Privacy Policy

Oifig IS Na hÉireann is data controller

The Office may process personal data, including special categories of personal data in accordance with the EU General Data Protection Regulation 2016/679 (GDPR) and the Data Protection Act 2018 to the extent necessary and proportionate for the performance of the Office’s functions under both the 2026 Act and the EU AI Act.

Section 51(2) of the 2026 Act designates the Office as a data controller in relation to personal data processed by it for the purposes of the performance of its functions under both the 2026 Act and the EU AI Act.

Lawfulness of Processing

The Office will lawfully process your data based on one, or a combination of the following, grounds:

(a)    You have given consent to the processing of your personal data for one or more specific purposes

(b)    The processing of your personal data is necessary for compliance with legal obligations the Office is subject to

(c)     The processing of your personal data is necessary for the performance of a task carried out in the public interest or in the exercise of official authority by the Office  

How we use your information

The purpose of this Privacy Policy is to provide information about how Oifig IS na hÉireann (The Office) collects, stores, shares or keeps personal data in accordance with the EU General Data Protection Regulation 2016/679 (GDPR) and the Data Protection Act 2018.

What types of information do we gather

We will gather information that you provide directly, and information that is collected automatically.

Information provided by you directly will include personal contact details from you, including postal and electronic email addresses, telephone numbers and personal information which may be included in forms or in attachments to forms submitted to the AI Service Desk. Where material sent to the AI Service Desk includes sensitive personal data to substantiate your report to the AI Service Desk these will be subject to additional measures (See Data Security statement below).   

Information that will be collected automatically may include the personal data of visitors to the AI Office’s website who go through the material of the website and may need to allow cookies in order to use the service.  The AI Office will make no attempt to identify individual visitors, or to associate the technical details listed above with any individual.  It is only used for statistical and other administrative purposes.

Who are the recipients of personal data processed by the Office?

Where there is a need to share your personal data to a third party, we will only do this either on the basis of your consent, on the basis that we have to share it to comply with our own legal obligations, or to allow us carry out a statutory function that we have.

When we receive a query to our AI Service Desk, we may need to share your personal information with certain of the Market Surveillance Authorities or other parties concerned. We will consider any request for anonymity in respect of a query to our AI Service Desk, but we cannot guarantee that it will be possible to maintain it in every circumstance. Third parties to whom we may disclose information in pursuit of complying without obligations and performing our functions include organisations such as the Market Surveillance Authorities[1], the EU AI Board, and law enforcement bodies.

Using the Oifig IS na hÉireann Service Desk

Any personal information which you provide to the Office by means of electronic or non-electronic communication, using the query form on the Office’s AI Service desk or otherwise will be treated with the highest standards of security and confidentiality, strictly in accordance with the Data Protection Acts and the GDPR.

Your personal data will be collected, used and stored to address the relevant subject matter of your engagement with the Office’s Service Desk or otherwise and may be used to compile statistics. It will not be used for any other purpose other than as provided for in this Statement. Where this website contains links to other external websites and any links to other websites are clearly identifiable as such. The Office is not responsible for the content or privacy practices of other websites. The policy of the Office is to only link to non-commercial sites relevant to the functions of the Office, including the activities of Market Surveillance Authorities and organisations promoting AI literacy.

When you send us a completed query form, a file is generated. This will usually contain personal information about the person making the query and any other individuals named in the form.

As noted above, resolving your query may involve transmitting your query to a Market Surveillance Authority for the purpose of their consideration of your query. We will gather and publish case studies and statistical information on the number and type of queries we receive, but all information is anonymised and does not identify any individual except in cases where the information has lawfully already come into the public domain.

If sensitive personal data is provided by you to engage with the AI Service Desk, appropriate measures will be taken to ensure that it is safely stored and processed. The information contained in query files will be kept in line with our retention policy until the date set for destruction has been reached. It will be kept in a secure environment and available only to those who need to access it.

Emailing us and writing to us

Any emails or written correspondence sent to us will be recorded and forwarded to the relevant Directorate. The sender’s email address will remain visible to all staff tasked with dealing with the query. Please be aware that it is the sender’s responsibility to ensure that the content of their emails is within the bounds of the law. Unsolicited material of a criminal nature may be reported to other relevant authorities and blocked.

Access to personal information

The Office will respond to requests made under the Data Protection Act 2018 and the GDPR, but we are bound by a statutory duty of confidentiality in relation to certain categories of information and therefore may not be able to release information to you, even if you are the data subject.

Transfers outside the European Economic Area

Your personal data may be transferred, stored and processed in one or more countries outside the European Economic Area (“EEA”), for example, when one of our third-party service providers use employees or equipment based outside the EEA. For transfers of your personal data to third parties outside of the EEA, we take additional steps in line with Data Protection Legislation. We will put in place adequate safeguards with respect to the protection of your privacy, fundamental rights and freedoms, and the exercise of your rights, e.g. we will establish an adequate level of data protection through EU Standard Contractual Clauses based on the EU Commission’s model clauses

Data Security

We will take security measures to protect any personal data held by the Office from accidental or unlawful destruction, loss or alteration, and from unauthorised disclosure or access. Access to your personal data – in particular where sensitive personal data is provided by you - is only granted to AI Office staff whose roles require them to process your personal data and, in certain circumstances, to third parties (see the “Sharing of Personal Data” section above).

Your rights

You have rights in relation to your personal data, as a data subject.

Important: These rights are subject to certain restrictions.

Right of access: You have the right to ask for access to the information that we hold about you.

Right to rectification and data erasure: If your personal data is inaccurate, you have the right to have the data rectified. If your personal data is incomplete, you have the right to have data completed, including by means of providing supplementary information. You have the right to request that your data is erased in certain limited circumstances.

Right to restriction of processing: You have a limited right of restriction of processing of your personal data by a data controller.

Right to object: You have the right to object to certain types of processing of your personal data where this processing is carried out in connection with tasks that are either in the public interest, under official authority, or in the legitimate interests of others.

Right to data portability: In some circumstances, you may be entitled to obtain your personal data from a data controller in a format that makes it easier to reuse your information in another context, and to transmit this data to another data controller of your choosing without hindrance.

Right to lodge a complaint:

You have the right to lodge a complaint with the Irish Data Protection Commission: info@dataprotection.ie Data Protection Commissioner 6 Pembroke Row, Dublin 2. D02 X963

See the Data Protection Commission website (How to contact us | Data Protection Commission) for more information.

Changes to this Policy

We reserve the right to change this Privacy Notice at any time in our sole discretion. If we make changes to this Privacy Notice, we will publish any relevant changes on our website. 

How to contact us

If you require further information regarding our Privacy Statement, you can contact our Data Protection Office, Mr. Alexander Cosgrave, at info@aioffice.gov.ie or write to us at: Oifig IS na hÉireann, 23 Kildare Street, Dublin 2 D02 TD 30

Note: The Market Surveillance Authorities are the Central Bank of Ireland (CBI), Data Protection Commission (DPC), Coimisiún na Meán, Commission for Communications Regulation (ComReg), Health and Safety Authority (HSA), Health Products Regulatory Authority (HPRA), Competition and Consumer Protection Commission (CCPC), Workplace Relations Commission (WRC), Commission for Railway Regulation (CRR), Commission for Regulation of Utilities (CRU, Marine Survey Office (MSO), Health Service Executive (HSE), National Transport Authority (NTA).

Cookies Policy