Law / Ireland

Ireland

European Union law applies in Ireland Ireland is a member state of the European Union, whose 37 researched instruments are listed on the European Union page, not here. The law of Ireland, described on this page below, applies here too.

21 of 24 named instruments researched to a stage, across all six areas of law we track: 19 in force and 2 proposed. As of 12 September 2026.

When they take effect19 of 21 carry a date, 2 do not. Earlier is before 2014.
Before 2014: 1 instrument (1 in force) earlier 2014: 0 instruments 2015: 0 instruments ’15 2016: 0 instruments 2017: 1 instrument (1 in force) 2018: 9 instruments (9 in force) 2019: 0 instruments 2020: 0 instruments ’20 2021: 3 instruments (3 in force) 2022: 0 instruments 2023: 1 instrument (1 in force) 2024: 1 instrument (1 in force) 2025: 2 instruments (2 in force) 2026: 1 instrument (1 in force) ’26 today

in forceenacted but not yet in forceproposedrepealed, withdrawn or blocked

  1. AI law 3
  2. Privacy law 7
  3. Scraping law 3
  4. Cybersecurity law 4
  5. Age gating law 3
  6. News aggregation law 1

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

AI law3 instruments, 3 in force

Research summary (300 words)

The EU AI Act (Regulation (EU) 2024/1689) applies directly in Ireland and is not restated here as Irish law. Ireland gave it further effect in two steps.

First, the European Union (Artificial Intelligence) (Designation) Regulations 2025 (S.I. No. 366 of 2025) designated the Minister for Enterprise, Tourism and Employment as national competent authority and single point of contact, and designated a set of sectoral bodies, including the Central Bank of Ireland and the Data Protection Commission, as market surveillance and notifying authorities.

Second, the Regulation of Artificial Intelligence Act 2026 (No. 31 of 2026), signed into law on 21 July 2026 and in operation from 31 July 2026, established Oifig IS na hÉireann (the AI Office of Ireland) as an independent statutory body with its own board and chief executive, created an AI regulatory sandbox and a real-world testing regime, and built a full supervision, adjudication and administrative-fines architecture for AI Act breaches, with a distinct EUR 1,000,000 cap on a fine imposed on a public body.

The Act also creates its own criminal offences for matters such as obstructing an authorised officer, unauthorised disclosure of confidential information and giving an adjudicator false information, and amends the Central Bank Act 1942, the Communications Regulation Act 2002, the Competition and Consumer Protection Act 2014 and the Freedom of Information Act 2014.

Separately from the AI Act framework, the Harassment, Harmful Communications and Related Offences Act 2020 criminalises distributing, publishing or threatening to distribute or publish an intimate image of a person without consent; the Act's definition of 'intimate image' reaches an image that merely purports to be the person's intimate depiction, made by any means including a digital representation, so the offence is not limited to a genuine photograph and reaches an AI-generated or digitally altered synthetic image of that kind.

AI governance

European Union (Artificial Intelligence) (Designation) Regulations 2025

European Union (Artificial Intelligence) (Designation) Regulations 2025 (S.I. No. 366 of 2025)Irish Statute Book, official text of S.I. No. 366 of 2025

In force since 25 July 2025. Binds government bodies.

What this law does

Made under section 3 of the European Communities Act 1972 to give further effect to the EU AI Act, these Regulations designate the Minister for Enterprise, Tourism and Employment as a national competent authority for the purposes of Article 70(1) and as the single point of contact for the purposes of Article 70(2).

They designate the Central Bank of Ireland as market surveillance authority for the purposes of Article 74(6) and the Data Protection Commission as market surveillance authority for the purposes of Article 74(8).

A schedule designates further sectoral market surveillance authorities, including the Health and Safety Authority, the Competition and Consumer Protection Commission, the Commission for Communications Regulation, the Commission for Railway Regulation, the Marine Survey Office and the Health Products Regulatory Authority, against the relevant points of Section A of Annex I to the AI Act, and designates notifying authorities for the purposes of Article 28.

The Regulations create no separate duty on an AI developer or deployer; they identify which State body enforces the AI Act against one.

What it requires

Regulation of Artificial Intelligence Act 2026

Regulation of Artificial Intelligence Act 2026 (No. 31 of 2026)Irish Statute Book, official text of the Regulation of Artificial Intelligence Act 2026

In force 54 days, effective 31 July 2026. Binds public and private bodies.

What this law does

This Act establishes Oifig IS na hÉireann as an independent statutory body, with its own Board and Chief Executive Officer, to give further effect to the EU AI Act in Ireland. Part 3 gives the Office the single-point-of-contact and AI register functions and creates an AI regulatory sandbox and a real-world testing regime for high-risk AI systems.

Part 4 sets general obligations on the relevant market surveillance authorities designated for the AI Act, including derogation, incident-reporting and complaints-handling duties. Parts 5 and 6 build a full supervision, adjudication and administrative-fines architecture: authorised officers may issue contravention notices, prohibition notices and forfeiture orders, and an independent adjudicator determines whether an AI Act breach occurred and what administrative fine, if any, to impose.

An administrative fine otherwise follows the ceiling the AI Act's own Article 99 sets for the type of breach, except that a fine imposed on a public body is capped at EUR 1,000,000 regardless of which Article 99 tier would otherwise apply.

Part 7 creates criminal offences, including for unauthorised disclosure of confidential information, obstructing or giving false information to an authorised officer or adjudicator, and disclosing material relevant to an adjudicator's finding without authorisation.

Parts 8 to 10 amend the Central Bank Act 1942 to give the Central Bank AI Act administrative-sanctioning powers, and make further amendments to the Communications Regulation Act 2002, the Competition and Consumer Protection Act 2014 and the Freedom of Information Act 2014.

What it requires

AI prohibited practices

Harassment, Harmful Communications and Related Offences Act 2020, Intimate Image Offences

Harassment, Harmful Communications and Related Offences Act 2020 (No. 32 of 2020), ss. 1-3Irish Statute Book, official text of the Harassment, Harmful Communications and Related Offences Act 2020

In force since 10 February 2021. Binds public and private bodies.

What this law does

Section 2 makes it an offence to distribute, publish or threaten to distribute or publish an intimate image of another person without that person's consent, with intent to cause harm or being reckless as to whether harm is caused. Section 3 separately makes it an offence to record, distribute or publish an intimate image of another person without consent where that act seriously interferes with the other person's peace and privacy or causes alarm, distress or harm.

The Act's definition of 'intimate image' covers any visual representation, made by any means including a photographic, film, video or digital representation, of what is, or purports to be, the person's genitals, buttocks, anal region, or, for a woman, her breasts, of underwear covering those areas, of a nude person, or of a person engaged in sexual activity.

Because the image need only purport to be the person's intimate depiction and may be made by any digital means, the offence reaches a fabricated or digitally altered image of that kind, including an AI-generated or AI-altered synthetic image, and is not limited to a genuine photograph of the person.

What it requires

Privacy law7 instruments, 7 in force

Research summary (79 words)

Ireland's private-sector regime is the General Data Protection Regulation (GDPR) plus the Data Protection Act 2018 (No. 7 of 2018), which supplies Ireland's national derogations, enforcement architecture, and the Data Protection Commission (DPC) as supervisory authority.

Because most large United States technology companies' EU headquarters sit in Ireland, the DPC is disproportionately significant as lead supervisory authority under the GDPR one-stop-shop mechanism, and its 2024 guidance applying existing privacy duties to AI training is a de facto reference point for the whole EU.

Breach notification

GDPR Articles 33-34, Breach Notification in Ireland

Regulation (EU) 2016/679, Arts. 33-34Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

A controller must notify the Data Protection Commission without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No DPA 2018 derogation from this timeline was identified.

What it requires

Comprehensive regime

DPC Guidance: AI, Large Language Models and Data Protection

Data Protection Commission, "AI, Large Language Models and Data Protection" guidance (18 July 2024)Data Protection Commission guidance page, dataprotection.ie

In force since 18 July 2024. Binds public and private bodies.

What this law does

The DPC's July 2024 guidance applies Ireland's existing General Data Protection Regulation (GDPR) and Data Protection Act 2018 duties, lawful basis before collecting personal data for AI training, data minimization, honoring access, rectification and erasure requests where feasible against a trained model, and data protection impact assessments for higher-risk processing, to the specific context of building and operating Large Language Models and other AI systems.

The guidance states directly that publicly accessible personal data still falls within the scope of the GDPR, and that a controller assessing necessity and proportionality for AI training must account for the purposes for which people made their personal data publicly accessible in the first place, not only for the fact of public accessibility.

This interprets Ireland's existing personal-data duties in an AI training context; it does not itself create a duty that attaches because a system is an AI system. The guidance does not itself distinguish a public-sector from a private-sector controller, but GDPR Article 4(7) defines a controller to include a public authority or body on the same footing as a natural or legal person, so the duties it applies to AI training bind either kind alike.

The DPC has since opened a formal inquiry into X Internet Unlimited Company's processing of EU/EEA users' publicly-accessible posts to train the Grok large language models (LLMs). It also engaged with Meta over its plans to train a generative AI model on public Facebook and Instagram content, leading Meta to pause and later revise the rollout.

And it has stated of LinkedIn's AI training that it has not approved or found compliant LinkedIn's use of members' personal data for that purpose, though LinkedIn's added measures have addressed its concerns enough that no further regulatory intervention is planned for now.

What it requires

Data Protection Act 2018

Data Protection Act 2018 (No. 7 of 2018)Irish Statute Book, official consolidated text

In force since 25 May 2018. Binds public and private bodies.

What this law does

The General Data Protection Regulation (GDPR) applies directly in Ireland, and the Data Protection Act 2018 (DPA 2018), No. 7 of 2018, gives it domestic effect: Part 3 supplies Ireland's national derogations and exemptions, Part 2 establishes the Data Protection Commission (DPC) as supervisory authority, and Part 6 supplies the enforcement architecture; Part 5 transposes the Law Enforcement Directive and is not the GDPR regime.

Because most large United States technology companies base their EU headquarters in Ireland, the DPC is the lead supervisory authority under the GDPR one-stop-shop mechanism for most of their cross-border processing, which makes Irish enforcement practice a de facto reference point for the whole EU, including on how existing privacy law reaches AI training uses of personal data.

What it requires

Cross border transfer

GDPR Chapter V, Cross-Border Transfer of Personal Data from Ireland

Regulation (EU) 2016/679, Arts. 44-49Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

Transferring personal data of a person in Ireland outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the highest Article 83(5) fine tier.

The DPC additionally operates the one-stop-shop coordination role given Ireland's concentration of EU-headquartered controllers, but this is an institutional and procedural role in cross-border enforcement coordination, not an added transfer restriction. No DPA 2018-specific derogation on outbound transfers was identified.

What it requires

Data subject rights

GDPR Article 22, Automated Decision-Making in Ireland

Regulation (EU) 2016/679, Art. 22, as transposed by the Data Protection Act 2018Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Articles 12 to 23 apply, including Article 22 rights against a decision based solely on automated processing that produces legal or similarly significant effects, which the DPA 2018 gives domestic effect to with the DPC as enforcement authority. Where an automated decision is permitted, on contract necessity, legal authorization, or explicit consent, the controller must implement human-intervention, point-of-view, and contest safeguards.

Sections 41 to 43 of the DPA 2018 narrow specific data-subject rights, including the Article 22 adjacent rights of access, rectification, restriction and objection, for archiving in the public interest, scientific or historical research, or statistical purposes where exercising the right would render the purpose impossible or seriously impair it.

What it requires

Enforcement supervision

GDPR Article 82, Data Protection Act 2018 Section 117, and DPC Enforcement in Ireland

Regulation (EU) 2016/679, Arts. 82-83; Data Protection Act 2018 §117Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

The DPC is Ireland's supervisory authority, established under Part 2 of the DPA 2018 and enforcing under Part 6, with General Data Protection Regulation (GDPR) Article 83 administrative fines. Article 82 arms an individual with a direct private right of action, and Section 117 DPA 2018 specifies that the civil action for material or non-material damage, including distress, is brought in the Circuit Court or the High Court.

Ireland's own collective-redress channel is limited: a not-for-profit body can act on a data subject's authorised behalf under Article 80(1), and the Representative Actions for the Protection of the Collective Interests of Consumers Act 2023 lets a body designated a qualified entity by the Minister for Enterprise, Trade and Employment bring representative actions covering DPA 2018 claims, a designation reviewed at least every five years and revocable.

What it requires

Sensitive categories

GDPR Article 9 and Data Protection Act 2018 Section 46, Special Categories and Employment Biometric Data in Ireland

Regulation (EU) 2016/679, Art. 9; Data Protection Act 2018 §46Official Journal text, EUR-Lex, Regulation (EU) 2016/679

In force since 25 May 2018. Binds public and private bodies.

What this law does

General Data Protection Regulation (GDPR) Article 9(1) governs biometric data as a special category, and the DPA 2018 explicitly lists biometric data among the special categories it elaborates on.

Section 46 addresses processing special category data, including biometric data, in the employment and social-welfare context: the processing is lawful where it is necessary for exercising or performing a right or obligation conferred or imposed by law on the controller or the data subject in connection with employment or social welfare law (the GDPR Article 9(2)(b) condition), with suitable and specific measures safeguarding the data subject.

No dedicated Irish provision on voiceprint capture, retention, or destruction specifically was found; the GDPR baseline, that a voiceprint captured through specific technical processing for identification is special category data on the same footing as a faceprint, governs by default.

What it requires

Scraping law3 instruments, 3 in force

Research summary (295 words)

Ireland has no scraping-specific statute, so each dimension rests on general law. The Criminal Justice (Offences Relating to Information Systems) Act 2017 criminalises intentionally accessing an information system without lawful authority, but section 2 requires infringing a security measure to gain access, so reading a public, unauthenticated page without defeating any access control falls outside a plain reading of that offence; no reported Irish case has tested the point.

The Act replaced the earlier, narrower unauthorised-access offence at section 5 of the Criminal Damage Act 1991, which it repealed outright. No Irish court has ruled on the enforceability of a browsewrap or clickwrap terms-of-service against a scraper.

The Copyright and Related Rights Act 2000 permits fair dealing with a work for research or private study, for criticism or review, and for reporting current events other than by photograph, each with sufficient acknowledgement, and permits incidental inclusion and non-prejudicial quotation; since the European Union (Copyright and Related Rights in the Digital Single Market) Regulations 2021, it also carries a text-and-data-mining exception with a rightholder opt-out for commercial use and an unconditional exception for research organisations and cultural heritage institutions.

The 2000 Act's Part V confers a sui generis database right on the maker of a database in which there has been a substantial investment in obtaining, verifying or presenting its contents, running for 15 years and renewable on a substantial new investment; this exists independently of any copyright in the database's contents. Personal-data protection over scraped Irish personal data is covered in the jurisdiction's privacy-topic document and is not restated here.

No Irish statute or reported case establishes a scraping-specific unfair-competition, misappropriation or trespass doctrine, and none assigns legal weight to a robots.txt directive or imposes an AI-training-specific rule beyond the general text-and-data-mining exception described above.

Computer misuse

Criminal Justice (Offences Relating to Information Systems) Act 2017

Criminal Justice (Offences Relating to Information Systems) Act 2017 (No. 11 of 2017), ss. 2-6, 8, 13Irish Statute Book, official text of the Criminal Justice (Offences Relating to Information Systems) Act 2017

In force since 12 June 2017. Binds public and private bodies.

What this law does

Section 2 makes it an offence to intentionally access an information system without lawful authority or reasonable excuse by infringing a security measure. Sections 3 and 4 separately criminalise intentionally hindering or interrupting the functioning of an information system, or intentionally deleting, damaging, altering or suppressing data on it, without lawful authority.

Section 5 criminalises intentionally intercepting a non-public transmission of data to, from or within an information system, without lawful authority. Section 6 criminalises producing, selling, procuring, importing, distributing or otherwise making available a computer programme, password, code or similar data designed for committing any of the section 2 to 5 offences.

Because section 2's trigger is infringing a security measure, reading a public, unauthenticated page without defeating any access control falls outside a plain reading of that offence; no reported Irish case has tested the point. The Act repealed the earlier, narrower 'unauthorised accessing of data' offence at section 5 of the Criminal Damage Act 1991, which had rested on operating a computer with intent to access data rather than on defeating a security measure.

What it requires

Copyright and text and data mining (TDM)

Text and Data Mining Exceptions, Copyright and Related Rights Act 2000 ss. 53A-53B

European Union (Copyright and Related Rights in the Digital Single Market) Regulations 2021 (S.I. No. 567 of 2021) regs. 3-4, inserting and amending ss. 53A and 53B of the Copyright and Related Rights Act 2000Irish Statute Book, official text of S.I. No. 567 of 2021

In force since 12 November 2021. Binds public and private bodies.

What this law does

The 2021 Regulations added a new section 53B to the Copyright and Related Rights Act 2000: where an author has not expressly reserved, in an appropriate manner, the use of a work for reproduction or extraction for the purposes of text and data mining, a person who has lawful access to the work may reproduce it for that purpose, and may retain the reproduction for as long as necessary for the mining.

A reservation is made in an appropriate manner where it is machine-readable, for content made publicly available online, including in the metadata or terms and conditions of a website or service, or otherwise clearly communicated to persons with lawful access.

The Regulations also amended the pre-existing research and non-commercial text-and-data-mining exception at section 53A by inserting new subsections requiring that a copy made under it be stored securely and retained only as necessary for scientific research, including for verification, and by providing that any contractual provision contrary to the section is unenforceable. A parallel exception for computer programs was inserted at section 82(3)-(5). A parallel exception for subject matter protected by related rights was inserted after section 225A as section 225AA.

What it requires

Database right

Copyright and Related Rights Act 2000, Database Right

Copyright and Related Rights Act 2000 (No. 28 of 2000), Part V, ss. 320, 321, 325Irish Statute Book, official text of the Copyright and Related Rights Act 2000

In force since 1 January 2001. Binds public and private bodies.

What this law does

Part V of the Copyright and Related Rights Act 2000 confers a property right, the database right, on a database in which there has been a substantial investment in obtaining, verifying or presenting its contents, whether or not the database or any of its contents is itself a copyright work. 'Extraction' means the permanent or temporary transfer of all or a substantial part of the database's contents to another medium.

'Re-utilisation' means making those contents available to the public by any means, and 'substantial' is judged by quantity or quality or a combination of both. The right expires 15 years from the end of the calendar year the database was completed, or from the end of the calendar year it was first lawfully re-utilised if that comes later, and a substantial change to the database's contents amounting to a substantial new investment qualifies the resulting database for its own fresh term. The right exists independently of any copyright in the database's underlying contents.

What it requires

Cybersecurity law4 instruments, 2 in force, 2 proposed

Research summary (418 words)

Ireland's cyber-resilience posture for the private-sector duty-bearer rests on an incomplete transposition.

The National Cyber Security Bill 2024, which would transpose the NIS2 Directive (Directive (EU) 2022/2555) and place the National Cyber Security Centre (NCSC) on a statutory footing, exists only as a General Scheme (Heads of Bill) published 30 August 2024; it has undergone pre-legislative scrutiny by an Oireachtas committee but had not been introduced as a Bill in either House as of the Government's own Summer 2026 Legislation Programme.

Ireland missed NIS2's 17 October 2024 transposition deadline, and on 8 July 2026 the European Commission referred Ireland to the Court of Justice of the European Union for failing to notify complete transposition; the Minister for Justice, Home Affairs and Migration has said he expects to notify transposition by the end of 2026.

Pending enactment, the predecessor regime, S.I. No. 360 of 2018 (transposing the original NIS Directive, Directive (EU) 2016/1148), remains in full effect and binds a designated operator of essential services across the energy, transport, banking, financial market infrastructure, health, drinking water and digital infrastructure sectors, and a relevant digital service provider such as an online marketplace, online search engine or cloud computing service, to security measures and to a 72-hour incident-notification clock to the State's CSIRT.

No Irish instrument locates a product-security or market-placement duty on a manufacturer independent of the directly applicable Cyber Resilience Act, which is documented at the European Union level and is not restated here; the General Scheme's own scope (Heads 20 to 23) classifies essential and important entities and public administration bodies rather than products, and no separate connected-device or manufacturer statute is described here.

Ireland has no general reasonable-security or information-security-programme statute with no sector gate; the closest general duty is General Data Protection Regulation (GDPR) Article 32's security-of-processing obligation and the Data Protection Act 2018's breach-notification duties to the Data Protection Commission, both of which sit in the privacy topic rather than here.

Both the risk-management and incident-reporting duties the General Scheme would create, and the equivalent duties S.I. No. 360 of 2018 already imposes, bind a wider class of essential and important entity by sector and size that no activity in this vocabulary expresses; only the digital-provider slice of that class (an online marketplace, online search engine, cloud computing service and comparable digital platform) is flagged here, and the broader sector classes, together with the public administration class the enacted Act would add, are recorded here as law the lint does not yet reach rather than flagged on a guess.

Sector security regimes

European Union (NIS) Regulations 2018, Security Requirements

S.I. No. 360/2018, Regs. 17 and 21Statutory Instrument text, Irish Statute Book, S.I. No. 360 of 2018

In force since 18 September 2018. Binds public and private bodies.

What this law does

Regulation 17 requires a designated operator of essential services (an undertaking the Minister or the Central Bank of Ireland designates in the energy, transport, banking, financial market infrastructure, health, drinking water supply and distribution, or digital infrastructure sectors listed in Schedule 1) to take appropriate and proportionate technical and organisational measures, having regard to the state of the art, to manage the risks to the network and information systems it uses and to prevent or minimise the impact of an incident on the continuity of its service.

Regulation 21 imposes the equivalent duty on a relevant digital service provider, an online marketplace, online search engine or cloud computing service under Schedule 2, and additionally requires it to take into account the security of its systems and facilities, incident handling, business continuity management, monitoring, auditing and testing, and compliance with international standards.

These Regulations transpose the original NIS Directive (Directive (EU) 2016/1148) and, according to the National Cyber Security Centre, remain in full effect pending the National Cyber Security Bill's transposition of its successor, NIS2, and cover the most critical operators in the State in the meantime.

What it requires

National Cyber Security Bill, Cybersecurity Risk-Management Measures

Head 29, General Scheme, National Cyber Security Bill 2024General Scheme (Heads of Bill), Department of Justice, Home Affairs and Migration, published 30 August 2024

Proposed: draft date not recorded. In committee, dated 15 July 2025, as of 12 September 2026. Binds public and private bodies.

What this law does

Head 29 of the General Scheme would require every essential and important entity to take appropriate and proportionate technical, operational and organisational measures to manage the risks to the network and information systems it uses for its operations or services, and to prevent or minimise the impact of an incident, transposing NIS2 Article 21.

Head 28 would require the entity's management board to approve and oversee those measures and would hold the board liable for an infringement; the same Head's own explanatory note states that an organisation's management and executives can be found personally liable where gross negligence is found following a cybersecurity incident, a duty NIS2 itself does not require a Member State to impose on a natural person.

Head 25 would exempt an entity from these measures to the extent an equivalent sector-specific EU regime, such as the Digital Operational Resilience Act for a banking or financial-market-infrastructure entity, already imposes at least equivalent risk-management duties. This duty does not yet bind: the General Scheme has undergone pre-legislative scrutiny but has not been introduced as a Bill in either House of the Oireachtas.

What it requires

Vulnerability and incident reporting

European Union (NIS) Regulations 2018, Incident Notification

S.I. No. 360/2018, Regs. 18 and 22Statutory Instrument text, Irish Statute Book, S.I. No. 360 of 2018

In force since 18 September 2018. Binds public and private bodies.

What this law does

Regulation 18 requires a designated operator of essential services to notify the State's CSIRT, without delay and in any event not later than 72 hours after becoming aware, of an incident with a significant impact on the continuity of an essential service it provides, including an incident affecting a third-party digital service provider it relies on, and to notify the CSIRT again once the incident is resolved.

Regulation 22 imposes the equivalent duty on a relevant digital service provider for an incident with a substantial impact on a service listed in Schedule 2. The CSIRT is the unit of the State's cybersecurity department that Regulation 10 designates.

Regulation 6 requires the competent authority, the CSIRT and the single point of contact to cooperate with the Data Protection Commission where a notified incident also compromises personal data, a duty distinct from the breach-notification duty General Data Protection Regulation (GDPR) itself imposes on a controller.

What it requires

National Cyber Security Bill, Incident Response Powers and Reporting Obligations

Head 15, General Scheme, National Cyber Security Bill 2024General Scheme (Heads of Bill), Department of Justice, Home Affairs and Migration, published 30 August 2024

Proposed: draft date not recorded. In committee, dated 15 July 2025, as of 12 September 2026. Binds public and private bodies.

What this law does

Head 15 of the General Scheme would require an essential or important entity to notify the CSIRT, without undue delay, of any incident with a significant impact on the provision of its service, submitting an early warning within 24 hours of becoming aware of the incident, an incident notification within 72 hours, and a final report within one month, on the same clock NIS2 Article 23 sets.

Where appropriate, the entity must also notify the recipients of its service of the incident and of any mitigating measures they can take. Head 16 would separately give the NCSC a coordinated vulnerability disclosure function for a vulnerability reported about any product or service in the State, a duty the General Scheme places on the NCSC rather than on the product's manufacturer.

This duty does not yet bind: the General Scheme has undergone pre-legislative scrutiny but has not been introduced as a Bill in either House of the Oireachtas.

What it requires

Age gating law3 instruments, 3 in force

Research summary (163 words)

Ireland's Online Safety and Media Regulation Act 2022 established Coimisiún na Meán (the Media Commission) as the national online safety and broadcasting regulator and gave it power to designate video sharing platforms and adopt binding online safety codes.

Under the Online Safety Code adopted in October 2024, designated video sharing platforms that carry pornography or gratuitous violence must use effective age assurance so that children are not normally able to access that content, with self declaration methods such as ticking a box or entering a date of birth explicitly ruled out as insufficient.

The Code's general child safety provisions took effect on 19 November 2024, and the pornography and violent content age assurance obligations became binding on 21 July 2025. Separately, section 31 of the Data Protection Act 2018 sets Ireland's digital age of consent at 16, the minimum age at which a child can consent to the processing of personal data by an information society service such as a social media platform.

Adult content age verification (AV)

Online Safety Code, Part B (age assurance for pornography and violent content)

Online Safety Code (Coimisiún na Meán, adopted 21 October 2024), Part Bofficial Code text and adoption decision, Coimisiún na Meán

In force since 21 July 2025. Binds private bodies.

What this law does

Requires designated video sharing platforms, including Facebook, Instagram, YouTube, TikTok, X, LinkedIn, Pinterest, Tumblr and Udemy, that allow pornography or gratuitous violence to implement effective age assurance so children are not normally able to access that content. Coimisiún na Meán has stated that self declaration alone does not satisfy the requirement, though it has not mandated one specific verification method.

General child safety provisions under Part A of the Code took effect on 19 November 2024, and the Part B age assurance obligations became binding on 21 July 2025.

Note and primary source

Social media and minors

Data Protection Act 2018, section 31 (digital age of consent)

Data Protection Act 2018, No. 7 of 2018, s. 31official Act text, Irish Statute Book

In force since 25 May 2018. Binds private bodies.

What this law does

Sets 16 as Ireland's digital age of consent under Article 8 of the General Data Protection Regulation (GDPR), the minimum age at which a child can consent to the processing of personal data in the context of an information society service offered directly to the child, including registering for a social media account. For children under 16, consent must be given or authorised by a parent or guardian. This is a data protection consent rule rather than a mandated identity verification requirement.

Note and primary source

Online Safety and Media Regulation Act 2022 (No. 41 of 2022)

Online Safety and Media Regulation Act 2022, No. 41 of 2022official Act text, Irish Statute Book

In force since 15 March 2023. Binds private bodies.

What this law does

Dissolved the Broadcasting Authority of Ireland and established Coimisiún na Meán (the Media Commission), giving it power to designate video sharing platforms with an establishment in Ireland and to adopt legally binding online safety codes, including rules protecting minors from harmful content.

Note and primary source

News aggregation law1 instrument, 1 in force

Research summary (233 words)

Ireland transposed the EU Digital Single Market Copyright Directive's press-publisher right through the European Union (Copyright and Related Rights in the Digital Single Market) Regulations 2021 (S.I. No. 567/2021), which applies the reproduction and making-available rights of the Copyright and Related Rights Act 2000 to press publishers for the online use of their publications, excluding private or non-commercial use, hyperlinking, and the use of individual words or very short extracts.

The right lasts two years from 1 January of the year following the press publication's own publication date and reaches only publications first published on or after 6 June 2019.

Ireland has no compelled platform-to-publisher bargaining regime comparable to Australia's News Media Bargaining Code or Canada's Online News Act; a publisher and a service provider negotiate the online-use authorisation directly, with disputes able to go to mediation under the Mediation Act 2017 rather than to a designated bargaining process.

Separately from the press-publisher right, the Copyright and Related Rights Act 2000's general fair-dealing provisions permit reproduction of a work for the purposes of criticism or review, or for reporting current events other than by photograph, each subject to sufficient acknowledgement, and permit the incidental inclusion of a work in another work and the use of quotations that do not prejudice the copyright owner's interests.

No hot-news or misappropriation doctrine distinct from ordinary copyright and unfair-competition law was located in the primary sources checked.

Press publishers' right

European Union (Copyright and Related Rights in the Digital Single Market) Regulations 2021, Press Publisher Right

European Union (Copyright and Related Rights in the Digital Single Market) Regulations 2021 (S.I. No. 567 of 2021) reg. 13, applying ss. 37, 39 and 40 of the Copyright and Related Rights Act 2000Irish Statute Book, official text of S.I. No. 567 of 2021

In force since 12 November 2021. Binds private bodies.

What this law does

Regulation 13 applies the reproduction and making-available rights in sections 37, 39 and 40 of the Copyright and Related Rights Act 2000 to publishers of press publications established in the State for the online use of their press publications by information society service providers. The right does not reach private or non-commercial use of a press publication by an individual user, acts of hyperlinking, or the use of individual words or very short extracts of a press publication.

It lasts two years, running from 1 January of the year following the year the press publication was published. It does not reach a press publication first published before 6 June 2019. Authors of works incorporated in a press publication are entitled to an appropriate share of the revenues the publisher receives for the publication's online use. A dispute under the Regulation may be submitted to a mediator under the Mediation Act 2017 without prejudice to judicial remedies.

Note and primary source

This page covers the instruments LexLint has researched to a stage. Instruments named in the corpus but not yet researched are counted in the head and are not listed here. Every entry carries its own primary source on its note page. This is a research index, not legal advice.