Skip to the content
Global Data RulesData governance rules, country by country

Ireland

Part of the European Union, so bloc-wide rules apply here too. Checked about 2 months ago, on 18 August 2026.

If you collect data about people in Ireland — customers, users, employees — these are the rules you have to follow. Here is the short version.

The short version

Depends on your industryWork: HighEnforcement: Aggressive

Ireland follows Europe's rules, so personal data can leave the country once you have the right paperwork in place. But a handful of Irish laws force certain records to be kept physically in Ireland. Breaking those is a crime rather than a fine. Ireland's privacy regulator is one of the toughest in Europe. In 2025 it fined TikTok 530 million euro and ordered it to stop sending data to China.

Data governance in Ireland

The eight things that decide how you handle data about people in Ireland. Same eight on every country page, so you can compare.

Who has to follow these rules

Yes. Ireland's data protection law reaches a company with no office in Ireland. It applies whenever you offer goods or services to people in Europe, or watch what they do online. There is no revenue or staff-count limit to duck under. A company based outside Europe normally has to name a representative inside Europe. Regulators and members of the public can write to that representative.

What you have to do here:
Appoint a representative

Where the data is allowed to live

In general, yes, with paperwork. Ireland has no general rule saying personal data must stay in the country. You may send it outside Europe once you use one of the approved legal routes. But several Irish laws quietly require particular records to sit on Irish soil. Those override the general answer.

What you have to do here:
Keep the data in the country

What to do: Check your own industry against the restricted list before you pick a hosting region.

Sending data out of the country

Ireland uses the European model. A destination outside Europe is off limits unless it is on the European Commission's approved list, or you put an approved safeguard in place first. The approved list is real and populated: it currently covers seventeen destinations, including the United Kingdom, Japan, South Korea, Switzerland and Brazil. The United States counts only for companies that have signed up to the European Union to United States Data Privacy Framework.

Ways to send data out:
Official 'this country is safe' decision · Standard contract clauses · Approved group rules · Certification scheme · Approved code of conduct · Explicit consent · Needed for a contract · Legal claims

What to do: Check the destination against the approved list first. Anywhere that is not on it needs the standard contract clauses signed before data leaves.

The regulator, and whether it actually acts

The Data Protection Commission, and it is very much awake. It has three commissioners in post. They are Des Hogan as chairperson, Dale Sunderland and Niamh Sweeney. It published its 2025 annual report on 30 June 2026. In 2025 it finished four large inquiries and imposed fines of just over 530 million euro (about 580 million US dollars). Almost all of that fell on TikTok. It also ordered TikTok to stop sending European user data to China.

What it costs if you get it wrong:
Percentage of global turnover · Order to stop

How long you must keep it — and when to delete it

Rules run in both directions, and Ireland's minimum periods are longer than most people expect. Anti-money-laundering customer records must be kept for at least five years. Company accounting records and returns must be kept for at least six years. Trust and company service providers and cheque-cashing firms must keep their records for six years, and keep them in Ireland. Telephone and internet providers must keep subscriber details for one year.

What you have to do here:
Keep data for a minimum period · Delete data after a period · Keep the data in the country

What to do: Write one deletion schedule that respects both the minimum keep-period and the deletion deadline.

If something goes wrong

Count three deadlines, not one. You have 72 hours to tell the Data Protection Commission about a personal data breach that puts people at risk. You must tell the affected people without delay if the risk is high. Telephone and internet providers report through a separate channel, under separate rules. And if the police send you an order to take down terrorist content, you have one hour.

What you have to do here:
Report breaches to the regulator · Tell affected people · Report cyber incidents · Keep records of how you use data

What to do: Your breach process has to reach both the regulator and the affected people inside the deadline above.

What catches people out

Five things that cost people their weekend. First, Ireland's famous ban on advertising to children has never come into force. Second, the official copy of the law on the government's own statute website can be out of date and misleading. Third, a child in Ireland is anyone under 16 for consent, not 13. Fourth, some record-keeping failures are crimes, not fines. Fifth, the regulator can only fine a public body up to 1 million euro (about 1.1 million US dollars), so it uses stop orders instead.

What you have to do here:
No tracking or ads to children · Get consent
What it costs if you get it wrong:
Criminal liability · Fixed maximum fine

What's changing next

Three things land in the next year. Ireland's new health records law is coming into force in stages. The parts that let doctors share your file are still switched off. So is the part that allows sharing with countries outside Europe. Europe's cloud switching rules make all data exit fees zero on 12 January 2027. And Ireland still has not written the European cybersecurity directive into Irish law, almost two years past the deadline.

What you have to do here:
Make switching cloud provider possible

What to do: Diarise 12 January 2027 — that is the date this changes.

The actual laws

Everything above comes from these. Industry rules beat the general ones — if you're in a listed industry, read that group first.

Applies only to certain industries8 rules

If your product does one of these things, read this group first — industry rules beat the general position.

Finance

Finance data needs a copy kept in the country

Official name: Criminal Justice (Money Laundering and Terrorist Financing) Act 2010, section 106 · No. 6 of 2010, s. 106 · Act of parliament

In forceA copy must stay

The strictest rule in Irish law about where data must sit. It covers a trust or company service provider authorised by the Minister for Justice. That firm must keep prescribed records at an office or other premises inside Ireland for at least six years. It must also tell the Minister where. Getting this wrong is a crime, not a fine.

In force since 15 July 2010

Enforced by Department of Justice, Home Affairs and Migration

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Payments

Payments data needs a copy kept in the country

Official name: Criminal Justice (Money Laundering and Terrorist Financing) Act 2010, section 108I · No. 6 of 2010, s. 108I, inserted by S.I. No. 600 of 2019 · Act of parliament

In forceA copy must stay

Cheque-cashing offices registered with the Central Bank of Ireland must hold their records at premises inside Ireland for at least six years. They must tell the Central Bank the address. The duty carries on even after the firm deregisters or shuts down.

In force since 2 December 2019

Enforced by Central Bank of Ireland

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Health and social care

Health data rules

Official name: Health Information Act 2026 · No. 10 of 2026 · Act of parliament

Partly in forceYes, with paperwork

Ireland's new health records law, giving effect to the European Health Data Space. It creates an Electronic Health Record for every patient. Sharing that record with a country outside Europe needs a reciprocal arrangement, agreed only after consulting the privacy regulator. That part has not come into force yet.

In force since 17 August 2026

Enforced by Health Service Executive

How this country controls where data goes: Approval each time · Accepted routes: Government sign-off needed, Official 'this country is safe' decision, Standard contract clauses

Applies to every company4 rules

These bind you whatever business you are in, once the country's rules reach you.

Children's data rules

Official name: Data Protection Act 2018 · No. 7 of 2018 · Act of parliament

Partly in forceYes, with paperwork

Ireland's own privacy law. It sets the digital age of consent at 16 and caps fines against public bodies at 1 million euro (about 1.1 million US dollars). It is only partly in force. The ban on using children's data for marketing has never been brought into force.

In force since 25 May 2018

Enforced by Data Protection Commission

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

Social media and online platforms

Children's data rules (Social media and online platforms)

Official name: Data Protection Act 2018, section 30 — micro-targeting and profiling of children · No. 7 of 2018, s. 30 · Act of parliament

Passed, not yet fully in forceYes, with paperwork

An offence for any company to use a child's personal data for direct marketing, profiling or micro-targeting. It has been in Irish law since 2018 and has never come into force. One ministerial order would make it binding. It binds nobody today.

Enforced by Data Protection Commission

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses

Record-keeping rules for tax and accounts

Official name: Companies Act 2014, sections 283 and 285 · No. 38 of 2014 · Act of parliament

In forceA copy must stay

Every Irish company may keep its accounting records on a foreign server. But it must send information and returns to Ireland, and keep them there. Those must be detailed enough to show the assets, liabilities and profit or loss at least every six months. Everything must be kept for at least six years.

In force since 1 June 2015

Enforced by Companies Registration Office

How this country controls where data goes: No restriction · Accepted routes: Nothing required

Applies across the European Union1 rule

Written once for the whole bloc, and in force in every member country.

Europe's main privacy law

Official name: General Data Protection Regulation · Regulation (EU) 2016/679, Chapter V · Directly binding regulation

In forceYes, with paperwork

The European bloc layer. Personal data does not have to stay in Europe, but it may only leave for an approved destination or under an approved safeguard. Ireland adds nothing to this at the general level.

In force since 25 May 2018

Enforced by Data Protection Commission

How this country controls where data goes: Only approved countries · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, To save someone’s life, Important public interest

Who you would hear from

  • An Coimisiún um Chosaint Sonraí

    General data protection, ePrivacy Regulations 2011, Law Enforcement Directive. Lead supervisory authority for most large technology companies with European headquarters in Ireland.

    Three commissioners in post: Des Hogan (chairperson), Dale Sunderland and Niamh Sweeney. 2025 annual report published 30 June 2026; fines of just over 530.77 million euro imposed in 2025; own-volition inquiries live in 2026.

  • Banc Ceannais na hÉireann

    Banking, payments, e-money, insurance, capital markets and funds. Outsourcing registers, digital operational resilience, anti-money-laundering registration of cheque-cashing offices.

    Fully operational. Domestic outsourcing register collection paused in 2025, resuming February 2027 with a 31 December 2026 reference date.

  • Coimisiún na Meán

    Online safety, video-sharing platforms, Digital Services Coordinator for Ireland, terrorist content online.

    Operational. Binding Online Safety Code published October 2024; maintains a public register of designated online services.

  • An Lárionad Náisiúnta Cibearshlándála

    National cybersecurity, national computer security incident response team, future NIS2 competent authority and single point of contact.

    Operational as an incident response body under the Department of Justice, Home Affairs and Migration. It has no supervisory powers under the European cybersecurity directive known as NIS2. Its registration and incident reporting portals are explicitly not available until Ireland writes that directive into Irish law.

  • An tÚdarás Rialála Cearrbhachais na hÉireann

    Licensing, supervision and control of gambling, gaming, betting and certain lotteries under the Gambling Regulation Act 2024, including record-keeping duties on licensees.

    Formally established March 2025. First annual report published; first remote betting licence applications invited February 2026. Record-keeping regulations under section 152 were still out for consultation until 20 August 2026, so licensee data duties are not yet fixed.

  • Health Research Consent Declaration Committee

    Grants declarations permitting health research to proceed without the explicit consent otherwise required by the Health Research Regulations 2018.

    Operational: publishes application guidance, meeting dates, decisions, appeals and annual reports.

  • Feidhmeannacht na Seirbhíse Sláinte

    Creates and assigns Electronic Health Records under the Health Information Act 2026 and may enter reciprocal arrangements with countries outside Europe.

    Operational. The Electronic Health Record powers commenced on 17 August 2026; the third-country exchange power has not yet been commenced.

  • Oifig IS na hÉireann

    National body established under the Regulation of Artificial Intelligence Act 2026 to give effect to the European Artificial Intelligence Act in Ireland.

    Legally set up by the Regulation of Artificial Intelligence Act 2026 (Establishment Day) Order 2026, S.I. No. 404 of 2026. The Act came into force on 31 July 2026. We found no decisions or enforcement action as of 18 August 2026. Treat it as standing up, not yet enforcing.

  • An Roinn Dlí agus Cirt, Gnóthaí Baile agus Imirce

    Authorises trust or company service providers and holds their in-State record addresses; applies to the High Court for communications data retention orders.

    Operational. It holds two of the most powerful unused powers in the Irish record. It authorises trust and company service providers. And it can apply for the order that makes providers keep communications data.

  • Oifig Chláraithe na gCuideachtaí

    Company law compliance, including the duty to keep accounting information and returns at a place in Ireland.

    Operational. Enforcement of accounting record duties is shared with the Corporate Enforcement Authority and the courts.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify against a government source.

  • The exact date on which the age assurance measures in the Online Safety Code began to apply to video-sharing platforms.

    We could not confirm the date the age check rules started to apply to video-sharing platforms. Coimisiún na Meán's pages confirm the Code was published in October 2024 but do not state that date in text we could read. We lowered the rule's confidence to medium. Check with the regulator if this date matters to you.

  • Whether any order under section 3A of the Communications (Retention of Data) Act 2011 is currently in force, requiring providers to retain traffic and location data.

    We could not confirm whether such an order is in force. These orders are applied for without notice, heard in private, and made public only afterwards. We found no current order on a government website on 18 August 2026. Treat the power as live and the current position as unknown.

  • That Ireland has not transposed the NIS2 cybersecurity directive.

    This is a statement that something has not happened, so it is hard to prove. The National Cyber Security Centre's own page on the directive, last updated 24 June 2025, says the deadline was missed. A search of the Houses of the Oireachtas legislation database on 18 August 2026 returned no transposing Bill among 622 bills since 2024. Ireland could also do it by ministerial regulation, which would not appear in that database. Confidence medium.

  • That there is no rule forcing data to stay in the country rule for mapping and geospatial data, education, defence or online gaming in Ireland.

    We found no rule requiring this, checked 18 August 2026. We could not confirm it against every government source, because our search budget ran out early and we relied on direct fetches from official sites. That cannot rule out an obscure licence condition. If you work in one of these industries, check before you rely on it.

  • The precise scope of records that the Minister for Justice has prescribed for trust and company service providers under section 106, and that the Central Bank has specified for cheque-cashing offices under section 108I.

    We could not confirm exactly which records are covered. Both laws require records 'as may be specified', and we did not find the documents that specify them on a government site. So the true breadth of the duty to keep records in Ireland is not pinned down. Ask the Minister for Justice or the Central Bank.

  • Whether the Central Bank of Ireland's Cross-Industry Guidance on Outsourcing contains any expectation about the geographic location of outsourced data.

    We could not confirm whether the Central Bank's Cross-Industry Guidance on Outsourcing says anything about where data must sit. Its landing pages returned not-found errors and the guidance document was not reachable. The register submission page confirms the guidance exists and dates from December 2021. We did not read its contents.

  • Whether the fine ceiling stated for breaches of the Online Safety Code is accurate.

    We could not confirm the fine ceiling for breaches of the Online Safety Code against the Broadcasting Act 2009 text on a government site. Treat the penalty entry as indicative only.

Freshness and refresh

Freshness

Checked about 2 months ago, on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.