
![]()
Fiosrú, the Garda watchdog responsible for investigating complaints against gardaí, recorded 38 data breaches over an 18-month period, including incidents involving sensitive personal information being sent to the wrong recipients and a laptop left behind in a Dublin taxi, The Irish Times reports.
Records released under the Freedom of Information Act detail a series of incidents during 2025 and the first six months of 2026, covering the transition from the Garda Síochána Ombudsman Commission to the newly established Fiosrú.
One of the incidents classified as high risk involved an email sent to an unintended recipient, with two attachments containing personal information including names, addresses, ages, gender and details of allegations. The breach was reported to the Data Protection Commission (DPC), and the affected individuals were notified.
In a separate incident, a Fiosrú staff member left a laptop, notebook and document in a bag in a Dublin taxi. The matter was reported to the DPC, although the bag and its contents were recovered later that day. Fiosrú said there was no evidence the laptop had been accessed.
The records also show that a letter intended for a complainant was mistakenly sent to the Garda Commissioner. The error occurred while an official was distributing 16 update letters.
Another incident involved an email intended for Fiosrú’s data protection unit being sent instead to Dublin Bus’s data protection office. According to the breach log, the email contained only staff members’ personal data. Dublin Bus confirmed the emails had been deleted twice and had not been shared with third parties.
Other incidents included emails, attachments and correspondence relating to complainants and garda members being sent to incorrect recipients. A staff member also left a mobile phone in a shop, while another case involved an online complaint submission being issued to an unintended recipient.
Four of the 38 incidents met the threshold for mandatory reporting to the DPC. Most were assessed as low risk and did not require notification to the commission.
Responding to the records, a Fiosrú spokesperson said appropriate measures had been taken promptly to address the incidents, the majority of which involved email correspondence.
The watchdog said its laptops were protected by security software, two-factor authentication and passcode technology, with hard drives encrypted.
Fiosrú has also introduced data-loss prevention software designed to reduce the risk of emails containing sensitive information being sent to the wrong people.
The system works with Microsoft Outlook, prompting staff to check external recipients and verify sensitive attachments before sending messages, the spokesperson said.