Ireland’s leading civil rights organization has urged the Department of Social Protection (DSP) to withdraw its appeal against a major ruling that found the government’s collection and use of biometric data from approximately 3.2 million citizens to be unlawful under European data protection law.
The Irish Council for Civil Liberties (ICCL) called on the department to accept the decision of the Data Protection Commission (DPC), which concluded that the DSP’s processing of facial biometric data for the Public Services Card (PSC) program violated the General Data Protection Regulation (GDPR). The DPC’s findings followed an investigation lasting nearly four years and resulted in a €550,000 fine imposed on the department in June of this year, alongside a nine-month deadline to bring its practices into compliance.
The case centers on the PSC scheme, which has been subject to scrutiny since its inception. Under the system, citizens are required to provide facial photographs as part of the SAFE 2 registration process, which uses facial matching technology to verify identities before individuals can access a range of government services.
Following its investigation, the DPC determined that the DSP did not have a valid legal basis under GDPR for processing sensitive biometric data, which is classified as “special category” information requiring enhanced protections. The regulator concluded that the data collection was disproportionate, lacked sufficient transparency, and failed to meet the necessity requirements set out in European data protection law.
A spokesperson for the Department of Social Protection confirmed in a statement filed with the High Court on July 9 that the department intends to challenge the ruling. The DSP maintains that its biometric processing is lawful and necessary to safeguard the integrity of Ireland’s social welfare system, asserting that it relies on GDPR provisions that allow processing of personal data for reasons of substantial public interest and fraud prevention.
The case reflects a growing trend of regulatory scrutiny surrounding biometric data processing across Europe. Similar initiatives are emerging in other EU member states and the United Kingdom, as data protection authorities tighten their oversight of biometric technologies in both public and private sectors. The adoption of the EU AI Act in 2024, which introduces significant restrictions on certain biometric surveillance practices, further underscores the increased focus on privacy risks associated with biometric identifiers.
The ICCL has called for the full text of the DPC’s decision, which spans over 200 pages, to be published to allow public review. In response, the DPC has indicated that it plans to release the complete decision in due course, subject to legal and procedural considerations. ICCL representatives argue that full transparency is essential to maintain public trust and ensure accountability when government agencies handle sensitive personal data.
Sources: ICCL, Compliance Hub
–
By the ID Tech Editorial Team






Follow Us