Fiosrú, Ireland’s Garda complaints and oversight body, recorded 38 data breaches over a period covering 2025 and the first six months of 2026. The incidents included sensitive personal information being emailed to the wrong recipient, correspondence intended for a complainant being sent to the Garda Commissioner and a work laptop left in a Dublin taxi.
The records, released under Freedom of Information legislation, provide a detailed look at the types of mistakes logged during the transition from the Garda Síochána Ombudsman Commission to Fiosrú. Four incidents met the threshold for mandatory reporting to the Data Protection Commission (DPC).
What happened in the latest Ireland News report?
The breaches varied in seriousness. Most were assessed as low risk and involved email correspondence, attachments or official documents being sent to an unintended recipient.
The highest-risk incident involved an email sent to the wrong person with two attachments containing sensitive personal information. The material included a person’s:
- Name and address
- Age and gender
- Details relating to allegations
Fiosrú classified the incident as high risk, notified the DPC and informed the people affected. The disclosure illustrates why data-handling procedures are particularly important for an organisation dealing with complaints about policing and allegations involving individuals.
Fiosrú laptop left in Dublin taxi
One of the more visible incidents involved a Fiosrú employee leaving a bag in a Dublin taxi. The bag contained a laptop, notebook and document.
The incident was reported to the DPC. Fiosrú said the bag was recovered later that day and that there was no evidence the laptop had been accessed. The other items were also recovered.
The organisation has said its laptops are protected with encrypted hard drives, passcode technology and two-factor authentication for network access. Those measures reduce the risk of unauthorised access, but the loss of equipment containing official material can still trigger a formal data-breach assessment.
- 38 breaches were recorded across the period covered by the FOI records.
- Four incidents required mandatory reporting to the DPC.
- Most breaches were assessed as low risk.
- The records covered 2025 and the first six months of 2026.
Other breaches recorded by the Garda watchdog
The database included several examples of administrative errors involving emails and correspondence. In one case, a letter intended for a complainant was accidentally sent to the Garda Commissioner. The document formed part of a batch of update letters, but the complainant’s letter was forwarded to the wrong recipient during the process.
Another incident involved an email meant for Fiosrú’s own data protection unit being sent instead to Dublin Bus’s data protection office. The organisation said only staff members’ email addresses were disclosed in that case. Dublin Bus confirmed that the messages were deleted twice and had not been shared with third parties.
Other entries referred to:
- Emails and attachments sent to incorrect recipients
- Correspondence involving complainants and garda members
- A mobile phone left in a shop
- An online complaint submission issued to an unintended recipient
Fiosrú said prompt steps were taken to mitigate the incidents. The watchdog also stated that most cases involved email correspondence and were assessed as low level.
Why the Fiosrú data breaches matter
Fiosrú handles information that can include personal details, complaints about Garda conduct and material connected with investigations. Even when no unauthorised access is confirmed, sending information to the wrong person can affect privacy, confidence in the complaints process and the rights of those involved.
Data protection rules require organisations to assess breaches based on factors such as the nature of the information, the people affected and the likelihood of harm. Higher-risk incidents may need to be reported to the DPC within the required timeframe, while affected individuals may also need to be informed.
The figures therefore should not be interpreted as meaning that every logged incident resulted in serious harm. A breach register can include near misses, accidental disclosures and lost equipment that is later recovered. Its value is that it identifies weaknesses that an organisation can address.
For further coverage of policing oversight, public accountability and Irish public services, visit DailyDigest.ie.
Fiosrú introduces extra email safeguards
In response to the pattern of incidents, Fiosrú said it had introduced data-loss prevention software. The system works with Microsoft Outlook and prompts employees to check external recipients and sensitive attachments before an email is sent.
The additional verification step is designed to prevent common mistakes, such as selecting the wrong contact from an address book or attaching the incorrect document. It is intended to complement, rather than replace, staff training and established data protection procedures.
Fiosrú also said its laptop security includes:
- Encrypted hard drives
- Two-factor authentication
- Passcode protection for network access
- Security software installed on all laptops
What happens next?
The released records are likely to keep attention on how Fiosrú manages personal data while carrying out its oversight role. The immediate focus will be whether the new safeguards reduce accidental disclosures and whether staff continue to report incidents promptly.
For members of the public, the central issue is transparency. Clear breach reporting, rapid containment and direct notification where necessary are important parts of maintaining trust in the Garda complaints system.
Frequently asked questions
How many data breaches did Fiosrú record?
Fiosrú recorded 38 incidents during the period covered by the released records, spanning 2025 and the first six months of 2026.
Were all of the breaches reported to the DPC?
No. Four incidents reached the threshold for mandatory reporting. Most were assessed as low risk and did not require notification to the DPC.
Was the laptop left in the Dublin taxi accessed?
Fiosrú said the bag was recovered later that day and that the laptop had not been accessed.
What is Fiosrú?
Fiosrú is the Garda oversight and complaints body that replaced the Garda Síochána Ombudsman Commission. It handles complaints and examines issues relating to policing conduct.
Conclusion
The Fiosrú data breaches show how quickly routine administrative errors can become privacy incidents when an organisation handles sensitive complaints and personal information. Although most of the 38 recorded cases were considered low risk, the high-risk email disclosure and the loss of equipment underline the need for strong controls. Fiosrú’s new email verification system, alongside encryption and authentication measures, will now be judged by whether it prevents similar mistakes and protects public confidence.




