GDPR
Health research in Ireland: explicit consent, and the way around it
The regulations are written around the activity rather than the institution, so a commercial medtech is inside them on the same terms as a hospital.
8 minute read6 sources
The GDPR is eight years old here and it is still the regulation that produces the Irish enforcement decisions you can read.
The AI Act gets the attention. The GDPR gets the decisions. Every published Irish enforcement action against an ordinary small business in the last five years has come from the Data Protection Commission, and the pattern in them is consistent: the incident is what starts the investigation, and the paperwork is what the fine is for.
These articles are about the parts of that an Irish SME actually touches. Whether a DPIA is mandatory rather than merely advisable. What a privacy notice has to say and when it has to be given. Whether a US supplier can lawfully receive your data. What happens in the first seventy two hours after a breach.
The Irish specifics matter more here than in most of European data protection law, because the DPC has published a binding list of processing that requires a DPIA, an Irish age of digital consent, and a separate regime for health research that catches private companies as well as universities.
The record, written
Compliance assessment
One assessment across the regimes that actually reach an Irish SME: GDPR, the EU AI Act, accessibility, and a DPIA where the law asks for one.
We run it
The retainer
Ongoing support after the build.
The platform
Cardinal
The client portal.