Petition updateIrish Government Grant Data Access to British Irish Whistleblower in Geneva, Switzerland

Ger Deering, Irish Ombudsman: Multiple Roles and Data Transparency

Susan BrittonGeneve, Switzerland
Jan 11, 2026

Update: At last, a response from the Irish Ombudsman's Office, but serious questions remain

After a prolonged period of silence a formal response has arrived from the Office of the Ombudsman in relation to GDPR concerns, following the recently disclosed cybersecurity incident affecting the Office.

This comes after media reporting revealed that the incident involved systems operating without a firewall, raising serious concerns about basic data security and governance.

On 7 January 2026, the Ombudsman’s Data Protection Officer acknowledged a GDPR request and assigned it a reference number (GDPR26001SB). A response is now expected by 4 February 2026.

This acknowledgement comes in the context of a long-running pattern of unresolved data requests and missed deadlines. By way of reference (non-exhaustive):

  • An email of 11 October 2024, raising concerns regarding the narrow scope of the response provided by the Data Protection Officer, Ms Connolly, in relation to SAROMB24023, and the failure to address wider categories of data and issues raised.
  • A follow-up correspondence of 4 November 2024 and 3 December 2024, reiterating unresolved issues concerning incomplete data disclosure, whistleblower-related harms, and the absence of substantive engagement with complaints.
  • A letter of 31 January 2025, expressly requesting an urgent update on SAROMB24023 and related complaints, and recording that no adequate or complete response had been provided despite the passage of time.
  • The acknowledgement from the Office dated 11 October 2024, confirming that a response to SAROMB24023 would issue no later than 1 November 2024, which has not been fulfilled in a complete or GDPR-compliant manner.

Data access requests have been outstanding for a very long time, well beyond statutory deadlines.

These requests relate to extensive personal data held by the Office of the Ombudsman, including complaints, evidence, internal records, and correspondence.

The existence of a cybersecurity incident, reportedly involving inadequate protections, makes transparency about what happened to that data absolutely essential.

This update is not about presuming a breach of personal data. It is about accountability. When an oversight body tasked with protecting citizens’ rights experiences a cybersecurity failure, timely, complete, and lawful responses are not optional but fundamental.

Thank you to everyone who continues to support this campaign and the wider call for accountability, transparency, and respect for whistleblowers and complainants.

Copy link
WhatsApp
Facebook
Nextdoor
Email
X