Data Request to DFA


🚨What happens when the Irish Department of Foreign Affairs isn't complying with a Subject Access Request?
On 24 March 2026, a formal data access request (Ref: DSAR-2026-023) was submitted to the DFA.
All requirements have been met:
proof of identity and address
definition of scope of request
prompt responses to all follow-up queries
Under Article 12(3) GDPR, the Department had one month to respond.
👉 That deadline has now passed
👉 No substantive response has been provided
Why this matters
This is not just an administrative delay—it raises serious concerns about:
❗ Failure by the Irish Department of Foreign Affairs to meet legal obligations
❗ Potential unlawful restriction of access to personal data
❗ Lack of transparency in a public authority
❗ Risk of broader systemic non-compliance
There have also been attempts to limit the scope of the request, excluding:
Historical records (pre-April 2021)
Known but undisclosed files (including a referenced “paper file”)
Email communications and metadata
This directly undermines the purpose of GDPR.
I am calling on the Irish Department of Foreign Affairs to:
✅ Confirm when the statutory timeframe began
✅ Provide a full explanation for the delay
✅ Commit to a clear deadline for full disclosure
✅ Confirm that all relevant systems are being searched, including:Email archives
Case management systems
Metadata and audit logs
Physical (paper) files
How effective is the Data Protection Commissioner? About as effective as every other government regulator, it seems.