Inquiry into Child and Family Agency - May 2020

Year2020
Date21 May 2020
SectionDecisions made under data protection act 2018
1
Decision of the Data Protection Commission under Section 111 of the Data Protection
Act 2018 on foot of the
Own-Volition Inquiry under Section 110 of the Data Protection Act, 2018
regarding
Tusla Child and Family Agency
Inquiry Reference: IN-19-12-8
Commission Decision-Maker:
Helen Dixon (Commissioner for Data Protection), sole member of the Commission
Date of Decision: 21st May 2020
2
Contents
1. Purpose of this Document .............................................................................................................. 3
2. Background ..................................................................................................................................... 3
3. The processing operation subject to this Decision ......................................................................... 5
4. Legal regime pertaining to the Inquiry and Decision ...................................................................... 6
5. Materials considered ...................................................................................................................... 6
6. Data Controller ................................................................................................................................ 7
7. Personal Data .................................................................................................................................. 7
8. Analysis and findings ....................................................................................................................... 7
A. Security of Processing ................................................................................................................. 7
i. Assessing Risk .......................................................................................................................... 8
ii. Security measures implemented by Tusla ............................................................................ 11
iii. The appropriate level of Security .......................................................................................... 12
iv. Finding ................................................................................................................................... 13
B. Data Breach Notification ........................................................................................................... 14
i. Analysis ................................................................................................................................. 14
ii. Finding ................................................................................................................................... 16
9. Corrective Powers ......................................................................................................................... 16
A. Reprimands ............................................................................................................................... 16
B. Order to Tusla to bring its processing into compliance with Article 32(1) of the GDPR........... 16
C. Administrative Fine ................................................................................................................... 17
i. Decision to impose an Administrative Fine .......................................................................... 18
ii. Calculating the Administrative Fine ...................................................................................... 24
10. Right of Appeal .......................................................................................................................... 26

To continue reading

Request your trial

VLEX uses login cookies to provide you with a better browsing experience. If you click on 'Accept' or continue browsing this site we consider that you accept our cookie policy. ACCEPT