I. Introduction
In 2018, Ireland enacted the Data Protection Act 2018 (Number 7 of 2018), which gives further effect to the General Data Protection Regulation (GDPR) and transposes the Law Enforcement Directive (EU) 2016/680. The Act amends and supplements the Data Protection Act 1988. The Data Protection Commission (DPC) — established under the Data Protection Act 2018, is the national supervisory authority responsible for overseeing, guiding, and enforcing the GDPR and its implementing regulations in Ireland. Irish Statute BookBritish and Irish Legal Information Institute Thus, Ireland has established a personal data protection system that complies with European Union requirements.
II. Scope
The regulations implementing the GDPR in Ireland apply to:
· any data controller or processor established in Irish territory;
· any organization located outside of Ireland offering goods or services to people located in Ireland, or monitoring their behavior on Irish territory.
Regardless of where the processing takes place, as long as it concerns the personal data of individuals located in Ireland, the law applies. It covers automated processing as well as non-automated processing that is part of a filing system. Activities of an exclusively personal or domestic nature are not covered by its scope.
III. Principles of Data Processing
Lawfulness, fairness and transparency: all processing must be based on a clear legal basis and be conducted transparently.
Limitation of purposes: data can only be used for specific and legitimate purposes.
Data minimization: only strictly necessary data should be collected.
Accuracy: the data must be accurate and updated regularly.
Limitation of retention: data should only be kept for the period strictly necessary, then deleted or anonymized.
Security and confidentiality: appropriate technical and organizational measures must be put in place to prevent any breach, alteration or loss of data.
IV. Rights of the persons concerned
In accordance with the GDPR and Irish law, natural persons have the following rights:
Right to information and access;
Right of rectification;
Right to erasure (right to be forgotten);
Right to restriction of processing;
Right to data portability;
Right to object.
For minors under 16 years of age, the processing of their data requires the consent of a parent or legal guardian, and the information must be provided to them in clear and understandable language.
V. Obligations of the processor
Processors must:
· strictly follow the written instructions of the data controller;
· implement appropriate security measures;
· assist the data controller in the performance of his obligations, in particular to respond to requests from data subjects;
· notify the data controller without delay in the event of a data breach, who must then inform the DPC within 72 hours.
Data controllers must maintain a record of processing activities and conduct a data protection impact assessment (DPIA) in cases of high risk. Some organizations must also appoint a data protection officer (DPO).
VI. International Data Transfers
When a transfer to a country outside the EU is envisaged, the data controller must ensure an adequate level of protection. This can be done through:
· an adequacy decision from the European Commission;
· or the signing of Standard Contractual Clauses (SCC).
Since the invalidation of the "Privacy Shield" on July 16, 2020, Irish entities must use the new Standard Contractual Clauses adopted on June 4, 2021, or any other legal mechanism.
VII. Control and Application
The DPC has extensive powers, including:
· issue warnings or reprimands;
· order an organization to comply with data subject requests or to bring its processing into line with data protection law;
· limit or prohibit certain processing operations;
· impose administrative fines of up to 20 million euros or 4% of global annual turnover, whichever is higher.Data Protection CommissionGovernment of Ireland
In Ireland, the GDPR does not generally apply to the personal data of deceased persons; access to such data may be available under Freedom of Information law (in respect of public bodies) or through the deceased's estate or executor. The Irish framework for implementing the GDPR aims to guarantee individual rights, strengthen business compliance, and promote trust in the digital environment.
VIII. Contact
Store Name: Chisel and Oak
Phone: +353 89 417 1335
E-mail: info@chiselandoak.com
Address: 3 O'Curry St, Mountkennet, Limerick, V94 R966, Ireland
Service Hours : Monday - Friday: 9:00 AM - 5:00 PM (CET)