Source methodology
Deferred official source
Ireland DPC data breach statistics
One annual national aggregate published in the regulator's annual report
Annual-report aggregates, subject to the reporting scope and definitions in each report.
- Regulator
- Data Protection Commission
- Jurisdiction
- Ireland
- Reporting scheme
- GDPR personal data breach notifications
- Publication level
- National Aggregate
- Coverage type
- Aggregate Reporting Periods
- Reporting threshold
- The annual figures concern valid personal data breach notifications received by the Data Protection Commission.
- Source population
- Valid notifications received by the Data Protection Commission during the reporting year.
- Licence state
- The Data Protection Commission permits reuse of public-sector information subject to attribution, accuracy, non-misleading presentation, and other stated conditions.
- Rights boundary reviewed
- 26 July 2026
- Redistribution decision
- Deferred
- Automated health
- Deferred
- Snapshot completeness
- Deferred
- Update checkpoint
- Deferred
- Reviewed record floor
- Not published
- Accepted records
- Not published
- Rejected records
- Not published
- Bounded retrieval limit
- Not published
- Source revision
- Not published
- Snapshot checksum
- Not published
- Latest update attempt
- Not published
- Last successful update
- Not published
Limitations
- The reviewed official HTTPS service did not provide a certificate chain that the bounded standards-based client could validate.
- TLS verification will not be disabled or bypassed to collect this source.
- No records are published until secure retrieval succeeds and the report schema is fixed and tested.
- Annual counts are notifications, not automatically unique real-world incidents.
Correction process
Recheck the official annual report and reuse conditions after the regulator's HTTPS certificate chain can be validated by the bounded client.
Attribution
Data Protection Commission, Ireland