Skip to main content
DPC Prosecution6 min read

GDPR Patient Communication Rules Ireland: Founding Practices

Learn how Regulation 13 of SI 336 of 2011 impacts Irish private clinics sending patient SMS, following the DPC prosecution on 7 September 2026.

Ask Brigid Team
28 September 2026 · Updated 28 Sept 2026

Researched and written by Ask Brigid's AI pipeline and published automatically — not individually reviewed by a person. Useful as a starting point; check clinical, legal and regulatory details against a primary source before relying on them.

An office worker stands at a wooden desk, feeding a blank sheet of paper into a small shredder next to a computer monitor.

Built in Dublin · GDPR · Early access

Ask Brigid takes the admin so the clinic day stays clinical.

What is the DPC Marketing Prosecution of September 2026?

On 7 September 2026, the Dublin Metropolitan District Court prosecuted Brown Thomas Arnotts Limited following a Data Protection Commission investigation into unsolicited marketing. The company pleaded guilty to breaching ePrivacy regulations due to a third-party software issue that prevented users from unsubscribing, and sending electronic communications without valid consent.

According to the Data Protection Commission news release published on 8 September 2026, the retailer faced 21 charges under Regulation 13 of Statutory Instrument 336 of 2011. They ultimately pleaded guilty to five sample charges. The court applied the Probation of Offenders Act, ordering a €1,000 charitable donation to Little Flower Penny Dinners and €1,000 toward the DPC’s legal costs. For private consultants in Ireland, this case highlights a critical regulatory risk: enforcement applies to any organization using electronic databases to contact individuals, irrespective of their sector or size.

Understanding Regulation 13 of Statutory Instrument 336 of 2011

Regulation 13 of Statutory Instrument 336 of 2011 governs electronic marketing, requiring explicit, opt-in consent before sending unsolicited communications. It mandates that any electronic message must provide a clear, functional opt-out mechanism, and obliges data controllers to respect verbal or written withdrawals of consent immediately.

The regulations draw a firm line on patient and consumer control over their data. In the recent court proceedings, Judge Halpin heard that complainants had contacted the organization via phone, in person, or other means to withdraw their consent. Despite these direct instructions, they continued to receive marketing messages. Following this high-profile dpc marketing prosecution, Irish regulators have re-emphasised that a data controller is fully responsible for maintaining an accurate, updated registry of consent, regardless of the communication channel used.

An office worker holds a blank smartphone over a desk in a wood-panelled records room filled with archive boxes.

How Do GDPR Patient Communication Rules Ireland Apply to Clinic SMS?

Under Irish data protection law, clinical communications like appointment reminders are administrative, but proactive patient recalls or clinic promotions fall under strict electronic marketing rules. To remain compliant, practices must secure explicit medical clinic sms consent and provide an immediate, functional opt-out method in every broadcast.

Private urology clinics frequently send SMS notifications for flexible cystoscopy appointments, transperineal prostate biopsy lists, or urodynamics clinics. While a direct booking reminder is processed under legitimate interest or contract performance, sending a broader broadcast—such as promoting a new Saturday vasectomy clinic or a general prostate health check—requires explicit, documented medical clinic sms consent. Practices must distinguish between necessary clinical coordination and promotional outreach. Maintaining clear consent records is as critical as managing medical files, a topic detailed in our guide on how long to keep medical records in Ireland.

Managing Third-Party Software and Patient Opt-Out Requests

Private consultants remain legally accountable for data breaches even if a third-party software provider causes the failure. The recent court ruling demonstrates that technical glitches in external booking, dictation, or messaging platforms do not absolve the practice owner of their statutory obligations under Irish law.

In the Dublin Metropolitan District Court, the defendant cited an intermittent technical issue with their third-party software provider that disabled the unsubscribe function. The DPC made it clear that data controllers remain the accountable party for any personal data processed for marketing activities. To prevent such vulnerabilities, consultants must select reliable administrative tools. Choosing dedicated medical secretary software that securely logs consent and handles patient contact preferences is essential for mitigating compliance risks.

Communication Type Primary Purpose Consent Required? Opt-Out Required?
Appointment confirmation (e.g., TRUS biopsy) Administrative / Clinical No (Legitimate Interest) No, but recommended
PSA annual recall broadcast Clinical Recall / Marketing Yes (Explicit Opt-In) Yes (Functional unsubscribe)
Clinic relocation notice Informational No No
New service announcement (e.g., LATP clinic) Marketing Yes (Explicit Opt-In) Yes (Immediate unsubscribe)

Steps to Ensure Compliant Patient Recalls in Private Practice

To ensure compliant patient recalls, private practices must audit their database consent records, establish clear protocols for recording verbal opt-outs, and verify that all software providers have functioning unsubscribe mechanisms. Every recall campaign must align with established gdpr patient recall rules to avoid regulatory action.

To prevent compliance failures and avoid the severe penalties highlighted by the recent dpc marketing prosecution, private rooms should implement a structured compliance protocol:

  1. Audit current lists: Ensure that any proactive recall (such as an annual PSA follow-up or a kidney stone check) aligns with documented gdpr patient recall rules.
  2. Train staff on manual opt-out handling: If a patient calls the rooms to opt out, this must be recorded instantly in the practice management system.
  3. Verify software capabilities: Ensure your messaging software has a reliable, tested unsubscribe path.

Modern platforms like Brigid manage patient diaries, intake forms, and records securely from AWS Dublin. Additionally, the companion patient app, MyBrigid (which is coming soon), is designed to put patients in control of their own data sharing and contact preferences, reducing administrative overhead for the rooms.

Review your practice's current SMS and email recall lists to ensure every patient has actively opted in to receive automated clinical reminders and health updates. Ensure your administrative staff have a clear, documented process for handling verbal opt-out requests immediately.

Ask Brigid is onboarding a small number of founding consultant practices. Request early access and we will reply with current availability and the next step.

Frequently asked questions

Ready to give Brigid the admin?

Request early access — founding practices are onboarding now. Or book a 30-minute walkthrough with our team to see Brigid run a workflow with your own data.

EU-hosted · GDPR · Founding-partner access · Cancel any time