General Data Protection Regulation 2018

December 8, 2017

The General Data Protection Regulations (GDPR) are coming into force on the 25th May 2018. As a regulation, the GDPR will have a direct effect on the Irish law system, including the Data Protection Acts 1988 & 2003 and the Data Protection Directive 95/46/EC.


Purpose

The GDPR focus is on standardising the European citizen’s right to data privacy, as well as emphasising transparency, security and accountability by data controllers.


Key Changes

Fines: The GDPR is providing data protection authorities with administrative fines which can turn out to be devastating for organisations. It allows fining for non-compliance of up to €20mln or 4% of total annual global turnover (whichever is greater) for the most serious breaches.


Data Request:

The new regulation will make it easier for individuals to request copies of data relating to them.


At the moment employees are liable to pay a fee of €6.35 and wait for up to 40 days, for the copies of the data to be supplied to them.


However under the GDPR, this request is now free of charge and an employer now has only 30 days to process the request.


An employer is now also required to provide an employee with additional information such as information on how long data is being stored and the right to have inaccurate data concerning them corrected.


Data Breaches:

Mandatory reporting of data breaches has also been introduced.


At the moment only some organisations are obliged to do this. Once the GDPR comes into force, all organisations will be obliged to report any data breaches to the Data Protection Commissioner within 72 hours.


Breaches that are required to be reported are those that are likely to bring harm to an individual. In addition any concerned individual needs to be informed about the breach also.


A failure to report it could result in a fine, as well as a fine for the breach itself.


Data Protection Officers:

Some companies will be required to appoint a Data Protection Officer. Such organisations include:


  • Public authorities
  • Organisations whose activities involve regular and systematic monitoring of data subjects on a large scale
  • Organisations who process what is known as a sensitive personal data on a large scale.


Recommendations

If your organisation is compliant under the existing law, your approach will be valid under GDPR.


The following are the main principles of Data Protection.We recommend that you make sure that your organisation is compliant with these, as this will vastly help you in the case of any inspection under GDPR:


  • Advise all employees that you are collecting data about them, why you do this, who your Data Controller is and who may have access to it.
  • Obtain and process information fairly
  • Keep it only for one or more specified, explicit and lawful purposes
  • Use and disclose it only in ways compatible with these purposes
  • Keep it safe and secure
  • Keep it accurate, complete and up-to-date
  • Ensure that it is adequate, relevant and not excessive
  • Retain it for no longer than is necessary for the purpose or purpose
  • Give a copy of his/her personal data to that individual on request
  • The GDPR introduces a number of significant changes that every employer must be aware of and be sure to comply with, in order to avoid significant penalties.. We recommend that Employers;


Review their existing Data Protection policies to ensure that they reflect the new changes.

  • Ensure to report any breach that is likely to bring harm to an individual, as well as informing the concerned individuals.
  • Consider whether their company are obliged to appoint a Data Protection Officer.
  • Finally, here are a few questions to bring you one step closer to being compliant:


What data do you hold?

  • Why are you holding it?
  • How long will you retain it?
  • Is it safe?

 


This update is provided by the MSS HR Support Service. For further details on the General Data Protection Regulations or on other HR services please email hr@mssirl.ie.

The 2026 Minimum Wage Increase — What It Means for Small Businesses and How to Get Ready
By Tara Daly October 22, 2025
The increase to €14.15 per hour will have a noticeable effect on small and medium sized businesses.
WRC Award €22k for Dismissal Regarding Sexually Explicit Texts
By Tara Daly October 14, 2025
A recent Workplace Relations Commission (WRC) ruling has once again reinforced one of the most important principles in employment law.
Thousands of ChatGPT Conversations Available Online
By Tara Daly October 14, 2025
With over 100,000 chats searchable online exposing private info, here's why employers need clear AI policies, training, and safeguards to protect sensitive data.
Budget 2026: What It Means for Employers and SMEs
By Tara Daly October 14, 2025
While there are some positive measures many SMEs will feel extra pressure from wage and pension changes taking effect in 2026.
Auto-Enrolment Update: November 2025 Payroll Deadline
By Tara Daly October 1, 2025
Ireland’s new Auto-Enrolment pension scheme, My Future Fund, is edging closer and the timeline has just shifted again. Employers now need to act sooner than expected
By Tara Daly September 3, 2025
What Employers Need to Know
By Tara Daly September 3, 2025
In this blog, we explore a recent WRC ruling where a school was ordered to pay €85,000 in compensation after a teacher was discriminated against during an interview. The case highlights how even seemingly harmless remarks can have serious legal consequences for employers. What Actually Happened? Employee, Emily Williams, who had been working at the school under fixed-term contract and had two years’ experience there, was on maternity leave when a permanent teaching post arose. She was neither notified nor considered, even though she was eligible. Instead, the school awarded the role to a less-experienced colleague not on leave. During a subsequent interview for a fixed-term position, the principal congratulated Williams on the birth of her baby and added: “You really should enjoy every moment at home with the baby.” Williams felt the comment was unprofessional and likely influenced the outcome against her as she had learned she was unsuccessful the very next day. Why the WRC Ruled It Was Discrimination The WRC adjudicator found that: The principal’s comment, made before scoring was complete, was inappropriate and highlighted Williams’ family status. The school could not justify why a less-experienced teacher was chosen. Their claim that it was based on prior interview scores was unsupported, with no clear process to back it up. One interviewer even adjusted a score for Williams downward without explanation, further undermining the credibility of the decision. Given these failures, the WRC concluded that Williams had established a clear case of discrimination on grounds of family status. She was awarded €85,000 in compensation, with the adjudicator stressing the importance of deterrence in cases like this. Why This Ruling Matters for Employers This case underscores three vital lessons for HR and hiring managers. First, keep personal matters out of formal interviews. Even a well-meaning comment can suggest bias or influence the panel. The interview must remain strictly professional. Second, ensure documentation and process are watertight. Reliable scoring systems, consistent policies, and clear records are essential. Without them, hiring decisions become legally and reputationally vulnerable. Finally, fairness must be more than form, it must be function. Interviews should be blind to protected statuses such as family or maternity, and all decisions must be transparent and defensible. How MSS The HR People Can Help MSS is here to help Irish businesses avoid situations like this: Designing discrimination-safe interview processes, from structuring interview panels to defining scoring metrics Training hiring panels on unconscious bias and employment equality legislation Developing clear recruitment communication policies that avoid risks around maternity or other protected characteristics Providing support and representation if a dispute arises before the WRC  Let’s ensure recruitment is fair, transparent, and free of unintended prejudice. Reach out to MSS The HR People, and we’ll help you build safe, compliant hiring practices. MSS The HR People info@mssthehrpeople.ie Ph: 01 8870690
By Tara Daly September 3, 2025
WRC Finds Dismissal Unfair When Employer Fails to Engage
By Tara Daly September 2, 2025
Every business needs solid HR support, that support doesn’t have to be an all-or-nothing affair, a flexible, scalable HR service can assist in your companies growth.
Three Tips to Improve Your Recruitment Process
By Tara Daly August 12, 2025
Lets explore how Irish employers can streamline hiring processes through technology, compliant CV screening, targeted advertising, and a strong employer brand.