the holding is today, nobody has published. SAFE 2 registration is not optional for a person who needs a Public Services Card in order to be paid.

The order requires the Department to stop processing that biometric data within nine months if it cannot identify a valid lawful basis. Nine months from mid-June 2025 landed around March 2026, which was six months ago.

Nobody has said what happened in March

On 7 July 2025 the Department issued High Court proceedings challenging the decision and said it believes its processing complies with data protection law. Irish Legal News reported both. Whether the proceedings stayed the order, whether any templates were deleted, whether SAFE 2 runs today on the basis it ran on last year — we could not establish, and nothing we have read answers it either.

So: a supervisory authority found the State's own identity infrastructure unlawful, ordered it wound down absent a legal fix, and the State went to court to say otherwise. The fine was paid, or netted, or appropriated. It is not the interesting number.

None of this is new law

The cap has been in Irish law since 2018, and the power to fine a public body has been available to the Commission for just as long. What changed is not the instrument. What changed is that somebody used it twice in fifteen months, and that the second time the regulator wrote down that the body had done this before and priced it accordingly.

That is the only mechanism in the set that compounds. A statutory ceiling does not rise. An aggravating factor does. Two decisions against arms of the State are a rounding error in a year the DPC closed 11,734 cases. They are also the only ones where the maximum is fixed by an act of the Oireachtas rather than by turnover.

The next Irish public body to appear in a decision arrives in front of a regulator that has now said, twice and in writing, what a repeat looks like. The ceiling will still be a million.

Primary The document itself. Claims in this piece rest only on these.

  1. Regulation (EU) 2016/679 (GDPR), Article 83(7)Official Journal of the European Union2016-05-04The sentence the whole piece rests on, and the only thing quoted in full. Read off a reproduction of the article text, not off the consolidated Official Journal PDF; an editor should check it against the OJ before this runs, because the argument collapses if the word is anything other than 'whether'. Article 83(1) is described rather than quoted — the effective, proportionate and dissuasive test — from a summary rather than the article itself, and that sentence should be verified or cut.
  2. Regulation (EU) 2016/679 (GDPR), Article 58(2)Official Journal of the European Union2016-05-04Used for one structural point: the corrective powers run (a) to (j), ten of them, and the fine is one. Each is described in a phrase and none is quoted. The lettering was read off a reproduction of the article, not the OJ text. If any letter has been miscounted, the sentence loses its number and keeps its point.
  3. DPC announces conclusion of investigation into use of facial matching technology in connection with the Public Services Card by the Department of Social ProtectionData Protection Commission (Ireland)2025-06-12Opened and read. Source for the four categories of infringement, the reprimand, the €550,000, the nine-month cease order, the July 2021 start of the inquiry and the seventy per cent figure. The press release does not break the €550,000 down by infringement and neither do we.
  4. Data Protection Commission announces Final Decision following Inquiry into the Health Service ExecutiveData Protection Commission (Ireland)2026-09-02Source for the €645,000, the reprimand and corrective orders, the 25 August 2026 notification date, the 24 May 2024 inquiry opening, the two breach notifications of October and November 2023, St Loman's Hospital, and the prior similar infringements treated as an aggravating factor. Read from the authority's own announcement.
  5. Data Protection Commission publishes Annual Report for 2025Data Protection Commission (Ireland)2026-06-30Source for the caseload figures — 16,160 new cases, 11,734 concluded, four large-scale inquiries finalised. The full report PDF was not opened for this piece; the figures come from the DPC's own summary of it. The report is where a per-power breakdown of corrective measures would live and somebody should go and get it.
  6. Placeholder: DPC final decision IN-21-7-3, Department of Social ProtectionData Protection Commission (Ireland)The full decision is published on the DPC site and we have not opened it. It is where the fine is apportioned between the four infringements, where the reasoning on 'clear and precise' national law sits, and where the exact wording of the cease order is. No claim here rests on it. Anyone editing this piece for print should read it first.
  7. Placeholder: section 141, Data Protection Act 2018 (Ireland)Load-bearing and unverified. The one million euro cap on fines against public authorities and public bodies, and the lifting of that cap where the body acts as an undertaking within the meaning of the Competition Act 2002, are described here from secondary material — the Irish Statute Book refused the request from this desk. The body says so. If the cap is a different number, or if the section is drafted as a power rather than a ceiling, the headline changes.
  8. Placeholder: Luxembourg law of 1 August 2018, and the Danish approach to penalties under Article 83(7)Neither text has been opened. Both are described in one sentence each, as illustrations of divergence rather than as claims anyone should act on. We have not built the twenty-seven-state map and the body says we have not. If the piece is to name a Member State's position with any weight, someone reads that Member State's implementing act.

Reporting Attributed, not relied on. Where the reporting is the fact, it says so.

  1. Department of Social Protection to fight GDPR ruling in courtIrish Legal News2025-07-09Attributed in the body. Source for the 7 July 2025 High Court proceedings and the Department's statement that it believes its processing is compliant. Nothing else rests on it, and it does not answer what happened to the nine-month order.
  2. Placeholder: Irish national coverage of the June 2025 decisionRTÉ, The Irish Times, Irish ExaminerRead for orientation. No claim in this piece is taken from any of it; every figure in the June 2025 paragraphs comes from the DPC's own release.

Lead Pointed us at the story. Nothing here is cited as authority.

  1. Placeholder: law firm summaries of the DPC annual reportsPointed us at the reprimand-and-order pattern in Irish public-sector decisions and at the existence of the HSE decision. Not cited, not relied on.

Marine Lefebvre

Policy correspondent

I cover EU tech regulation and the people who write it, from the AI Act to the next fight over data sovereignty. I have a soft spot for any Brussels leak that lands before the official press release.