I. Introduction
On May 25, 2018, Ireland implemented the General Data Protection Regulation (GDPR) alongside the Irish Data Protection Act 2018. This legislation updates and consolidates the national data protection framework. The Data Protection Commission (DPC), as the national supervisory authority, is responsible for the supervision, management and enforcement of the GDPR and its implementing regulations in Ireland. In this way, Ireland has implemented a system of personal data protection in accordance with the requirements of the European Union.
II. Scope of application
The regulations implementing the GDPR in Ireland apply to:
any controller or data processor established in Ireland;
any organization outside Ireland that offers goods or services to people located in Ireland, or monitors their behavior on the territory of Ireland.
Regardless of the place of processing, if this applies to personal data of persons located in Ireland, the law applies. It includes both automated processing and non-automated processing, which forms part of the cataloguing system. Personal or domestic activities are not covered by its scope.
III. Principles of data processing
Legality, integrity and transparency: All processing must be based on a clear legal basis and be carried out with full transparency.
Purpose limitation: The data may only be used for specific and legitimate purposes.
Data minimisation: Only strictly necessary data should be collected.
Accuracy: Data must be accurate and regularly updated.
Storage Limitation: Data should only be stored for a strictly necessary period and then deleted or anonymized.
Security and confidentiality: Appropriate technical and organisational measures should be taken to prevent any breach, alteration or loss of data.
IV. Rights of data subjects
According to the GDPR and Irish law, natural persons have the following rights:
The right to information and access;
The right to rectification;
The right to erasure (the right to be forgotten);
The right to restriction of processing;
The right to data portability;
Right to object.
In the case of minors under the age of 16, the processing of their data requires the consent of a parent or legal guardian, and the information must be provided to them in a clear and understandable language.
V. Obligations of the processor
Processors must:
strictly comply with the written instructions of the data controller;
implement appropriate security measures;
assist the data controller in fulfilling his/her obligations, in particular in responding to requests from data subjects;
notify the data controller without undue delay in the event of a data breach, which must then inform the DPC within 72 hours.
Data controllers must maintain a record of processing activities and carry out a data protection impact assessment (DPIA) in high-risk cases. Some organizations must also appoint a Data Protection Officer (DPO) and liaise with the DPC (Data Protection Commission).
VI. International data transfer
When the transfer of data is planned to be transferred to a non-EU country, the data controller must ensure an adequate level of protection. This can be achieved by:
the European Commission's decision on the adequacy;
or the signing of Standard Contractual Clauses (SCCs).
Since the cancellation of the “Privacy Shield” on July 16, 2020, Irish companies must apply the new Standard Contractual Clauses adopted on June 4, 2021 or another legal mechanism.
VII. Control and enforcement
DPC has broad powers, including:
issuing warnings or formal notifications;
restricting or prohibiting certain processing operations;
imposing fines of up to 20 million euros or 4% of global turnover, whichever is higher.
Irish law also allows individuals to issue instructions on the use of their data after their death. Otherwise, the processing must comply with the applicable regulations. The Irish framework for the implementation of the GDPR is aimed at guaranteeing the rights of the individual, increasing corporate compliance and building trust in the digital environment.
VIII. Contact
Store Name: All This Fancy Junk
Phone: +1 325 212 5313
E-mail: info@allthisfancyjunk.com
Address: 1401 S 1st St, Abilene, TX 79602, United States
Service Hours : Monday - Friday: 9:00 AM - 5:00 PM (CET)