Photo of Jessica Morris

The Data Protection Commission (DPC) recently published its decision following a formal inquiry into the Irish Credit Bureau DAC (the ICB) following the ICB’s notification to the DPC of a personal data breach on the 31 August 2018. The ICB is a credit reference agency that maintains a database on the performance of credit agreements between financial institutions and borrowers.

The personal data breach occurred when the ICB implemented a code change to its database that contained a technical error. As a result, between 28 June 2018 and 30 August 2018, the ICB database inaccurately updated the records of 15,120 closed accounts. This update had the effect of changing key data in a data subject’s record so that it appeared that their accounts had been closed recently, even where the loans or credit facilities had been paid off years before. This caused the ICB to disclose 1,062 inaccurate account records to financial institutions as part of credit checks, which would have potentially resulted in a refusal of credit in circumstances where it would have been granted. The records did not, however, misstate that a balance was outstanding on the accounts.

The incident was handled by the ICB as a data breach and was reported to the DPC. The DPC’s investigation focussed on the application of Data Protection by Design and by Default (Article 25), the appropriateness of organisational and technical controls under Article 24, and whether or not there was a joint controller relationship under Article 26 GDPR between the ICB and the lenders who shared data with them.


Continue Reading Irish Credit Bureau fine offers insight into the DPC’s use of its corrective powers

The provisions of the Copyright and Other Intellectual Property Law Provisions Act 2019 (the Act), which was signed into law on 26 June 2019, were commenced on 2 December 2019.

The only provisions which are not yet in effect are sections 2(1), 9 and 21, which will automatically come into operation on 26 December (i.e. 6 months from the passing of the Act on 26 June 2019).


Continue Reading Commencement of the Copyright and Other Intellectual Property Law Provisions Act 2019

​The DPC has released new CCTV Guidance to assist owners and occupiers of premises to understand their data protection obligations when using CCTV. Data controllers should already be aware that footage or images containing identifiable individuals captured by CCTV is personal data and therefore data protection laws apply.

Continue Reading Guidance on the Use of CCTV for Data Controllers