Ireland
Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.
If you collect data about people in Ireland — customers, users, employees — these are the rules you have to follow. Here is the short version.
The short version
Ireland follows Europe's rules, so personal data can leave the country once you have the right paperwork in place. But a handful of Irish laws force certain records to be kept physically in Ireland. Breaking those is a crime rather than a fine. Ireland's privacy regulator is one of the toughest in Europe. In 2025 it fined TikTok 530 million euro and ordered it to stop sending data to China.
Data governance in Ireland
The eight things that decide how you handle data about people in Ireland. Same eight on every country page, so you can compare.
Who has to follow these rules
Yes. Ireland's data protection law reaches a company with no office in Ireland. It applies whenever you offer goods or services to people in Europe, or watch what they do online. There is no revenue or staff-count limit to duck under. A company based outside Europe normally has to name a representative inside Europe. Regulators and members of the public can write to that representative.
- What you have to do here:
- Appoint a representative
The Data Protection Act 2018 gives effect to the General Data Protection Regulation. The Regulation itself sets out who is caught. Ireland matters far more than its size suggests, because so many large technology companies put their European headquarters in Dublin. That makes the Irish Data Protection Commission their 'lead supervisory authority' under the one-stop-shop system. In that role the Commission closed 208 valid cross-border complaints in 2025, up 43 per cent on 2024. It also opened an inquiry of its own into X Internet Unlimited Company on 17 February 2026.
Sources
- Official sourceOffice of the Attorney General, Irish Statute BookData Protection Act 2018 (No. 7 of 2018) — full text
irishstatutebook.ie
Link checked 18 August 2026
- Official sourceData Protection CommissionData Protection Commission publishes Annual Report for 2025, 30 June 2026 — cross-border caseload as lead supervisory authority
dataprotection.ie
“The DPC concluded 208 valid cross-border complaints (as EU/EEA Lead Supervisory Authority). This represented a 43% increase on 2024.”
Link checked 18 August 2026
- Official sourceData Protection CommissionData Protection Commission press releases — inquiry opened into X Internet Unlimited Company, 17 February 2026
dataprotection.ie
Link checked 18 August 2026
Where the data is allowed to live
In general, yes, with paperwork. Ireland has no general rule saying personal data must stay in the country. You may send it outside Europe once you use one of the approved legal routes. But several Irish laws quietly require particular records to sit on Irish soil. Those override the general answer.
- What you have to do here:
- Keep the data in the country
Industry by industry, checked 18 August 2026. BANKING, PAYMENTS, INSURANCE, SECURITIES: allowed with conditions. We found no Irish rule that data must stay in the country. The Central Bank of Ireland works through its Cross-Industry Guidance on Outsourcing and through the European Digital Operational Resilience Act. Both require you to know and disclose where your data sits. Neither requires you to keep it here. The Central Bank paused its own outsourcing register collection in 2025. It will resume in February 2027, with a reference date of 31 December 2026. ANTI-MONEY-LAUNDERING REGULATED FIRMS: a copy must stay in Ireland, and this is the real Irish restriction. Take a trust or company service provider authorised by the Minister for Justice. It must keep prescribed records 'at an office or other premises in the State' for at least six years. It must also tell the Minister the address where they are held. A cheque-cashing office registered with the Central Bank has the same duty. Breaking either is a crime. The equivalent duty for ordinary designated persons was removed in 2013. See the traps. ALL COMPANIES: a copy must stay in Ireland. You may keep accounting records outside Ireland. But you must send information and returns to Ireland, and keep them there. They must be good enough to show the assets, liabilities and profit or loss at intervals of no more than six months. HEALTH: allowed with conditions, and tightening. The Health Information Act 2026 lets the Health Service Executive share an Electronic Health Record with a country outside Europe only through a reciprocal arrangement. It must consult the Data Protection Commission first. That part of the Act is not yet in force. TELECOMS: allowed with conditions. Service providers must keep subscriber 'user data' for one year. Keeping traffic and location data is not general. It happens only if the Minister obtains a High Court order. GOVERNMENT AND PUBLIC SECTOR: allowed with conditions. The Data Sharing and Governance Act 2019 controls sharing between public bodies through written data-sharing agreements. We found no requirement in that Act that data stay in Ireland. MAPPING AND GEOSPATIAL, EDUCATION, DEFENCE, GAMING: we found no Irish rule that data must stay in the country, checked 18 August 2026. Confidence medium. The gambling regulator's record-keeping regulations were still out for public consultation until 20 August 2026 and have not been made.
Sources
- Official sourceLaw Reform Commission of IrelandCriminal Justice (Money Laundering and Terrorist Financing) Act 2010, Revised Act — sections 55, 106 and 108I
revisedacts.lawreform.ie
“The holder of an authorisation shall— (a) retain at an office or other premises in the State such records as may be specified by the Minister, and (b) notify the Minister in writing of the address of any office or other premises where those records are retained.”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookCompanies Act 2014, section 283 — where accounting records are to be kept
irishstatutebook.ie
“If accounting records are kept at a place outside the State, there shall be sent to and kept at a place in the State such information and returns relating to the business dealt with in the accounting records so kept as will— (a) disclose with reasonable accuracy the assets, liabilities, financial position and profit or loss of that business at intervals not exceeding 6 months”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookHealth Information Act 2026, section 18 — electronic exchange of Electronic Health Record information with a third country
irishstatutebook.ie
“The Executive shall not enter into an arrangement or agreement under this section except after consultation with the Data Protection Commission.”
Link checked 18 August 2026
- Official sourceCentral Bank of IrelandOutsourcing Registers — Submission Requirements
centralbank.ie
“The Central Bank of Ireland will resume the domestic collection of Outsourcing Registers in February 2027.”
Link checked 18 August 2026
What to do: Check your own industry against the restricted list before you pick a hosting region.
Sending data out of the country
Ireland uses the European model. A destination outside Europe is off limits unless it is on the European Commission's approved list, or you put an approved safeguard in place first. The approved list is real and populated: it currently covers seventeen destinations, including the United Kingdom, Japan, South Korea, Switzerland and Brazil. The United States counts only for companies that have signed up to the European Union to United States Data Privacy Framework.
- Ways to send data out:
- Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Certification scheme · Approved code of conduct · Explicit consent · Needed for a contract · Legal claims
The Irish regulator's own guidance sets out the order to work through. First, is the destination on the European Commission's list of countries decided to be safe enough. If not, use an approved safeguard. That usually means one of five things. The 2021 standard contract clauses. Company-wide binding rules. An approved code of conduct. An approved certification. Or a binding legal agreement between public bodies. Only then come the narrow exceptions in the Regulation. The regulator says those must not be your first port of call. Separately, Regulation (EU) 2018/1807 stops member states from requiring non-personal data to stay in the country, except on public security grounds. That is why Ireland's few in-country storage rules are all attached to specific record-keeping duties rather than to data in general. The one unstable piece is the European Union to United States Data Privacy Framework. It is still in force and legally valid today. But it is under appeal at the Court of Justice. And on 31 July 2026 the European Data Protection Board formally wrote to the Commission, asking it to look again at whether the decision holds. You can use it today. Never use it as your only route.
Sources
- Official sourceData Protection CommissionTransfers of Personal Data to Third Countries or International Organisations — Irish regulator's guidance, listing an approved Binding Corporate Rules list dated July 2026
dataprotection.ie
“The effect of such a decision is that personal data can flow from the EEA to that third country without any further safeguard being necessary.”
Link checked 18 August 2026
- Official sourceEuropean CommissionAdequacy decisions — the populated approved-destination list
commission.europa.eu
Link checked 18 August 2026
- Official sourceEUR-LexCommission Implementing Decision (EU) 2021/914 — Standard Contractual Clauses
eur-lex.europa.eu
Link checked 18 August 2026
What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.
The regulator, and whether it actually acts
The Data Protection Commission, and it is very much awake. It has three commissioners in post. They are Des Hogan as chairperson, Dale Sunderland and Niamh Sweeney. It published its 2025 annual report on 30 June 2026. In 2025 it finished four large inquiries and imposed fines of just over 530 million euro (about 580 million US dollars). Almost all of that fell on TikTok. It also ordered TikTok to stop sending European user data to China.
- What it costs if you get it wrong:
- Percentage of global turnover · Order to stop
Here is the evidence that it is working, all from the regulator's own site. It received 16,160 new cases in 2025, a 45 per cent rise. It closed 11,734 cases. It received 6,521 valid breach notifications. It closed 275 electronic direct marketing investigations, an 88 per cent rise. It sent 50 warning letters about unsolicited marketing. Recent decisions include Permanent TSB on 8 May 2026 and Midlands Regional Hospital Tullamore on 15 June 2026. It has open inquiries of its own into X Internet Unlimited Company, from February 2026, and Children's Health Ireland, from August 2025. The Commission also went after a government department. In June 2025 it reprimanded the Department of Social Protection over facial recognition in the Public Services Card scheme. It fined the Department 550,000 euro (about 600,000 US dollars) and ordered it to stop using face data within nine months. Other regulators that matter. The Central Bank of Ireland supervises financial firms and their outsourcing. Coimisiún na Meán regulates video-sharing platforms under the Online Safety Code and is the Irish Digital Services Coordinator. The Gambling Regulatory Authority of Ireland was formally set up in March 2025. It published its first annual report and invited its first remote betting licence applications in February 2026. The Health Research Consent Declaration Committee sits under the Department of Health and publishes decisions. The National Cyber Security Centre exists and runs the national incident response team. It does not yet have powers under the European cybersecurity directive known as NIS2, because Ireland has not written that directive into Irish law.
Sources
- Official sourceData Protection CommissionData Protection Commission publishes Annual Report for 2025, 30 June 2026
dataprotection.ie
“The DPC finalised 4 large scale inquiries in 2025 and imposed administrative fines totalling just over €530.77m and multiple reprimands and compliance orders”
Link checked 18 August 2026
- Official sourceData Protection CommissionData Protection Commission press releases — commissioners named, decisions in May and June 2026
dataprotection.ie
“Commissioners for Data Protection, Dr Des Hogan (Chairperson), Mr Dale Sunderland and Ms Niamh Sweeney”
Link checked 18 August 2026
- Official sourceGambling Regulatory Authority of IrelandGambling Regulatory Authority of Ireland — first annual report and phased licensing
grai.ie
“Formally established in March 2025, the GRAI's role is to licence, supervise and control gambling activities as set out in the Gambling Regulation Act 2024.”
Link checked 18 August 2026
- Official sourceNational Cyber Security CentreNational Cyber Security Centre — NIS2 page, transposition status
ncsc.gov.ie
“Unfortunately, the transposition deadline for NIS2 of 17 October 2024 has not been met.”
Link checked 18 August 2026
How long you must keep it — and when to delete it
Rules run in both directions, and Ireland's minimum periods are longer than most people expect. Anti-money-laundering customer records must be kept for at least five years. Company accounting records and returns must be kept for at least six years. Trust and company service providers and cheque-cashing firms must keep their records for six years, and keep them in Ireland. Telephone and internet providers must keep subscriber details for one year.
- What you have to do here:
- Keep data for a minimum period · Delete data after a period · Keep the data in the country
MINIMUMS, all verified against the laws. Anti-money-laundering: a designated person must keep customer checks and transaction records for at least five years after the relationship or transaction ends. Trust and company service providers: at least six years, at premises in the State, with the address notified to the Minister for Justice. Cheque-cashing offices registered with the Central Bank: the same six years in the State. Breaking that carries a fine of up to 500,000 euro (about 550,000 US dollars) or three years in prison in the more serious cases. Companies: accounting records must be kept for at least six years after the end of the financial year they relate to. So must the information and returns that have to stay in Ireland where the books are abroad. Telecoms: subscriber 'user data' for one year, which the Minister can extend by regulation to a maximum of two years. Traffic and location data for twelve months, but only where a High Court judge has made an order on the Minister's application. MAXIMUMS. The general European rule is that you keep personal data no longer than you need it. Telecoms have a sharper rule. Traffic data must be erased or made anonymous once it is no longer needed to carry or bill for the communication. CONFLICT. Ireland settles a clash the same way the rest of Europe does. A keeping period set by law is a legal duty, which is a lawful reason to keep the data. It beats a deletion request for as long as the duty runs. The trap is the location, not the length. A six-year duty that also says 'in the State' is not satisfied by a cloud region abroad plus the ability to restore from it.
Sources
- Official sourceLaw Reform Commission of IrelandCriminal Justice (Money Laundering and Terrorist Financing) Act 2010, Revised Act — sections 55(4), 106(3) and 108I(3)
revisedacts.lawreform.ie
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookCompanies Act 2014, section 285 — retention of accounting records
irishstatutebook.ie
“shall be preserved by the company concerned for a period of at least 6 years after the end of the financial year containing the latest date to which the record, information or return relates.”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookCommunications (Retention of Data) (Amendment) Act 2022, section 3 — one-year retention of user data
irishstatutebook.ie
“A service provider shall retain, in accordance with section 12D, user data for a period of one year”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookS.I. No. 336/2011 — ePrivacy Regulations, Regulation 6(1), erasure of traffic data
irishstatutebook.ie
“an undertaking shall ensure that traffic data relating to subscribers and users processed and stored for the purpose of the transmission of a communication shall be erased or made anonymous when it is no longer needed for that purpose.”
Link checked 18 August 2026
What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.
If something goes wrong
Count three deadlines, not one. You have 72 hours to tell the Data Protection Commission about a personal data breach that puts people at risk. You must tell the affected people without delay if the risk is high. Telephone and internet providers report through a separate channel, under separate rules. And if the police send you an order to take down terrorist content, you have one hour.
- What you have to do here:
- Report breaches to the regulator · Tell affected people · Report cyber incidents · Keep records of how you use data
CLOCK ONE. You have 72 hours to tell the Data Protection Commission about a personal data breach that puts people at risk. The clock starts the moment you become aware of it. You must also tell the people themselves without undue delay where the risk to them is high. The Commission received 6,521 valid breach notifications in 2025. This is a well-worn path rather than a theoretical duty. CLOCK TWO. Providers of public electronic communications networks or services have their own duty under the 2011 ePrivacy Regulations. They must tell the Commission without undue delay, using a separate telecoms breach form. They must also keep an internal list of every breach, recording the facts, the effects and what they did about it. Your general privacy playbook does not cover this. The regulator flags it as separate. CLOCK THREE. One hour to remove terrorist content after you get a removal order from An Garda Síochána, the Irish police. That comes from the European terrorist content online rules. WHAT IS MISSING. The European cybersecurity directive known as NIS2 would add a 24-hour early warning and a 72-hour incident report for covered organisations. Ireland has not written it into Irish law, so those deadlines do not run here yet. The older 2016 duties still apply to operators of essential services already designated in Ireland.
Sources
- Official sourceData Protection CommissionBreach Notification — Irish regulator's guidance, including the separate telecoms channel
dataprotection.ie
“Organisations must do this within 72 hours of becoming aware of the breach.”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookS.I. No. 336/2011 — ePrivacy Regulations, Regulation 4(6) and 4(12), telecoms breach notification and breach inventory
irishstatutebook.ie
“Where there has been a personal data breach, the undertaking shall, without undue delay— (a) notify the Commissioner of the said breach”
Link checked 18 August 2026
- Official sourceCoimisiún na MeánLegislation explained — terrorist content removal orders
cnam.ie
“The platform has one hour to remove the content once the Removal Order has been received.”
Link checked 18 August 2026
- Official sourceNational Cyber Security CentreNational Cyber Security Centre — NIS2 not yet transposed, reporting portal not available
ncsc.gov.ie
“The NIS2 registration and incident reporting portals are not available at this time.”
Link checked 18 August 2026
What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.
What catches people out
Five things that cost people their weekend. First, Ireland's famous ban on advertising to children has never come into force. Second, the official copy of the law on the government's own statute website can be out of date and misleading. Third, a child in Ireland is anyone under 16 for consent, not 13. Fourth, some record-keeping failures are crimes, not fines. Fifth, the regulator can only fine a public body up to 1 million euro (about 1.1 million US dollars), so it uses stop orders instead.
- What you have to do here:
- No tracking or ads to children · Get consent
- What it costs if you get it wrong:
- Criminal liability · Fixed maximum fine
TRAP 1. The Data Protection Act 2018 makes it an offence for a company to use a child's personal data for direct marketing, profiling or micro-targeting. It has been in the law since 2018. As of 18 August 2026 the Irish Statute Book's own table records it as 'Not yet commenced. Commencement order required under s. 1(3).' It is one signature away from being live. It does not bind anyone today. TRAP 2. The as-enacted text on the official statute website is not the law in force. The as-enacted version of the anti-money-laundering Act still says records must be kept 'at an office or other premises in the State'. Those words were removed by the Criminal Justice Act 2013, with effect from 14 June 2013. A plain text search of the government's own site turns up a rule that has not existed for thirteen years. Always check the consolidated Revised Act. TRAP 3. Ireland set its digital age of consent at 16. That is the highest the General Data Protection Regulation allows. A consent flow built for 13-year-olds fails here. TRAP 4. Criminal, not administrative. A trust or company service provider that fails to keep its records at Irish premises commits an offence. In the more serious cases it carries a fine or up to five years in prison. A cheque-cashing office faces up to 500,000 euro (about 550,000 US dollars) or three years. Separately, disclosing identifiable information collected by the Central Statistics Office is banned outright. TRAP 5. The fine cap for the public sector. Where the Commission fines a public authority or public body that is not acting as a business, the fine cannot exceed 1 million euro. That is why enforcement against Irish state bodies arrives as an order to stop rather than a large fine. The Department of Social Protection was ordered in June 2025 to stop using face data within nine months. TRAP 6. Health research in Ireland needs explicit consent from each participant before the research starts. That is on top of everything the General Data Protection Regulation requires. If you cannot get consent, you must apply to the Health Research Consent Declaration Committee for a declaration waiving it. There is no quiet 'legitimate interests' route.
Sources
- Official sourceOffice of the Attorney General, Irish Statute BookData Protection Act 2018 — commencement table, section 30 not yet commenced
irishstatutebook.ie
“S. 30 — Not yet commenced. Commencement order required under s. 1(3)”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookData Protection Act 2018, section 141(4) — 1 million euro cap on fines against public bodies
irishstatutebook.ie
“the amount of the administrative fine concerned shall not exceed €1,000,000.”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookCriminal Justice (Money Laundering and Terrorist Financing) Act 2010, section 55 as enacted — the superseded 'in the State' wording
irishstatutebook.ie
“shall be retained by the designated person, at an office or other premises in the State, for a period of not less than 5 years”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookS.I. No. 314/2018 — Health Research Regulations, Regulation 3(1)(e) explicit consent and Regulation 7 consent declaration committee
irishstatutebook.ie
“explicit consent has been obtained from the data subject, prior to the commencement of the health research, for the processing of his or her personal data for the purpose of specified health research”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookStatistics Act 1993, section 33 — prohibition on disclosure of identifiable statistical information
irishstatutebook.ie
Link checked 18 August 2026
What's changing next
Three things land in the next year. Ireland's new health records law is coming into force in stages. The parts that let doctors share your file are still switched off. So is the part that allows sharing with countries outside Europe. Europe's cloud switching rules make all data exit fees zero on 12 January 2027. And Ireland still has not written the European cybersecurity directive into Irish law, almost two years past the deadline.
- What you have to do here:
- Make switching cloud provider possible
WITH DATES, CONFIRMED. 17 August 2026: the first parts of the Health Information Act 2026 came into force. That includes the Health Service Executive's power to create an Electronic Health Record for every patient. Three sets of rules still need commencement orders. The duty on providers to share patient data. The rules on access and restrictions. And the rules on permitted uses and exchange with countries outside Europe. 31 July 2026: almost all of the Regulation of Artificial Intelligence Act 2026 came into force. Ireland's new artificial intelligence office, Oifig IS na hÉireann, was formally set up. One limb of the market surveillance definition is still not in force. 20 August 2026: the gambling regulator's consultation on record-keeping regulations for licence holders closed. Regulations are expected to follow. 12 January 2027: under the European Data Act, all cloud switching charges and fees for moving your data out must fall to zero. 28 February 2027: Central Bank of Ireland outsourcing registers must be submitted, with a data reference date of 31 December 2026. The Bank will contact firms in the last quarter of 2026. OVERDUE. The European cybersecurity directive known as NIS2 should have been in Irish law by 17 October 2024. A General Scheme was published in September 2024. No Bill appears in the Oireachtas legislation database as of 18 August 2026. The regulator's registration and incident reporting portals are still switched off. POWERS ALREADY HELD, which could change the answer with no consultation. 1. The Minister for Justice can apply, without notice and in private, to a designated High Court judge. The order can compel every telecoms and internet provider in Ireland to keep traffic and location data for twelve months. It is made public only afterwards. 2. A single commencement order would switch on the criminal ban on profiling and micro-targeting children that has been unused since 2018. 3. The Minister may make regulations setting technical requirements for how kept communications data is held. That is the natural place for any future in-country storage condition. 4. The Minister for Health may make regulations governing access to Electronic Health Records under the Health Information Act 2026.
Sources
- Official sourceOffice of the Attorney General, Irish Statute BookHealth Information Act 2026 — commencement table, updated to 10 August 2026
irishstatutebook.ie
“Ss. 7 - 9 — Not yet commenced. Commencement order required under s. 1(2)”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookRegulation of Artificial Intelligence Act 2026 — commencement table and establishment day order
irishstatutebook.ie
“Ss. 1 - 77 — 31 July 2026 — Regulation of Artificial Intelligence Act 2026 (Commencement) Order 2026 (S.I. No. 403 of 2026), art. 2”
Link checked 18 August 2026
- Official sourceNational Cyber Security CentreNational Cyber Security Centre — NIS2 transposition status
ncsc.gov.ie
“Ireland continues to work through the transposition requirements of the Directive.”
Link checked 18 August 2026
- Official sourceLaw Reform Commission of IrelandCommunications (Retention of Data) Act 2011, Revised Act — section 3A, ministerial application for a retention order
revisedacts.lawreform.ie
“An order under this subsection shall require all service providers to retain Schedule 2 data ... for a period of 12 months from the date on which the data were first processed”
Link checked 18 August 2026
- Official sourceCentral Bank of IrelandOutsourcing Registers — 2027 collection, deadline 28 February 2027
centralbank.ie
Link checked 18 August 2026
What to do: Diarise 12 January 2027 — that is the date this changes.
The actual laws
Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.
Applies only to certain industries8 rules
If your product does one of these things, read this group first — industry rules beat the general position.
Finance data needs a copy kept in the country
Official name: Criminal Justice (Money Laundering and Terrorist Financing) Act 2010, section 106 · No. 6 of 2010, s. 106 · Act of parliament
The strictest rule in Irish law about where data must sit. It covers a trust or company service provider authorised by the Minister for Justice. That firm must keep prescribed records at an office or other premises inside Ireland for at least six years. It must also tell the Minister where. Getting this wrong is a crime, not a fine.
Enforced by Department of Justice, Home Affairs and Migration
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep the data in the country — 6 yearsRecords must be held at an office or other premises in Ireland. Copies elsewhere are allowed, but the Irish copy is compulsory.
- Register or notifyThe address of the Irish premises where records are held must be notified in writing to the Minister.
- Keep data for a minimum period — 6 years
What it costs if you get it wrong
- Criminal liability: Unlimited fine or 5 years imprisonment on indictment; €5,000 or 12 months on summary conviction — about $6 thousandFailure to keep the records at Irish premises, or to notify the address
Sources
- Official sourceLaw Reform Commission of IrelandCriminal Justice (Money Laundering and Terrorist Financing) Act 2010, Revised Act, section 106
revisedacts.lawreform.ie
“The holder of an authorisation shall— (a) retain at an office or other premises in the State such records as may be specified by the Minister, and (b) notify the Minister in writing of the address of any office or other premises where those records are retained.”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookCriminal Justice (Money Laundering and Terrorist Financing) Act 2010, section 106 as enacted
irishstatutebook.ie
Link checked 18 August 2026
Payments data needs a copy kept in the country
Official name: Criminal Justice (Money Laundering and Terrorist Financing) Act 2010, section 108I · No. 6 of 2010, s. 108I, inserted by S.I. No. 600 of 2019 · Act of parliament
Cheque-cashing offices registered with the Central Bank of Ireland must hold their records at premises inside Ireland for at least six years. They must tell the Central Bank the address. The duty carries on even after the firm deregisters or shuts down.
Enforced by Central Bank of Ireland
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep the data in the country — 6 yearsRecords specified by the Central Bank of Ireland must be held at an office or other premises in Ireland.
- Register or notifyThe address of the Irish premises must be notified in writing to the Central Bank of Ireland.
- Keep data for a minimum period — 6 yearsThe duty survives after the firm stops being registered or stops trading.
What it costs if you get it wrong
- Criminal liability: €500,000 or 3 years imprisonment on indictment — about $550 thousandFailure to keep the records at Irish premises or to notify the address
Sources
- Official sourceLaw Reform Commission of IrelandCriminal Justice (Money Laundering and Terrorist Financing) Act 2010, Revised Act, section 108I
revisedacts.lawreform.ie
“A person registered shall — (a) retain at an office or other premises in the State such records as may be specified by the Bank”
Link checked 18 August 2026
Health data rules
Official name: Health Information Act 2026 · No. 10 of 2026 · Act of parliament
Ireland's new health records law, giving effect to the European Health Data Space. It creates an Electronic Health Record for every patient. Sharing that record with a country outside Europe needs a reciprocal arrangement, agreed only after consulting the privacy regulator. That part has not come into force yet.
Enforced by Health Service Executive
How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Official 'this country is safe' decision, Standard contract clauses
What you have to do
- Put a transfer safeguard in place — from 17 August 2026NOT yet in force. Once it is, sharing an Electronic Health Record with a country outside Europe will need a reciprocal arrangement. That arrangement can only be entered into after consulting the Data Protection Commission.
- Tell people what you doPatients must be told about access to their Electronic Health Record. That part is not yet in force.
- Secure the data
What it costs if you get it wrong
- Order to stopEnforcement runs through the Health Service Executive and the Data Protection Commission rather than through a bespoke fine in the Act
Sources
- Official sourceOffice of the Attorney General, Irish Statute BookHealth Information Act 2026, section 18 — exchange with a third country
irishstatutebook.ie
“The Executive shall not enter into an arrangement or agreement under this section except after consultation with the Data Protection Commission.”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookHealth Information Act 2026 — commencement table, updated to 10 August 2026
irishstatutebook.ie
“Ss. 17 , 18 — [not yet commenced]”
Link checked 18 August 2026
- Official sourceHouses of the OireachtasHealth Information Bill 2024 — enacted as the Health Information Act 2026, signed 30 April 2026
oireachtas.ie
Link checked 18 August 2026
Health data rules (Health and social care)
Official name: Data Protection Act 2018 (Section 36(2)) (Health Research) Regulations 2018 · S.I. No. 314 of 2018 · Directly binding regulation
Health research in Ireland needs explicit consent from every participant before it starts. If you cannot get consent, you must apply to a government committee for a formal declaration waiving it. This sits on top of everything Europe's privacy law already requires.
Enforced by Health Research Consent Declaration Committee
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Explicit consent
What you have to do
- Get consentExplicit consent must be obtained BEFORE the research starts. A waiver requires a declaration from the Health Research Consent Declaration Committee.
- Assess high-risk projectsAn assessment of the data protection implications of the research is mandatory.
- Independent auditEthical approval by a research ethics committee is required before the research is treated as commenced.
- Delete data after a periodArrangements to anonymise, archive or destroy the data once the research is complete.
What it costs if you get it wrong
- Order to stopProcessing without explicit consent or a declaration is unlawful and can be stopped by the Data Protection Commission
Sources
- Official sourceOffice of the Attorney General, Irish Statute BookS.I. No. 314/2018 — Health Research Regulations, Regulation 3(1)(e)
irishstatutebook.ie
“explicit consent has been obtained from the data subject, prior to the commencement of the health research, for the processing of his or her personal data for the purpose of specified health research”
Link checked 18 August 2026
- Official sourceHealth Research Consent Declaration CommitteeHealth Research Consent Declaration Committee — application process, decisions and appeals
hrcdc.ie
Link checked 18 August 2026
Telecoms rules
Official name: Communications (Retention of Data) Act 2011, as amended by the Communications (Retention of Data) (Amendment) Act 2022 · No. 3 of 2011; amendments commenced by S.I. No. 287 of 2023 · Act of parliament
Ireland rebuilt its rules on keeping communications data after Europe's top court struck down blanket keeping. Today providers must keep subscriber details for one year. Keeping who-called-whom and location records is not automatic. It happens only if the Minister for Justice gets a secret High Court order covering every provider in the country.
Enforced by Department of Justice, Home Affairs and Migration
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep data for a minimum period — 1 yearSubscriber 'user data' for one year. The Minister may prescribe a different period, up to a maximum of two years.
- Keep logs — 1 yearA POWER ALREADY HELD, currently unused. Traffic and location data are kept only where the Minister obtains an order from a designated High Court judge. The application is made without notice and heard in private. The order requires all service providers to keep the data for twelve months.
What it costs if you get it wrong
- Criminal liabilityFailure to comply with a retention or disclosure duty under the Act
Sources
- Official sourceLaw Reform Commission of IrelandCommunications (Retention of Data) Act 2011, Revised Act — sections 3, 3A, 3B and 12D
revisedacts.lawreform.ie
“An order under this subsection shall require all service providers to retain Schedule 2 data, or such Schedule 2 data as are specified in the order— (a) for a period of 12 months from the date on which the data were first processed by the service provider concerned”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookCommunications (Retention of Data) Act 2011 — amendments table showing the 2022 Act commenced on 26 June 2023
irishstatutebook.ie
Link checked 18 August 2026
Telecoms rules (Telecoms)
Official name: European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011 · S.I. No. 336 of 2011 · Directly binding regulation
The separate Irish rulebook for phone and internet providers. It adds its own breach reporting channel and a compulsory internal breach list. It also adds a duty to wipe or anonymise connection records. That applies as soon as they are no longer needed for carrying or billing the call.
Enforced by Data Protection Commission
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What you have to do
- Report breaches to the regulatorA separate telecoms breach channel and form, distinct from the general 72-hour route.
- Tell affected people
- Keep records of how you use dataAn inventory of every personal data breach must be kept, recording the facts, the effects and the remedial action.
- Delete data after a periodTraffic data must be erased or made anonymous once it is no longer needed to carry or bill for the communication.
- Get consentConsent is needed to use traffic or location data for marketing or value-added services.
What it costs if you get it wrong
- Criminal liabilitySeveral duties under these Regulations are backed by criminal offences
- Order to stopEnforcement notice from the Data Protection Commission
Sources
- Official sourceOffice of the Attorney General, Irish Statute BookS.I. No. 336/2011 — ePrivacy Regulations, Regulations 4 and 6
irishstatutebook.ie
“Undertakings shall maintain an inventory of personal data breaches which shall comprise the following information— (a) the facts surrounding the breach, (b) the effects of the breach”
Link checked 18 August 2026
- Official sourceData Protection CommissionBreach Notification — separate telecoms form signposted by the regulator
dataprotection.ie
Link checked 18 August 2026
Children's data rules (2024)
Official name: Online Safety Code · Made by Coimisiún na Meán under Part 8A of the Broadcasting Act 2009 · Statutory code of practice
A binding Irish rulebook for video-sharing platforms, made by the media regulator. It forces age checks where adult content is allowed and bans certain advertising aimed at children. Because so many platforms are headquartered in Dublin, this code reaches far beyond Ireland.
Enforced by Coimisiún na Meán
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What you have to do
- Get a parent's consent for childrenAge assurance systems are required where the service permits adult-only video content.
- No tracking or ads to childrenRestrictions on advertising directed at children, including alcohol displays aimed at children.
- Tell people what you doProtections must be written into and applied through the service's terms and conditions.
What it costs if you get it wrong
- Percentage of global turnover: Up to 10% of turnover under the Irish online safety regimeContravention of an online safety code
Sources
- Official sourceCoimisiún na MeánOnline Safety Code
cnam.ie
“The Code requires children to be protected from: video content that may impair their physical, mental, or moral development; and adult-only video content, including pornography and gross or gratuitous violence.”
Link checked 18 August 2026
- Official sourceCoimisiún na MeánLegislation explained — publication of the Online Safety Code
cnam.ie
“The Online Safety Code (OSC) was published in October 2024.”
Link checked 18 August 2026
AI rules
Official name: Regulation of Artificial Intelligence Act 2026 · No. 31 of 2026; commenced by S.I. No. 403 of 2026 · Act of parliament
Ireland's law putting the European Artificial Intelligence Act into effect. It created a national artificial intelligence office, Oifig IS na hÉireann. Almost all of it came into force on 31 July 2026. One part of the market surveillance definition is still not in force.
Enforced by Ireland's AI Office — not yet operational
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What you have to do
- Check your algorithms — from 31 July 2026
- Register or notifyMarket surveillance and notification structures for artificial intelligence systems sit with designated Irish authorities.
What it costs if you get it wrong
- Percentage of global turnoverPenalties flow from the European Artificial Intelligence Act, which this Act enforces in Ireland
Sources
- Official sourceOffice of the Attorney General, Irish Statute BookRegulation of Artificial Intelligence Act 2026 — commencement table and establishment day order (S.I. No. 404 of 2026)
irishstatutebook.ie
“Ss. 1 - 77 — 31 July 2026”
Link checked 18 August 2026
- Official sourceHouses of the OireachtasRegulation of Artificial Intelligence Bill 2026 — enacted 21 July 2026
oireachtas.ie
Link checked 18 August 2026
Applies to every company4 rules
These bind you whatever business you are in, once the country's rules reach you.
Children's data rules
Official name: Data Protection Act 2018 · No. 7 of 2018 · Act of parliament
Ireland's own privacy law. It sets the digital age of consent at 16 and caps fines against public bodies at 1 million euro (about 1.1 million US dollars). It is only partly in force. The ban on using children's data for marketing has never been brought into force.
Enforced by Data Protection Commission
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules
What you have to do
- Get a parent's consent for children — applies at: under 16The Act sets the age for online services at 16, the highest allowed in Europe.
- Appoint a data protection officer
- Secure the data
- Let people see their data
What it costs if you get it wrong
- Fixed maximum fine: €1,000,000 — about $1 millionFine on a public authority or public body that is not acting as a commercial undertaking
- Criminal liabilityRequiring a person to make a subject access request as a condition of recruitment or employment
Sources
- Official sourceOffice of the Attorney General, Irish Statute BookData Protection Act 2018, sections 31 and 141
irishstatutebook.ie
“The age of a child specified for the purposes of Article 8 is 16 years of age.”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookData Protection Act 2018 — commencement table, updated to 10 August 2026
irishstatutebook.ie
Link checked 18 August 2026
Children's data rules (Social media and online platforms)
Official name: Data Protection Act 2018, section 30 — micro-targeting and profiling of children · No. 7 of 2018, s. 30 · Act of parliament
An offence for any company to use a child's personal data for direct marketing, profiling or micro-targeting. It has been in Irish law since 2018 and has never come into force. One ministerial order would make it binding. It binds nobody today.
Enforced by Data Protection Commission
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses
What you have to do
- No tracking or ads to childrenNOT YET IN FORCE. It needs a commencement order from the Minister. Unused since 2018.
What it costs if you get it wrong
- Criminal liabilityWould be an offence, punishable by administrative fine under section 141 — if commenced
Sources
- Official sourceOffice of the Attorney General, Irish Statute BookData Protection Act 2018, section 30 — micro-targeting and profiling of children
irishstatutebook.ie
“It shall be an offence under this Act for any company or corporate body to process the personal data of a child as defined by section 29 for the purposes of direct marketing, profiling or micro-targeting.”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookData Protection Act 2018 — commencement table showing section 30 not yet commenced
irishstatutebook.ie
“S. 30 — Not yet commenced. Commencement order required under s. 1(3)”
Link checked 18 August 2026
Record-keeping rules for tax and accounts
Official name: Companies Act 2014, sections 283 and 285 · No. 38 of 2014 · Act of parliament
Every Irish company may keep its accounting records on a foreign server. But it must send information and returns to Ireland, and keep them there. Those must be detailed enough to show the assets, liabilities and profit or loss at least every six months. Everything must be kept for at least six years.
Enforced by Companies Registration Office
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Keep the data in the countryThe books themselves may live abroad. But summary information and returns must be sent to a place in Ireland and kept there. They must be refreshed at least every six months.
- Keep data for a minimum period — 6 years
What it costs if you get it wrong
- Criminal liabilityFailure to keep adequate accounting records is an offence under the Companies Act
Sources
- Official sourceOffice of the Attorney General, Irish Statute BookCompanies Act 2014, section 283 — where accounting records are to be kept
irishstatutebook.ie
“If accounting records are kept at a place outside the State, there shall be sent to and kept at a place in the State such information and returns relating to the business dealt with in the accounting records so kept”
Link checked 18 August 2026
- Official sourceOffice of the Attorney General, Irish Statute BookCompanies Act 2014, section 285 — six-year retention
irishstatutebook.ie
Link checked 18 August 2026
Cyber security rules
Official name: National Cyber Security Bill — General Scheme published September 2024 · General Scheme only; transposes Directive (EU) 2022/2555 (NIS2) · Draft law
Europe's cybersecurity directive should have been Irish law by 17 October 2024. As of 18 August 2026 no transposing Act appears in the Irish parliament's legislation database. The regulator's registration and incident reporting portals are still switched off. The older 2016 rules continue to apply to already-designated operators.
Enforced by National Cyber Security Centre
How this country controls where data goes: No restriction · Accepted routes: Nothing required
What you have to do
- Report cyber incidents — within 24 hoursNOT IN FORCE IN IRELAND. This is the deadline the directive would impose once transposed. Do not plan around it as a current Irish duty.
- Register or notifyThe registration portal is built but switched off pending legislation.
Sources
- Official sourceNational Cyber Security CentreNational Cyber Security Centre — NIS2 national steps
ncsc.gov.ie
“Unfortunately, the transposition deadline for NIS2 of 17 October 2024 has not been met. Ireland continues to work through the transposition requirements of the Directive.”
Link checked 18 August 2026
- Official sourceHouses of the OireachtasHouses of the Oireachtas — bills database, searched 18 August 2026 for a cybersecurity transposition Bill
oireachtas.ie
Link checked 18 August 2026
Applies across the European Union1 rule
Written once for the whole bloc, and in force in every member country.
Europe's main privacy law
Official name: General Data Protection Regulation · Regulation (EU) 2016/679, Chapter V · Directly binding regulation
The European bloc layer. Personal data does not have to stay in Europe, but it may only leave for an approved destination or under an approved safeguard. Ireland adds nothing to this at the general level.
Enforced by Data Protection Commission
How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, To save someone’s life, Important public interest
What you have to do
- Put a transfer safeguard in placeYou must also write down why the destination country is safe, on top of the route you choose.
- Report breaches to the regulator — within 72 hours
- Tell affected people
- Keep records of how you use data
- Assess high-risk projects
- Appoint a data protection officer
- Appoint a representativeRequired for companies outside Europe that target or monitor people in Europe.
- Written vendor contract
What it costs if you get it wrong
- Percentage of global turnover: 4% of worldwide group turnoverUnlawful transfer, breach of basic principles or individual rights, defying a regulator order
- Fixed maximum fine: €20,000,000 — about $22 millionSame tier, whichever is higher
- Order to stopOrder to suspend transfers to a third country
- Claims by individualsCompensation claims by individuals
Sources
- Official sourceEUR-LexRegulation (EU) 2016/679 (General Data Protection Regulation)
eur-lex.europa.eu
Link checked 18 August 2026
- Official sourceData Protection CommissionTransfers of Personal Data to Third Countries or International Organisations
dataprotection.ie
Link checked 18 August 2026
What we're not sure about
An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.
The exact date on which the age assurance measures in the Online Safety Code began to apply to video-sharing platforms.
We could not confirm the date the age check rules started to apply to video-sharing platforms. Coimisiún na Meán's pages confirm the Code was published in October 2024 but do not state that date in text we could read. We lowered the rule's confidence to medium. Check with the regulator if this date matters to you.
Whether any order under section 3A of the Communications (Retention of Data) Act 2011 is currently in force, requiring providers to retain traffic and location data.
We could not confirm whether such an order is in force. These orders are applied for without notice, heard in private, and made public only afterwards. We found no current order on a government website on 18 August 2026. Treat the power as live and the current position as unknown.
That Ireland has not transposed the NIS2 cybersecurity directive.
This is a statement that something has not happened, so it is hard to prove. The National Cyber Security Centre's own page on the directive, last updated 24 June 2025, says the deadline was missed. A search of the Houses of the Oireachtas legislation database on 18 August 2026 returned no transposing Bill among 622 bills since 2024. Ireland could also do it by ministerial regulation, which would not appear in that database. Confidence medium.
That there is no rule forcing data to stay in the country rule for mapping and geospatial data, education, defence or online gaming in Ireland.
We found no rule requiring this, checked 18 August 2026. We could not confirm it against every government source, because our search budget ran out early and we relied on direct fetches from official sites. That cannot rule out an obscure licence condition. If you work in one of these industries, check before you rely on it.
The precise scope of records that the Minister for Justice has prescribed for trust and company service providers under section 106, and that the Central Bank has specified for cheque-cashing offices under section 108I.
We could not confirm exactly which records are covered. Both laws require records 'as may be specified', and we did not find the documents that specify them on a government site. So the true breadth of the duty to keep records in Ireland is not pinned down. Ask the Minister for Justice or the Central Bank.
Whether the Central Bank of Ireland's Cross-Industry Guidance on Outsourcing contains any expectation about the geographic location of outsourced data.
We could not confirm whether the Central Bank's Cross-Industry Guidance on Outsourcing says anything about where data must sit. Its landing pages returned not-found errors and the guidance document was not reachable. The register submission page confirms the guidance exists and dates from December 2021. We did not read its contents.
Whether the fine ceiling stated for breaches of the Online Safety Code is accurate.
We could not confirm the fine ceiling for breaches of the Online Safety Code against the Broadcasting Act 2009 text on a government site. Treat the penalty entry as indicative only.
Freshness and refresh
Freshness
Checked about 2 months ago, on 18 August 2026.
Re-checked every 30 days. Next check due 17 September 2026.