Garda Síochána (Recording Devices) (Amendment) Bill 2025: Report and Final Stages Seanad Éireann — 2026-06-23 ============================================================ Alice-Mary Higgins (IND), National University of Ireland I thank the Minister. He again sought to clarify between biometric analysis and biometric identification. That was one question we had, but the actual question I have been asking repeatedly is why he is choosing to narrow the definition of biometric identification that he proposed in this legislation. When the Minister spoke, he compared biometric information with a biometric database. That is not what the legislation states. The legislation states it is of named individuals. The Minister is proposing that biometric identification will only be deemed to be happening when the biometric information is compared with a specific database that contains names. That is a radically different and narrower definition of biometric identification than what we have in the EU AI Act. I will read recital 17 of the Act again for clarity. It states: ... 'remote biometric identification system’ ... should be defined functionally, as an AI system intended for the identification of natural persons [which sounds very like the particular persons mentioned in the Minister's definition] without their active involvement, typically at a distance, through the comparison of a person’s biometric data with the biometric data contained in a reference database, irrespectively of the particular technology, processes or types of biometric data used. Even if the Minister were to argue that names are somehow biometric data, which they are not, is he willing to say that these names with photographs contain biometric data, too? The point is, recital 17 explicitly stated that it should not be narrowed. The document goes on to clarify further and gives the example of the kinds of databases where material is being compared, such as pictures or video footage generated by CCTV or private devices, and where those are generated before the use of the systems. This language of a reference database containing named individuals is an extraordinary narrowing of what is meant to be a comparator of biometric information with a biometric database or databases. The EU drafters make the greatest of efforts to be clear that they wish to be technology neutral in this regard. The Minister is saying it is only going to apply to databases of named individuals. That is an extraordinary choice. Why has the Minister narrowed it to named individuals versus a comparison of biometric data with a database of other biometric data? Why is he choosing to introduce an extra layer of requirement that it will only be biometric identification when it is compared with the persons who we not only have pictures of but have their names? That is a choice. It is a choice that is at odds with the EU AI Act. That is why I have concerns about how it is going to be applied and what its implications will be for the necessary international co-operation we might need in all of the instances outlined. Returning to amendments Nos. 7 and 8, it is good that there will be a code of conduct. The problem is the idea that a data protection impact assessment is done at the very beginning, it inspires or influences the writing of the code of conduct, there is engagement on that and then it is left. The AI Act's drafters envisage that deployers - those who are doing this work - would be submitting annual reports to the relevant national data protection authorities on their use of these identification systems. They are not saying to consult with them when you set out the code of conduct at the beginning. I worry that so much has been placed on the Garda Commissioner. Ministerial accountability is important and of ongoing relevance as well. We know in other situations that individually you cannot just make a general rule. You either have to apply your data protection assessment individually as came up on the information and tracing Bill, or you have to look at creating clear regulations that meet necessity and proportionality. I guess the code of conduct is a proxy for regulations here because the Minister is placing it before the Houses of the Oireachtas. That is a good step, and I welcome it. However, I am concerned as to whether it is the Garda Commissioner's code of conduct, the State's code of conduct or the Minister's code of conduct. What happens if that code of conduct proves to be poorly drafted and not appropriate for the facts, challenges or issues that are arising? What is the mechanism for the annual reporting required and suggested under Article 26.10 of the AI Act? What does it look like after the code of conduct gets voted through by the Oireachtas? What happens next in terms of a data impact assessment and data protection? Also, where does the accountability ultimately sit? Is it with the Garda Commissioner or with the Minister? I would also like that clarified. --- Source: Houses of the Oireachtas. Licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). The Official Report is revised after first publication; the fetch timestamp below identifies the version quoted. Record URI: https://data.oireachtas.ie/akn/ie/debateRecord/seanad/2026-06-23/debate/main Retrieved: 2026-08-14T04:55:05+00:00 Sitting date: 2026-06-23