The Data Protection Commission (DPC) in Ireland has announced a final decision following its inquiry into the Health Service Executive (HSE), the country's public healthcare provider, the European Data Protection Board reported.
The published summary does not specify the substantive findings, corrective measures, or any financial penalty attached to the decision. Organisations awaiting fuller detail should consult the DPC's own publication of the decision once available.
Health service bodies process large volumes of special category data, including health records, and are consequently subject to heightened obligations under data protection law. Regulatory scrutiny of such bodies often signals wider attention to data governance practices across the healthcare sector.
While this decision arises under data protection law rather than the EU AI Act, it is relevant to organisations deploying or planning to deploy AI systems in healthcare settings. Many such systems, particularly those used for diagnosis, triage or treatment recommendations, are likely to fall within Annex III as high-risk AI systems under the Act.
As a compliance matter, healthcare organisations preparing for the EU AI Act should note that data governance failures identified under existing data protection enforcement can foreshadow scrutiny of the data quality and data governance requirements that apply to high-risk AI systems, including under Art. 10.
Organisations already engaged in EU AI Act compliance planning may find it useful to review how existing data protection findings, such as this one, intersect with the data governance documentation they are building for high-risk AI system providers and deployers.
Further detail on the scope and outcome of the DPC's inquiry is expected to be published by the Commission directly, and Veritome will report on substantive findings once they are confirmed.