Skip to main content
Normal View

Data Protection

Dáil Éireann Debate, Wednesday - 10 June 2026

Wednesday, 10 June 2026

Questions (159, 160, 161, 162)

William Aird

Question:

159. Deputy William Aird asked the Minister for Social Protection if he is satisfied that the data-sharing and data-processing provisions contained in the general scheme of the Social Welfare and Other Matters Bill 2026, comply with the principles of necessity and proportionality under the GDPR and constitutional privacy protections; whether a detailed assessment or justification has been undertaken in respect of the scale of personal and financial data processing proposed, particularly for fraud prevention purposes; the statutory safeguards that will be included in the legislation to protect citizens' personal data; and if he will make a statement on the matter. [44593/26]

View answer

William Aird

Question:

160. Deputy William Aird asked the Minister for Social Protection if he is satisfied that the proposed legislation in the general scheme of Social Welfare and Other Matters Bill 2026 provides sufficient transparency to social welfare recipients regarding how their personal data may be collected, shared, cross-checked, profiled or otherwise processed across State bodies; what measures are proposed to prevent "function creep", whereby data collected for the administration of social welfare schemes may subsequently be used for unrelated enforcement or monitoring purposes; and if he will make a statement on the matter. [44594/26]

View answer

William Aird

Question:

161. Deputy William Aird asked the Minister for Social Protection the assessment that has been undertaken of international experiences where automated decision-making systems, welfare analytics or fraud detection technologies resulted in wrongful suspensions, incorrect overpayments, or discriminatory outcomes; whether consideration has been given to the potential for algorithmic bias or indirect discrimination arising from increased automation in eligibility assessments or fraud detection processes under the proposed general scheme of Social Welfare and Other Matters Bill 2026, the safeguards that will be implemented to mitigate such risks; and if he will make a statement on the matter. [44595/26]

View answer

William Aird

Question:

162. Deputy William Aird asked the Minister for Social Protection if he is satisfied that the current oversight framework provides the Data Protection Commission with sufficient statutory powers and resources to effectively monitor compliance with large-scale interdepartmental welfare data-sharing arrangements; the way in which the Government intends to balance the legitimate objective of tackling welfare fraud with the privacy and constitutional rights of citizens who are fully compliant with the social protection system; and if he will make a statement on the matter. [44596/26]

View answer

Written answers

I propose to take Questions Nos. 159, 160, 161 and 162 together.

The Social Welfare and Other Matters Bill 2026 provides for amendments to the Charities Act 2009, the Civil Registration Act 2004, and the Social Welfare Consolidation Act 2005.

The amendments to the Charities Act 2009 do not involve any processing of personal data. The amendments in the Bill relating to the Civil Registration Act and the Social Welfare Consolidation Act involve the processing of personal data, but do not include any provisions relating to either the processing of financial data or the sharing of personal data between State bodies or any other bodies, nor do they relate to any processing of personal data for the purposes of fraud prevention, enforcement or monitoring.

I am satisfied that the provisions of the Bill are necessary and proportionate and sufficiently clear. My department has consulted with the Data Protection Commission (DPC) on this Bill as required under the Data Protection Act 2018, and officials from both my department and the DPC have appeared before the relevant Oireachtas Committee during the pre-legislative process.

I am also satisfied that, in relation to the carrying out of its statutory functions in relation to preventing, detecting, investigating and prosecuting identity fraud and social welfare fraud, my department remains fully compliant with the Law Enforcement Directive and the Data Protection Act 2018, which governs the processing of personal data for those purposes.

My department shares personal data with a number of Government Departments, bodies, agencies, and local authorities, for the purposes which are set out in the Social Welfare Consolidation Act 2005 and in other Acts.  The data shared may be aggregated or individual depending on the legislative provisions and purpose which relate to the data sharing activity, which provisions set out the purpose for which the data can be shared.

Schedule 5 of the Social Welfare Consolidation Act 2005 lists the specified bodies which are authorised to use the PPSN when carrying out their statutory functions and with which the Department can share personal data in relation to identity.  Other provisions in that Act provide for the sharing of data for other purposes.  In addition, other Acts provide a legal basis for sharing of personal data between the Department and other bodies.

In addition, my department has for many years automated its processes as much as possible by programming scheme rules into its IT systems.  It is important to note that no claim is disallowed using these automated systems.  Any claim that is not awarded on a flow-through basis is referred to a deciding officer of the department for human intervention.

My department is committed to embedding safeguards—including human review, bias testing, and strict governance—to ensure that any increased automation in eligibility assessment and fraud analytics cannot give rise to algorithmic bias or indirect discrimination. Furthermore, representatives from my department participate on numerous international and EU wide committees and as such are aware of emergent technologies and the associated risks.

My department has an effective data governance framework in place to ensure that it meets its obligations as a data controller under the General Data Protection Regulation (GDPR) and the Data Protection Act 2018 in respect of its data sharing activities.  This includes putting in place specific data sharing agreements in respect of the sharing of data with other departments and agencies. 

Any questions relating to the powers and resources of the Data Protection Commission, or the current oversight framework in respect of data protection, are a matter for the Minister for Justice.

I trust this clarifies the matter for the Deputy.

Question No. 160 answered with Question No. 159.
Question No. 161 answered with Question No. 159.
Question No. 162 answered with Question No. 159.
Share