Léim ar aghaidh chuig an bpríomhábhar
Gnáthamharc

Data Protection

Dáil Éireann Debate, Tuesday - 24 July 2018

Tuesday, 24 July 2018

Ceisteanna (2522)

Maureen O'Sullivan

Ceist:

2522. Deputy Maureen O'Sullivan asked the Minister for Employment Affairs and Social Protection if she is satisfied that Intreo offices comply with EU data privacy laws when they send information to Seetec without knowledge or consent of persons; and if she will make a statement on the matter. [33854/18]

Amharc ar fhreagra

Freagraí scríofa

My Department collects and holds large volumes of personal data on customers and is very aware of the need to have adequate data protection policies, procedures and structures in place in line with the GDPR. Preparations for the GDPR have been overseen by the Department’s Data Management Programme Board. The Department has a dedicated GDPR implementation team in place and has commissioned external expertise to assist it with achieving GDPR compliance.

Seetec are contracted providers of activation services and act on behalf of the Department for the purpose of delivering these services and are subject to strict obligations imposed by the Department in terms of data protection.

The purpose of sharing information is to assist in the development of tailored plans for individual jobseekers in order to support them back into paid employment.

JobPath providers are contractually required to register with the Office of the Data Protection Commissioner. Data protection legislation requires that personal data shall be kept only for one or more specified and lawful purposes and that personal data shall be used and disclosed only in ways compatible with these purposes. The legislation also requires that the data should be adequate, relevant and not excessive. Any suspected breach of the data protection legislation will be investigated by the Department and may also be a matter for the Office of the Data Protection Commissioner. JobPath providers may use jobseekers’ data only for the purposes of delivering employment services for the Department.

My Department has regular meetings with both JobPath providers to ensure that they are fulfilling their contractual obligations, including those concerned with data protection compliance. Both companies have undertaken regular independent audits of their data processes and procedures as part of these contractual obligations, in addition, the Office of the Data Protection Commissioner has recently conducted audits of each company. Employees of both companies, and their subcontractors, are subject to the same data protection laws as Departmental staff.

I trust this clarifies the matter for the Deputy.

Barr
Roinn