Tusla Child and Family Agency

public body

We found 3 decisions about Tusla Child and Family Agency from DPC, the latest dated 12 August 2020.

Fine, Reprimand, Order to comply — 12 August 2020
Data Protection Commission

Background .................................................................................................................................... 4 3. Topics Arising in this Decision ......................................................................................................... 6 4. Legal Regime Pertaining to the Inquiry and the Decision ............................................................... 8 5. Materials Considered ...................................................................................................................... 9 6. Data Controller .............................................................................................................................. 10 7. Personal Data ................................................................................................................................ 10 8. Analysis and Findings .................................................................................................................... 11 A. Transmitting Personal Data on the NCCIS: Security of Processing ........................................... 11 i. Assessing Risk ........................................................................................................................ 13 ii. Security Measures Implemented by Tusla ............................................................................ 15 iii. The Appropriate Level of Security......................................................................................... 15 iv. Finding ................................................................................................................................... 16 B. Transmitting Personal Data Internally by Email: Security of Processing .................................. 17 i. Assessing Risk ........................................................................................................................ 17 ii. Security Measures Implemented by Tusla ............................................................................ 18 iii. The Appropriate Level of Security......................................................................................... 19 iv. Finding ................................................................................................................................... 20 C. Transmitting Personal Data Externally: Security of Processing ................................................ 20 i. Assessing Risk ........................................................................................................................ 20 ii. Security Measures Implemented by Tusla ............................................................................ 21 iii. The Appropriate Level of Security......................................................................................... 22 iv. Finding ................................................................................................................................... 24 D. Printing and Scanning: Security of Processing .......................................................................... 24 i. Assessing Risk ........................................................................................................................ 24 ii. Security Measures Implemented by Tusla ............................................................................ 25 iii. The Appropriate Level of Security......................................................................................... 26 iv. Finding ................................................................................................................................... 26 E. Processes for Testing Security Measures: Security of Processing ............................................ 26 i. Assessing Risk ........................................................................................................................ 27 ii. Security Measures Implemented by Tusla ............................................................................ 28 iii. The Appropriate Level of Security......................................................................................... 29 iv. Finding ................................................................................................................................... 30 3 F. Data Accuracy: Sharing Personal Data and Updating Tusla Records ........................................ 30 i. Accuracy of Personal Data Disclosed to Third Parties .......................................................... 31 ii. Accuracy of Tusla’s Internal Records .................................................................................... 31 iii. Findings ................................................................................................................................. 32 G.

Extract from the regulator's publication.
Read the decision on the DPC website
Fine, Reprimand, Order to comply — 21 May 2020
Data Protection Commission — €40,000

Background ..................................................................................................................................... 3 3. The processing operation subject to this Decision ......................................................................... 5 4. Legal regime pertaining to the Inquiry and Decision ...................................................................... 6 5. Materials considered ...................................................................................................................... 6 6. Data Controller ................................................................................................................................ 7 7. Personal Data .................................................................................................................................. 7 8. Analysis and findings ....................................................................................................................... 7 A. Security of Processing ................................................................................................................. 7 i. Assessing Risk .......................................................................................................................... 8 ii. Security measures implemented by Tusla ............................................................................ 11 iii. The appropriate level of Security .......................................................................................... 12 iv. Finding ................................................................................................................................... 13 B. Data Breach Notification ........................................................................................................... 14 i. Analysis ................................................................................................................................. 14 ii. Finding ................................................................................................................................... 16 9. Corrective Powers ......................................................................................................................... 16 A. Reprimands ............................................................................................................................... 16 B. Order to Tusla to bring its processing into compliance with Article 32(1) of the GDPR........... 16 C. Administrative Fine ................................................................................................................... 17 i. Decision to impose an Administrative Fine .......................................................................... 18 ii. Calculating the Administrative Fine ...................................................................................... 24 10. Right of Appeal .......................................................................................................................... 26 3 1. Purpose of this Document 1.1 This document (“the Decision”) is the decision of the Data Protection Commission (“the DPC”) in accordance with Section 111 of the Data Protection Act 2018 (“the 2018 Act”). I make this Decision having considered the information obtained in the separate own volition inquiry (“the Inquiry”) conducted by an Authorised Officer of the DPC (“the DPC Investigator”). The DPC Investigator who conducted the Inquiry provided Tusla Child and Family Agency (“Tusla”) with the Draft Inquiry Report and the Final Inquiry Report.

Extract from the regulator's publication.
Read the decision on the DPC website
Fine, Reprimand, Order to comply — 7 April 2020
Data Protection Commission — €75,000

Background ..................................................................................................................................... 3 3. Legal regime pertaining to the Inquiry and the Decision................................................................ 5 4. Materials considered ...................................................................................................................... 5 5. Data Controller ................................................................................................................................ 6 6. Personal Data .................................................................................................................................. 6 7. Analysis and findings ....................................................................................................................... 7 A. Security of Processing ................................................................................................................. 7 i. Assessing Risk .......................................................................................................................... 8 ii. Nature, Scope, Context and Purposes of Tusla’s processing ................................................ 10 iii. Security measures implemented by Tusla ............................................................................ 10 iv. The appropriate level of security .......................................................................................... 11 v. Finding ................................................................................................................................... 13 B. Data Breach Notification ........................................................................................................... 13 i. Analysis ................................................................................................................................. 13 ii. Finding ................................................................................................................................... 14 8. Corrective Measures ..................................................................................................................... 15 A. Reprimand ................................................................................................................................. 15 B. Order to Tusla to bring its processing into compliance with Article 32(1) of the GDPR........... 15 C. Administrative Fine ................................................................................................................... 16 i. Decision to impose an Administrative Fine .......................................................................... 16 ii. Calculating the Administrative Fine ...................................................................................... 20 9. Right of Appeal .............................................................................................................................. 22 1. Purpose of this Document 1.1 This document (“the Decision”) is the decision of the Data Protection Commission (“the DPC”) in accordance with Section 111 of the Data Protection Act 2018 (“the 2018 Act”). I make this Decision having considered the information obtained in the separate own volition inquiry conducted by Authorised Officers of the Data Protection Commission. The Authorised Officers who conducted the Inquiry provided Tusla Child and Family Agency (“Tusla”) with the draft Inquiry Report and the final Inquiry Report.

Extract from the regulator's publication.
Read the decision on the DPC website

No decision about Tusla Child and Family Agency from the Central Bank (last read 9 October 2026).

Monitor Tusla Child and Family Agency (email on any new decision) or order a dated report (€19).

Nearby in the register

See also: DPC