Skip to main content
Normal View

Data Protection

Dáil Éireann Debate, Wednesday - 16 October 2024

Wednesday, 16 October 2024

Questions (55)

Peadar Tóibín

Question:

55. Deputy Peadar Tóibín asked the Minister for Transport the number of data breaches experienced by his Department in each of the past ten years and to date in 2024; if a breakdown will be provided on the nature of the breaches; and if he will make a statement on the matter. [41744/24]

View answer

Written answers

Data breaches are taken very seriously within my Department and staff are provided with training and procedures on what steps to take in the event of a possible data breach, including notifying, as soon as possible, the Department's Data Protection Officer.

I have outlined the number of data breaches within the timeframe requested by the Deputy in the table below. Please note that our records comprise 2017 to the present date.

The Deputy may also wish to be aware that the majority of the breaches identified were determined to be unlikely to result in a risk to data subjects and were handled in accordance with the Department's Personal Data Breach Response Policy.

Year

Number of Data Breaches

Number of breaches reported to the Data Protection Commission

Number of breaches notified to data subject(s)

2017

No records of any data breaches within the Department.

-

-

2018

3

1

3

2019

9

4

5

2020

5

0

2

2021

8

4

6

2022

11

0

5

2023

5

1

2

2024 to 10/10/2024

7

1

2

All breaches must be formally notified to the Department’s Data Protection Officer for assessment. In line with DPC guidance, the majority of confirmed data breaches were deemed not to meet the threshold that would require reporting to the DPC due to the nature of the particular risk they represented and as such notification of the DPC was not undertaken. These were managed internally with steps taken to ensure that similar breaches would not reoccur.

The majority of confirmed data breaches relate to incidents where personal data was accidentally and inadvertently disclosed to third parties. Examples include emails sent to the wrong recipient, incorrect photos issued in certificates, and errors in IT access permissions allowing staff to access information of other staff. There were also a number of incidents where laptops/tablets/mobile phones were temporarily mislaid but were recovered and it was confirmed with IT that no unauthorised access had been made to the devices.

Share