Skip to the content
Global Data RulesData governance rules, country by country

Ireland

Part of the European Union, so bloc-wide rules apply here too. Checked today.

The answer

Depends on your industryWork: HighEnforcement: Aggressive

Ireland follows Europe's rules, so personal data can leave the country once you have the right paperwork in place. But a handful of Irish laws force certain records to be kept physically in Ireland, and breaking those is a crime rather than a fine. Ireland's privacy regulator is one of the toughest in Europe: in 2025 it fined TikTok 530 million euro and ordered it to stop sending data to China.

Eight questions about Ireland

The questions a team asks when they are deciding where to store their users' data. Every country on this site answers the same eight, in the same order.

Do Ireland's rules apply to my company?

Yes. Ireland's data protection law reaches a company with no office in Ireland whenever it offers goods or services to people in Europe or watches what they do online. There is no revenue or headcount threshold to duck under. A company based outside Europe normally has to name a representative inside Europe who regulators and members of the public can write to.

High confidenceNational rulesAppoint a local representative

Can I store my users' data outside Ireland?

In general, yes, with paperwork. Ireland does not have a general rule saying personal data must stay in the country. Sending it outside Europe is allowed once you use one of the approved legal routes. But several Irish laws quietly demand that particular records sit on Irish soil, and those override the friendly headline.

High confidenceDepends on your industryAllowlistKeep the data in the country

What do I need in place before data leaves Ireland?

Ireland uses the European model. A destination outside Europe is off limits unless it is on the European Commission's approved list, or you put an approved safeguard in place first. The approved list is real and populated: it currently covers seventeen destinations, including the United Kingdom, Japan, South Korea, Switzerland and Brazil. The United States counts only for companies that have signed up to the European Union to United States Data Privacy Framework.

High confidenceAllowlistOfficial 'this country is safe' decisionStandard contract clausesApproved group rulesCertification schemeApproved code of conductExplicit consentNeeded for a contractLegal claims

Who enforces the rules in Ireland, and what can they do?

The Data Protection Commission, and it is very much awake. It has three commissioners in post — Des Hogan as chairperson, Dale Sunderland and Niamh Sweeney — and it published its 2025 annual report on 30 June 2026. In 2025 it finished four large inquiries and imposed fines of just over 530 million euro (about 580 million US dollars), almost all of it on TikTok, which it also ordered to stop sending European user data to China.

High confidenceAggressivePercentage of global turnoverOrder to stop

How long do I have to keep the data?

Both directions apply, and Ireland's floors are longer than most people expect. Anti-money-laundering customer records must be kept for at least five years. Company accounting records and returns must be kept for at least six years. Trust and company service providers and cheque-cashing firms must keep their records for six years and keep them in Ireland. Telephone and internet providers must keep subscriber details for one year.

High confidenceKeep data for a minimum periodDelete data after a periodKeep the data in the country

What happens if there is a breach?

Count three clocks, not one. You have 72 hours to tell the Data Protection Commission about a personal data breach that puts people at risk, and you must tell the affected people without delay if the risk is high. Telephone and internet providers report through a separate channel under separate rules. And if the police send you an order to take down terrorist content, you have one hour.

High confidenceReport breaches to the regulatorTell affected peopleReport cyber incidentsKeep records of processing

What trips people up in Ireland?

Five things that cost people their weekend. First, Ireland's famous ban on advertising to children has never actually switched on. Second, the official copy of the law on the government's own statute website can be out of date and misleading. Third, a child in Ireland is anyone under 16 for consent purposes, not 13. Fourth, some record-keeping failures are crimes, not fines. Fifth, the regulator can only fine a public body up to 1 million euro (about 1.1 million US dollars), so it uses stop orders instead.

High confidencePassed, not yet fully in forceCriminal liabilityFixed maximum fineNo tracking or ads to childrenGet consent

What is changing soon in Ireland?

Three things land in the next year. Ireland's new health records law is switching on in stages, and the parts that let doctors share your file and that allow sharing with countries outside Europe are still switched off. Europe's cloud switching rules make all data exit fees zero on 12 January 2027. And Ireland still has not written the European cybersecurity directive into Irish law, almost two years past the deadline.

High confidencePartly in forceProposedMake switching cloud provider possible

The rules, layer by layer

Rules stack in layers. Knowing which layer a rule sits in tells you whether your industry, your state, or a contract can override it.

  1. Layer 1

    Bloc rules

    Made by a group of countries together. Applies inside every member country.

    1 rule here

  2. Layer 2

    National rules

    Added by this country on top of any bloc rules.

    4 rules here

  3. Layer 3

    Industry rules

    Made by an industry regulator. These usually beat the general position.

    8 rules here

Read the stack from the top down. Anything lower normally wins: an industry rule beats the national position, and the national position sits on top of the bloc rules.

Bloc rules1 rule

General Data Protection Regulation

Directly binding regulation · Regulation (EU) 2016/679, Chapter V

In forceYes, with paperwork

The European bloc layer. Personal data does not have to stay in Europe, but it may only leave for an approved destination or under an approved safeguard. Ireland adds nothing to this at the general level.

In force since 25 May 2018

Enforced by Data Protection Commission

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules, Certification scheme, Approved code of conduct, Explicit consent, Needed for a contract, Legal claims, Someone's life is at risk, Important public interest

High confidence

National rules4 rules

Data Protection Act 2018

Act of parliament · No. 7 of 2018

Partly in forceYes, with paperwork

Ireland's national privacy statute. It sets the digital age of consent at 16 and caps fines against public bodies at 1 million euro (about 1.1 million US dollars). It is only partly in force: section 30 has never been commenced.

In force since 25 May 2018

Enforced by Data Protection Commission

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses, Approved group rules

High confidence

Data Protection Act 2018, section 30 — micro-targeting and profiling of children

Act of parliament · No. 7 of 2018, s. 30 · Social media and online platforms

Passed, not yet fully in forceYes, with paperwork

An offence for any company to use a child's personal data for direct marketing, profiling or micro-targeting. Printed in Irish law since 2018 and never switched on. It is one ministerial order away from binding, and is widely and wrongly quoted as current law.

Enforced by Data Protection Commission

Transfer model: Allowlist · Accepted routes: Official 'this country is safe' decision, Standard contract clauses

High confidence

Companies Act 2014, sections 283 and 285

Act of parliament · No. 38 of 2014

In forceA copy must stay

Every Irish company may keep its accounting records on a foreign server, but it must send to Ireland, and keep in Ireland, information and returns detailed enough to show the assets, liabilities and profit or loss at least every six months. Everything must be kept for at least six years.

In force since 1 June 2015

Enforced by Companies Registration Office

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Industry rules8 rules

Criminal Justice (Money Laundering and Terrorist Financing) Act 2010, section 106

Act of parliament · No. 6 of 2010, s. 106 · Finance

In forceA copy must stay

The hardest data residency rule in Irish law. A trust or company service provider authorised by the Minister for Justice must keep prescribed records at an office or other premises inside Ireland for at least six years, and must tell the Minister where. Getting this wrong is a crime, not a fine.

In force since 15 July 2010

Enforced by Department of Justice, Home Affairs and Migration

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Criminal Justice (Money Laundering and Terrorist Financing) Act 2010, section 108I

Act of parliament · No. 6 of 2010, s. 108I, inserted by S.I. No. 600 of 2019 · Payments

In forceA copy must stay

Cheque-cashing offices registered with the Central Bank of Ireland must hold their records at premises inside Ireland for at least six years and tell the Central Bank the address. The duty carries on even after the firm deregisters or shuts down.

In force since 2 December 2019

Enforced by Central Bank of Ireland

Transfer model: No restriction · Accepted routes: Nothing required

High confidence

Health Information Act 2026

Act of parliament · No. 10 of 2026 · Health and social care

Partly in forceYes, with paperwork

Ireland's new health records law, giving effect to the European Health Data Space. It creates an Electronic Health Record for every patient. Sharing that record with a country outside Europe needs a reciprocal arrangement agreed only after consulting the privacy regulator — but that section has not been switched on yet.

In force since 17 August 2026

Enforced by Health Service Executive

Transfer model: Approval each time · Accepted routes: Government sign-off needed, Official 'this country is safe' decision, Standard contract clauses

High confidence

Who you would hear from

  • An Coimisiún um Chosaint Sonraí

    General data protection, ePrivacy Regulations 2011, Law Enforcement Directive. Lead supervisory authority for most large technology companies with European headquarters in Ireland.

    Three commissioners in post: Des Hogan (chairperson), Dale Sunderland and Niamh Sweeney. 2025 annual report published 30 June 2026; fines of just over 530.77 million euro imposed in 2025; own-volition inquiries live in 2026.

  • Banc Ceannais na hÉireann

    Banking, payments, e-money, insurance, capital markets and funds. Outsourcing registers, digital operational resilience, anti-money-laundering registration of cheque-cashing offices.

    Fully operational. Domestic outsourcing register collection paused in 2025, resuming February 2027 with a 31 December 2026 reference date.

  • Coimisiún na Meán

    Online safety, video-sharing platforms, Digital Services Coordinator for Ireland, terrorist content online.

    Operational. Binding Online Safety Code published October 2024; maintains a public register of designated online services.

  • An Lárionad Náisiúnta Cibearshlándála

    National cybersecurity, national computer security incident response team, future NIS2 competent authority and single point of contact.

    Operational as an incident response body under the Department of Justice, Home Affairs and Migration, but has no NIS2 supervisory powers: its registration and incident reporting portals are explicitly not available pending transposition.

  • An tÚdarás Rialála Cearrbhachais na hÉireann

    Licensing, supervision and control of gambling, gaming, betting and certain lotteries under the Gambling Regulation Act 2024, including record-keeping duties on licensees.

    Formally established March 2025. First annual report published; first remote betting licence applications invited February 2026. Record-keeping regulations under section 152 were still out for consultation until 20 August 2026, so licensee data duties are not yet fixed.

  • Health Research Consent Declaration Committee

    Grants declarations permitting health research to proceed without the explicit consent otherwise required by the Health Research Regulations 2018.

    Operational: publishes application guidance, meeting dates, decisions, appeals and annual reports.

  • Feidhmeannacht na Seirbhíse Sláinte

    Creates and assigns Electronic Health Records under the Health Information Act 2026 and may enter reciprocal arrangements with countries outside Europe.

    Operational. The Electronic Health Record powers commenced on 17 August 2026; the third-country exchange power has not yet been commenced.

  • Oifig IS na hÉireann

    National body established under the Regulation of Artificial Intelligence Act 2026 to give effect to the European Artificial Intelligence Act in Ireland.

    Legally established by the Regulation of Artificial Intelligence Act 2026 (Establishment Day) Order 2026, S.I. No. 404 of 2026, with the Act commencing on 31 July 2026. No decisions or enforcement action identified as of 18 August 2026 — treat as standing up, not yet enforcing.

  • An Roinn Dlí agus Cirt, Gnóthaí Baile agus Imirce

    Authorises trust or company service providers and holds their in-State record addresses; applies to the High Court for communications data retention orders.

    Operational. Holds two of the most consequential dormant powers in the Irish record: the trust and company service provider authorisation regime and the communications data retention order power.

  • Oifig Chláraithe na gCuideachtaí

    Company law compliance, including the duty to keep accounting information and returns at a place in Ireland.

    Operational. Enforcement of accounting record duties is shared with the Corporate Enforcement Authority and the courts.

What we're not sure about

An honest gap is more useful than a confident guess. These are the claims we could not verify from an official source on the last check.

  • The exact date on which the age assurance measures in the Online Safety Code began to apply to video-sharing platforms.

    Coimisiún na Meán's own pages confirm the Code was published in October 2024 but do not state the deferred application date for the age assurance measures in text we could read. The Code PDF did not yield reliable machine-readable text. Rule confidence lowered to medium.

  • Whether any order under section 3A of the Communications (Retention of Data) Act 2011 is currently in force, requiring providers to retain traffic and location data.

    Such orders are applied for without notice and heard in private, and are publicised in the national media and Iris Oifigiúil only after being made. No current order was located on a government domain on 18 August 2026. Treat the power as live and the current state as unknown.

  • That Ireland has not transposed the NIS2 cybersecurity directive.

    This is a negative. It rests on the National Cyber Security Centre's own NIS2 page, which was last updated 24 June 2025 and says the deadline was missed, plus a search of the Houses of the Oireachtas legislation database on 18 August 2026 which returned no cybersecurity transposition Bill among 622 bills since 2024. A statutory instrument route would not appear in that database. Confidence medium.

  • That there is no data localisation rule for mapping and geospatial data, education, defence or online gaming in Ireland.

    No rule found, checked 18 August 2026. This is an absence of evidence rather than evidence of absence; the web search budget for this run was exhausted early and verification relied on direct fetches from official domains, which cannot rule out an obscure licence condition.

  • The precise scope of records that the Minister for Justice has prescribed for trust and company service providers under section 106, and that the Central Bank has specified for cheque-cashing offices under section 108I.

    Both sections require records 'as may be specified'. The specifying instruments were not located on a government domain during this run, so the practical breadth of the in-State duty is not pinned down.

  • Whether the Central Bank of Ireland's Cross-Industry Guidance on Outsourcing contains any expectation about the geographic location of outsourced data.

    The Central Bank's own outsourcing landing pages returned 404 and the guidance PDF was not reachable at the expected path. The register submission page confirms the guidance exists and dates from December 2021, but its contents were not verified in this run.

  • Whether the fine ceiling stated for breaches of the Online Safety Code is accurate.

    The percentage-of-turnover figure was not verified against the Broadcasting Act 2009 text on a government domain during this run. The penalty entry should be treated as indicative only.

Freshness and refresh

Freshness

Checked today — on 18 August 2026.

Re-checked every 30 days. Next check due 17 September 2026.

Read the exact prompt used to research this page

Compare with

This is a map, not legal advice. It tells you which questions to ask. It cannot tell you whether your specific setup is lawful — for that you need a qualified adviser looking at your actual data flows.

Every claim on this page links to the government's own website. Click any source to verify it yourself.