Petition updateIrish Government Grant Data Access to British Irish Whistleblower in Geneva, Switzerland

Systemic issues? Six Data Protection Commission References

Susan BrittonGeneve, Switzerland
Aug 12, 2026

As of August 2026, the Irish Data Protection Commission (DPC) has at least six separately numbered current cases concerning access to Irish whistleblower data held by different Irish public bodies.

These concern:

An Garda Síochána — DPC0426686944
Department of Foreign Affairs — DPC1025892675
Fiosrú, Office of the Police Ombudsman — DPC0426160707
Office of the Ombudsman — DPC0526909312
Houses of the Oireachtas/PAC — DPC0326742487
Standards in Public Office Commission (SIPO) — DPC0226001071
Three — concerning An Garda Síochána, the Department of Foreign Affairs and Fiosrú — have expressly been transferred to the DPC's Complaint Assessment and Early Resolution Team (CAERU).

A serious backlog
The DPC's correspondence reveals something striking about how long complainants may have to wait.

On 31 July 2026, when transferring the Fiosrú complaint to CAERU, the DPC stated that:

“Cases which were received in July 2025 are currently being assigned to case officers for assessment.”
In other words, complaints were facing a backlog of approximately a year simply to reach case-officer assignment.

This matters because the underlying complaints already concern delays or disputes over access to personal data. A person can therefore wait for a public authority to respond to a subject access request, complain when access is not provided, and then potentially wait many additional months for regulatory assessment.

The problem goes back years
The current cases cannot be viewed entirely in isolation from what happened previously.

Historical DPC files C-20-10-827 and C-24-6-867 also concerned access to personal data held by Irish public authorities.

In June 2026, the DPC said those historical files had been concluded because requested documentation had been sought and “no further response was received”.

But the documentary record raises serious questions about that explanation.

For C-20-10-827, the DPC wrote on 18 May 2021 saying that if it did not hear from me within two months it would presume the access matters resolved.

I responded on 1 June 2021 — only 14 days later — expressly quoting the case reference and stating that my Department of Foreign Affairs data-access problem remained unresolved. Further correspondence followed.

There is a similar issue concerning C-24-6-867. Records show correspondence sent to the DPC after its September 2024 request, including correspondence expressly carrying that case reference, followed by further follow-ups.

I have therefore asked the DPC to establish when these files were actually closed, why they were closed, what correspondence was recorded against them, and whether their histories need to be corrected.

The Oireachtas case raises another important issue
The Houses of the Oireachtas has now confirmed that there was an internally generated document containing my personal data.

It was considered by the Committee on Parliamentary Privilege and Oversight (CPPO) on 28 April 2026, and a decision was made not to release it to me.

Questions remain about why it was referred to the CPPO, the legal basis for withholding access, the nature of the document, and whether searches captured all other records containing my personal data — including internal emails, briefing material, notes, minutes, referral records, metadata and any recordings.

Six cases, but a wider question
Each public authority is a separate data controller and each complaint must, of course, be determined on its own facts.

But when six current DPC cases involving one data subject and multiple Irish public authorities repeatedly concern access to personal data, there is also a legitimate wider regulatory question.

At what point does a series of individual access disputes become something the regulator should examine collectively for recurring compliance problems?

I have therefore asked the DPC not to merge the complaints, but to cross-reference them at senior and regulatory level, while preserving their separate case references and individual assessments.

I have also asked for clear confirmation of the status of all six current cases, proper progress information, and a review of the disputed closure histories of the earlier files.

This is ultimately about something very simple:

A right of access that cannot be exercised effectively, or that takes years of correspondence and regulatory complaints to enforce, risks becoming a right on paper rather than a right in practice.

The request to the DPC is straightforward: deal with each complaint fairly and independently, correct the historical record where necessary, and examine whether the repeated problems reveal a wider pattern requiring regulatory attention.

#DataProtection #GDPR #Ireland #Accountability #Transparency #RightOfAccess

Copy link
WhatsApp
Facebook
Nextdoor
Email
X