Oireachtas Joint and Select Committees
Wednesday, 3 April 2019
Joint Oireachtas Committee on Justice, Defence and Equality
Implementation of the General Data Protection Regulation: Data Protection Commission
Ms Anna Morgan:
There are 33 domestic inquiries, 31 of which relate to the CCTV investigations we have running in respect of to the use of CCTV and other types of electronic surveillance by local authorities. Of the other two inquiries, one relates to a series of data breach notifications made to us relating to Tusla so we are examining the security issues around those data breach notifications.
Insofar as the financial sector is concerned, we certainly receive an awful lot of complaints from consumers regarding banks and insurance companies in particular. Data breach issues constitute a very salient issue for that industry. A very large proportion of the data breach notifications we receive relate to banks and insurance companies. It is something at which we are looking to decide whether or not there is merit in opening statutory inquiries of our volition rather than inquiries being complaint-led with regard to that ongoing stream of breach notifications. From analysing the breach notifications that come to us, we can see that organisational security measures remain a really big risk and a very large number of breaches relate to disclosure that really should not have happened. An example would be a bank statement or an insurance policy being sent out to the wrong address or an old address. That is something we are actively targeting in terms of further statutory inquiries on the domestic front.
No comments