Governance framework for the lawful and secure handling of personal data
This policy explains how Pact protects personal data, assigns responsibility for compliance, and gives practical effect to the rights of service users, employees and other individuals. It applies to personal data in every format and throughout its lifecycle.
| Organisation | Pact |
| Policy owner | Data Protection Officer |
| Version | 2.0 |
| Updated | 15 September 2026 |
| Approval status | For approval by the Board of Directors |
| Effective date | On approval |
| Next review | September 2027 or earlier if required |
Document control
| Document owner | Data Protection Officer |
| Approving authority | Board of Directors or an authorised committee or delegate |
| Implementation | All staff, Board members, volunteers, contractors and relevant third parties |
| Review cycle | At least annually and following a material legal, regulatory, organisational or processing change |
| Related documents | Privacy notices; Records of Processing Activities; retention schedule; data subject rights procedure; personal data breach procedure; DPIA procedure; information security policies; processor and data-sharing agreements |
Contents
- 1 Purpose and status
- 2 Scope
- 3 Legal and regulatory framework
- 4 Roles and responsibilities
- 5 Data protection principles
- 6 Lawful processing and special category data
- 7 Transparency and collection
- 8 Rights of individuals
- 9 Children and people who may need additional support
- 10 Sharing personal data and engaging processors
- 11 International transfers
- 12 Records retention and secure disposal
- 13 Information security
- 14 Personal data breaches
- 15 Data protection by design and impact assessments
- 16 Training monitoring and compliance
- 17 Queries complaints and escalation
- 18 Review and approval
- Appendix A Key terms
1 Purpose and status
Pact is committed to protecting the rights and freedoms of individuals and to processing personal data lawfully, fairly, transparently and securely. This policy establishes the minimum rules that apply whenever Pact controls or processes personal data.
The policy is an internal governance document. It is supported by privacy notices and operating procedures that provide more detailed information for particular services, groups of individuals and processing activities. If another internal document conflicts with this policy on a data-protection matter, this policy applies unless the Data Protection Officer has approved a different approach supported by law.
2 Scope
This policy applies to all Pact Board members, employees, agency workers, volunteers, students, contractors and other persons who process personal data for or on behalf of Pact. It covers personal data relating to service users, prospective and adoptive parents, birth parents and relatives, adopted persons, children, employees, applicants, volunteers, donors, suppliers, professional contacts and any other identifiable living person.
It applies to electronic and paper records, photographs, recordings, correspondence, case files, databases, email, collaboration platforms, portable devices, archived material and any other system or medium used for Pact business.
3 Legal and regulatory framework
Pact will comply with the General Data Protection Regulation, Regulation (EU) 2016/679, the Data Protection Act 2018, and applicable Irish and European Union law. Pact will also take account of sectoral obligations, including the Adoption Act 2010 as amended, where they govern the creation, disclosure, preservation or use of records.
This policy is interpreted consistently with binding law and with relevant guidance and decisions of the Data Protection Commission, the European Data Protection Board and the courts. Sectoral obligations may require Pact to retain information or limit the exercise of a right; any such restriction must have a lawful basis and be applied only to the extent necessary and proportionate.
4 Roles and responsibilities
Board of Directors
- Approve this policy and oversee material data-protection risks.
- Ensure that appropriate resources, reporting lines and organisational measures are in place.
- Receive assurance on significant incidents, compliance findings and remediation.
Data Protection Officer
- Advise Pact and its staff on applicable data-protection obligations.
- Monitor compliance, awareness, training, audits and the allocation of responsibilities.
- Advise on data protection impact assessments and monitor their performance.
- Co-operate with the Data Protection Commission and act as its contact point.
- Perform these tasks independently, without instructions on the exercise of the role, and report to the highest management level.
Managers and service leads
- Ensure that processing in their area is documented, lawful and consistent with relevant privacy notices.
- Maintain accurate processing, retention, access and sharing controls.
- Consult the Data Protection Officer before new or materially changed high-risk processing begins.
- Escalate rights requests, suspected breaches and compliance concerns immediately.
All personnel
- Access and use personal data only where authorised and necessary for their role.
- Follow this policy, related procedures, confidentiality duties and security requirements.
- Complete required training and report concerns, errors, loss or unauthorised disclosure without delay.
- Seek advice where the lawful basis, purpose, recipient or permitted use is unclear.
Processors and other third parties
Processors and other third parties must comply with their written agreements, documented instructions and applicable law. They must support Pact in meeting individual rights, security, breach, audit, deletion and return obligations.
5 Data Protection principles
| Principle | Pact requirement |
| Lawfulness fairness and transparency | Use personal data only on a valid legal basis, treat people fairly, and explain processing clearly. |
| Purpose limitation | Collect personal data for specified, explicit and legitimate purposes and do not reuse it incompatibly. |
| Data minimisation | Use only personal data that is adequate, relevant and necessary for the purpose. |
| Accuracy | Take reasonable steps to keep personal data accurate and up to date and correct or delete inaccurate data without undue delay. |
| Storage limitation | Keep identifiable personal data only for as long as necessary, subject to legal, regulatory, safeguarding, archival and evidential requirements. |
| Integrity and confidentiality | Protect personal data through appropriate technical and organisational measures. |
| Accountability | Be able to demonstrate compliance through records, decisions, controls, training and oversight. |
6 Lawful processing and special category data
Selecting and documenting a lawful basis
Before processing begins, Pact must identify and record at least one lawful basis under Article 6 GDPR. Depending on the activity, this may be consent, performance of a contract, compliance with a legal obligation, protection of vital interests, performance of a task in the public interest or exercise of official authority, or legitimate interests where those interests are not overridden by the individual’s rights and interests.
Consent is not the default basis and must not be used where an individual has no genuine choice. Where Pact relies on consent, it must be freely given, specific, informed, unambiguous and capable of being withdrawn as easily as it was given. Withdrawal does not affect processing that was lawful before withdrawal, and it does not override a separate legal basis.
Special category and criminal offence data
Where processing reveals racial or ethnic origin, political opinions, religious or philosophical beliefs, trade-union membership, genetic or biometric identifiers used for unique identification, health information, or information about a person’s sex life or sexual orientation, Pact must identify both an Article 6 basis and an applicable condition under Article 9 GDPR and Irish law.
Personal data relating to criminal convictions or offences may be processed only where permitted by Article 10 GDPR and applicable Irish law, with appropriate safeguards. Decisions must be documented in the Record of Processing Activities or other approved record.
7 Transparency and collection
Pact will provide concise, transparent, intelligible and easily accessible information in clear language. The relevant privacy notice must be made available when personal data is collected directly and within the time required by Article 14 GDPR when it is obtained from another source, unless a lawful exception applies.
Privacy information will address, as applicable, Pact’s identity and contact details, the Data Protection Officer, purposes and lawful bases, legitimate interests, recipients, international transfers, retention, individual rights, complaint rights, whether provision is mandatory, the source of information, and any automated decision-making.
Information must be accessible to the intended audience. Where age, disability, literacy, language or circumstances make a standard written notice ineffective, Pact will use suitable additional formats or explanations and record the approach where appropriate. Accessibility support does not replace the requirement to identify a lawful basis.
8 Rights of individuals
Pact will facilitate the exercise of data-protection rights. Requests may be made verbally or in writing and do not have to use a particular form or mention the GDPR. Any person receiving a request must send it to the Data Protection Officer immediately. Identity checks must be reasonable and proportionate.
Pact will respond without undue delay and normally within one month of receipt. Where a request is complex or numerous, the period may be extended by up to two further months; the individual must be told within the first month and given the reasons. Information and action are normally free of charge. A fee or refusal is permitted only where the request is manifestly unfounded or excessive and Pact can demonstrate this.
| Right | How Pact will address it |
| Access | Confirmation of processing, a copy of personal data and the information required by Article 15 GDPR. |
| Rectification | Correction of inaccurate personal data and completion of incomplete data. |
| Erasure | Deletion where the legal conditions apply. This right is not absolute and may be limited by legal, safeguarding, public-interest, archival or legal-claims requirements. |
| Restriction | Restriction of processing where the conditions in Article 18 GDPR apply. |
| Portability | A structured, commonly used and machine-readable copy where processing is automated and based on consent or contract, including direct transmission where technically feasible. |
| Objection | Objection to processing based on public task, official authority or legitimate interests, and an absolute right to object to direct marketing. |
| Automated decisions | Protection from a decision based solely on automated processing that produces legal or similarly significant effects, subject to the limited exceptions and safeguards in Article 22 GDPR. |
| Complaint | The right to complain to Pact and to the Data Protection Commission, and to seek a judicial remedy. |
When responding, Pact must protect the rights and freedoms of other people. Any restriction, redaction, refusal or reliance on an exemption must be lawful, necessary, proportionate, documented and explained to the individual together with available complaint and remedy routes.
9 Children and people who may need additional support
Pact recognises that children and some adults may be particularly vulnerable to the effects of misuse of their personal data. Information and communications will be adapted to their age, capacity and circumstances, and safeguards will reflect the sensitivity of adoption, family, health and safeguarding records.
Consent and representation will be assessed carefully. A parent, guardian or representative does not automatically have an unrestricted right to another person’s personal data. Pact will consider the identity and authority of the requester, the rights and best interests of the person concerned, confidentiality, safeguarding and applicable sectoral law.
10 Sharing personal data and engaging processors
Pact will share personal data only where there is a defined purpose, a lawful basis, an appropriate recipient, and a proportionate amount of information. Sharing with public bodies or other organisations must be supported by law or another valid basis and documented through an appropriate agreement or decision record.
Before appointing a processor, Pact will conduct proportionate due diligence and put in place a written contract meeting Article 28 GDPR. The contract must cover documented instructions, confidentiality, security, sub-processors, assistance with rights and breaches, deletion or return, information needed to demonstrate compliance, and audits or inspections.
The Data Protection Officer must be consulted on new or materially changed sharing arrangements involving sensitive, large-scale, novel, vulnerable-person or otherwise high-risk processing. Emergency or safeguarding disclosures must be documented as soon as practicable.
11 International transfers
A transfer of personal data to a country or international organisation outside the European Economic Area must comply with Chapter V GDPR. Before the transfer begins, Pact must confirm and document an available transfer mechanism, such as a European Commission adequacy decision or appropriate safeguards including approved Standard Contractual Clauses.
Where required, Pact will assess the laws and practices affecting the transfer and implement supplementary measures. Article 49 derogations, including explicit consent in limited circumstances, are exceptions and must not be used as a routine substitute for an adequacy decision or appropriate safeguards. The Data Protection Officer must approve the documented transfer assessment before a new restricted transfer begins.
12 Records retention and secure disposal
Pact will maintain a retention schedule that links record categories to their operational, statutory, safeguarding, archival and legal-claims requirements. Personal data must not be retained indefinitely merely because storage is available. Retention periods and disposal decisions must be reviewed and documented.
At the end of the approved retention period, records will be securely deleted, destroyed, anonymised or transferred to an appropriate archive where lawful. Disposal methods must reflect the sensitivity and format of the information. Legal holds, investigations, complaints or litigation may require disposal to be suspended; the reason and duration must be recorded.
13 Information security
Pact will implement technical and organisational measures appropriate to the nature, scope, context and purpose of processing and the risks to individuals. Measures will be reviewed and improved as necessary.
- Role-based access, least privilege, timely joiner mover and leaver controls, and periodic access reviews.
- Secure authentication, encryption where appropriate, supported systems, patching, malware protection and secure configuration.
- Physical security, clear-desk practices and secure handling of paper records and portable media.
- Secure backup, restoration, resilience and business-continuity arrangements.
- Logging, monitoring, vulnerability management and proportionate testing of controls.
- Confidentiality commitments, training and clear procedures for remote work, email, sharing and disposal.
- Supplier security assessment and oversight throughout the contract lifecycle.
14 Personal data breaches
A personal data breach is a security breach leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. Loss of availability can also be a breach. All actual or suspected breaches, including misdirected email, lost devices or records, inappropriate access and accidental deletion, must be reported immediately to datacontroller@pact.ie and handled under Pact’s breach procedure.
- Contain the incident, preserve relevant evidence and limit further harm without delaying escalation.
- Notify the Data Protection Officer immediately and provide known facts. Staff must not investigate alone, or contact affected people without authorisation.
- Assess the likely consequences and risks to individuals, record the decision and take remedial action.
- Notify the Data Protection Commission without undue delay and, where feasible, within 72 hours after becoming aware of a breach that is likely to result in a risk to individuals. Reasons for any delay must be recorded.
- Inform affected individuals without undue delay where the breach is likely to result in a high risk, unless a lawful exception applies.
- Document every personal data breach, including facts, effects, decisions and remedial action, whether or not external notification is required.
15 Data protection by design and impact assessments
Data protection by design and by default must be built into projects, procurement, service changes, forms, systems and data-sharing arrangements from the outset. Default settings should limit the amount collected, extent of processing, retention and accessibility to what is necessary for each purpose.
A Data Protection Impact Assessment must be completed before processing that is likely to result in a high risk to individuals, including relevant large-scale, systematic, novel, monitoring or vulnerable-person processing. The assessment must describe the processing, examine necessity and proportionality, assess risks and identify measures to address them. The Data Protection Officer will advise on the assessment. Pact will consult the Data Protection Commission before processing where residual high risk cannot be mitigated.
16 Training monitoring and compliance
Pact will maintain records sufficient to demonstrate compliance, including its Record of Processing Activities, lawful-basis decisions, privacy notices, consent records where relevant, contracts, data-sharing arrangements, transfer assessments, DPIAs, rights requests, breaches, retention actions, training and audits.
Personnel will receive appropriate induction and refresher training. Compliance will be monitored through risk-based reviews, audits, incident analysis and management reporting. Findings must have named owners and reasonable completion dates, and significant unresolved risks must be escalated to the Board.
A deliberate, reckless or repeated breach of this policy may result in action under the applicable employment, volunteer, contractor or supplier arrangements. Nothing in this section prevents good-faith reporting of mistakes or concerns; prompt reporting is required and supports effective mitigation.
17 Queries complaints and escalation
Questions, rights requests, complaints and suspected personal data breaches should be directed to Pact’s Data Protection Officer at datacontroller@pact.ie. General enquiries may also be made through info@pact.ie or by telephone on 01 296 2000.
Pact will handle complaints fairly and without retaliation. Individuals may also complain to the Data Protection Commission through www.dataprotection.ie and have the right to seek a judicial remedy. Pact will co-operate with the Data Protection Commission and other competent authorities as required.
18 Review and approval
The Data Protection Officer will review this policy at least annually and earlier where there is a significant legal, regulatory, technological, organisational or processing change, a material incident, or an audit finding that requires revision. Material amendments require approval by the Board of Directors or its authorised committee or delegate.
| Approval record | Details |
| Approved by | |
| Approval date | |
| Effective date | |
| Next scheduled review | September 2027 |
Appendix A Key terms
| Term | Meaning |
| Controller | The person or organisation that determines why and how personal data is processed. |
| Processor | A person or organisation that processes personal data on behalf of a controller, excluding the controller’s employees acting in that capacity. |
| Personal data | Information relating to an identified or identifiable living individual. |
| Processing | Any operation performed on personal data, including collection, recording, organisation, use, disclosure, storage, alteration, retrieval, restriction, deletion or destruction. |
| Data subject | The living individual to whom personal data relates. |
| Special category data | Personal data covered by Article 9 GDPR, including specified health, biometric, genetic, belief, ethnicity, political, trade-union and sexual-life or sexual-orientation information. |
| Personal data breach | A breach of security leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. |
| DPIA | A documented assessment of the necessity, proportionality and risks of processing and the measures used to address those risks. |
| EEA | The European Economic Area. |
| ROPA | The Record of Processing Activities maintained under Article 30 GDPR. |
| Supervisory authority | The independent public authority responsible for monitoring data-protection law. In Ireland this is the Data Protection Commission. |
