Léim ar aghaidh chuig an bpríomhábhar
Gnáthamharc

Data Protection

Dáil Éireann Debate, Wednesday - 17 December 2025

Wednesday, 17 December 2025

Ceisteanna (344)

Liam Quaide

Ceist:

344. Deputy Liam Quaide asked the Minister for Justice, Home Affairs and Migration the reason Section 30 of the Data Protection Act 2018 has yet to be commenced; the timeline for its commencement; and if he will make a statement on the matter. [73238/25]

Amharc ar fhreagra

Freagraí scríofa

The General Data Protection Regulation (GDPR) is an EU wide instrument and Member States, including Ireland, cannot deviate from its provisions. Commencement of section 30 of the Data Protection Act 2018 has been raised previously by way of parliamentary question and the position, as outlined at that time, remains the same. Should section 30 be commenced, Ireland could face the serious risk of infringement proceedings and the potential for significant penalties against the State.

Processing of personal data for marketing and profiling purposes takes place under Article 6(1)(f) (“legitimate interests” ground) of the GDPR, with the case law of the European Court of Justice underlining the importance of free movement of personal data and establishing that Member States are not permitted to impose additional conditions that would have the effect of amending the scope of any of the grounds now set out in Article 6.1 of the GDPR. The Office of the Attorney General has also previously advised my Department that section 30 of the 2018 Act appears to go beyond the margin of discretion afforded to Member States in giving further effect to the GDPR and would conflict with Article 6(1)(f), read alongside Recital (47).

Additionally, the European Commission has confirmed that processing of personal data for direct marketing purposes may be regarded as being carried out for a legitimate interest and that Article 6(1)(f) of the GDPR does not make the processing of personal data of a child for the purposes of direct marketing unlawful. The EU Commission also indicated that subject to Article 22 (automated decision-making), processing of personal data of a child for the purposes of profiling is not generally prohibited, albeit the processing must take into account that children merit specific protection as clarified in recital (38). Moreover, the Commission has indicated that the term "micro-targeting", as referenced in Section 30 of the Act, is not mentioned in the GDPR, as such its scope remains uncertain and undefined.

Put simply, it is not an option for a Member State to unilaterally prohibit a category of processing activities which might otherwise be lawful under Article 6(1)(f). The commencement of section 30 could, therefore, give rise to a substantial risk of infringement proceedings against the State pursuant to Article 258 of the Treaty on the Functioning of the European Union.

Notwithstanding the above-mentioned issues with section 30 of the Data Protection Act 2018, the protection of minors is a priority for the Data Protection Commission (DPC). For example, in early December 2025, the DPC launched a nationwide awareness campaign to highlight the potential risks and consequences of sharing of personal information, photos and videos by parents of their children online.

Furthermore, apart from this apparent conflict with the GDPR, the Office of the Attorney General has advised that section 30 gives rise to difficulties under Article 38.1 of the Constitution and under Article 7 of the European Convention on Human Rights. Article 38.1 provides that no person shall be tried on any criminal charge save in due course of law. For a domestic offence provision to comply with Article 38.1, it must be clear, precise and foreseeable in its application. It is not clear under section 30 what might constitute the processing of personal data of a child for the purposes of micro-targeting. It is also a requirement under Article 7 of the Convention that offence provisions must be sufficiently clear and precise to enable individuals to ascertain which conduct constitutes a criminal offence and to foresee the consequences of engaging in such conduct.

Finally, since the last parliamentary question on this matter, the Digital Services Act (DSA) has come into force across the EU. The DSA is a key EU Regulation designed to regulate and harmonise how digital and online platforms operate and engage with users. The DSA contains many features dedicated to the protection of minors. These include obligations to implement privacy by design, provide default high security settings for minors, a prohibition on profiling minors for targeted ads and requirements around age warnings and a possibility for the implementation of age verification measures.

Coimisiún na Meán is Ireland's designated Digital Services Coordinator (DSC) under the DSA and is responsible for overseeing and enforcing DSA rules for online platforms established in Ireland. Coimisiún na Meán has also published guidelines on the protection of minors under the DSA: digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-protection-minors.

Roinn