Skip to main content
Normal View

Data Protection

Dáil Éireann Debate, Tuesday - 17 October 2023

Tuesday, 17 October 2023

Questions (655)

Peadar Tóibín

Question:

655. Deputy Peadar Tóibín asked the Minister for Rural and Community Development further to Parliamentary Question No. 731 of 3 October 2023, if she will provide detail on the nature of the data breaches suffered by her Department; the severity of the breaches; if all individuals whose information was compromised were notified of the breach; if the Data Protection Commission was notified of all data breaches; and if she will make a statement on the matter. [45342/23]

View answer

Written answers

My Department was established in July 2017. Details of data breaches which occurred in each year between July 2017 and 2023 to date, and the numbers which were reported to the Data Protection Commission (DPC) are set out in the table below:

Year

Number of data breach incidents

Number of breaches reported to the DPC

2017 (July – Dec 2017)

0

0

2018

1

1

2019

0

0

2020

2

1

2021

1

0

2022

5

1

2023 (to date)

0

0

In terms of the nature of the breaches, in all cases the incident related to information disclosed in error to incorrect recipients. All data breaches are reported to and assessed by the Department’s Data Protection Officer (DPO) in accordance with guidance issued by the Data Protection Commission.

In terms of severity, the majority of the breaches identified were determined to be minor and unlikely to result in a risk to data subjects and were handled in accordance with the Department's Data Protection Policy. A total of 3 data breaches were deemed notifiable to the DPC and my Department acted accordingly. The remainder were deemed low risk and therefore not required to be reported to the DPC.

In the case of each incident immediate remedial action was undertaken to rectify the breach and to put in place measures to prevent re-occurrence.

Top
Share