Garda Síochána (Recording Devices) (Amendment) Bill 2025: Report and Final Stages Seanad Éireann — 2026-06-23 ============================================================ Alice-Mary Higgins (IND), National University of Ireland I begin by noting that the Minister has sadly again declined to answer my repeated question as to why he is choosing to narrow the definition of biometric identification to only include situations where it is being compared with a database of named individuals when that is not what the EU AI Act defines it as or applies it to. If the Minister recalls my previous intervention, I was clear on the importance of international co-operation. That is why it is important we co-operate with regard to international definitions. We should expect Ireland to seek to be aligned with other countries that are also engaging in biometric identification in order for us to be able to work and co-operate with them. I have asked the Minister this again and again. It is quite an anomaly. Frankly, the narrowing of the definition of biometric identification to say it only applies when it is compared with a database of named individuals, when that is not how it is understood in the EU context or by others, is a big red flag. I will continue to say it. We still have not had a rationale for it. I know there has been certain grace given to Ireland within the EU AI Act because of Northern Ireland. There is this idea that Ireland will have flexibility when it comes to certain measures. That flexibility has been somewhat misused in this legislation, however. One area where we do not have flexibility is GDPR. There are clear requirements under GDPR. Ireland does not have a special carve-out, opt-out or anything else when it comes to data protection. Those same issues the Minister mentioned about proportionality, necessity and all of the other safeguards of GDPR still apply. That is why I suggest in amendment No. 7 that where biometric analysis is carried out in accordance with section 43C(2), it should be subject to a data protection impact assessment. Amendment No. 8 would also make biometric analysis carried out in accordance with section 43C(2)(a) subject to a data protection impact assessment. We discussed this issue on Committee Stage, but the Minister did not have the opportunity to come back in. Perhaps he will now. The European Data Protection Board has issued guidelines on the use of facial recognition technology. When we talk about AI and computer-enabled processing of footage, photographs, videos, CCTV footage and the use of body cameras, we are talking about facial recognition. That is the kind of software and technology being used. The data protection board was asked to provide guidelines on the use of facial recognition technology in the area of law enforcement. It was asked to specify how those guidelines outline specific scenarios, examining the remote processing of biometric data in public spaces for identification purposes. Let us use the same exact scenario where the window gets broken and someone gets on a bus. That person may be seen later at a railway station or on another piece of CCTV. Maybe someone takes a photograph, but is it the same person? Is it the same particular individual as is described under the Minister’s definition? The European Data Protection Board was asked whether facial recognition technology could be used to examine biometric data in public spaces for identification purposes and it found that such use would constitute a disproportionate interference in the data subject’s rights under Articles 7 and 8 of the Charter of Fundamental Rights of the EU. Article 26.10 of the AI Act, which we will be discussing further when we come to amendment No. 9, is quite clear in this regard. It outlines that, "Deployers shall submit annual reports to the relevant market surveillance and national data protection authorities on their use of post-remote biometric identification systems". Post-remote identification systems use material, such as pictures or video footage, generated by CCTV or private devices in respect of natural persons. There is a clear requirement to ensure a line of communication between the deployers of high-risk AI systems, like those employed for biometric analysis or identification, and the data protection authorities. That is outlined by the expectation of an annual report. If the Minister does not want to accept our amendments, which look for specific data impact assessments, will he outline the processes by which he will be ensuring, in an ongoing way, that the use of biometric analysis by authorities is continually and regularly - at least annually as outlined in the AI Act – in compliance with GDPR, given the scenarios the Minister used and those the data protection board described as being in breach of the data protection Act are very similar? Under the AI Act, Article 27 states that deployers "shall perform an assessment of the impact on fundamental rights that the use of such systems may produce". Can the Minister tell us definitely that there has been, or will be, an impact assessment regarding the use of these systems? --- Source: Houses of the Oireachtas. Licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). The Official Report is revised after first publication; the fetch timestamp below identifies the version quoted. Record URI: https://data.oireachtas.ie/akn/ie/debateRecord/seanad/2026-06-23/debate/main Retrieved: 2026-08-14T04:55:05+00:00 Sitting date: 2026-06-23