Essential GDPR training for health sector staff.
Are your staff confident they understand their data protection obligations when handling patient records? Could your organisation withstand a Data Protection Commission investigation?
With the DPC actively focusing compliance efforts on the healthcare sector, understanding data protection requirements has never been more critical.
Given the immense sensitivity of medical records, it is imperative that professionals in this sector are clear about their use of patient data.
Discover the importance of data protection and how to ensure compliance with regulations.
Nearly 75 data breach incidents have been reported by the Department of Health since 2018, with most attributed to human error. The DPC received 7,781 breach notifications in 2024, an 11% increase from 2023. Healthcare data breaches cost an average of €9.77 million per incident globally. The 2021 HSE ransomware attack remains Ireland's most significant cybercrime incident, causing widespread service disruption and compromising patient data.
This highly practical half day course is essential for those accessing, maintaining or creating medical records.
What you will learn:
Clear understanding of data protection regulations in healthcare contexts.
Practical approaches to handling patient records ethically and legally.
How to identify and prevent common breach scenarios.
Best practices for maintaining confidentiality in day-to-day operations.
The confidentiality of patient records is central to the ethical tradition of health and social care and is in line with the requirements of the Data Protection Acts. La Touche Training’s Data Protection in the Health Sector course provides practical guidance on safeguarding patient information and maintaining compliance with GDPR and the Data Protection Acts.

Niamh Flynn is a solicitor and now works as a full-time Legal Programme Developer and Trainer with La Touche Training.
...
Our training sessions are not lectures—they're practical, interactive experiences. The small group format allows every attendee to ask questions, take part in discussions involving practical exercises and role-plays.
This method of training allows attendees to put the skills learned into practice immediately. Course participants benefit from the focused attention and guidance of an independent expert.
| Course Dates | Location | Price | Spaces Left | Book |
|---|---|---|---|---|
| 20/11/26 i 20/11/2026 09:30 - 12:30 | Zoom Online | €245.00 | 12 |
Healthcare organisations process large volumes of sensitive personal and medical information. Strong data protection practices are essential to protect patient privacy, maintain trust, and comply with GDPR and Irish data protection legislation.
Healthcare providers in Ireland must comply with the EU General Data Protection Regulation (GDPR) and the Data Protection Act 2018, alongside professional confidentiality obligations and sector-specific guidance.
This course is suitable for healthcare professionals, practice managers, HR personnel, administrators, data protection officers, compliance staff, and public sector employees handling patient information.
Health data is classified as special category personal data under GDPR because it is particularly sensitive and requires enhanced protections when collected, processed, stored, or shared.
Key principles include lawful processing, transparency, data minimisation, accuracy, confidentiality, purpose limitation, storage limitation, and accountability in handling patient information.
Organisations can reduce risk through staff training, secure systems, clear data handling policies, access controls, encryption, regular audits, and prompt incident response procedures.
Staff should report the breach immediately through internal procedures so the organisation can assess the risk, contain the issue, and determine whether notification to the Data Protection Commission or affected individuals is required.
Confidentiality relates to the ethical and professional duty to keep patient information private, while data protection law governs how personal data is collected, processed, stored, and shared legally and securely.
Patient information may be shared where there is a lawful basis, a clear care-related purpose, and appropriate safeguards in place to protect confidentiality and comply with GDPR obligations.
Participants typically develop knowledge of GDPR compliance, handling special category data, breach management, confidentiality obligations, records management, and practical risk reduction strategies.