Case Study 10: Customer Data Transfer for Waste Collection Service in Dublin [2012] IEDPC 10 (2012)

Case Study 10: Customer Data Transfer for Waste Collection Service in Dublin [2012] IEDPC 10 (2012)

The transfer of customer data as part of the sale of the waste collection business did not breach the Data Protection Acts, but the timing of customer notification failed to meet fair processing requirements. No unlawful transfer of personal data occurred in relation to debt collection, provided that agreed controls and audit procedures are implemented.

Citation
[2012] IEDPC 10
Parties
Data Controller / Seller: Dublin City Council; Data Processor / Buyer: Greyhound Recycling and Recovery; Regulator / Investigator: Office of the Data Protection Commissioner
Jurisdiction
Ireland
Procedural Posture
Data Protection Investigation / Final Decision / Case Study Publication
Outcome
No breach found in core data transfer; fair processing requirements not fully met due to late notification; undertakings and audit procedures required for future compliance.
Legal Topics
Personal Data Transfer, Fair Processing, Data Processor Obligations, Sale of Business, Customer Notification, Debt Collection

Case Brief

Summary, issues, holding and outcome

More case intelligence is available

Unlock the full research layer for this judgment.

Full judgment text Downloadable case file Legal principles 2 Authorities cited 1 Party arguments 2 Amounts and remedies 1
Sign in to unlock

Parties

Dublin City Council

Data Controller / Seller

Greyhound Recycling and Recovery

Data Processor / Buyer

Office of the Data Protection Commissioner

Regulator / Investigator

Procedural Posture

Data Protection Investigation / Final Decision / Case Study Publication

  1. 1 Whether the transfer of customer data from Dublin City Council to Greyhound Recycling and Recovery complied with the Data Protection Acts, 1988 & 2003
  2. 2 Whether the collection of Dublin City Council customer debts by Greyhound involved unlawful transfer or processing of personal data

Ratio Decidendi

The transfer of customer data as part of the sale of the waste collection business did not breach the Data Protection Acts, but the timing of customer notification failed to meet fair processing requirements. No unlawful transfer of personal data occurred in relation to debt collection, provided that agreed controls and audit procedures are implemented.

Court Disposition

No breach found in core data transfer; fair processing requirements not fully met due to late notification; undertakings and audit procedures required for future compliance.

Orders

  • Dublin City Council to comply with Data Protection Commissioner guidance in future similar situations.
  • Greyhound to implement and maintain strict separation and audit controls for debt collection data.