Ireland
Part of the European Union, so bloc-wide rules apply here too. Checked today.
The answer
Ireland follows Europe's rules, so personal data can leave the country once you have the right paperwork in place. But a handful of Irish laws force certain records to be kept physically in Ireland, and breaking those is a crime rather than a fine. Ireland's privacy regulator is one of the toughest in Europe: in 2025 it fined TikTok 530 million euro and ordered it to stop sending data to China.
Eight questions about Ireland
The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.
Do Ireland's rules apply to my company?
Yes. Ireland's data protection law reaches a company with no office in Ireland whenever it offers goods or services to people in Europe or watches what they do online. There is no revenue or headcount threshold to duck under. A company based outside Europe normally has to name a representative inside Europe who regulators and members of the public can write to.
The Data Protection Act 2018 gives effect to the General Data Protection Regulation, whose territorial scope in Article 3(2) is the operative test. Ireland matters far more than its size suggests because so many large technology companies place their European headquarters in Dublin, which makes the Irish Data Protection Commission their 'lead supervisory authority' under the one-stop-shop mechanism. The Commission concluded 208 valid cross-border complaints in that role in 2025, a 43 per cent increase on 2024. It also opened an own-volition inquiry into X Internet Unlimited Company under section 110 of the Data Protection Act 2018 on 17 February 2026.
Sources
- Official sourceOffice of the Attorney General, Irish Statute BookData Protection Act 2018 (No. 7 of 2018) — full text
irishstatutebook.ie
Link checked 18 August 2026
- Official sourceData Protection CommissionData Protection Commission publishes Annual Report for 2025, 30 June 2026 — cross-border caseload as lead supervisory authority
dataprotection.ie
“The DPC concluded 208 valid cross-border complaints (as EU/EEA Lead Supervisory Authority). This represented a 43% increase on 2024.”
Link checked 18 August 2026
- Official sourceData Protection CommissionData Protection Commission press releases — inquiry opened into X Internet Unlimited Company, 17 February 2026
dataprotection.ie
Link checked 18 August 2026
Can I store my users' data outside Ireland?
In general, yes, with paperwork. Ireland does not have a general rule saying personal data must stay in the country. Sending it outside Europe is allowed once you use one of the approved legal routes. But several Irish laws quietly demand that particular records sit on Irish soil, and those override the friendly headline.
Sector by sector, checked 18 August 2026. BANKING, PAYMENTS, INSURANCE, SECURITIES — conditional. No Irish localisation rule found. The Central Bank of Ireland regulates through its Cross-Industry Guidance on Outsourcing and through the European Digital Operational Resilience Act, both of which demand that you know and disclose where your data sits, not that you keep it here. The Central Bank paused its own outsourcing register collection in 2025 and will resume it in February 2027 with a reference date of 31 December 2026. ANTI-MONEY-LAUNDERING REGULATED FIRMS — mirror, and this is the real Irish wall. A trust or company service provider authorised by the Minister for Justice must retain prescribed records 'at an office or other premises in the State' for at least six years and must tell the Minister the address where they are held. A cheque-cashing office registered with the Central Bank carries an identical duty. Both are criminal offences if breached. Note that the equivalent duty for ordinary designated persons under section 55 was removed in 2013 — see the traps. ALL COMPANIES — mirror. Accounting records may be kept outside Ireland, but information and returns good enough to show the assets, liabilities and profit or loss at intervals of no more than six months must be sent to and kept at a place in Ireland. HEALTH — conditional, tightening. The Health Information Act 2026 lets the Health Service Executive share an Electronic Health Record with a non-European country only through a reciprocal arrangement, and only after consulting the Data Protection Commission. That section has not yet been commenced. TELECOMS — conditional. Service providers must retain subscriber 'user data' for one year. Retention of traffic and location data is not general: it happens only if the Minister obtains a High Court order. GOVERNMENT AND PUBLIC SECTOR — conditional. The Data Sharing and Governance Act 2019 controls sharing between public bodies through written data-sharing agreements. No localisation requirement found in the Act. MAPPING AND GEOSPATIAL, EDUCATION, DEFENCE, GAMING — no Irish localisation rule found, checked 18 August 2026, confidence medium. The gambling regulator's record-keeping regulations were still out for public consultation until 20 August 2026 and have not been made.
Sources
- Official sourceLaw Reform Commission of IrelandCriminal Justice (Money Laundering and Terrorist Financing) Act 2010, Revised Act — sections 55, 106 and 108I
revisedacts.lawreform.ie
“The holder of an authorisation shall— (a) retain at an office or other premises in the State such records as may be specified by the Minister, and (b) notify the Minister in writing of the address of any office or other premises where those records are retained.”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookCompanies Act 2014, section 283 — where accounting records are to be kept
irishstatutebook.ie
“If accounting records are kept at a place outside the State, there shall be sent to and kept at a place in the State such information and returns relating to the business dealt with in the accounting records so kept as will— (a) disclose with reasonable accuracy the assets, liabilities, financial position and profit or loss of that business at intervals not exceeding 6 months”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookHealth Information Act 2026, section 18 — electronic exchange of Electronic Health Record information with a third country
irishstatutebook.ie
“The Executive shall not enter into an arrangement or agreement under this section except after consultation with the Data Protection Commission.”
Link checked 18 August 2026
- Official sourceCentral Bank of IrelandOutsourcing Registers — Submission Requirements
centralbank.ie
“The Central Bank of Ireland will resume the domestic collection of Outsourcing Registers in February 2027.”
Link checked 18 August 2026
What do I need in place before data leaves Ireland?
Ireland uses the European model. A destination outside Europe is off limits unless it is on the European Commission's approved list, or you put an approved safeguard in place first. The approved list is real and populated: it currently covers seventeen destinations, including the United Kingdom, Japan, South Korea, Switzerland and Brazil. The United States counts only for companies that have signed up to the European Union to United States Data Privacy Framework.
The Irish regulator's own guidance sets out the ladder: an adequacy decision under Article 45 first; then appropriate safeguards under Article 46, which in practice means the 2021 Standard Contractual Clauses, Binding Corporate Rules, an approved code of conduct, an approved certification, or a legally binding instrument between public bodies; and only then the narrow derogations in Article 49, which the regulator says must not be the first port of call. Regulation (EU) 2018/1807 separately forbids member states from imposing localisation on non-personal data except on public-security grounds, which is why Ireland's few residency rules are all attached to specific record-keeping duties rather than to data in general. The one genuinely unstable piece is the European Union to United States Data Privacy Framework: it is still in force and legally valid today, but it is under appeal at the Court of Justice and the European Data Protection Board formally wrote to the Commission on 31 July 2026 asking it to re-examine the decision's validity. Usable today, but never as your only mechanism.
Sources
- Official sourceData Protection CommissionTransfers of Personal Data to Third Countries or International Organisations — Irish regulator's guidance, listing an approved Binding Corporate Rules list dated July 2026
dataprotection.ie
“The effect of such a decision is that personal data can flow from the EEA to that third country without any further safeguard being necessary.”
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions — the populated approved-destination list
commission.europa.eu
Link checked 18 August 2026
- Official sourceEUR-LexCommission Implementing Decision (EU) 2021/914 — Standard Contractual Clauses
eur-lex.europa.eu
Link checked 18 August 2026
Who enforces the rules in Ireland, and what can they do?
The Data Protection Commission, and it is very much awake. It has three commissioners in post — Des Hogan as chairperson, Dale Sunderland and Niamh Sweeney — and it published its 2025 annual report on 30 June 2026. In 2025 it finished four large inquiries and imposed fines of just over 530 million euro (about 580 million US dollars), almost all of it on TikTok, which it also ordered to stop sending European user data to China.
Observable evidence of activity, all from the regulator's own site: 16,160 new cases received in 2025, a 45 per cent rise; 11,734 cases concluded; 6,521 valid breach notifications; 275 electronic direct marketing investigations concluded, an 88 per cent rise; 50 warning letters on unsolicited marketing. Recent decisions include Permanent TSB on 8 May 2026 and Midlands Regional Hospital Tullamore on 15 June 2026, and open own-volition inquiries into X Internet Unlimited Company (February 2026) and Children's Health Ireland (August 2025). The Commission also went after a government department: it reprimanded the Department of Social Protection over facial recognition in the Public Services Card scheme in June 2025, fined it 550,000 euro (about 600,000 US dollars) and ordered it to stop the biometric processing within nine months. Other regulators that matter. The Central Bank of Ireland supervises financial firms and their outsourcing. Coimisiún na Meán regulates video-sharing platforms under the Online Safety Code and is the Irish Digital Services Coordinator. The Gambling Regulatory Authority of Ireland was formally established in March 2025, published its first annual report and invited its first remote betting licence applications in February 2026. The Health Research Consent Declaration Committee sits under the Department of Health and publishes decisions. The National Cyber Security Centre exists and runs the national incident response team, but it does not yet have NIS2 powers because the directive has not been transposed.
Sources
- Official sourceData Protection CommissionData Protection Commission publishes Annual Report for 2025, 30 June 2026
dataprotection.ie
“The DPC finalised 4 large scale inquiries in 2025 and imposed administrative fines totalling just over €530.77m and multiple reprimands and compliance orders”
Link checked 18 August 2026
- Official sourceData Protection CommissionData Protection Commission press releases — commissioners named, decisions in May and June 2026
dataprotection.ie
“Commissioners for Data Protection, Dr Des Hogan (Chairperson), Mr Dale Sunderland and Ms Niamh Sweeney”
Link checked 18 August 2026
- Official sourceGambling Regulatory Authority of IrelandGambling Regulatory Authority of Ireland — first annual report and phased licensing
grai.ie
“Formally established in March 2025, the GRAI's role is to licence, supervise and control gambling activities as set out in the Gambling Regulation Act 2024.”
Link checked 18 August 2026
- Official sourceNational Cyber Security CentreNational Cyber Security Centre — NIS2 page, transposition status
ncsc.gov.ie
“Unfortunately, the transposition deadline for NIS2 of 17 October 2024 has not been met.”
Link checked 18 August 2026
How long do I have to keep the data?
Both directions apply, and Ireland's floors are longer than most people expect. Anti-money-laundering customer records must be kept for at least five years. Company accounting records and returns must be kept for at least six years. Trust and company service providers and cheque-cashing firms must keep their records for six years and keep them in Ireland. Telephone and internet providers must keep subscriber details for one year.
FLOORS, all verified against the statutes. Anti-money-laundering: a designated person must keep customer due diligence and transaction records for not less than five years after the relationship or transaction ends. Trust and company service providers: not less than six years, at premises in the State, address notified to the Minister for Justice. Cheque-cashing offices registered with the Central Bank: the same six years in the State, with an offence carrying a fine of up to 500,000 euro (about 550,000 US dollars) or three years in prison on indictment. Companies: accounting records, and the information and returns that must be kept in Ireland where the books are abroad, must be preserved for at least six years after the end of the financial year they relate to. Telecoms: 'user data' for one year, extendable by ministerial regulation to a maximum of two years; traffic and location data for twelve months, but only where a High Court judge has made an order on the Minister's application. CEILINGS. The storage limitation principle in the General Data Protection Regulation is the general ceiling: keep it no longer than you need it. For telecoms there is a sharper rule — traffic data must be erased or made anonymous once it is no longer needed to carry or bill for the communication. CONFLICT. Ireland resolves a clash the same way the rest of Europe does: a specific statutory retention duty is a legal obligation, which is a lawful basis to keep the data, and it beats a deletion request for as long as the duty runs. The practical trap is the location, not the length — a six-year duty that also says 'in the State' cannot be satisfied by a cloud region abroad plus a restore capability.
Sources
- Official sourceLaw Reform Commission of IrelandCriminal Justice (Money Laundering and Terrorist Financing) Act 2010, Revised Act — sections 55(4), 106(3) and 108I(3)
revisedacts.lawreform.ie
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookCompanies Act 2014, section 285 — retention of accounting records
irishstatutebook.ie
“shall be preserved by the company concerned for a period of at least 6 years after the end of the financial year containing the latest date to which the record, information or return relates.”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookCommunications (Retention of Data) (Amendment) Act 2022, section 3 — one-year retention of user data
irishstatutebook.ie
“A service provider shall retain, in accordance with section 12D, user data for a period of one year”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookS.I. No. 336/2011 — ePrivacy Regulations, Regulation 6(1), erasure of traffic data
irishstatutebook.ie
“an undertaking shall ensure that traffic data relating to subscribers and users processed and stored for the purpose of the transmission of a communication shall be erased or made anonymous when it is no longer needed for that purpose.”
Link checked 18 August 2026
What happens if there is a breach?
Count three clocks, not one. You have 72 hours to tell the Data Protection Commission about a personal data breach that puts people at risk, and you must tell the affected people without delay if the risk is high. Telephone and internet providers report through a separate channel under separate rules. And if the police send you an order to take down terrorist content, you have one hour.
CLOCK ONE — 72 hours to the Data Protection Commission from the moment you become aware of a personal data breach that poses a risk to individuals, plus notification to the individuals themselves without undue delay where the risk to them is high. The Commission received 6,521 valid breach notifications in 2025, so this is a well-trodden path rather than a theoretical duty. CLOCK TWO — providers of publicly available electronic communications networks or services have their own duty under the 2011 ePrivacy Regulations to notify the Commission without undue delay, using a dedicated telecoms breach form, and to keep an internal inventory of every breach recording the facts, the effects and the remedial action. Do not assume your general privacy playbook covers this; the regulator explicitly signposts it as separate. CLOCK THREE — one hour to remove terrorist content after receiving a removal order from An Garda Síochána, the Irish police, under the European terrorist content online rules. WHAT IS MISSING — the NIS2 cybersecurity directive would add a 24-hour early warning and a 72-hour incident report for in-scope entities. Ireland has not transposed it, so those clocks do not yet run here. The older NIS1 duties continue to apply to operators of essential services already designated in Ireland.
Sources
- Official sourceData Protection CommissionBreach Notification — Irish regulator's guidance, including the separate telecoms channel
dataprotection.ie
“Organisations must do this within 72 hours of becoming aware of the breach.”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookS.I. No. 336/2011 — ePrivacy Regulations, Regulation 4(6) and 4(12), telecoms breach notification and breach inventory
irishstatutebook.ie
“Where there has been a personal data breach, the undertaking shall, without undue delay— (a) notify the Commissioner of the said breach”
Link checked 18 August 2026
- Official sourceCoimisiún na MeánLegislation explained — terrorist content removal orders
cnam.ie
“The platform has one hour to remove the content once the Removal Order has been received.”
Link checked 18 August 2026
- Official sourceNational Cyber Security CentreNational Cyber Security Centre — NIS2 not yet transposed, reporting portal not available
ncsc.gov.ie
“The NIS2 registration and incident reporting portals are not available at this time.”
Link checked 18 August 2026
What trips people up in Ireland?
Five things that cost people their weekend. First, Ireland's famous ban on advertising to children has never actually switched on. Second, the official copy of the law on the government's own statute website can be out of date and misleading. Third, a child in Ireland is anyone under 16 for consent purposes, not 13. Fourth, some record-keeping failures are crimes, not fines. Fifth, the regulator can only fine a public body up to 1 million euro (about 1.1 million US dollars), so it uses stop orders instead.
TRAP 1 — Section 30 of the Data Protection Act 2018 makes it an offence for a company to process a child's personal data for direct marketing, profiling or micro-targeting. It has sat on the statute book since 2018 and, as of 18 August 2026, the Irish Statute Book's own commencement table records it as 'Not yet commenced. Commencement order required under s. 1(3).' It is one signature away from being live. Anyone quoting it as binding Irish law today is wrong. TRAP 2 — The as-enacted text on the official statute website is not the law in force. The anti-money-laundering Act's section 55(4) still reads, in the as-enacted version, that records must be retained 'at an office or other premises in the State'. Those words were removed by the Criminal Justice Act 2013 with effect from 14 June 2013. A naive text search of the government's own site produces a localisation rule that has not existed for thirteen years. Always check the consolidated Revised Act. TRAP 3 — Ireland set its digital age of consent at 16, the top of the range the General Data Protection Regulation allows. A consent flow built for 13-year-olds fails here. TRAP 4 — Criminal, not administrative. A trust or company service provider that fails to keep its records at Irish premises commits an offence punishable on indictment by a fine or up to five years in prison. A cheque-cashing office faces up to 500,000 euro (about 550,000 US dollars) or three years. Separately, disclosing identifiable information collected by the Central Statistics Office is prohibited outright. TRAP 5 — The fine cap for the public sector. Where the Commission fines a public authority or public body that is not acting as a commercial undertaking, the fine cannot exceed 1 million euro. That is why enforcement against Irish state bodies arrives as orders to stop processing rather than as large fines — the Department of Social Protection was ordered in June 2025 to cease biometric processing within nine months. TRAP 6 — Health research in Ireland needs explicit consent from each participant before the research starts, on top of everything the General Data Protection Regulation requires. If you cannot get it, you must apply to the Health Research Consent Declaration Committee for a declaration waiving it. There is no quiet 'legitimate interests' route.
Sources
- Official sourceOffice of the Attorney General, Irish Statute BookData Protection Act 2018 — commencement table, section 30 not yet commenced
irishstatutebook.ie
“S. 30 — Not yet commenced. Commencement order required under s. 1(3)”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookData Protection Act 2018, section 141(4) — 1 million euro cap on fines against public bodies
irishstatutebook.ie
“the amount of the administrative fine concerned shall not exceed €1,000,000.”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookCriminal Justice (Money Laundering and Terrorist Financing) Act 2010, section 55 as enacted — the superseded 'in the State' wording
irishstatutebook.ie
“shall be retained by the designated person, at an office or other premises in the State, for a period of not less than 5 years”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookS.I. No. 314/2018 — Health Research Regulations, Regulation 3(1)(e) explicit consent and Regulation 7 consent declaration committee
irishstatutebook.ie
“explicit consent has been obtained from the data subject, prior to the commencement of the health research, for the processing of his or her personal data for the purpose of specified health research”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookStatistics Act 1993, section 33 — prohibition on disclosure of identifiable statistical information
irishstatutebook.ie
Link checked 18 August 2026
What is changing soon in Ireland?
Three things land in the next year. Ireland's new health records law is switching on in stages, and the parts that let doctors share your file and that allow sharing with countries outside Europe are still switched off. Europe's cloud switching rules make all data exit fees zero on 12 January 2027. And Ireland still has not written the European cybersecurity directive into Irish law, almost two years past the deadline.
DATED AND CONFIRMED. 17 August 2026 — the first tranche of the Health Information Act 2026 came into operation. Sections 1 to 6, 10 to 12, 16, and 19 to 24 are live, including the Health Service Executive's power to create an Electronic Health Record for every patient. Sections 7 to 9 (the duty on providers to share patient data), 13 to 15 (access and restrictions) and 17 to 18 (permitted uses and exchange with countries outside Europe) still need commencement orders. 31 July 2026 — almost all of the Regulation of Artificial Intelligence Act 2026 came into operation, and Ireland's new artificial intelligence office, Oifig IS na hÉireann, was formally established. One limb of the market surveillance definition remains uncommenced. 20 August 2026 — the gambling regulator's consultation on record-keeping regulations for licence holders closed. Regulations are expected to follow. 12 January 2027 — under the European Data Act, all cloud switching charges and data egress fees must fall to zero. 28 February 2027 — Central Bank of Ireland outsourcing registers must be submitted, with a data reference date of 31 December 2026. The Bank will contact firms in the last quarter of 2026. OVERDUE. The NIS2 cybersecurity directive should have been in Irish law by 17 October 2024. A General Scheme was published in September 2024 but no Bill appears in the Oireachtas legislation database as of 18 August 2026, and the regulator's own registration and incident reporting portals are still switched off. DORMANT SWITCHES — powers already held that could change the picture with no consultation. 1. The Minister for Justice can apply, without notice and in private, to a designated High Court judge for an order compelling every telecoms and internet provider in Ireland to retain traffic and location data for twelve months. It is publicised only after the fact. 2. A single commencement order would switch on the criminal ban on profiling and micro-targeting children that has been dormant since 2018. 3. The Minister may make regulations setting technical requirements for how retained communications data is held, which is the natural home for any future in-country storage condition. 4. The Minister for Health may make regulations governing access to Electronic Health Records under the Health Information Act 2026.
Sources
- Official sourceOffice of the Attorney General, Irish Statute BookHealth Information Act 2026 — commencement table, updated to 10 August 2026
irishstatutebook.ie
“Ss. 7 - 9 — Not yet commenced. Commencement order required under s. 1(2)”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookRegulation of Artificial Intelligence Act 2026 — commencement table and establishment day order
irishstatutebook.ie
“Ss. 1 - 77 — 31 July 2026 — Regulation of Artificial Intelligence Act 2026 (Commencement) Order 2026 (S.I. No. 403 of 2026), art. 2”
Link checked 18 August 2026
- Official sourceNational Cyber Security CentreNational Cyber Security Centre — NIS2 transposition status
ncsc.gov.ie
“Ireland continues to work through the transposition requirements of the Directive.”
Link checked 18 August 2026
- Official sourceLaw Reform Commission of IrelandCommunications (Retention of Data) Act 2011, Revised Act — section 3A, ministerial application for a retention order
revisedacts.lawreform.ie
“An order under this subsection shall require all service providers to retain Schedule 2 data ... for a period of 12 months from the date on which the data were first processed”
Link checked 18 August 2026
- Official sourceCentral Bank of IrelandOutsourcing Registers — 2027 collection, deadline 28 February 2027
centralbank.ie
Link checked 18 August 2026
The rules, layer by layer
Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.
Layer 1
Bloc rules
Made by a group of countries together. Applies inside every member country.
1 rule here
Layer 2
National rules
Added by this country on top of any bloc rules.
4 rules here
Layer 3
Industry rules
Made by an industry regulator. These usually beat the general position.
8 rules here
Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.
Bloc rules1 rule
General Data Protection Regulation
Directly binding regulation · Regulation (EU) 2016/679, Chapter V
The European bloc layer. Personal data does not have to stay in Europe, but it may only leave for an approved destination or under an approved safeguard. Ireland adds nothing to this at the general level.
Enforced by Data Protection Commission
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk, Important public interest
What it makes you do
- Put a transfer safeguard in placeA transfer impact assessment is expected on top of the chosen mechanism.
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Keep records of processing
- Assess high-risk projects
- Appoint a data protection officer
- Appoint a local representativeRequired for controllers and processors outside Europe that target or monitor people in Europe.
- Written vendor contract
What it costs if you get it wrong
- Percentage of global turnover: 4% of worldwide group turnoverUnlawful transfer, breach of basic principles or individual rights, defying a regulator order
- Fixed maximum fine: €20,000,000 — about $22 millionSame tier, whichever is higher
- Order to stopOrder to suspend transfers to a third country
- Claims by individualsCompensation claims by individuals
Sources
- Official sourceEUR-LexRegulation (EU) 2016/679 (General Data Protection Regulation)
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceData Protection CommissionTransfers of Personal Data to Third Countries or International Organisations
dataprotection.ie
Link checked 18 August 2026
National rules4 rules
Data Protection Act 2018
Act of parliament · No. 7 of 2018
Ireland's national privacy statute. It sets the digital age of consent at 16 and caps fines against public bodies at 1 million euro (about 1.1 million US dollars). It is only partly in force: section 30 has never been commenced.
Enforced by Data Protection Commission
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What it makes you do
- Get a parent's consent for children — applies at: under 16Section 31 sets the age for information society services at 16, the highest permitted in Europe.
- Appoint a data protection officer
- Secure the data
- Let people see their data
What it costs if you get it wrong
- Fixed maximum fine: €1,000,000 — about $1 millionFine on a public authority or public body that is not acting as a commercial undertaking
- Criminal liabilityRequiring a person to make a subject access request as a condition of recruitment or employment
Sources
- Official sourceOffice of the Attorney General, Irish Statute BookData Protection Act 2018, sections 31 and 141
irishstatutebook.ie
“The age of a child specified for the purposes of Article 8 is 16 years of age.”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookData Protection Act 2018 — commencement table, updated to 10 August 2026
irishstatutebook.ie
Link checked 18 August 2026
Data Protection Act 2018, section 30 — micro-targeting and profiling of children
Act of parliament · No. 7 of 2018, s. 30 · Social media and online platforms
An offence for any company to use a child's personal data for direct marketing, profiling or micro-targeting. Printed in Irish law since 2018 and never switched on. It is one ministerial order away from binding, and is widely and wrongly quoted as current law.
Enforced by Data Protection Commission
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What it makes you do
- No tracking or ads to childrenNOT YET IN FORCE. Requires a commencement order under section 1(3). Dormant since 2018.
What it costs if you get it wrong
- Criminal liabilityWould be an offence, punishable by administrative fine under section 141 — if commenced
Sources
- Official sourceOffice of the Attorney General, Irish Statute BookData Protection Act 2018, section 30 — micro-targeting and profiling of children
irishstatutebook.ie
“It shall be an offence under this Act for any company or corporate body to process the personal data of a child as defined by section 29 for the purposes of direct marketing, profiling or micro-targeting.”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookData Protection Act 2018 — commencement table showing section 30 not yet commenced
irishstatutebook.ie
“S. 30 — Not yet commenced. Commencement order required under s. 1(3)”
Link checked 18 August 2026
Companies Act 2014, sections 283 and 285
Act of parliament · No. 38 of 2014
Every Irish company may keep its accounting records on a foreign server, but it must send to Ireland, and keep in Ireland, information and returns detailed enough to show the assets, liabilities and profit or loss at least every six months. Everything must be kept for at least six years.
Enforced by Companies Registration Office
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep the data in the countryThe books themselves may live abroad, but summary information and returns must be sent to and kept at a place in Ireland, refreshed at least every six months.
- Keep data for a minimum period — 6 years
What it costs if you get it wrong
- Criminal liabilityFailure to keep adequate accounting records is an offence under the Companies Act
Sources
- Official sourceOffice of the Attorney General, Irish Statute BookCompanies Act 2014, section 283 — where accounting records are to be kept
irishstatutebook.ie
“If accounting records are kept at a place outside the State, there shall be sent to and kept at a place in the State such information and returns relating to the business dealt with in the accounting records so kept”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookCompanies Act 2014, section 285 — six-year retention
irishstatutebook.ie
Link checked 18 August 2026
National Cyber Security Bill — General Scheme published September 2024
Draft law · General Scheme only; transposes Directive (EU) 2022/2555 (NIS2)
Europe's cybersecurity directive should have been Irish law by 17 October 2024. As of 18 August 2026 no transposing Act appears in the Irish parliament's legislation database and the regulator's registration and incident reporting portals are still switched off. The older 2016 rules continue to apply to already-designated operators.
Enforced by National Cyber Security Centre
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Report cyber incidents — within 24 hoursNOT IN FORCE IN IRELAND. This is the deadline the directive would impose once transposed. Do not plan around it as a current Irish duty.
- Register or notifyThe registration portal is built but switched off pending legislation.
Sources
- Official sourceNational Cyber Security CentreNational Cyber Security Centre — NIS2 national steps
ncsc.gov.ie
“Unfortunately, the transposition deadline for NIS2 of 17 October 2024 has not been met. Ireland continues to work through the transposition requirements of the Directive.”
Link checked 18 August 2026
- Official sourceHouses of the OireachtasHouses of the Oireachtas — bills database, searched 18 August 2026 for a cybersecurity transposition Bill
oireachtas.ie
Link checked 18 August 2026
Industry rules8 rules
Criminal Justice (Money Laundering and Terrorist Financing) Act 2010, section 106
Act of parliament · No. 6 of 2010, s. 106 · Finance
The hardest data residency rule in Irish law. A trust or company service provider authorised by the Minister for Justice must keep prescribed records at an office or other premises inside Ireland for at least six years, and must tell the Minister where. Getting this wrong is a crime, not a fine.
Enforced by Department of Justice, Home Affairs and Migration
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep the data in the country — 6 yearsRecords must be held at an office or other premises in Ireland. Copies elsewhere are not prohibited, but the Irish copy is mandatory.
- Register or notifyThe address of the Irish premises where records are held must be notified in writing to the Minister.
- Keep data for a minimum period — 6 years
What it costs if you get it wrong
- Criminal liability: Unlimited fine or 5 years imprisonment on indictment; €5,000 or 12 months on summary conviction — about $6 thousandFailure to keep the records at Irish premises, or to notify the address
Sources
- Official sourceLaw Reform Commission of IrelandCriminal Justice (Money Laundering and Terrorist Financing) Act 2010, Revised Act, section 106
revisedacts.lawreform.ie
“The holder of an authorisation shall— (a) retain at an office or other premises in the State such records as may be specified by the Minister, and (b) notify the Minister in writing of the address of any office or other premises where those records are retained.”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookCriminal Justice (Money Laundering and Terrorist Financing) Act 2010, section 106 as enacted
irishstatutebook.ie
Link checked 18 August 2026
Criminal Justice (Money Laundering and Terrorist Financing) Act 2010, section 108I
Act of parliament · No. 6 of 2010, s. 108I, inserted by S.I. No. 600 of 2019 · Payments
Cheque-cashing offices registered with the Central Bank of Ireland must hold their records at premises inside Ireland for at least six years and tell the Central Bank the address. The duty carries on even after the firm deregisters or shuts down.
Enforced by Central Bank of Ireland
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep the data in the country — 6 yearsRecords specified by the Central Bank of Ireland must be held at an office or other premises in Ireland.
- Register or notifyThe address of the Irish premises must be notified in writing to the Central Bank of Ireland.
- Keep data for a minimum period — 6 yearsThe duty survives after the firm stops being registered or stops trading.
What it costs if you get it wrong
- Criminal liability: €500,000 or 3 years imprisonment on indictment — about $550 thousandFailure to keep the records at Irish premises or to notify the address
Sources
- Official sourceLaw Reform Commission of IrelandCriminal Justice (Money Laundering and Terrorist Financing) Act 2010, Revised Act, section 108I
revisedacts.lawreform.ie
“A person registered shall — (a) retain at an office or other premises in the State such records as may be specified by the Bank”
Link checked 18 August 2026
Health Information Act 2026
Act of parliament · No. 10 of 2026 · Health and social care
Ireland's new health records law, giving effect to the European Health Data Space. It creates an Electronic Health Record for every patient. Sharing that record with a country outside Europe needs a reciprocal arrangement agreed only after consulting the privacy regulator — but that section has not been switched on yet.
Enforced by Health Service Executive
Transfer model: Approval each time · Accepted routes: Government sign-off needed, Official 'this country is safe' decision, Standard contract clauses
What it makes you do
- Put a transfer safeguard in place — from 17 August 2026Section 18 is NOT yet commenced. Once it is, sharing an Electronic Health Record with a non-European country requires a reciprocal arrangement entered into only after consulting the Data Protection Commission.
- Tell people what you doPatients must be told about access to their Electronic Health Record. Sections 13 to 15 not yet commenced.
- Secure the data
What it costs if you get it wrong
- Order to stopEnforcement runs through the Health Service Executive and the Data Protection Commission rather than through a bespoke fine in the Act
Sources
- Official sourceOffice of the Attorney General, Irish Statute BookHealth Information Act 2026, section 18 — exchange with a third country
irishstatutebook.ie
“The Executive shall not enter into an arrangement or agreement under this section except after consultation with the Data Protection Commission.”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookHealth Information Act 2026 — commencement table, updated to 10 August 2026
irishstatutebook.ie
“Ss. 17 , 18 — [not yet commenced]”
Link checked 18 August 2026
- Official sourceHouses of the OireachtasHealth Information Bill 2024 — enacted as the Health Information Act 2026, signed 30 April 2026
oireachtas.ie
Link checked 18 August 2026
Data Protection Act 2018 (Section 36(2)) (Health Research) Regulations 2018
Directly binding regulation · S.I. No. 314 of 2018 · Health and social care
Health research in Ireland needs explicit consent from every participant before it starts. If you cannot get consent, you must apply to a government committee for a formal declaration waiving it. This sits on top of everything Europe's privacy law already requires.
Enforced by Health Research Consent Declaration Committee
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Explicit consent
What it makes you do
- Get consentExplicit consent must be obtained BEFORE the research starts. A waiver requires a declaration from the Health Research Consent Declaration Committee.
- Assess high-risk projectsAn assessment of the data protection implications of the research is mandatory.
- Independent auditEthical approval by a research ethics committee is required before the research is treated as commenced.
- Delete data after a periodArrangements to anonymise, archive or destroy the data once the research is complete.
What it costs if you get it wrong
- Order to stopProcessing without explicit consent or a declaration is unlawful and can be stopped by the Data Protection Commission
Sources
- Official sourceOffice of the Attorney General, Irish Statute BookS.I. No. 314/2018 — Health Research Regulations, Regulation 3(1)(e)
irishstatutebook.ie
“explicit consent has been obtained from the data subject, prior to the commencement of the health research, for the processing of his or her personal data for the purpose of specified health research”
Link checked 18 August 2026
- Official sourceHealth Research Consent Declaration CommitteeHealth Research Consent Declaration Committee — application process, decisions and appeals
hrcdc.ie
Link checked 18 August 2026
Communications (Retention of Data) Act 2011, as amended by the Communications (Retention of Data) (Amendment) Act 2022
Act of parliament · No. 3 of 2011; amendments commenced by S.I. No. 287 of 2023 · Telecoms
Ireland rebuilt its communications data retention regime after Europe's top court struck down blanket retention. Today providers must keep subscriber details for one year. Keeping who-called-whom and location records is not automatic: it only happens if the Minister for Justice gets a secret High Court order covering every provider in the country.
Enforced by Department of Justice, Home Affairs and Migration
Transfer model: No restriction · Accepted routes: Nothing required
What it makes you do
- Keep data for a minimum period — 1 yearSubscriber 'user data' for one year. The Minister may prescribe a different period, up to a maximum of two years.
- Keep logs — 1 yearDORMANT SWITCH. Traffic and location data are retained only where the Minister obtains an order from a designated High Court judge, applied for without notice and heard in private, requiring all service providers to retain the data for twelve months.
What it costs if you get it wrong
- Criminal liabilityFailure to comply with a retention or disclosure duty under the Act
Sources
- Official sourceLaw Reform Commission of IrelandCommunications (Retention of Data) Act 2011, Revised Act — sections 3, 3A, 3B and 12D
revisedacts.lawreform.ie
“An order under this subsection shall require all service providers to retain Schedule 2 data, or such Schedule 2 data as are specified in the order— (a) for a period of 12 months from the date on which the data were first processed by the service provider concerned”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookCommunications (Retention of Data) Act 2011 — amendments table showing the 2022 Act commenced on 26 June 2023
irishstatutebook.ie
Link checked 18 August 2026
European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011
Directly binding regulation · S.I. No. 336 of 2011 · Telecoms
The separate Irish rulebook for phone and internet providers. It adds its own breach reporting channel, a compulsory internal breach inventory, and a duty to wipe or anonymise connection records as soon as they are no longer needed for carrying or billing the call.
Enforced by Data Protection Commission
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What it makes you do
- Report breaches to the regulatorA separate telecoms breach channel and form, distinct from the general 72-hour route.
- Tell affected people
- Keep records of processingAn inventory of every personal data breach must be kept, recording the facts, the effects and the remedial action.
- Delete data after a periodTraffic data must be erased or made anonymous once it is no longer needed to carry or bill for the communication.
- Get consentConsent is needed to use traffic or location data for marketing or value-added services.
What it costs if you get it wrong
- Criminal liabilitySeveral duties under these Regulations are backed by criminal offences
- Order to stopEnforcement notice from the Data Protection Commission
Sources
- Official sourceOffice of the Attorney General, Irish Statute BookS.I. No. 336/2011 — ePrivacy Regulations, Regulations 4 and 6
irishstatutebook.ie
“Undertakings shall maintain an inventory of personal data breaches which shall comprise the following information— (a) the facts surrounding the breach, (b) the effects of the breach”
Link checked 18 August 2026
- Official sourceData Protection CommissionBreach Notification — separate telecoms form signposted by the regulator
dataprotection.ie
Link checked 18 August 2026
Online Safety Code
Statutory code of practice · Made by Coimisiún na Meán under Part 8A of the Broadcasting Act 2009 · Social media and online platforms
A binding Irish rulebook for video-sharing platforms, made by the media regulator. It forces age checks where adult content is allowed and bans certain advertising aimed at children. Because so many platforms are headquartered in Dublin, this code reaches far beyond Ireland.
Enforced by Coimisiún na Meán
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What it makes you do
- Get a parent's consent for childrenAge assurance systems are required where the service permits adult-only video content.
- No tracking or ads to childrenRestrictions on advertising directed at children, including alcohol displays aimed at children.
- Tell people what you doProtections must be written into and applied through the service's terms and conditions.
What it costs if you get it wrong
- Percentage of global turnover: Up to 10% of turnover under the Irish online safety regimeContravention of an online safety code
Sources
- Official sourceCoimisiún na MeánOnline Safety Code
cnam.ie
“The Code requires children to be protected from: video content that may impair their physical, mental, or moral development; and adult-only video content, including pornography and gross or gratuitous violence.”
Link checked 18 August 2026
- Official sourceCoimisiún na MeánLegislation explained — publication of the Online Safety Code
cnam.ie
“The Online Safety Code (OSC) was published in October 2024.”
Link checked 18 August 2026
Regulation of Artificial Intelligence Act 2026
Act of parliament · No. 31 of 2026; commenced by S.I. No. 403 of 2026 · Artificial intelligence
Ireland's law putting the European Artificial Intelligence Act into effect. It created a national artificial intelligence office, Oifig IS na hÉireann, and switched on almost all of its provisions on 31 July 2026. One part of the market surveillance definition is still not commenced.
Enforced by Ireland's AI Office — not yet operational
Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What it makes you do
- Check your algorithms — from 31 July 2026
- Register or notifyMarket surveillance and notification structures for artificial intelligence systems sit with designated Irish authorities.
What it costs if you get it wrong
- Percentage of global turnoverPenalties flow from the European Artificial Intelligence Act, which this Act enforces in Ireland
Sources
- Official sourceOffice of the Attorney General, Irish Statute BookRegulation of Artificial Intelligence Act 2026 — commencement table and establishment day order (S.I. No. 404 of 2026)
irishstatutebook.ie
“Ss. 1 - 77 — 31 July 2026”
Link checked 18 August 2026
- Official sourceHouses of the OireachtasRegulation of Artificial Intelligence Bill 2026 — enacted 21 July 2026
oireachtas.ie
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.
The exact date on which the age assurance measures in the Online Safety Code began to apply to video-sharing platforms.
Coimisiún na Meán's own pages confirm the Code was published in October 2024 but do not state the deferred application date for the age assurance measures in text we could read. The Code PDF did not yield reliable machine-readable text. Rule confidence lowered to medium.
Whether any order under section 3A of the Communications (Retention of Data) Act 2011 is currently in force, requiring providers to retain traffic and location data.
Such orders are applied for without notice and heard in private, and are publicised in the national media and Iris Oifigiúil only after being made. No current order was located on a government domain on 18 August 2026. Treat the power as live and the current state as unknown.
That Ireland has not transposed the NIS2 cybersecurity directive.
This is a negative. It rests on the National Cyber Security Centre's own NIS2 page, which was last updated 24 June 2025 and says the deadline was missed, plus a search of the Houses of the Oireachtas legislation database on 18 August 2026 which returned no cybersecurity transposition Bill among 622 bills since 2024. A statutory instrument route would not appear in that database. Confidence medium.
That there is no data localisation rule for mapping and geospatial data, education, defence or online gaming in Ireland.
No rule found, checked 18 August 2026. This is an absence of evidence rather than evidence of absence; the web search budget for this run was exhausted early and verification relied on direct fetches from official domains, which cannot rule out an obscure licence condition.
The precise scope of records that the Minister for Justice has prescribed for trust and company service providers under section 106, and that the Central Bank has specified for cheque-cashing offices under section 108I.
Both sections require records 'as may be specified'. The specifying instruments were not located on a government domain during this run, so the practical breadth of the in-State duty is not pinned down.
Whether the Central Bank of Ireland's Cross-Industry Guidance on Outsourcing contains any expectation about the geographic location of outsourced data.
The Central Bank's own outsourcing landing pages returned 404 and the guidance PDF was not reachable at the expected path. The register submission page confirms the guidance exists and dates from December 2021, but its contents were not verified in this run.
Whether the fine ceiling stated for breaches of the Online Safety Code is accurate.
The percentage-of-turnover figure was not verified against the Broadcasting Act 2009 text on a government domain during this run. The penalty entry should be treated as indicative only.
Freshness and refresh
Freshness
Checked today — on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.
Compare with
- Ireland versus Argentina
- Ireland versus Armenia
- Ireland versus Australia
- Ireland versus Austria
- Ireland versus Azerbaijan
- Ireland versus Brazil
- Ireland versus Bulgaria
- Ireland versus Cambodia
- Ireland versus Canada
- Ireland versus China
- Ireland versus Croatia
- Ireland versus Cyprus
- Ireland versus Estonia
- Ireland versus France
- Ireland versus Georgia
- Ireland versus Germany
- Ireland versus Greece
- Ireland versus Hong Kong SAR
- Ireland versus Hungary
- Ireland versus Iceland
- Ireland versus India
- Ireland versus Indonesia
- Ireland versus Israel
- Ireland versus Italy
- Ireland versus Japan
- Ireland versus Latvia
- Ireland versus Lithuania
- Ireland versus Luxembourg
- Ireland versus Malta
- Ireland versus Mexico
- Ireland versus Mongolia
- Ireland versus Nepal
- Ireland versus Netherlands
- Ireland versus Poland
- Ireland versus Russia
- Ireland versus Saudi Arabia
- Ireland versus Serbia
- Ireland versus Singapore
- Ireland versus Slovakia
- Ireland versus Slovenia
- Ireland versus South Korea
- Ireland versus Spain
- Ireland versus Sri Lanka
- Ireland versus Sweden
- Ireland versus Switzerland
- Ireland versus Taiwan
- Ireland versus Thailand
- Ireland versus Turkey
- Ireland versus Ukraine
- Ireland versus United Arab Emirates
- Ireland versus United Kingdom
- Ireland versus United States
- Ireland versus Uzbekistan