Garda Síochána (Recording Devices) (Amendment) Bill 2025: Report and Final Stages Seanad Éireann — 2026-06-23 ============================================================ Jim O'Callaghan (FF), Dublin Bay South I thank Senator Higgins for her amendments. We are discussing amendments Nos. 7 and 8. Before getting into the substance of the amendments, I wish to address the question Senator Higgins raised at the outset. She again said that I failed to identify the distinction between biometric analysis, which is provided for in this legislation, and biometric identification, which she rightly says is covered in the AI Act. While I do not want to go back over old ground, the biggest distinction between the two is the fact that biometric identification involves identification against a database of biometric information. I will provide an example of the use of biometric identification, were it to be introduced. The way it would operate is that the Garda on its systems would have photographs and images of tens of thousands of people. If the Garda identified an individual committing an offence or a suspect it was interested in identifying coming out of a nightclub in Dublin last night, if gardaí got his image, they would play and reference it against the database of those tens of thousands of individuals. If the system identified the individual as, say, Mark Daly, that is an example of biometric identification. It identifies the individual against a database. Biometric analysis is different. It does not have a database. The name of the individual is not known after the process, but it provides the Garda with an opportunity to filter, sort or seek to know whether the person in the image is the same as a person in a subsequent image. We do not have a database. The amendments proposed here are to include a new subsection in section 43C providing for data protection impact assessments where biometric analysis is carried out in the context of both sections 43C(2) and 43C(2)(a). Section 47A, which I will refer to presently, is to be inserted by section 10 of this Bill. I want Senator Higgins and other Senators to know that this already provides for data protection and human rights impact assessments to be conducted prior to the use of biometric analysis as part of the development of a code of practice. The GDPR that Senator Higgins referred to is a regulation that is directly effective in Ireland. In terms of its transposition, the Data Protection Act is also operating in Ireland. This legislation cannot ignore other legislation. Even if that other legislation was not there, I would be very satisfied because of what is being proposed under Part 8A of the Bill and the codes of practice for Part 6A that the concerns the Senator has will be met in the legislation and the codes of practice. Section 10 of the Bill inserts a new section 47A that will provide for a code of practice for biometric analysis. What the House will notice in subsection (2)(c) is that the draft code of practice shall include provisions relating to "the confidentiality, security, storage, access, retention, erasure and destruction of data obtained as a result of the operation of Part 6A", which is biometric analysis. There is a clear statutory imperative that the code of practice must deal with all those data issues, whether confidentiality, security, storage, access, retention, erasure or destruction. If that is not sufficient, the Garda Commissioner, who is responsible for preparing a code of practice, must, in accordance with section 47A(4), consult with a number of other statutory entities. One of those entities is the Data Protection Commission. Another is the Irish Human Rights and Equality Commission, IHREC. In terms of the requirements for the code of practice, there is a requirement on the Garda Commissioner to engage with the Data Protection Commission and IHREC in respect of how the code of practice operates, particularly in light of the statutory obligation on him to ensure that the code of practice respects the data requirements that I just spoke about a few moments ago. Even if that was not sufficient, the draft code of practice must then be presented to me so that I get an opportunity to appraise it. Then, it is set before the Houses of the Oireachtas and Members of this House and the Lower House shall have an opportunity to assess it. It will not come into force until such time as there is a vote of both Houses of the Oireachtas to approve the code of practice. When the Senator looks at the concerns she has in terms of whether there will vigilance in respect of data, there is a whole myriad and series of layers there to ensure that data is protected in accordance with the laws that exist at present. First, there is the operation of GDPR, which is directly effective. Second, there are the provisions of the Data Protection Act. Third, there is an express statutory requirement on the Garda Commissioner to ensure that the code of practice covers issues in respect of the confidentiality, storage and destruction of data. Fourth, there is a requirement on the Garda Commissioner in terms of preparing that code of practice, which has those statutory obligations contained in it, to consult with the Data Protection Commission and IHREC. Finally, it has to go past me. Even if I am asleep at the wheel, there is the requirement that it be presented to both Houses of the Oireachtas to ensure that it only comes into force if there is a vote of both Houses of the Oireachtas. I have no doubt that, if there were any defects or flaws in the area of data retention and protection, they would be readily identified by Members in this House and the Lower House during that process. --- Source: Houses of the Oireachtas. Licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). The Official Report is revised after first publication; the fetch timestamp below identifies the version quoted. Record URI: https://data.oireachtas.ie/akn/ie/debateRecord/seanad/2026-06-23/debate/main Retrieved: 2026-08-14T04:55:05+00:00 Sitting date: 2026-06-23