I can confirm that 252 data breaches were recorded by my Department in 2025, with 25 reaching the threshold to be notified to the Data Protection Commission.
My Department is a very large organisation comprising over 4,000 people which process a very large volume of personal data, with correspondence annually numbering in the tens of thousands of cases. Despite this, the number of breaches remains relatively low, indicating effective data protection controls and awareness.
My Department is committed to protecting the rights and privacy of all individuals in accordance with the EU General Data Protection Regulation, 2016/679 (GDPR) and the Data Protection Act 2018. My Department complies fully with data breach reporting requirements.
Securing and managing personal data in accordance with the GDPR principles is a priority and is governed by a comprehensive set of policies, procedures and systems. For example, a Department Data Protection and Records Management Steering Group operates with membership of senior personnel from across the Department to assist the Management Board and the Data Protection Officer in fulfilling their Data Protection responsibilities. My Department also has put in place a network of data stewards to champion data protection awareness in each business unit.
In addition, all staff must complete compulsory data protection training in order to ensure that my Department is compliant with obligations to protect all personal data processed. This includes data protection training provided as part of staff induction and an online Introduction to Data Protection e-learning course.
My Department has implemented appropriate measures to ensure that all data held under its control is secure and is not at risk from unauthorised access. Measures for the protection of personal data are reviewed on an ongoing basis.