Case Study 10: Customer Data Transfer for Waste Collection Service in Dublin [2012] IEDPC 10 (2012)
The transfer of customer data as part of the sale of the waste collection business did not breach the Data Protection Acts, but the timing of customer notification failed to meet fair processing requirements. No unlawful transfer of personal data occurred in relation to debt collection, provided that agreed controls and audit procedures are implemented.
- Citation
- [2012] IEDPC 10
- Parties
- Data Controller / Seller: Dublin City Council; Data Processor / Buyer: Greyhound Recycling and Recovery; Regulator / Investigator: Office of the Data Protection Commissioner
- Jurisdiction
- Ireland
- Procedural Posture
- Data Protection Investigation / Final Decision / Case Study Publication
- Outcome
- No breach found in core data transfer; fair processing requirements not fully met due to late notification; undertakings and audit procedures required for future compliance.
- Legal Topics
- Personal Data Transfer, Fair Processing, Data Processor Obligations, Sale of Business, Customer Notification, Debt Collection
Case Brief
Summary, issues, holding and outcome
More case intelligence is available
Unlock the full research layer for this judgment.
Parties
Dublin City Council
Data Controller / Seller
Greyhound Recycling and Recovery
Data Processor / Buyer
Office of the Data Protection Commissioner
Regulator / Investigator
Procedural Posture
Data Protection Investigation / Final Decision / Case Study Publication
Legal Issues
- 1 Whether the transfer of customer data from Dublin City Council to Greyhound Recycling and Recovery complied with the Data Protection Acts, 1988 & 2003
- 2 Whether the collection of Dublin City Council customer debts by Greyhound involved unlawful transfer or processing of personal data
Ratio Decidendi
The transfer of customer data as part of the sale of the waste collection business did not breach the Data Protection Acts, but the timing of customer notification failed to meet fair processing requirements. No unlawful transfer of personal data occurred in relation to debt collection, provided that agreed controls and audit procedures are implemented.
Court Disposition
No breach found in core data transfer; fair processing requirements not fully met due to late notification; undertakings and audit procedures required for future compliance.
Orders
- Dublin City Council to comply with Data Protection Commissioner guidance in future similar situations.
- Greyhound to implement and maintain strict separation and audit controls for debt collection data.
Full Case Text
Judgment text and source record
Sign in to read
Sign in to read the full judgment text
Sign in to read the full judgment text. Downloads and additional research tools may depend on your plan.
Sign in to read the full judgment