I propose to take Questions Nos. 159, 160, 161 and 162 together.
The Social Welfare and Other Matters Bill 2026 provides for amendments to the Charities Act 2009, the Civil Registration Act 2004, and the Social Welfare Consolidation Act 2005.
The amendments to the Charities Act 2009 do not involve any processing of personal data. The amendments in the Bill relating to the Civil Registration Act and the Social Welfare Consolidation Act involve the processing of personal data, but do not include any provisions relating to either the processing of financial data or the sharing of personal data between State bodies or any other bodies, nor do they relate to any processing of personal data for the purposes of fraud prevention, enforcement or monitoring.
I am satisfied that the provisions of the Bill are necessary and proportionate and sufficiently clear. My department has consulted with the Data Protection Commission (DPC) on this Bill as required under the Data Protection Act 2018, and officials from both my department and the DPC have appeared before the relevant Oireachtas Committee during the pre-legislative process.
I am also satisfied that, in relation to the carrying out of its statutory functions in relation to preventing, detecting, investigating and prosecuting identity fraud and social welfare fraud, my department remains fully compliant with the Law Enforcement Directive and the Data Protection Act 2018, which governs the processing of personal data for those purposes.
My department shares personal data with a number of Government Departments, bodies, agencies, and local authorities, for the purposes which are set out in the Social Welfare Consolidation Act 2005 and in other Acts. The data shared may be aggregated or individual depending on the legislative provisions and purpose which relate to the data sharing activity, which provisions set out the purpose for which the data can be shared.
Schedule 5 of the Social Welfare Consolidation Act 2005 lists the specified bodies which are authorised to use the PPSN when carrying out their statutory functions and with which the Department can share personal data in relation to identity. Other provisions in that Act provide for the sharing of data for other purposes. In addition, other Acts provide a legal basis for sharing of personal data between the Department and other bodies.
In addition, my department has for many years automated its processes as much as possible by programming scheme rules into its IT systems. It is important to note that no claim is disallowed using these automated systems. Any claim that is not awarded on a flow-through basis is referred to a deciding officer of the department for human intervention.
My department is committed to embedding safeguards—including human review, bias testing, and strict governance—to ensure that any increased automation in eligibility assessment and fraud analytics cannot give rise to algorithmic bias or indirect discrimination. Furthermore, representatives from my department participate on numerous international and EU wide committees and as such are aware of emergent technologies and the associated risks.
My department has an effective data governance framework in place to ensure that it meets its obligations as a data controller under the General Data Protection Regulation (GDPR) and the Data Protection Act 2018 in respect of its data sharing activities. This includes putting in place specific data sharing agreements in respect of the sharing of data with other departments and agencies.
Any questions relating to the powers and resources of the Data Protection Commission, or the current oversight framework in respect of data protection, are a matter for the Minister for Justice.
I trust this clarifies the matter for the Deputy.