
Person pretending to be Tusla worker turned up at children's residential unit on night shift
Tusla
agency worker gained entry to a residential unit for children and 'obtained unauthorised access' to their personal data, records released to The Irish Times show.
The 'high-risk' incident happened when the individual used the 'credentials of an authorised person working at the unit' rostered that night.
They remained at the unit overnight, with access to the children, their files and the personal data of people who worked there.
'The 'unauthorised party' was acting with the assistance of the 'authorised operative',' the records also stated.
READ MORE
'The other authorised staff who were coming off duty or coming on duty would not have known of the full identity (other than name) of the other external recruitment agency worker who was rostered to work that night shift, as this was a recent recruit who the staff would not have worked with before.
'Therefore, 'bona fides' of the 'bad actor' were not in question and [other staff] had no reason to suspect 'personation'/'false identity'.'
The incident, which happened on June 27th, 2023, was reported to Tusla's data protection unit three days later. The affected children, staff and the
Data Protection Commission
were alerted.
A review of this incident found 'no suggestion that any service user was adversely impacted', a Tusla spokesman said.
Details of the incident, which was categorised 'high risk' and as an 'access control deficit', are contained in a large release of records under the Freedom of Information Act on personal data breaches at Tusla, which is the Child and Family Agency.
They show there were 2,184 breaches between 2019 and the end of 2024, with about 150 more to July 5th this year.
In another high-risk incident, files containing 'personal data' were missing for 26 years when found in the 'private home' of a former Tusla staff member. The incident in the southeast came to light in January last year.
'Staff member had originally taken the files home in 1998 to work on and had left them in a home study where they went unnoticed/undiscovered until recently,' a description states.
'Files were absent (location unknown) and unavailable to Tusla (and predecessor agencies) during this period when business needs did arise that required access by Tusla to some of the files.
'No backup copies of the data was available to Tusla during the period the data was absent from Tusla control.'
It was recorded as a 'misplaced/lost/exposed record or device'.
Almost a quarter (515) of the breaches during the six years were 'high risk', with 58 per cent (1,274) categorised as 'low risk', 11 per cent (243) 'zero' risk and 6.5 per cent (143) 'medium' risk.
In 2021 about a third (117 out of 362) were high-risk breaches.
The most common breaches (706) were emails sent to the wrong address. A total of 383 were caused by 'information overshare'. This could be when a file was sent to a person with their own details, but also containing details about other people they had no right to see.
A breach similar to this allegedly occurred this year when the whereabouts of a mother and child fleeing abuse were provided to their alleged abuser.
The alleged abuser had sought their own file from Tusla following an allegation of abuse against them.
David Hall
, chief executive of Sonas domestic violence charity, which was accommodating the mother and 'very young child', said Tusla failed to redact both the name of the shelter where the woman and child were staying and that of a domestic violence support worker who reported the alleged abuse, putting them all 'at risk'.
When the alleged breach came to light in March, he said the data of women and children fleeing domestic violence were 'not safe'.
On Friday he said he had not received satisfactory assurances from Tusla that 'vulnerable women and children's' data was safe.
Other breaches since 2019 include 348 incidents of 'misplaced/lost/exposed record or device'; 273 'incorrect record shared'; 120 'access control deficit'; and 35 'misdirected phone call or message' – including Tusla staff leaving messages with the intended recipient's personal details on the wrong number.
Tusla's national adoption information and tracing service had the highest volume of high-risk breaches between 2022 and 2024 – accounting for 19 per cent (56) of the 295 such breaches in those years, mainly concerning too much information released to people seeking their birth and early-life history, including information about other people.
These new figures come as the cost to Tusla since 2020, due to personal breaches, tops €500,000.
Figures released under FoI show the agency has paid damages of €134,500 for data breaches since 2022, incurring related legal costs of €177,164.
These are in addition to fines levied by the Data Protection Commission (DPC) in 2020 totalling €200,000. The DPC conducted three investigations into Tusla in 2020 for alleged breaches of the EU's General Data Protection Regulation (GDPR), resulting in separate fines of €75,000, €40,000, €50,000 and €35,000.
The DPC ordered Tusla to 'bring its processing operations into compliance ... by implementing appropriate organisational measures to ensure a level of security appropriate to the risk'.
Breaches have however increased since – from 362 in 2020 and 362 in 2021 to 408 for 2022, 481 in 2023 and 441 last year.
The DPC has not investigated Tusla since August 2020, a spokesman confirmed, but has 'continued to engage with Tusla after the conclusion of all inquiries undertaken to ensure that the orders contained within the decisions issued were complied with. In addition, the DPC has regular and ongoing engagement with Tusla like we have with all other public sector bodies'.
The
Irish Council for Civil Liberties
said the number of breaches was 'very concerning'.
'Tusla processes very sensitive data about vulnerable people, including children. We are not just talking about people's rights to privacy and data protection, but also in some cases their safety,' it said.
'These figures raise serious questions about how Tusla is carrying out its obligations under the GDPR and what policies and protocols are in place. The Data Protection Commission should examine these figures and take appropriate action.'
A Tusla spokesman said: 'Due to the large volume of data we process daily ... breaches occasionally and regrettably occur, which can have a significant impact on those involved.
'We are fully aware of our responsibilities regarding the handling of sensitive data, and we take all breaches very seriously.
'In the case of any data breach, we will react quickly to inform impacted persons or their parent/caregiver of the breach, identify the cause and undertake a full assessment and comprehensive risk evaluation.
'Tusla conducts systematic reviews of all reported breach incidents, and we adapt and update training and operational practices to mitigate against similar breaches occurring in the future.
'We will continue to work with the DPC with full transparency on the matter, as appropriate. Where required, we take all possible steps to recover the information subject to the breach.
'Over the last number of years, a comprehensive programme of work has been under way ... to improve awareness in relation to data breaches, ensure staff are aware of their duty to report all breaches and to mitigate the risk of data breaches occurring..
'Over the last year there has been a 63 per cent reduction in 'high-risk' breaches, a 29 per cent reduction in 'misaddressed post' and an 18 per cent decrease in 'information overshare' breaches.'
Hashtags

Try Our AI Features
Explore what Daily8 AI can do for you:
Comments
No comments yet...
Related Articles


Irish Times
34 minutes ago
- Irish Times
Airport security man demoted for kissing colleague should get job back, says WRC
Airport chiefs have been urged to give a security worker his old job as a supervisor back after he was demoted for kissing a subordinate while they were at work together on a screening line two summers ago. The decision to demote the worker from airport search supervisor to a junior position on the airport search unit was 'excessive', a Workplace Relations Commission (WRC) adjudicator decided in a non-binding recommendation under the Industrial Relations Act 1969. The tribunal heard the supervisor had more than five years' service on the airport search unit, screening passengers and baggage, with two years as supervisor, when he was placed under investigation in September 2023 and suspended. The employer said it considered the complainant to have committed gross misconduct by 'kissing a colleague during active operational duties' on the two days before his suspension. READ MORE The other worker, a more junior airport search unit officer, had been operating an x-ray machine on one occasion, and was working in a 'premium services area' under the supervisor on the other occasion. The outcome of the disciplinary process was that the complainant was demoted from his €46,000 a year supervisor post and placed on a final written warning. The decision reflected the 'safety-critical nature of the breaches, the worker's leadership responsibilities and the need to preserve the integrity of security operations', the employer submitted. The disciplinary officer's view was that the kissing 'had the potential to compromise both safety and the employer's reputation'. The demotion and warning were upheld on appeal, an internal appeals officer taking the view that the sanction was 'consistent with those issued in comparable cases', the tribunal heard. Joseph Ateb of the Siptu Workers' Rights Centre, who appeared for the worker, said his client had appealed the decision as being 'excessively harsh' and contended that his previous good record in employment was not given due consideration. The final written warning had expired by the time the WRC heard the case, leaving only the demotion as an issue, the tribunal noted. Adjudicator Breiffni O'Neill wrote that the employer's decision not to consider transferring the supervisor to another department 'calls into question the true extent of the safety concerns'. 'This inconsistency undermines the credibility of the employer's rationale and suggests a lack of proportionality,' he wrote. 'In light of the worker's unblemished prior record, his acceptance of responsibility and the employer's failure to consider a less punitive and reasonable alternative, I find that the additional sanction of demotion was excessive,' Mr O'Neill wrote. His recommendation on the dispute was that the demotion be rescinded and that the worker be reinstated as a supervisor 'with full restoration of duties and remuneration' within a week. The recommendation was published without the names of either the worker or his employer, in line with the WRC's usual practice under the Industrial Relations Act's voluntary arbitration process.


Irish Times
2 hours ago
- Irish Times
Inquest into prisoner's death delayed after DPP ‘mislaid' file, court hears
An inquest into the death of a prisoner has been adjourned for a further three months after a file for the Director of Public Prosecutions (DPP) was 'mislaid', a coroner's court sitting has heard. Michael Devlin absconded from the Shelton Abbey open prison in Arklow, Co Wicklow, in 2020 and remained on the run until he was detained again in January 2024. He died about a month later in Cloverhill Prison. He died from complications associated with supraglottitis, an acute bacterial infection that can cause severe airway obstruction. At a preliminary hearing at Dublin District Coroner's Court on Wednesday morning, Det Insp Brian Hanley sought a further adjournment of three months, as a file has been submitted to the DPP concerning the death. READ MORE Upon questioning from Michael Finucane, representing Mr Devlin's family, Det Insp Hanley said a file was initially submitted in hard copy form in May. 'Following an inquiry after this date, it became apparent that the file had been mislaid. It was resubmitted approximately two weeks ago,' he said. The DPP subsequently requested the postmortem report, which was not included with the file. This was requested by gardaí last week. 'I am mystified as to why a file would be submitted to the DPP in relation to a death in custody without the postmortem report,' Mr Finucane said. Mr Finucane said he had several questions relating to the 'expeditious nature of the investigation or lack thereof'. These included the delay in requesting a postmortem and the delivery and subsequent mislaying of the file for the DPP. Coroner Dr Clare Keane said the questions were 'reasonable' but would not hear such evidence during a preliminary hearing and adjourned the case until November. In a separate case, the family of a 38-year-old man who died in a workplace-related incident in December 2019 said they are 'in limbo' after a request was made for a further adjournment. Health and Safety Authority (HSA) inspector Frank Kearns sought an adjournment of six months as a file concerning Karl McKeon's death remains with the DPP. 'I understand the last time I was here, six months ago, it was also with the DPP then,' he said. Family members present said they were unaware the case would be pushed out again and expressed frustration that they have been waiting almost six years for answers. 'Karl's five and a half years dead, and it's destroying our family. We don't know why he died or how he died,' his mother, Mary, said. Noting she has been in hospital three times since her son died, she said: 'I don't know if I'm going to live to find out what happened to my son.' 'The HSA had it for a very long time and now it's been in the DPP's hands and I think at this stage, we should be having answers and maybe we'd be able to go up to Karl's grave and know why he's lying in the grave,' she said. 'I've actually rung the DPP myself,' she said, adding that she has 'given up'. 'It's heartbreaking and I can't do it any more,' she said. Dr Keane asked the HSA inspector to contact her office if updates arise, and another preliminary hearing will be listed 'immediately'. She adjourned the case for a further three months. Separately, the case of John Murphy, a 41-year-old who died after sustaining extensive burn and blast injuries in an industrial incident at the Stryker plant in Carrigtwohill, Co Cork, has been adjourned for a further six months. Mr Murphy died at St James's Hospital in Dublin almost two months after the incident in June 2023. Mr Kearns said the death is still under investigation by the HSA, but a file will be submitted to the DPP.

Irish Times
2 hours ago
- Irish Times
Police secure CCTV footage in Babatunde murder investigation
Police have obtained CCTV footage tracking the movements of a man suspected of stabbing an asylum seeker to death in Dublin, a court in Belfast heard today. Prosecutors also revealed that a new detective has been appointed to head the investigation into the killing of Quham Babatunde. The details emerged as Ryan Ndede (24) was remanded in continuing custody, charged with his murder. Mr Babatunde, who was 34 and from Nigeria, was stabbed four times during a suspected group fight on Anne Street South in Dublin city in the early hours of February 15th this year. READ MORE Footage allegedly shows Mr Ndede, of Boroimhe Birches in Dublin, producing a blade and targeting the victim. Police Service of Northern Ireland officers arrested him after he subsequently travelled to Belfast and boarded a ferry to Birkenhead in England. Eight other men have also been charged in the Republic with violent disorder, assault or weapons offences related to the incident. Belfast Magistrates' Court heard on Wednesday that there is currently no other suspect being prosecuted for the alleged murder. Providing an update in the case against Mr Ndede, a Crown lawyer disclosed: 'A new detective inspector has been appointed. 'The investigating officer has now received the full CCTV compilation, tracking the attacker's movements throughout Dublin.' Forensic tests are also being carried out on a knife and glove recovered as part of the murder inquiry. Mr Ndede's barrister, Michael Halleron, argued that more details were required on progress being made in the investigation. Adjourning the case to next month, District Judge Conor Heaney said it would give the new lead detective time to provide a further 'meaningful update'.