Ireland - AI Data Protection Guidance
Data Protection Commission Guidance on AI and Large Language Models
Ireland
RAI-IE-NA-DPCGAXX-2024The Data Protection Commission (DPC) of Ireland published guidance titled "AI, Large Language Models and Data Protection" on 18 July 2024. The guidance explains how the GDPR and Irish data protection law apply to the development, training and use of AI systems — particularly Large Language Models (LLMs) — and sets out recommended compliance steps for controllers, processors and AI providers.
Summary
Read full text ↗Plain English
Overview
The Data Protection Commission of Ireland published "AI, Large Language Models and Data Protection" on 18 July 2024 as an explanatory guidance note for organisations, AI providers and the public. The document explains why Large Language Models (LLMs) and generative AI systems can raise data protection issues, highlights common risk scenarios, and provides practical steps to align LLM development and deployment with the General Data Protection Regulation (GDPR) and Ireland’s Data Protection Act 2018. It addresses both training-phase processing (use of datasets to build or fine-tune models) and runtime usage (user prompts, model outputs and integration into services), and emphasises that publicly available personal data can still be personal data under GDPR when individuals are identifiable.
Definitions
For clarity the DPC guidance defines key terms used in the AI context: Large Language Model (LLM) — a class of generative AI model trained on large text corpora to produce human‑like text; training data — the datasets used to develop or fine‑tune a model; controller/processor — GDPR roles that apply to AI providers and deployers depending on decision‑making and purposes; personal data — any information relating to an identified or identifiable person; special categories of personal data — the GDPR’s sensitive data classifications requiring extra safeguards. The guidance also explains technical concepts such as memorisation, prompt-based inference, model tuning and fine‑tuning in accessible language so legal obligations can be mapped to technical design choices.
Governance and Institutional Framework
The DPC positions itself as the primary Irish supervisory authority for data protection matters related to AI, and highlights its role in supervising many multinational tech firms with EU headquarters in Ireland. The guidance explains internal governance expectations for organisations: appoint accountable leads, ensure board/senior oversight, maintain documentation evidencing DPIAs and lawful-basis assessments, and integrate data protection by design. The note refers to coordination with the European Data Protection Board (EDPB) and the EU AI policy framework including the Artificial Intelligence Act (Regulation (EU) 2024/1689). The DPC encourages cross-functional governance involving legal, privacy, security, engineering and product teams to manage the lifecycle of AI systems.
Key Focus Areas
The guidance sets out the primary data protection focus areas for LLMs: (1) Lawfulness, transparency and purpose limitation — ensure a legal basis exists for training and operations, and inform data subjects where appropriate; (2) Data minimisation and quality — limit training and input data to what is necessary, and manage model updates to avoid incorporating irrelevant personal data; (3) Rights and freedoms — design systems that allow controllers to fulfil access/rectification/erasure requests and enable practical mechanisms for exercising rights where personal data is embedded or outputs contain personal data; (4) DPIAs and high risk — carry out DPIAs for high‑risk processing and adopt mitigation measures; (5) Security and model‑level risks — protect models from extraction, inversion and prompt‑injection attacks, and secure training datasets; (6) Accountability and documentation — maintain records of processing activities, dataset provenance, model cards and risk assessments; (7) Contracts and third‑party supply chain — require suppliers to document their data sources, retention and re‑use policies. The DPC warns that accuracy, bias, and the potential for unexpected dissemination of personal data are central concerns.
Implementation Framework
The guidance offers a phased implementation approach: start with scoping (identify whether AI work involves personal data), then map processing flows and legal bases, perform DPIAs where appropriate, adopt privacy‑by‑design measures during model design, and establish retention and deletion regimes for datasets and model artifacts. It recommends practical measures such as prompt filters, input redaction, access limitations, logging of prompts and outputs, and contractual safeguards with cloud/AI service providers. Organisations are advised to require transparency from AI suppliers about whether models were trained on personal data and whether the supplier retains or re‑uses prompts and outputs. The guidance also recommends testing regimes and human oversight mechanisms for decision points with legal or material effects on individuals.
Monitoring and Evaluation
The DPC recommends continuous monitoring and evaluation of deployed AI systems: periodic model audits, bias and accuracy testing, incident response plans for unintended disclosures, and maintenance of audit trails for data provenance and model changes. It advises that monitoring include technical validation (e.g., red-team tests, adversarial testing for prompt injection) and policy checks (e.g., verifying contractual commitments). The DPC expects organisations to be able to demonstrate ongoing compliance through records and to update DPIAs as systems or datasets change.
Penalties, Liability, and Appeals
While the guidance itself is non‑binding, it reminds readers that non‑compliance with GDPR can trigger the DPC’s enforcement powers under the Data Protection Act 2018 and the GDPR, including orders to cease processing, audits, corrective measures and administrative fines (as per GDPR — up to €20 million or 4% of global annual turnover). The DPC also notes the potential for judicial review and appeals against administrative measures. The guidance encourages remediation through practical mitigation rather than experimentation without safeguards.
Relationship to Other Instruments
The DPC guidance explains its relationship with core EU instruments: the GDPR (Regulation (EU) 2016/679), the national Data Protection Act 2018, and the EU Artificial Intelligence Act. It positions the guidance as complementary to EDPB work and to national implementations of the AI Act, noting the need for coordination between DPAs and market surveillance authorities. It also references international standards and ISO guidance for NLP and model testing where relevant.
International Alignment
The guidance observes that Ireland’s DPC engages with other supervisory authorities and international bodies to align approaches. It cites EDPB positions and encourages organisations operating across borders to consider cross‑border data transfer rules, equivalence mechanisms and contractual safeguards. The DPC notes that multinational AI providers must ensure compliance not only with Irish and EU data protection law but also with obligations under the incoming AI regulatory framework and possible sectoral rules (e.g., health sector confidentiality standards).
Implementation Timeline
| Event | Date |
|---|---|
| Publication of DPC guidance "AI, Large Language Models and Data Protection" | 2024-07-18 |
| Publication of EU AI Act (Regulation (EU) 2024/1689) in OJ | 2024-07-12 |
| EDPB statement on DPAs’ role in AI framework (plenary) | 2024-07-16/17 |
| AI Act staggered entry into force / application windows (selected provisions) | 2025-02-02 to 2027-08-02 (varied by Article) |
Compliance Checklist
| Requirement | Actions |
|---|---|
| Scoping & mapping | Identify roles (controller/processor), data flows, training datasets and cross-border transfers. |
| DPIA | Conduct DPIA when processing is likely to result in high risk; document mitigations. |
| Legal basis | Record lawful basis for training and runtime processing; review contracts for downstream use. |
| Transparency | Provide clear information to data subjects about processing and rights. |
| Data minimisation | Limit training and prompt inputs to necessary data; apply redaction/filters. |
| Security | Implement model and dataset security, monitor for extraction and prompt attacks. |
| Rights management | Prepare procedures to respond to access, rectification, erasure requests affecting model outputs or datasets. |
Sources and References
| Source | Type |
|---|---|
| AI, Large Language Models and Data Protection (DPC guidance) | Primary Source |
| European Data Protection Board – Artificial Intelligence materials | Primary Source |
| Regulation (EU) 2016/679 (GDPR) | Primary Source |
| Regulation (EU) 2024/1689 (AI Act) | Primary Source |
The Irish Data Protection Commission (DPC) has issued new guidance clarifying how existing data protection laws, including the GDPR, apply to organisations developing, training, and using Artificial Intelligence (AI) systems, especially Large Language Models (LLMs). This guidance directly impacts any organisation, AI provider, or service deployer that processes personal data through AI, including many multinational tech firms with EU headquarters in Ireland.
The DPC emphasizes several key obligations. First, all AI processing of personal data must have a clear legal basis, be transparent to individuals, and adhere to specific purposes. Second, organisations must practice data minimisation, using only necessary data for training and inputs, and ensure data quality. Third, systems must be designed to enable individuals to exercise their data protection rights, such as access, rectification, and erasure, even when their data is embedded within models or outputs. High-risk AI processing requires a Data Protection Impact Assessment (DPIA) to identify and mitigate risks. Finally, robust security measures are essential to protect models and datasets from attacks like data extraction or prompt injection, alongside comprehensive accountability through documentation of processing activities, data sources, and risk assessments. Organisations are also expected to demand transparency from their AI suppliers regarding data sources and retention policies.
While the guidance itself was published on July 18, 2024, it clarifies how existing GDPR obligations *already* apply. Non-compliance can trigger significant enforcement actions from the DPC, including orders to cease processing, audits, and administrative fines. These penalties can be substantial, reaching up to €20 million or 4% of a company's global annual turnover, as stipulated by the GDPR.
A crucial takeaway is that personal data, even if publicly available, remains subject to GDPR requirements when used in AI systems. The DPC warns that accuracy, bias, and the potential for unexpected dissemination of personal data are major concerns that organisations must proactively address through careful design, testing, and continuous monitoring. Effective governance requires collaboration across legal, privacy, security, engineering, and product teams.
Plain-English rewrite by Regulations.ai — not legal advice. Verify against the official text.
What you must do — compliance checklist
0 / 13 marked completePlain-English obligations under Ireland - AI Data Protection Guidance. Not legal advice — verify against the official text before relying on it.
- #1CriticalGovernance and Institutional Framework
Applies to: Organisations developing or deploying AI systems.
“appoint accountable leads, ensure board/senior oversight”
- #2CriticalGovernance and Institutional Framework⏰ Before placing on market
Applies to: Organisations developing or deploying AI systems.
“integrate data protection by design”
- #3CriticalImplementation Framework⏰ Before processing personal data
Applies to: Organisations developing or deploying AI systems.
“start with scoping (identify whether AI work involves personal data), then map processing flows and legal bases”
- #4CriticalKey Focus Areas⏰ Before processing personal data
Applies to: Controllers and processors using AI systems.
“ensure a legal basis exists for training and operations”
- #5CriticalKey Focus Areas⏰ Before processing personal data
Applies to: Controllers and processors using AI systems.
“inform data subjects where appropriate”
- #6CriticalKey Focus Areas⏰ Before processing personal data
Applies to: Controllers and processors using AI systems.
“limit training and input data to what is necessary, and manage model updates to avoid incorporating irrelevant personal data”
- #7CriticalKey Focus Areas⏰ Before placing on market
Applies to: Controllers and processors using AI systems.
“design systems that allow controllers to fulfil access/rectification/erasure requests”
- #8CriticalKey Focus Areas⏰ Before high-risk processing
Applies to: Controllers and processors using AI systems.
“carry out DPIAs for high‑risk processing and adopt mitigation measures”
- #9CriticalKey Focus Areas⏰ Before processing personal data
Applies to: Controllers and processors using AI systems.
“protect models from extraction, inversion and prompt‑injection attacks, and secure training datasets”
- #10CriticalKey Focus Areas
Applies to: Controllers and processors using AI systems.
“maintain records of processing activities, dataset provenance, model cards and risk assessments”
- #11CriticalKey Focus Areas⏰ Before contracting suppliers
Applies to: Organisations procuring AI systems or services.
“require suppliers to document their data sources, retention and re‑use policies”
- #12CriticalImplementation Framework⏰ Before processing personal data
Applies to: Controllers and processors using AI systems.
“establish retention and deletion regimes for datasets and model artifacts”
- #13CriticalMonitoring and Evaluation
Applies to: Organisations deploying AI systems.
“continuous monitoring and evaluation of deployed AI systems: periodic model audits, bias and accuracy testing”
Related Regulations
ICO guidance: AI and data protection (updated guidance and AI risk toolkit)
United Kingdom93% similar
Interim Guidelines for Use of AI (Public Service)
Ireland93% similar
National Cyber Security Centre: Cyber Security Guidance on Generative AI for Public Sector Bodies
Ireland92% similar
Guidelines for the Responsible Use of AI in the Public Service
Ireland92% similar
Office of the Privacy Commissioner — Guidance/Expectations on the use of AI (privacy guidance)
New Zealand91% similar
© Regulations.AI — created on 13-Jun-2026