Act 2018
Data Protection Act 2018
An tAcht um Chosaint Sonraí, 2018
Issued by Data Protection Commission
Effective: 25 May 2018
Last amended: 16 Jul 2026
Plain-English summary
Data Protection Act 2018 is an effective piece of primary legislation that incorporates the EU General Data Protection Regulation into domestic Irish law. It is regulated by the Data Protection Commission, which sets rules for global data protection standards and makes regular updates.
Who it applies to
Banking · Insurance · Telecom & Tech
Topics
Data Protection & Privacy
Obligations arising from this instrument
| Obligation | Timing | Regulator | Source | Detail |
|---|---|---|---|---|
| Lawful basis, notice and data subject rights | Ongoing | DPC | source | |
The obligation of lawfulness, notice, and data subject rights in Ireland has created an extremely rigid and mandatory governance of data that compels the organization to provide a legal justification and mapping for each level of personal data processing. It is categorized as a continuous compliance and event-driven obligation where organizations have to ensure the availability of transparent and accessible privacy notices and lawful bases of processing from day one of data collection. At the same time, it is required to possess capabilities to address the rights of the data subjects in a timely manner. If there is any failure in data processing or denial of fulfilling the privacy rights within a one-month deadline, then it can attract serious enforcement actions against corporations. |
||||
| Personal data breach notification | Deadline 72-hour | DPC | source | |
The obligation to notify personal data breaches in Ireland is defined as an absolute statutory requirement under the GDPR and the Data Protection Act 2018 and imposes legal obligations on organizations to notify data security incidents to supervisory authorities. Clearly categorized as an event-driven compliance obligation, the legal reporting mechanism gets triggered at the exact point when the organization realizes that its personal data have been breached and unauthorizedly disclosed or lost [dataprotection.ie]. The legal framework imposes a strict 72-hour regulatory period, during which the organization is required to submit its formal breach notification to the Data Protection Commission (DPC) in a secure manner and communicate the same to the impacted parties, if the breach carries significant risks to personal privacy [dataprotection.ie]. Under the active surveillance of the DPC and subject to rigorous audits, the non-reporting of a breach within the statutory time period or attempting to hide such an incident amounts to a serious compliance failure, resulting in mandatory audits and huge fines. |
||||
| No obligations match these filters. | ||||
Latest news
No related news yet. We publish updates as regulators act.