Report of the Irish Data Protection Commission highlights significant increase in complaints
The release of the 2019 Annual Report of the Irish Data Protection Commission on 20 February 2020 has revealed that the numbers of complaints which the Commission received in the past year in relation to data protection issues has increased by a margin of 75% over the number received in 2018. The Commission received a total of 7,215 complaints over the course of the past 12 months, a substantial increase over the 4,113 received in 2018.
Perhaps of little surprise to legal firms and large-scale employers alike, over 2,000 of the complaints received by the Commission in 2019 related to data subject access requests and the right to access, particularly in relation to the failure of organisations in control of personal data to respond to an access request, or failure by such organisations to release all the appropriate data on foot of an access request. Indeed, the Report acknowledges that an increased number of complaints received were against banks and solicitors’ practices and that disputes between employees and employers or former employers remain a significant theme of the complaints, with the contention based around a disputed access request.
Outside of complaints in relation to access rights, another key takeaway from the Commission’s 2019 Report is the vast increase in data breaches being reported to the Commission. 6,069 valid data security breaches were notified representing a 71% increase on the total number of valid data security breaches (3,542) recorded in 2018. This increase reflects the increasing awareness amongst the public of their data protection rights under the GDPR and highlights the care which organisations must take in ensuring data breaches are appropriately prevented, in particular when internally deciding that a breach is not to be reported to the Commission. In this case, controllers must remember that they are obliged to record at least the basic details of the breach, the assessment thereof, its effects, and the steps taken in response, as required under Article 33(5) GDPR.
How we can help
For more information on complying with your obligations under the GDPR or enforcing your data protection rights, please feel free to contact Joe McVeigh or Lee Taren in our Technology and Intellectual Property Team.
This article is for general information purposes. Legal advice must be obtained for individual circumstances. Whilst every effort has been made to ensure the accuracy of this article, no liability is accepted by the author for any inaccuracies.