Securiti leads GigaOm's DSPM Vendor Evaluation with top ratings across technical capabilities & business value.

View

What is Irish Data Protection Act of 2018

Published February 2, 2021 / Updated August 22, 2024
Author

Maria Khan

Data Privacy Legal Manager at Securiti

FIP, CIPT, CIPM, CIPP/E

Listen to the content

The Irish Data Protection Act, 2018 (Irish DPA) implements the General Data Protection Regulation (GDPR) and transposes the European Union Law Enforcement Directive in Ireland. Since it incorporates most of the provisions from the GDPR and the Law Enforcement Directive with limited additions and deletions as per the national law, it is considered to be the principal data protection legislation in Ireland.


Rights of Data Subjects

The Irish DPA provides the same rights to data subjects with respect to their personal data as that of the GDPR. These rights give data subjects control over their data and may be processed under particular conditions and limitations.

Right to be informed

Data subjects have the right to be informed of when and how their data is being used and collected. This refers to the obligation of the data controller to inform and notify any relevant details to the data subjects for any important action taken on their data.

Right to access

On a request of the data subject, an organization must provide data subject access to his/her personal data and information about the ways personal data has been or may have been used, disclosed, or processed by the organization.

Right to restriction of processing

This right applies when the accuracy of data is contested by the data subject and when processing is unlawful and the data subject opposes the deletion of the data. Data subjects need to be informed before any such restriction is lifted.

What is CCPA

Right to data portability

The right to data portability allows data subjects to receive their personal data for their own purposes across different services in a structured and commonly used format. It allows data subjects to copy, move, and/or transfer their personal data easily from one IT environment to another. The right to data portability may be declined where it is not technically feasible to support.

Right to object

There exists an absolute right for data subjects to object to their personal data being processed for direct marketing purposes. As per the Irish DPA, this right shall not apply to processing carried out in the course of electoral activities in the state by a political party, or a candidate for election to, or a holder of, elective political office in the state and by the Referendum Commission in the performance of its functions.
What is CCPA

Right to No Discrimination

The CCPA strictly requires businesses not to discriminate against their consumers for exercising their rights under the CCPA. Businesses are allowed to vary their services or change the price of goods and services, if the difference in service or price is reasonably related to the value of the consumers’ personal information to the business.

What is CCPA

Right to Erasure

The right to erasure gives consumers the right to request deletion of all their data stored by the organization. Not only are organizations supposed to comply within 45 days but are also required to deliver a report on the deleted information to the consumer.

Right to restriction of processing

This right applies when the accuracy of data is contested by the data subject and when processing is unlawful and the data subject opposes the deletion of the data. Data subjects need to be informed before any such restriction is lifted.

Rights in relation to automated decision making and profiling

Data subjects have the right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects concerning data subjects or similarly significantly affects them. The Irish DPA allows the restriction of this right where the decision is authorised by law and the data subject has the possibility to make representations to the competent authority regarding the decision or where the data controller has taken adequate steps to safeguard the legitimate interests of the data subject.

Right to rectification

Data subjects have a right to rectify and correct inaccurate personal data held by the organization.

Where the personal data is processed for archiving purposes in the public interest, or processed for scientific or historical research purposes or statistical purposes, the Irish DPA allows the restriction of data subjects’ rights, if the exercise of the right would likely render impossible, or seriously impair the achievement of those purposes and such restriction is necessary for the fulfillment of those purposes.


Responsibilities of data controllers

The Irish DPA reaffirms the obligations of organizations as outlined in the GDPR. Some of the key obligations for Irish organizations are as follows:

  • Ensure appropriate security controls to uphold data protection principles of lawfulness, transparency and fairness, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, and accountability,
  • Maintain records of each category of a data processing activity in writing to demonstrate compliance to the Data Protection Commission (DPC),
  • Notify personal data breaches to DPC without undue delay and within 72 hours of becoming aware of the breach,
  • Notify personal data breaches to data subjects without undue delay where a breach is likely to cause high risk to the rights and freedoms of data subjects,
  • Notify personal data breaches to the data controller if the organization is a data processor,
  • Implement data protection by design and by default approaches to ensure the security and confidentiality of personal data.

Irish DPC Cookie Consent Guidelines

In Ireland, the European Union’s e-Privacy Directive was implemented into the e-Privacy Regulations of 2011. These regulations require organizations to obtain data subject’s valid consent prior to the installation of cookies and provide the data subject clear and comprehensive information in accordance with the Irish DPA.

Between August and December 2019, the Irish DPC carried out a cookie sweep survey, sending questionnaires to 40 Irish organizations to examine the use of cookies and similar technologies. Based on the results of the survey, the DPC released a substantive Guidance Note on Cookies and Other Tracking Technologies later in April 2020, containing the following key requirements for organizations:

  • Organizations must obtain valid user’s consent prior to the use of cookies, development kits, pixel trackers, or any other form of tracking technology.
  • Users must have the ability to change their cookie preferences easily, at any given time, and without facing any detriment.
  • The DPC requires organizations to reaffirm user’s consent no longer than six months after they have stored their consent status.
  • Any record of consent must be backed up by the organization through demonstrable organizational measures to ensure a user’s expression of consent (or withdrawal).
  • Organizations must assess the role of third parties using cookies on their website as data controllers or data processors.
  • Organizations are not required to obtain prior user’s consent for the use of strictly necessary cookies (strictly necessary exemption) and cookies that are solely used for carrying out the transmission of a communication over a network (communication exemption). To ensure cookies fall under the strictly necessary cookie exemption, organizations must ensure that such cookies are necessary to provide specific functionality to the user, that has been explicitly requested by the user as part of an information society service.
  • If an organization uses a cookie consent banner, the banner must be placed in a position to not obscure the text of the privacy policy or the cookie policy. The cookie banner must allow users to accept as well as reject the use of cookies and provide clear and comprehensive information about the types and purposes of cookies including third-party cookies.

Learn further about Irish Guidance on Consent and Cookies


Automating privacy operations across your organization

The multi-disciplinary practice to grow trust-equity of your brand and comply with privacy regulations.

Get the Book

“By leveraging the PrivacyOps constructs from this book across our organization we were able to not only save time and money but also mitigate the risks associated with manual methods of privacy management.”

- Marty Collins, Chief Privacy and Legal Officer, QuinStreet, Inc

What is Egypt’s Data Protection Law

Automating Compliance

securiti.ai’s privacy regulations compliance solution is based on the PrivacyOps methodology, which recruits robotic automation and artificial intelligence. It provides organizations with a system that can help automate the majority of their compliance tasks and in turn, freeing up resources for other areas of business.

securiti.ai assists businesses in discovering data over a web of internal and external systems, links personal data with its correct owners, conducts an automated internal assessment of policies as well as third-party vendors, manages consent, and much more!

While organizations may hesitate to take the leap towards automation from their current manual methods for fear of the costs and change in infrastructure, it is clear that automation is truly the way forward. Automation increases ROI as well as productivity lowers cost and improves accuracy. It pays for itself and brings organizations a number of benefits along with it.

Automation helps you with swift and efficient compliance with GDPR as well as other data privacy regulations. Watch it in action today!

Ask for a DEMO today to understand how securiti.ai can help you comply with Irish Data Protection Act, GDPR, e-Privacy Directive, and a whole host of other global privacy laws and regulations, with ease and automation.


Frequently Asked Questions (FAQs)

Ireland’s Data Protection Act protects personal data and follows GDPR rules. It gives people the right to access, change, or delete their data. Businesses must keep data safe and ask for consent before using it.

Ireland is part of the European Union, and the General Data Protection Regulation (GDPR) applies to all EU member states, including Ireland.

The 8 principles of data protection in Ireland, as per GDPR, include lawful and transparent processing, purpose limitation, data minimization, accuracy, storage limitation, integrity and confidentiality, accountability, and fairness.

The Data Protection Commission (DPC) is the authority responsible for regulating data protection and enforcing GDPR in Ireland.

GDPR is a comprehensive regulation that applies across the European Union, while a Data Protection Act is specific legislation adopted by individual EU member states to supplement and implement GDPR within their national legal framework.

Join Our Newsletter

Get all the latest information, law updates and more delivered to your inbox


Share

More Stories that May Interest You
Videos
View More
Mitigating OWASP Top 10 for LLM Applications 2025
Generative AI (GenAI) has transformed how enterprises operate, scale, and grow. There’s an AI application for every purpose, from increasing employee productivity to streamlining...
View More
Top 6 DSPM Use Cases
With the advent of Generative AI (GenAI), data has become more dynamic. New data is generated faster than ever, transmitted to various systems, applications,...
View More
Colorado Privacy Act (CPA)
What is the Colorado Privacy Act? The CPA is a comprehensive privacy law signed on July 7, 2021. It established new standards for personal...
View More
Securiti for Copilot in SaaS
Accelerate Copilot Adoption Securely & Confidently Organizations are eager to adopt Microsoft 365 Copilot for increased productivity and efficiency. However, security concerns like data...
View More
Top 10 Considerations for Safely Using Unstructured Data with GenAI
A staggering 90% of an organization's data is unstructured. This data is rapidly being used to fuel GenAI applications like chatbots and AI search....
View More
Gencore AI: Building Safe, Enterprise-grade AI Systems in Minutes
As enterprises adopt generative AI, data and AI teams face numerous hurdles: securely connecting unstructured and structured data sources, maintaining proper controls and governance,...
View More
Navigating CPRA: Key Insights for Businesses
What is CPRA? The California Privacy Rights Act (CPRA) is California's state legislation aimed at protecting residents' digital privacy. It became effective on January...
View More
Navigating the Shift: Transitioning to PCI DSS v4.0
What is PCI DSS? PCI DSS (Payment Card Industry Data Security Standard) is a set of security standards to ensure safe processing, storage, and...
View More
Securing Data+AI : Playbook for Trust, Risk, and Security Management (TRiSM)
AI's growing security risks have 48% of global CISOs alarmed. Join this keynote to learn about a practical playbook for enabling AI Trust, Risk,...
AWS Startup Showcase Cybersecurity Governance With Generative AI View More
AWS Startup Showcase Cybersecurity Governance With Generative AI
Balancing Innovation and Governance with Generative AI Generative AI has the potential to disrupt all aspects of business, with powerful new capabilities. However, with...

Spotlight Talks

Spotlight 11:29
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Not Hype — Dye & Durham’s Analytics Head Shows What AI at Work Really Looks Like
Watch Now View
Spotlight 11:18
Rewiring Real Estate Finance — How Walker & Dunlop Is Giving Its $135B Portfolio a Data-First Refresh
Watch Now View
Spotlight 13:38
Accelerating Miracles — How Sanofi is Embedding AI to Significantly Reduce Drug Development Timelines
Sanofi Thumbnail
Watch Now View
Spotlight 10:35
There’s Been a Material Shift in the Data Center of Gravity
Watch Now View
Spotlight 14:21
AI Governance Is Much More than Technology Risk Mitigation
AI Governance Is Much More than Technology Risk Mitigation
Watch Now View
Spotlight 12:!3
You Can’t Build Pipelines, Warehouses, or AI Platforms Without Business Knowledge
Watch Now View
Spotlight 47:42
Cybersecurity – Where Leaders are Buying, Building, and Partnering
Rehan Jalil
Watch Now View
Spotlight 27:29
Building Safe AI with Databricks and Gencore
Rehan Jalil
Watch Now View
Spotlight 46:02
Building Safe Enterprise AI: A Practical Roadmap
Watch Now View
Spotlight 13:32
Ensuring Solid Governance Is Like Squeezing Jello
Watch Now View
Latest
View More
Databricks AI Summit (DAIS) 2025 Wrap Up
5 New Developments in Databricks and How Securiti Customers Benefit Concerns over the risk of leaking sensitive data are currently the number one blocker...
Inside Echoleak View More
Inside Echoleak
How Indirect Prompt Injections Exploit the AI Layer and How to Secure Your Data What is Echoleak? Echoleak (CVE-2025-32711) is a vulnerability discovered in...
What Is Data Risk Assessment and How to Perform it? View More
What Is Data Risk Assessment and How to Perform it?
Get insights into what is a data risk assessment, its importance and how organizations can conduct data risk assessments.
What is AI Security Posture Management (AI-SPM)? View More
What is AI Security Posture Management (AI-SPM)?
AI SPM stands for AI Security Posture Management. It represents a comprehensive approach to ensure the security and integrity of AI systems throughout the...
Beyond DLP: Guide to Modern Data Protection with DSPM View More
Beyond DLP: Guide to Modern Data Protection with DSPM
Learn why traditional data security tools fall short in the cloud and AI era. Learn how DSPM helps secure sensitive data and ensure compliance.
Mastering Cookie Consent: Global Compliance & Customer Trust View More
Mastering Cookie Consent: Global Compliance & Customer Trust
Discover how to master cookie consent with strategies for global compliance and building customer trust while aligning with key data privacy regulations.
View More
Key Amendments to Saudi Arabia PDPL Implementing Regulations
Download the infographic to gain insights into the key amendments to the Saudi Arabia PDPL Implementing Regulations. Learn about proposed changes and key takeaways...
Understanding Data Regulations in Australia’s Telecom Sector View More
Understanding Data Regulations in Australia’s Telecom Sector
Gain insights into the key data regulations in Australia’s telecommunication sector. Learn how Securiti helps ensure swift compliance.
Gencore AI and Amazon Bedrock View More
Building Enterprise-Grade AI with Gencore AI and Amazon Bedrock
Learn how to build secure enterprise AI copilots with Amazon Bedrock models, protect AI interactions with LLM Firewalls, and apply OWASP Top 10 LLM...
DSPM Vendor Due Diligence View More
DSPM Vendor Due Diligence
DSPM’s Buyer Guide ebook is designed to help CISOs and their teams ask the right questions and consider the right capabilities when looking for...
What's
New