Skip to main content
Normal View

Data Protection

Dáil Éireann Debate, Wednesday - 15 April 2026

Wednesday, 15 April 2026

Questions (217)

Naoise Ó Cearúil

Question:

217. Deputy Naoise Ó Cearúil asked the Minister for Public Expenditure, Infrastructure, Public Service Reform and Digitalisation the safeguards that will govern the operation of the Government Digital Wallet; to detail the way in which the principle of data-minimisation will be maintained as additional public services are incorporated into the platform; and if he will make a statement on the matter. [27527/26]

View answer

Written answers

My Department has engaged with the Data Protection Office in advance of launching the Government Digital Wallet, and a deliberately cautious, phased public Beta is now underway, to ensure that privacy and data-protection safeguards are rigorously tested before any broader deployment. A dedicated Data Protection Impact Assessment (DPIA) has been completed specifically for the Beta, recognising its use of innovative technology, and this DPIA strictly limits the scope, duration and purpose of all processing. The Beta is time-bound, voluntary and research-focused, and is limited to the issuance of a single foundational credential. Participation is entirely consent-based, with users retaining full control over their data. Credentials are stored solely on the individual’s own device; no central repository of credential data or verification outcomes is created, and the Beta is structured so that all verification interactions are single-use and ephemeral, with no data retained once a verification session ends.

The principle of data minimisation is embedded by design and maintained through strict technical and governance controls. Only the minimum data required for a specific, user-initiated action is processed and, during the Beta, this is further constrained by the issuance of a single foundational credential only. Verification is designed to take place on a per-transaction basis, with explicit user approval of precisely which attributes, if any, are shared. Privacy-enhancing techniques, including zero-knowledge proofs, are used within the Beta to allow specific facts to be verified without disclosing underlying personal data. Importantly, the Beta is phased to expand functionality only incrementally, and no additional credentials, services or verification patterns can be introduced without first completing a separate or supplementary DPIA to assess necessity, proportionality and risk. For any full production rollout of the Digital Wallet, both the issuers of credentials and the verifiers of those credentials will be tightly controlled, reflecting the fact that governance of who issues and who verifies credentials is a key safeguard in maintaining data minimisation and public trust as additional services are added over time.

Share