The Data Protection Act, 2019 introduced two separate obligations that businesses frequently conflate: having a compliant data protection practice, and being formally registered with the Office of the Data Protection Commissioner (ODPC) as a data controller or data processor. A business can have excellent privacy practices and still be in breach simply because nobody registered it.
Controller versus processor
A data controller determines the purposes and means of processing personal data — a business collecting customer information to run its own operations is a controller in relation to that data. A data processor processes personal data on behalf of and on the instructions of a controller — a payroll bureau processing employee data on a client’s behalf, or a cloud provider hosting a client’s customer database, is typically a processor in relation to that data. The distinction matters because the Act imposes registration and compliance obligations on both, though the specific obligations differ, and a single business is often a controller for some of its data (its own staff and customers) and a processor for other data it handles on behalf of clients.
Who has to register
Registration is mandatory for data controllers and processors, but the Act and its regulations set out exemption thresholds for smaller entities, assessed by factors that include the number of employees and annual turnover [VERIFY: current registration exemption thresholds — employee count and turnover figures — under the Data Protection (Registration of Data Controllers and Data Processors) Regulations]. Certain categories of processing are treated as requiring registration regardless of the size of the business, because of the nature of the data involved — this typically catches organisations processing health data, financial data, or data relating to children, and businesses whose processing is systematic and carried out on a large scale even if the business itself is small. A small business that assumes it is exempt purely because of its headcount, without checking whether the nature of its processing brings it into a mandatory category, is a common way this gets missed.
What a compliance programme needs beyond a privacy notice
A privacy notice on a website is usually the first thing a business puts in place and often the last thing it updates. It is necessary but not sufficient. A functioning compliance programme also needs: a lawful basis identified for each category of processing, not just consent by default; a data processing agreement in place with any third party that processes personal data on the business’s behalf, addressing what that processor may do with the data and what happens to it at the end of the relationship; a documented approach to data subject rights — access, correction, deletion — including who within the business actually handles a request when one arrives; and a breach response process, since the Act imposes a notification obligation to the Commissioner and, in some circumstances, to affected individuals, within a set timeframe of becoming aware of a breach [VERIFY: current statutory breach notification timeframe].
For higher-risk processing — new systems that process personal data at scale, or processing of sensitive categories of data — a data protection impact assessment is required before the processing begins, not as an afterthought once the system is already live.
Where this usually goes wrong
The most common gap is not malicious non-compliance but sequencing: a business builds a product or a customer database first and asks about data protection registration once it is already operating, by which point the processing has been happening unregistered for however long the business has existed. The second common gap is treating the privacy notice as the whole of compliance, when it is one document among several that a functioning programme needs. The third is assuming a small business is automatically exempt without checking whether the type of data it processes removes that exemption.
Where to start
If your business has not assessed whether it needs to register, or registered some time ago and has not revisited what the registration actually requires operationally, that assessment is the sensible starting point — it is considerably more straightforward to build a compliant programme from the outset than to reconstruct one after a regulator or a client asks to see it.