Source methodology

Deferred official source

Ireland DPC data breach statistics

One annual national aggregate published in the regulator's annual report

Annual-report aggregates, subject to the reporting scope and definitions in each report.

Regulator
Data Protection Commission
Jurisdiction
Ireland
Reporting scheme
GDPR personal data breach notifications
Publication level
National Aggregate
Coverage type
Aggregate Reporting Periods
Reporting threshold
The annual figures concern valid personal data breach notifications received by the Data Protection Commission.
Source population
Valid notifications received by the Data Protection Commission during the reporting year.
Licence state
The Data Protection Commission permits reuse of public-sector information subject to attribution, accuracy, non-misleading presentation, and other stated conditions.
Rights boundary reviewed
26 July 2026
Redistribution decision
Deferred
Automated health
Deferred
Snapshot completeness
Deferred
Update checkpoint
Deferred
Reviewed record floor
Not published
Accepted records
Not published
Rejected records
Not published
Bounded retrieval limit
Not published
Source revision
Not published
Snapshot checksum
Not published
Latest update attempt
Not published
Last successful update
Not published

Limitations

  • The reviewed official HTTPS service did not provide a certificate chain that the bounded standards-based client could validate.
  • TLS verification will not be disabled or bypassed to collect this source.
  • No records are published until secure retrieval succeeds and the report schema is fixed and tested.
  • Annual counts are notifications, not automatically unique real-world incidents.

Correction process

Recheck the official annual report and reuse conditions after the regulator's HTTPS certificate chain can be validated by the bounded client.

Attribution

Data Protection Commission, Ireland