Léim ar aghaidh chuig an bpríomhábhar
Gnáthamharc

Departmental Policies

Dáil Éireann Debate, Wednesday - 13 May 2026

Wednesday, 13 May 2026

Ceisteanna (40)

Darren O'Rourke

Ceist:

40. Deputy Darren O'Rourke asked the Tánaiste and Minister for Finance if financial institutions can legally request biometric ID from existing customers to update their accounts; if a customer refuses can a financial institution refuse to offer them services; and if he will make a statement on the matter. [35462/26]

Amharc ar fhreagra

Freagraí scríofa

I am informed by the Central Bank that the Central Bank of Irelands’ Consumer Protection Code (‘Code’) is technology neutral. This means that regulated entities are obliged to meet the requirements of the Code irrespective of the delivery method used and any underlying technology used in that delivery.

In addition, firms are subject to an overarching obligation which requires that they secure their customers’ interests. This would also apply to the use of technology in the provision of financial products and services. However, the Central Bank does not prescribe the use of any specific tools for ID verification whether technology based or traditional processes; with the obligation being on financial institutions to design and implement their own processes to comply with their obligations.

The Central Bank’s General Guidance on the Code also reminds firms that the requirements in the Code are without prejudice to their obligations under the General Data Protection Regulations. Certain types of sensitive personal data are subject to additional protection under the GDPR. These are listed under Article 9 of the GDPR as “special categories” of personal data. Genetic data and biometric data processed for the purpose of uniquely identifying a natural person is categorised as a special category.

The Data Protection Commission (DPC) is the primary independent supervisory authority in Ireland, responsible for enforcing the GDPR, investigating breaches, and handling complaints. It oversees compliance with the Data Protection Act 2018 and the ePrivacy Regulations.

Finally, the Central Bank’s consumer protection framework provides that consumers who are not satisfied with a regulated firm’s handling of their service can make a complaint directly to the firm. If a consumer is not satisfied with how their complaint is dealt with by a regulated entity, they have the option of then making a complaint to the Financial Services and Pensions Ombudsman (FSPO).

Roinn