GDPR and the DPC, for Irish businesses

GDPR

An SEO plugin updated itself, and the DPC found three separate failures

The interesting part is not the breach. It is that once the DPC looked, the record of processing and the processor agreement failed too.

By Oscar CobbeCurrent as at 7 minute read3 sources

What happened

In 2018 a small credit union in County Meath notified the Data Protection Commission of a breach. Board reports relating to membership enquiries, stored within its website, had become publicly available through search engine results.

The cause, in the decision's own words: this incident occurred due to an update to a search engine optimisation tool installed on the website that Slane Credit Union had not anticipated.

Nobody was attacked. Nobody made a decision. A plugin updated itself and changed what it exposed, which is a thing that happens on a great many websites every week and is noticed on very few of them.

This piece is about the mechanism rather than the organisation. Slane Credit Union is a small community body that had a bad month in 2018 and has long since dealt with it, and the decision is public precisely so that others can learn from it.

The decision

Inquiry into Slane Credit Union, IN-19-7-5, decided 26 January 2022, on a breach notified to the DPC on 30 November 2018.

Four findings, and only one of them is about the plugin

The DPC found infringements of Article 5 and Article 32, the security obligations, for failing to implement appropriate technical measures.

It also found a failure to implement organisational measures that took account of the nature, scope, context and purposes of the processing, and a failure to include all appropriate information in the record of processing. That is Article 24 and Article 30: the record itself was found wanting.

And it found that Article 28(1) and (3) were infringed, by failing to conduct due diligence on the processor and by failing to put in place an agreement with the processor that met the Regulation's requirements.

Read that list again. One finding is about the incident. Three are about paperwork that was already required before the plugin ever updated, and were not created by the incident.

What was foundArticleWhen it became a problem
No appropriate technical measures5 and 32The day the plugin updated
Record of processing missing information24 and 30Long before
No due diligence on the processor28(1)Long before
No compliant agreement with the processor28(3)Long before

The sanction, and why the number is not the point

An administrative fine of €5,000 in respect of the security infringement, and a reprimand in respect of all of the infringements.

Five thousand euro is not a number that frightens anybody, and quoting it as a threat would be silly. The cost of an inquiry is not the fine. It is the correspondence, the legal advice, the time of whoever has to reconstruct what happened four years earlier, and a published decision with your name on it that turns up in a search for your organisation forever.

The reprimand is the part worth reading twice. It was issued in respect of all of the infringements, not just the one that was fined. The record and the processor agreement were not incidental findings mentioned in passing; they were formally the subject of a corrective power.

Why an incident becomes an audit

This is the pattern to take from it. A breach notification is not a report you file about one event. It is an invitation for a regulator to look at how you process personal data generally, and once they are looking they see everything.

Article 33 gives you 72 hours to notify a reportable breach. Nobody assembles a record of processing in 72 hours, and nobody negotiates a processor agreement retrospectively. Whatever is in place on the day the notification goes in is what the regulator assesses.

That is the real argument for doing the record first, and it is an argument about odds rather than about fear. The probability that a plugin on your website changes behaviour this year is not small. The probability that you are asked what you hold and who processes it, in a week when you are already dealing with something, is not small either.

The 72 hours are not preparation time

Article 33 runs from awareness. Whatever documentation exists on that day is what gets assessed, and a record assembled during an incident is a record assembled under the worst possible conditions.

The processor question, which almost nobody has answered

Article 28 requires a written contract with anybody who processes personal data on your behalf, setting out the subject matter, duration, nature and purpose of the processing, the type of data, the categories of people, and the obligations of both sides. It also requires you to use only processors providing sufficient guarantees, which is the due diligence half.

In practice that means the plugin vendor, the hosting company, the email platform, the booking system, the analytics provider and the accountant's software. Most small businesses have between six and a dozen and have signed a specific agreement with none of them, because the agreement is usually sitting inside the vendor's terms waiting to be accepted rather than arriving as a document.

Our own compliance record flags this automatically, and when we ran it against ourselves it returned sixteen open findings, each naming a processor holding data on our behalf with no agreement recorded. That is not a comfortable thing to publish and it is the honest number: the work is real, it is tedious, and a firm that claims to have finished it is a firm that has not started.

What to actually do

Write the record of processing. It is the document that makes every other answer possible, and it is the one the DPC found wanting here.

List the processors and find the agreement for each. Most exist and are unread; the ones that do not exist are the finding.

And then look at the website, because that is where this one started. A plugin that updates itself is a supplier making changes to your systems without telling you, which is a reasonable thing to allow and an unreasonable thing to not know about.

Sources

  1. 1.Inquiry into Slane Credit Union, IN-19-7-5 · Data Protection Commission
  2. 2.Decisions listing · Data Protection Commission
  3. 3.Regulation (EU) 2016/679, the GDPR: articles 28, 30 and 33 · Official Journal of the European Union

Free, and the answers stay in your browser

Check what a third-party plugin puts you on the hook for

A plugin that reads member data can pull you into an assessment you have not done. The free check runs the Irish Article 35(4) list against what you actually do.

Run the free check

The record, before anybody asks for it

We map where personal data actually goes, write the Article 30 record from that, and list every processor with the agreement for each or the fact that there is none. The gaps are the deliverable as much as the document is.

Talk to us about compliance

Who wrote this

Oscar Cobbe · Founder, FourWinds Digital

Writes and maintains the legal explainers on this site, and does the compliance work behind them. Every date and article number here is checked against the instrument itself before it is published, and corrected in place when the law moves.

More about how we work →

Read next

More on GDPR and the DPC, for Irish businesses

Written on 27 August 2026 and accurate as at that date. This is general information about how the rules work, not legal advice on your situation. We are not solicitors and we say so when you need one.