Court of Appeal: HSE employee whose personal data was allegedly breached during 2021 ransomware attack loses appeal
The Court of Appeal has dismissed the appeal of a HSE employee whose complaint in relation to the alleged compromise of his personal data during the 2021 ransomware cyber-attack on HSE IT systems was dismissed by the Data Protection Commission.
About this case:
- Citation:[2026] IECA 141
- Judgment:
- Court:Court of Appeal
- Judge:Mr Justice Charles Meenan
Delivering judgment for the Court of Appeal, Mr Justice Charles Meenan determined that having regard to the appellant’s initial complaint to the HSE, it was clear that the complaint related to the appellant’s personal accounts unrelated to his work.
The Court of Appeal also rejected the proposition that the Data Protection Commission was under some form of duty to look behind the appellant’s complaint, finding that there would have been a “clear breach of procedural fairness” to the HSE if it were required to defend a complaint that was never made.
Background
The appellant was employed by the Health Service Executive (HSE) as a fire prevention officer. In February 2020, the appellant was provided with a laptop and mobile phone by the HSE for him to use in connection with his work. The appellant also used the phone for personal use, including emails, a Fitbit account and a Binance account.
Around April/May 2021, the HSE was subject to a serious cyber-attack which resulted in a serious data breach involving over 90,000 data subjects. Shortly thereafter, the appellant discovered that his personal email accounts on his HSE mobile had been hacked and that cryptocurrency to the value of €1,400 had been stolen from his Binance account.
The appellant submitted a complaint to the HSE and later, to the Data Protection Commission (DPC). The DPC dismissed the complaint on the basis that the HSE could not be considered the controller of the appellant’s personal data stored on his HSE phone without the HSE’s apparent knowledge or agreement.
Notwithstanding the appellant’s contention that the HSE phone also held significant personal data with the authority and consent of his employer, which data was also breached, the decision of the DPC was confirmed by email dated 21 June 2022.
The High Court
The appellant applied for leave to bring judicial review proceedings against the DPC, arguing inter alia that his complaint concerned his work-related personal data as well his unauthorised non-work related data and challenging the DPC’s finding that the HSE was not a “data controller” under Article 4(7) of the General Data Protection Regulation (EU) 2016/679.
The appellant was granted leave. At trial, the DPC contended by way of preliminary objection that there was a statutory right of appeal available to the appellant and as such, he was not entitled to bring judicial review proceedings.
The High Court dismissed the preliminary objection, making it clear that the court would only determine the issues pleaded and in respect of which leave was granted.
The trial judge considered that the “clear gravamen” of the complaint to the respondent was not that his work device contained work-related personal data, but that it contained non-work related personal data. The DPC insisted that the appellant’s “work data” was not the subject of the complaint.
Having regard to the complaint sent by the appellant’s solicitors to the HSE, the court was satisfied that the appellant’s concern was that there had been a data breach and that his Gmail, Yahoo, Binance and Fitbit account had been compromised, noting that “It would be entirely oppressive for a body such as the DPC to be required not only to handle a complaint was made on its own terms but also, for that body to have to speculate as to whether there might be additional matters worthy of investigation hidden, as it were, in the shadows of the actual complaint.”
The trial judge concluded that the DPC had engaged in an appropriate and proportionate investigation of the complaint which had actually been made, and as per Ryan v. Data Protection Commission [2024] IECA 152, the point of the handling exercise is to address complaints in a manner appropriate to the specific case made.
Finding no evidential basis for the allegation that his personal accounts had been compromised in the cyber-attack on the HSE ICT infrastructure, the High Court dismissed the application for judicial review.
The Court of Appeal
On appeal, Mr Justice Meenan considered the appellant’s contentions that the High Court erred in finding inter alia that the complaint was limited only to investigating “non-work” data on the phone, that the HSE was not a “data controller” for any personal data on the work phone and that there was no “work related” personal data on the phone.
Observing that it did not appear to be disputed that the HSE was not a “data controller” for the purposes of non-work related data on the phone but was a “data controller” for the purposes of work-related personal data, the judge considered that a question arose as to whether the terms of the appellant’s complaint included work-related personal data.
Examining the appellant’s initial complaint to the HSE, Mr Justice Meenan determined that it was clear from the terms of the letter that the complaint related to the appellant’s personal accounts unrelated to work and had repeatedly referred to “this personal data breach”.
The court considered that the response of the HSE put the matter “beyond dispute” in circumstances where it outlined that the appellant had initially informed his line manager that the breach related to his personal Yahoo account which he accessed on his HSE phone, a statement which went uncorrected by the appellant.
The judge opined: “If this, in the view of the appellant, was not a correct representation of his complaint one would have thought, at the least, there would be a response to the HSE to that effect… The issue of work-related personal data was only raised by an email from the appellant dated 27 May 2022, in response to the decision of the respondent which had been communicated by email a number of days previously, on 23 May 2022.”
Finding that the appellant had “broadened his attack” on the DPC’s decision in the course of his submissions to the Court of Appeal by suggesting that his complaint had not been adequately investigated and that the respondent was under some form of duty to look behind the complaint, Mr Justice Meenan identified three fundamental problems with that submission.
The judge considered that firstly, it was for the appellant to formulate his own complaint and it was not for the DPC to investigate matters not the subject of the complaint.
Secondly, the court emphasised that if the appellant’s submission was accepted by the respondent, there would be an “obvious unfairness” to the HSE in being required to defend a complaint that was never made.
Finally, the court pointed out that leave had not been granted on that ground.
Conclusion
Finding no infirmity in the High Court’s decision, the Court of Appeal dismissed the appeal.
McShane v Data Protection Commission [2026] IECA 141

