Tusla Child and Family Agency
public body
We found 3 decisions about Tusla Child and Family Agency from DPC, the latest dated 12 August 2020.
Data Protection Commission
Extract from the regulator's publication.Background .................................................................................................................................... 4 3. Topics Arising in this Decision ......................................................................................................... 6 4. Legal Regime Pertaining to the Inquiry and the Decision ............................................................... 8 5. Materials Considered ...................................................................................................................... 9 6. Data Controller .............................................................................................................................. 10 7. Personal Data ................................................................................................................................ 10 8. Analysis and Findings .................................................................................................................... 11 A. Transmitting Personal Data on the NCCIS: Security of Processing ........................................... 11 i. Assessing Risk ........................................................................................................................ 13 ii. Security Measures Implemented by Tusla ............................................................................ 15 iii. The Appropriate Level of Security......................................................................................... 15 iv. Finding ................................................................................................................................... 16 B. Transmitting Personal Data Internally by Email: Security of Processing .................................. 17 i. Assessing Risk ........................................................................................................................ 17 ii. Security Measures Implemented by Tusla ............................................................................ 18 iii. The Appropriate Level of Security......................................................................................... 19 iv. Finding ................................................................................................................................... 20 C. Transmitting Personal Data Externally: Security of Processing ................................................ 20 i. Assessing Risk ........................................................................................................................ 20 ii. Security Measures Implemented by Tusla ............................................................................ 21 iii. The Appropriate Level of Security......................................................................................... 22 iv. Finding ................................................................................................................................... 24 D. Printing and Scanning: Security of Processing .......................................................................... 24 i. Assessing Risk ........................................................................................................................ 24 ii. Security Measures Implemented by Tusla ............................................................................ 25 iii. The Appropriate Level of Security......................................................................................... 26 iv. Finding ................................................................................................................................... 26 E. Processes for Testing Security Measures: Security of Processing ............................................ 26 i. Assessing Risk ........................................................................................................................ 27 ii. Security Measures Implemented by Tusla ............................................................................ 28 iii. The Appropriate Level of Security......................................................................................... 29 iv. Finding ................................................................................................................................... 30 3 F. Data Accuracy: Sharing Personal Data and Updating Tusla Records ........................................ 30 i. Accuracy of Personal Data Disclosed to Third Parties .......................................................... 31 ii. Accuracy of Tusla’s Internal Records .................................................................................... 31 iii. Findings ................................................................................................................................. 32 G.
Read the decision on the DPC website
Data Protection Commission — €40,000
Extract from the regulator's publication.Background ..................................................................................................................................... 3 3. The processing operation subject to this Decision ......................................................................... 5 4. Legal regime pertaining to the Inquiry and Decision ...................................................................... 6 5. Materials considered ...................................................................................................................... 6 6. Data Controller ................................................................................................................................ 7 7. Personal Data .................................................................................................................................. 7 8. Analysis and findings ....................................................................................................................... 7 A. Security of Processing ................................................................................................................. 7 i. Assessing Risk .......................................................................................................................... 8 ii. Security measures implemented by Tusla ............................................................................ 11 iii. The appropriate level of Security .......................................................................................... 12 iv. Finding ................................................................................................................................... 13 B. Data Breach Notification ........................................................................................................... 14 i. Analysis ................................................................................................................................. 14 ii. Finding ................................................................................................................................... 16 9. Corrective Powers ......................................................................................................................... 16 A. Reprimands ............................................................................................................................... 16 B. Order to Tusla to bring its processing into compliance with Article 32(1) of the GDPR........... 16 C. Administrative Fine ................................................................................................................... 17 i. Decision to impose an Administrative Fine .......................................................................... 18 ii. Calculating the Administrative Fine ...................................................................................... 24 10. Right of Appeal .......................................................................................................................... 26 3 1. Purpose of this Document 1.1 This document (“the Decision”) is the decision of the Data Protection Commission (“the DPC”) in accordance with Section 111 of the Data Protection Act 2018 (“the 2018 Act”). I make this Decision having considered the information obtained in the separate own volition inquiry (“the Inquiry”) conducted by an Authorised Officer of the DPC (“the DPC Investigator”). The DPC Investigator who conducted the Inquiry provided Tusla Child and Family Agency (“Tusla”) with the Draft Inquiry Report and the Final Inquiry Report.
Read the decision on the DPC website
Data Protection Commission — €75,000
Extract from the regulator's publication.Background ..................................................................................................................................... 3 3. Legal regime pertaining to the Inquiry and the Decision................................................................ 5 4. Materials considered ...................................................................................................................... 5 5. Data Controller ................................................................................................................................ 6 6. Personal Data .................................................................................................................................. 6 7. Analysis and findings ....................................................................................................................... 7 A. Security of Processing ................................................................................................................. 7 i. Assessing Risk .......................................................................................................................... 8 ii. Nature, Scope, Context and Purposes of Tusla’s processing ................................................ 10 iii. Security measures implemented by Tusla ............................................................................ 10 iv. The appropriate level of security .......................................................................................... 11 v. Finding ................................................................................................................................... 13 B. Data Breach Notification ........................................................................................................... 13 i. Analysis ................................................................................................................................. 13 ii. Finding ................................................................................................................................... 14 8. Corrective Measures ..................................................................................................................... 15 A. Reprimand ................................................................................................................................. 15 B. Order to Tusla to bring its processing into compliance with Article 32(1) of the GDPR........... 15 C. Administrative Fine ................................................................................................................... 16 i. Decision to impose an Administrative Fine .......................................................................... 16 ii. Calculating the Administrative Fine ...................................................................................... 20 9. Right of Appeal .............................................................................................................................. 22 1. Purpose of this Document 1.1 This document (“the Decision”) is the decision of the Data Protection Commission (“the DPC”) in accordance with Section 111 of the Data Protection Act 2018 (“the 2018 Act”). I make this Decision having considered the information obtained in the separate own volition inquiry conducted by Authorised Officers of the Data Protection Commission. The Authorised Officers who conducted the Inquiry provided Tusla Child and Family Agency (“Tusla”) with the draft Inquiry Report and the final Inquiry Report.
Read the decision on the DPC website
No decision about Tusla Child and Family Agency from the Central Bank (last read 9 October 2026).
Nearby in the register
- Twitter International Company
- TikTok Technology Limited
- University of Limerick
- Springboard Mortgages Limited trading as Springboard Mortgages
- Archbishop of Dublin
- Permanent TSB p.l.c.
- Dolmen Stockbrokers Limited
- J.P. Morgan Administration Services Limited
- Axa Insurance Limited
- New Ireland Assurance Company plc
See also: DPC