Social Welfare, Civil Registration and Charities (Amendment) Bill 2026: Second Stage Dail Éireann — 2026-09-22 ============================================================ Eoin Hayes (SD), Dublin Bay South I thank the Minister and his officials for bringing forward this Bill, much of which contains, as he said, technical and administrative rationalisations. That is the unseen and unglamorous work in legislation and Departments but it is important, and I sincerely thank the officials for doing it. Improvements to the operations of the Charities Regulator are very welcome to ensure public confidence in the efficiency and effectiveness of its governance. Charities do incredible work across this State in aiding our most vulnerable, and proper administration, enabled by legislation and the regulator, is critical to proper oversight. I also welcome the adjustments to the Civil Registration Act to make it more inclusive for the modern era. It is not very often that we do this continuously in Government Departments, and when it does happen it should be applauded. Progress sometimes means reform, and this is a very good example of it. I also thank the Minister and his officials for the meaningful engagement with those adopted or boarded out. I hope that is progress that continues hereafter. Lastly, I acknowledge the changes to the eligibility requirements for jobseeker's benefit to include those who have received redundancy payments. Losses of income and livelihoods should not be compounded by a State that does not do all it can to help people in that moment. The change here to include people who have recently been made redundant is very welcome, especially in the context of cascading layoffs in many companies in my constituency. I encourage the Minister, however, to explore how people who are in self-employment and who may have catastrophic collapses in their income are supported. Many contractors in these companies in my constituency employ people who are dependent on occasional gig-like work, who earn on average much less than PAYE workers do and who need to be similarly supported so they are not put into incredible precarity. There is work to be done there, and if the principle of this change in the Bill is to support people who have lost their income regardless of redundancy payments or other means, that should be a universal principle applied equally. There is, however, a core issue in this Bill that featured prominently in the pre-legislative scrutiny at committee, which I will now turn to, namely section 8 of the Bill, which seeks to amend legislation for an operation of the public services card. I want to be very clear in acknowledging the good parts of the public services card. It is a free card, unlike other forms of identification, like a driver's licence or a passport. That is of particular importance to people in low-income populations. I support the provisions of the Bill in ensuring that individuals are in control of who or what entity they give their public services card information to and can do so only with the cardholder's consent. That is a good principle. The existing use of the public services card in engagement with public services is primarily for social protection payments. Public use has increased drastically since its introduction, and many entities, like credit unions and NGOs, have voiced support for more widespread allowance of the use of the card to facilitate ordinary transactions, particularly for populations without a driver's licence or a passport. There is no denying, however, that the public services card as an identity card has had a controversial past in this Chamber and outside of it since its introduction as a pilot by then Labour Minister Joan Burton in 2011. Today, 15 years later, there are 3.25 million cards in circulation, and 4.5 million in the population are SAFE registered, or have registered their information with the data system governing the card, including supplying biometric data that can be used by facial recognition software. Core to the criticism of the public services card in the past, including by the Data Protection Commission and the Comptroller and Auditor General, is that there has been no primary legislation, business case or meaningful public debate on the issue of a broader digital identity infrastructure for citizens of this State. In effect, the card has introduced a State identity infrastructure through the back door. In 2012 the Department started using the card's biometric facial data with facial recognition technology, and in 2025 the Data Protection Commissioner found that this use was "unlawful" and levied a fine of €550,000 against the Department of Social Protection, a decision later appealed by the Department and currently before the courts. It is notable that the use of facial recognition technology on this data means that the Department and, by extension, others, including the Garda, can facially detect up to 70% of the population. This leaves some significant cause for concern. Notably, the DPC has said in committee that if it wins the case, it may use its full enforcement powers against the Department, namely: Where we make a finding of unlawful processing of personal data, we can require the processing to cease, ban the processing from recommencing and require the data to be deleted. If our decision in this case is upheld, what we will be looking for is for those types of corrective measures to be implemented ... This would effectively mean that all facial images may have to be purged from the Department's databases and the practice of collecting them and using them in facial recognition by the Department would have to halt. To date, no High Court or Supreme Court judgment has determined whether the PSC scheme is lawful or unlawful. The governance, legislative basis and operations of the data associated with citizens through the PSC have been challenged repeatedly by other NGOs, including the ICCL, UCD's centre for digital policy and other concerned citizens. Some have gone so far as to call it "unlawful". The central controversy surrounding the card in Ireland historically has been its use, or potential use, as an identity card without being called one, or such use being legislated for, or this being the subject of sufficient public debate about the need, business case, purpose or risks associated with such use. I am reminded here, as were other speakers, of the radio interview in which then Fine Gael Minister Regina Doherty declared it was "mandatory" but "not compulsory". Today many social protection services and, reportedly, many other public services are in effect not easily accessible without a public services card. One witness at committee, Dr. Elizabeth Farries of the UCD centre for digital policy, said it was "becoming effectively mandatory". Notwithstanding the concerns about the PSC and identity infrastructure as they currently exist, much of my core concern during our pre-legislative scrutiny focused on how the scheme may be applied in the future. As Dr. Ferries described, the PSC enables a "broad interoperable identity infrastructure in which data sets become linkable, profiling becomes easier and information collection for one purpose migrates into others". On the question of function creep, or the data that would be used for things that it was not originally intended to be used for, there is precedent, as was reported to the committee. Given recent pronouncements by the Minister for culture and the President of the European Commission with regard to digital ID and integration of such IDs to authorise access to social media, there is some cause for concern that such identity infrastructure would extend use into the digital sphere and, in particular, social media. Dr. T.J. McIntyre of the ICCL said at committee that he suspected the effort from the Department of Social Protection and the Department of public expenditure and reform: ... was to become an all-in-one public identification database, ... all of which is viewable by everybody and every government department. ... The problem is that, as things stand, the underlying database of the public services card ... is essentially a 360 degree view of the individual which contains all this information and does not have these more granular access controls in place regarding who can see what and which, if it is expanded for identity verification or age verification in other contexts, will unnecessarily leak information in those other contacts as well. There are fraud risks associated with giving out too much of this data. If the future of the SAFE data, or PSC data, in particular facial recognition data, is the starting point of a more comprehensive database of activity of people on this island, the further contention is that this could lead to a kind of Big Brother or surveillance state infrastructure, including the use of such technology to profile the population. This was the most significant warning from witnesses - that the use of this data and the associated technologies could underpin a surveillance architecture through facial recognition. Dr. Ferries highlighted this repeatedly as a future risk. There are, she said, risks in surveillance associated with "proportionality, democratic oversight, discrimination risks and the protection of fundamental rights showing up time and again". It is clear that there should have been a more comprehensive national debate on the question of national identity infrastructure. Primary legislation should have been moved, and the question of the primary uses of such infrastructure, the business case for its costs, the benefits, advantages or disadvantages and the oversight of such a system should have been part of that debate. We have still not had that. However, I acknowledge the public desire that the State facilitate the use of public services through more modern technologies. Many would argue that the State needs to modernise even more, and that public service cards yield usability benefits to the general public. Since independence the Republic has had no major crisis of civil liberties. We live in a liberal society where privacy is respected in virtually all aspects of the law. Ireland also enjoys a fairly high level of trust among the public and the organs of the State. There is an expectation that they will interact with them in a fair way. This is internationally unusual. There are countless examples of other countries' police or military infrastructure being used against the populace in a systematic way. This has led, in other jurisdictions, to an inherent distrust of the state holding data on the person, restrictions on the use of that data and stronger legal and constitutional protections for privacy, confidentiality and proper oversight and governance. In the age of information technology, the ability of any state to use personal information for nefarious purposes has extended. The linking of data sets has become a much easier proposition than it was in the past, leading to a higher functionality for state systems in a variety of use cases. In the case of domestic surveillance of the population, new frontiers have opened and been pursued by governments internationally. That must be opposed and condemned, and I join anyone in that mission. Notwithstanding Ireland's unique peaceful and lawful experience in these areas, there is always a risk that a future government or administration could use the infrastructure of the State to encroach on civil liberties, to target minority populations, for instance, or suppress political dissent. Furthermore, should the data be accessed by unscrupulous actors like hackers, compromised individuals within State bodies or foreign state actors, especially in the age of supercharged invasive AI, individuals could be targeted using the information held by the State without proper protection. There is a real risk that the infrastructure we build today could be misused. From the perspective of the Oireachtas it is difficult to make an assessment of the proper governance of this data, or its future uses without more information on how the Department is using it, so I sought to do just that. I recently corresponded with the Minister for Social Protection on issues that have been raised in pre-legislative scrutiny, namely the uses, governance and future plans for public services card infrastructure. The information he provided was helpful and I sincerely thank him and his officials for being transparent, clear and comprehensive on these matters. I have some follow-up questions that I will return to him in due course. One part of the correspondence did cause me some concern, however. Under section 41(b) of the Data Protection Act 2018, the Department of Social Protection can supply any public services card data to An Garda if deemed, "necessary and proportionate for the purposes [of] (a) of preventing a threat to national security, defence or public security [or] (b) of preventing, detecting, investigating or prosecuting criminal offences." That does create a wide applicability without oversight, judicial or otherwise, and may be used as a pretext for law enforcement powers to use the data for means beyond what we might reasonably expect for social protection purposes. International experience would suggest this can be misused. While I have every faith, as I believe most people in this country do, that An Garda acts with probity in its role, that unfortunately may not always be the case in the future. In summary, I welcome most of the provisions in this Bill. I still have some outstanding concerns on the identity infrastructure in Ireland, in particular how it might be misused in the future. I encourage the Minister to engage with the Data Protection Commissioner and other concerned citizens on their concerns about civil liberties and privacy, and on how we build a modern state that works for all of us and protects us all. --- Source: Houses of the Oireachtas. Licensed under CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). The Official Report is revised after first publication; the fetch timestamp below identifies the version quoted. Record URI: https://data.oireachtas.ie/akn/ie/debateRecord/dail/2026-09-22/debate/main Retrieved: 2026-09-28T05:50:49+00:00 Sitting date: 2026-09-22