We use Google Analytics to see which pages are read and how the site is used, so we know what to improve. This only runs if you accept. See our privacy notice for details.

Dáil
‹ Ceisteanna ó Cheannairí - Leaders' Questions

Sale of mobile phone location data

Summary

Ivana Bacik raised concerns that brokers could sell mobile phone location data, enabling users’ movements, political representatives’ addresses and sensitive locations to be tracked. The Minister said the issue was serious, confirmed engagement with the Data Protection Commission and advised disabling location-sharing apps, while acknowledging that consent did not authorise resale.

The recent RTÉ “Prime Time" programme into the purchase of mobile phone location data was shocking. For very little money, and with very little effort, journalists were able to buy data which tracked the journeys of smartphone users across Ireland, based in different locations. They even tracked naval vessels, people in Irish prisons and phones here in Leinster House. Using this data, as we know, they were able to trace the residential addresses of political representatives. The Minister and Deputy Barry Ward were featured in the programme.

It was particularly chilling - and the findings were chilling - given the recent reports of very serious online abuse and threats of violence against the Tánaiste, Simon Harris, and his family. I want again to condemn absolutely outright those threats. Threats against public representatives and their families represent a threat to democracy. They undermine our political system and they deter people from entering politics.

This is a very serious issue but it is not new. It affects the civil liberties of all our citizens and not just those in public life. As long ago as 2020, the Irish Council for Civil Liberties, ICCL, undertook a similar exercise to RTÉ’s “Prime Time” team. It purchased data identifying 200 Irish people who had been tagged as survivors of abuse but despite handing those findings to the Minister's predecessor and the Data Protection Commission, no action was taken at the time to protect the privacy of individuals.

Following the recent “Prime Time” programme just last month, the Data Protection Commission, DPC, has pledged to look into this matter at last but it seems that the best response the Government could give was a watery commitment to looking at the possibility of vague new laws. Frankly, that is not good enough nor is it appropriate.

As I made clear, the GDPR already contains the safeguards necessary to enable the DPC to take the action that is needed to prevent the sale of data where no meaningful or informed consent has been given as it could not be given when we see this absolutely brazen use of data in this way. As the Minister knows, the DPC has the statutory powers it needs to protect the privacy of smartphone users in this country and we know this but, to date, it has not taken necessary action to protect people whose smartphone data is up for sale right now. It is welcome that the DPC has announced it will commence investigations with a view to taking enforcement proceedings against two of the companies featured in the “Prime Time" programme but the question remains: why did the DPC not use its existing statutory powers sooner to protect people’s privacy? Why has the Government taken such a hands-off approach to this?

I raised this in this Chamber two weeks ago in advance of the “Prime Time” programme. The Tánaiste offered me only a holding response and nothing of substance and the Government did not put up a spokesperson on the “Prime Time” programme that evening.

What is the Minister doing to protect the privacy rights of our communities and, because we are an EU tech hub, what is he doing to protect privacy across the EU? Let us be clear: this poses a risk not only to individuals but also to our national cybersecurity. We know that Ireland lacks an adequate overarching strategy to guard against cyber attack. We saw that with the HSE ransomware attack recently.

Comment on this

I thank the Deputy for her question. I did see the “Prime Time” programme two weeks ago and I thought it was very concerning. It was an issue of considerable concern to me, not that fact that I or, indeed, other politicians were identified in it, but the potential that was there for brokers, of whom we were unaware, to sell on the market details about an individual’s movements. Obviously, from a security point of view, that could be an extremely serious matter if it was the case that individuals could identify the movement of individuals such as gardaí or prison officers. I am extremely concerned about it. In the aftermath of the programme, I met with officials in my Department and asked them to engage with the DPC, which, as the Deputy correctly pointed out, has statutory responsibility for this area. My information is that the DPC has used the statutory powers it has already to investigate this matter. As a result of its investigations, it has been able to identify that one of the two entities identified in the “Prime Time” programme is based in Ireland. I understand the DPC has visited its offices for the purposes of continuing its investigation. I am also aware that the other entity that was identified in the programme that is selling what is personal data is based not in Ireland but in another EU country. I am informed by the DPC that it has contacted the equivalent of the DPC in that country and notified it of it.

The Deputy asked why I did not do anything sooner. Just because I did not announce it does not mean I am not doing something. I have given her an indication of what has been done in the two weeks since the programme. It is important to point out that the Data Protection Commissioner has very considerable powers under the data protection legislation that this House has enacted. Under those powers, they are responsible to protect the personal data of individuals in this country. If one looks at what was revealed in the “Prime Time” programme, what was most concerning was that individuals' movements could be so readily identified and also sold on. We do not want to find ourselves in a situation where that type of personal data as to where a person is going on a daily basis is available for sale on the commercial market.

On what the commission is continuing to do, it is, as the Deputy knows, fully independent in the exercise of its functions but it does engage with officials in my Department. I am satisfied that the investigation that has commenced is ongoing and we will get to the bottom of who these data brokers are. Personal data is very clear when we identify it. It is unquestionably the case that the movements of an individual - whether he or she is a TD or not is irrelevant - being sold on the market for the purpose of commercial enterprise or more nefarious activity is unacceptable.

Comment on this

I thank the Minister for that response. It is welcome to hear that his officials are engaging with the DPC on this and that the DPC is using the statutory powers. I am also glad that the Minister confirmed to me what I had said at the start, which is that the DPC does have adequate statutory powers and that the issue is about the usage and application of those powers.

The Minister said that one of the brokers is based here in Ireland. That is welcome because clearly enforcement proceedings will be more straightforward. He said there is another in another EU country. He might clarify which EU country that is. It is vital that there is follow-up here in relation to data brokers who are acting in flagrant disregard of GDPR and of our own data protection laws. However, individuals still have concerns. Appeals Centre Europe, which is based in Ireland, issued a transparency report today. It says that only 78 eligible disputes emerged from Ireland between November 2024 and August 2025 and only 50 decisions have issued.

Given the widespread proliferation of online abuse, toxic language and horrible threats, it is extraordinary that so few decisions have been made by this body, which is supposed to be safeguarding citizens' rights. The decisions it makes are not even legally binding on platforms. What are the Government's plans to reassure citizens that our data will be private?

Comment on this

I am not going to identify the other EU country as of yet.

Comment on this
Deputies

Why not?

Comment on this

I do not want to put the focus on that country or the entity. In terms of the issues that arise, one of the difficulties is that many of us have granted permission to use apps to gain certain services on our mobile phones, for instance weather apps, location apps or maps. This can have the impact that we are giving information out about our location. I am not suggesting all responsibility should rest on the individual but certainly since that programme aired, I have turned off any of the location apps on my phone and I recommend to other Deputies that they do the same. We can turn them on when we need to use them or when we need to use a map.

Comment on this

But the consent does not cover sale.

Comment on this

Of course it does not but notwithstanding that, if we manage to put ourselves in a situation where we are not making the information available it cannot then subsequently be sold on. This is a recommendation I make. It is certainly inappropriate for it to be sold on and I know the DPC is looking at it. Further engagement will take place in respect of it.

Comment on this