Legal

Privacy notice

1. About this notice

This Privacy Notice explains how Industry Research and Development Group Company Limited by Guarantee, trading as IRDG, collects and uses personal data when you:

  • visit an IRDG website;
  • contact us or make an enquiry;
  • apply for membership or use a member service;
  • register for or take part in an event, course or programme;
  • participate in a survey, consultation or research activity;
  • contribute to policy or member-network activity; or
  • subscribe to news or other communications.

It also explains your data-protection rights and how to exercise them.

This notice applies to services operated by IRDG. A linked event, booking, learning, survey or other service may be operated by another organisation. Where another organisation determines how and why it uses your personal data, its own privacy notice also applies.

2. Who we are

Industry Research and Development Group Company Limited by Guarantee, trading as IRDG (“IRDG”, “we”, “us” or “our”), is the controller of personal data used for IRDG's own purposes as described in this notice.

Registered number: 193384
Registered office and contact address: Regus Pembroke House, 28–32 Upper Pembroke Street, Dublin 2, Ireland
Telephone: (01) 234 2401
Email: info@irdg.ie

Mary Byrne is IRDG's privacy and data-protection contact. She has not been appointed as a Data Protection Officer. Data-protection enquiries and rights requests should be sent to info@irdg.ie.

IRDG Innovation Skillnet

IRDG Innovation Skillnet is operated by IRDG and supported by Skillnet Ireland. Skillnet Ireland is funded from the National Training Fund through the Department of Further and Higher Education, Research, Innovation and Science.

When you apply for or take part in a Skillnet-supported programme, IRDG and Skillnet Ireland process trainee information for programme administration, funding, monitoring and evaluation. Depending on the particular activity, IRDG may act:

  • as a controller for processing it determines for its own programme administration, communications, member relationship, delivery and records; and
  • as a processor where it collects or handles prescribed trainee information on Skillnet Ireland's documented instructions, including information uploaded to Skillnet Ireland's Sonraí system.

IRDG's current understanding is that it and Skillnet Ireland do not act as joint controllers under the present arrangement. Skillnet Ireland's own purposes, systems, retention and rights arrangements are described in the Skillnet Ireland Trainee Privacy Statement.

3. Personal data we obtain

“Personal data” means information relating to an identified or identifiable living person.

Information you give us

Depending on how you interact with IRDG, this may include:

  • your name, job title, work contact details and communication preferences;
  • your employer or organisation, its sector and other organisational information;
  • membership enquiries, applications, authorised-contact details and service history;
  • the content of enquiries, support requests and correspondence;
  • event and programme bookings, attendance, eligibility, feedback, certification and limited dietary or allergy information where requested for event catering;
  • information submitted through mentoring, diagnostic, Funding, policy, practice-group or other member services;
  • survey, consultation, policy and research responses;
  • newsletter subscriptions, email-delivery, open and link-click information, and records of consent, withdrawal or objection;
  • invoicing, transaction and payment-administration information; and
  • records relating to complaints, legal matters or requests to exercise data-protection rights.

Where an event or programme is photographed, filmed or recorded, personal data may also include a person's image, voice, display name, contribution or chat message, depending on how they participate.

For Skillnet-supported training, the prescribed trainee information may include your name and contact details, age range, gender, county of residence, education or NQF level, employment status, employer and occupation, attendance, course feedback and certification information. The fields used for a particular programme are shown on the relevant registration forms.

Information already held or supplied indirectly

IRDG ordinarily obtains contact and participation information directly from the individual or uses information already held through an existing member relationship. IRDG does not obtain contacts from employers, colleagues, public professional sources or legacy lists. Where an employer arranges or funds participation, the participant is expected to provide their own personal details directly to IRDG.

Information created through your interaction with us

We may create or record information about:

  • enquiries, referrals, services requested and action taken;
  • membership and member-service participation;
  • bookings, attendance, course completion and certificates;
  • preferences, permissions, consent and objections;
  • communications and follow-up; and
  • survey or consultation administration and analysis.

Some online Skillnet sessions may be recorded using Zoom, and some in-person sessions may be photographed, as explained in section 6.

Website and technical information

When you use an IRDG website or online form, limited technical information may be processed to deliver and protect the service, diagnose faults and prevent misuse. This may include an IP address, browser or device information, requested pages, timestamps, security events and form-delivery logs. Optional analytics or similar technologies are addressed in section 9.

Special-category information

IRDG collects only limited dietary or allergy information where it is needed to provide food safely for a particular attendee at an event. This information is used only for event catering and health-and-safety arrangements and is not used for marketing or another purpose. Access should be limited to authorised IRDG event staff and the venue or caterer that needs the minimum information to provide food safely.

Providing this information is voluntary. Because an allergy or dietary request may reveal health information, IRDG relies on the attendee's explicit consent under Article 9(2)(a) of the GDPR, alongside consent as the Article 6 basis. The information should be deleted when the catering and immediate event-safety purpose has ended and, under the retention rule in section 12, no later than 30 days after the event.

4. Why we use personal data and our lawful bases

We use personal data only where we have a lawful basis. Depending on the activity, this may be consent, performance of a contract or steps requested before a contract, compliance with a legal obligation, or our legitimate interests or those of another person.

Our legitimate interests may include operating and protecting our services, administering corporate membership, responding to professional enquiries, delivering requested member support, organising participation, understanding members' needs, representing members' collective interests, improving our services and establishing or defending legal rights. We assess whether the processing is necessary and whether those interests are outweighed by the person's rights and interests.

Processing activities and their lawful bases
ActivityWhat we use and whyLawful basis
Website delivery, security and fault diagnosisLimited technical and security information used to deliver, protect, monitor and troubleshoot the websiteLegitimate interests; consent where required for optional technologies
General enquiries and complaintsContact details and message content used to answer, route and retain an appropriate recordLegitimate interests; requested pre-contract steps where Article 6(1)(b) applies
Membership enquiries and applicationsProfessional, organisational and application information used to assess eligibility, discuss membership and administer joiningRequested pre-contract steps where applicable; legitimate interests where the prospective contract is with an organisation rather than the individual
Membership administration and member servicesAuthorised member contacts, participation and service records used to administer corporate membership and provide requested supportLegitimate interests; contract where applicable; legal obligation for required records
Mentoring, diagnostic, Funding and specialist supportContact, organisational and enquiry information used to route and provide the requested serviceLegitimate interests and/or contract, depending on the service; an approved Article 9 condition where special-category information is necessary
Non-Skillnet events and programmesBooking, attendance, payment administration, communications, certification and feedback used to organise and deliver the activityContract where the individual is a party; legitimate interests for employer or member bookings; legal obligation where applicable
Dietary and allergy arrangementsLimited information supplied voluntarily to provide food safely for an attendeeConsent, and explicit consent under Article 9(2)(a) where the information concerns health
Event photography, filming and recordingsImages, voice and contributions used to provide participant access, document an event or support IRDG communicationsConsent gathered at the event and, where appropriate, legitimate interests in documenting and communicating IRDG activity
Skillnet-supported programmesRegistration, delivery, eligibility, attendance, certification, funding administration, compliance, evaluation and quality assurancePurpose-specific bases described in section 6
Practice groups, consultations and policy workContact and contribution information used to administer participation, analyse issues and represent members' collective interestsLegitimate interests; express permission where a person or contribution will be quoted or publicly attributed
Surveys, research and Innovation Index activitiesContact details, responses and preferences used to administer participation, analyse results and provide separately requested research updatesLegitimate interests and/or consent, as explained at collection; research participation, research updates and marketing are separate choices
Newsletters and optional promotional communicationsContact details, preferences, consent and engagement information used to send and administer requested communicationsConsent for optional newsletters and promotional electronic communications
Accounts, audit and legal complianceMembership, transaction, invoice and related records used for accounting, audit, legal obligations and claimsLegal obligation, contract and legitimate interests
Data-protection requests and incidentsIdentity, correspondence and relevant records used to verify, investigate and respondLegal obligation and legitimate interests

Article 6(1)(b) is used only where processing is objectively necessary for a contract with you or to take steps you requested before such a contract. Where a membership or booking contract is with your employer rather than with you personally, IRDG will normally rely on its legitimate interests in administering that relationship.

5. Enquiries, membership, member support and website forms

When you contact us, we use the information you provide to respond, provide a requested service and keep an appropriate record. Access is limited to authorised IRDG staff, or an authorised service provider, who need the information for that purpose.

An enquiry does not by itself add you to a general marketing list. IRDG asks separately for consent to optional electronic marketing.

Forms and Zoho services

IRDG uses Zoho services, including CRM, Campaigns, Forms, Bookings and Backstage, depending on the activity. Information submitted through an IRDG form is intended for the relevant Zoho service or IRDG service queue and is accessible only to authorised staff who need it for the relevant purpose. A submission does not go to every Zoho product.

For Skillnet bookings, IRDG's separate booking and administrative record is held in Zoho. Where a participant works for an IRDG member, some contact, company and membership information may already be present in Zoho before the course is booked. IRDG associates only the information needed for the booking, delivery and applicable records with that participation.

If automated form delivery fails, a submission may be routed to IRDG's controlled info@irdg.ie mailbox. Access is restricted to authorised staff. Once the matter has been routed or resolved, fallback copies are reviewed and deleted from the active mailbox monthly. A record retained in the relevant service system follows that system's retention rule.

Members Question Time

Members Question Time submissions are handled through email rather than stored in IRDG's CRM. The original email is submitted by the individual in the member company who asks the question. Access to the identified email is limited to authorised IRDG staff who need it for administration or follow-up. The questioner's identity or contact details are shared beyond that restricted team only where the questioner has expressly agreed; otherwise an authorised team member removes identifying information before the question is circulated within the Question Time process.

Member, Influence and consultation contributions

Access to member-support information is limited to authorised IRDG staff who need it to deliver the service requested. IRDG will quote or publicly attribute an identifiable Influence or consultation contribution only where the contributor has given express permission.

To represent members' interests, IRDG may share the substance of non-public Influence or consultation submissions with the Department of Finance, the Department of Enterprise, Tourism and Employment, the Department of Further and Higher Education, Research, Innovation and Science, Enterprise Ireland and IDA Ireland. Identifying or attributed details are shared only with the contributor's express permission. The relevant collection point should explain these recipients and choices.

6. Events, programmes and IRDG Innovation Skillnet

General events and programmes

We use booking and participant information to organise and deliver events or programmes, provide necessary joining information, record attendance, arrange certification where applicable, obtain feedback and administer payment or funding where relevant.

A booking or learning platform, venue, co-host, programme provider or awarding body may receive the information necessary for its role. Some act only on IRDG's instructions; others may be separate controllers for their own activities. Important independent controllers and their notices will be identified at or before registration.

IRDG does not circulate attendee or delegate lists to other attendees, venues, hosts, sponsors or partners. It may disclose only the limited information needed to deliver the event — for example, a dietary or allergy requirement to a venue or caterer. IRDG will explain that use at collection.

IRDG events may be photographed, filmed or recorded. Attendees are given notice before or at the event and may opt out of identifiable photography. A person who does not want to appear visually in an online recording may keep their camera off and will not be deliberately included on screen. Online-event recordings are deleted after 12 months.

Skillnet-supported training

For a programme funded or part-funded by Skillnet Ireland, relevant information is used to:

  • administer the application and booking;
  • assess or record funding eligibility;
  • register the trainee and deliver the programme;
  • record and verify attendance;
  • issue applicable attendance records, CPD certificates or course records;
  • obtain feedback;
  • manage and demonstrate the appropriate use of programme funding; and
  • conduct authorised compliance reviews, programme evaluation and quality assurance.

IRDG collects the trainee, employer, eligibility, attendance, feedback and certification information required by the applicable Skillnet arrangements. Prescribed data is uploaded to Skillnet Ireland's Sonraí system. IRDG also retains a separate booking and administrative record in Zoho; where a trainee is associated with an IRDG member, relevant contact and company information may already be held there.

Relevant information may be shared with Skillnet Ireland and with course-delivery, evaluation, quality-assurance or attendance-verification providers. Those contracted by IRDG receive only the minimum information required for their task and are intended to process it for that purpose under contract. An awarding or certification body may instead be an independent controller and will be identified where applicable.

Where a trainee's employer has arranged, funded or needs to verify participation, IRDG may provide the employer with an attendance record and the applicable CPD certificate. IRDG does not disclose assessment feedback or other course information to an employer unless this has been specifically explained and has an appropriate basis.

Skillnet Ireland is part-funding relevant programmes from the National Training Fund through the Department of Further and Higher Education, Research, Innovation and Science. IRDG uploads the prescribed information to Skillnet Ireland. Skillnet Ireland determines its onward use and disclosures, including reporting to the Department, as explained in the Skillnet Ireland Trainee Privacy Statement. IRDG does not state that the Department receives aggregate information only unless Skillnet Ireland confirms that position.

You may be contacted by IRDG, Skillnet Ireland or an authorised evaluator by email or telephone for administration, compliance, evaluation or quality-assurance purposes connected with the programme.

Providing information marked as required may be necessary to register you, deliver the programme, verify attendance or apply the funded rate. If it is not provided, IRDG may be unable to register you, deliver the programme or apply that rate.

Lawful basis and the mandatory Skillnet form

IRDG uses the current registration form wording prescribed for Skillnet-supported training and records the acknowledgement or consent required by that form. The presence of a consent statement on a mandatory form does not by itself settle the lawful basis for every purpose.

The lawful basis must be allocated separately for IRDG's own booking and delivery, funding eligibility, the prescribed Sonraí upload, attendance verification, evaluation, employer reporting and future marketing. Processing that is necessary to receive or administer funded training is not treated as optional merely because a form has been submitted. Consent is kept separate for genuinely optional purposes, including future marketing, identifiable publicity photography and a recording where participation in the recording is optional.

Online recordings and in-person photography

Some online Skillnet sessions are recorded using Zoom for access by registered participants. Attendees are informed before recording starts and consent is captured through Zoom. Recordings are not intended for public access and are deleted after 12 months. An attendee who does not want to appear visually may keep their camera off and will not be deliberately included on screen.

Some in-person Skillnet sessions may be photographed. Attendees are informed and may opt out of identifiable photography. Where consent is used for a particular image or publicity use, IRDG records that consent.

7. Research, surveys, the Innovation Index and policy activity

Where IRDG conducts research, a survey or a consultation, the collection point should explain the purpose, whether responses are identifiable or anonymous, intended recipients, publication approach and any project-specific retention rule.

For Innovation Index activities, participation in the research, receipt of research-related updates and receipt of general IRDG marketing are presented as separate choices. Refusing marketing does not prevent research participation.

Innovation Index survey responses are intended not to identify the respondent. A respondent may separately provide an email address solely to receive the report and an invitation to the related webinar. That address is not used for general marketing unless the person makes a separate marketing choice.

We aim to publish research and policy findings in aggregated or de-identified form. We quote or attribute an identifiable response only with express permission, unless disclosure is otherwise required by law and has been transparently explained.

8. Newsletters and direct marketing

IRDG uses a tested double-opt-in process for newsletter subscriptions. After a person requests a subscription, the subscription is activated only after the person completes the confirmation step.

Zoho records the wording and version of the consent, its source, date and time, and any later withdrawal. IRDG uses a single suppression rule across Zoho products, exports and manual lists so that an opt-out continues to be respected.

Where you subscribe, we use your contact details and preferences to send and administer the requested communication. IRDG does not rely on an existing-customer, member or role-relevant business-email exception for optional electronic marketing; it uses consent.

Where consent is the basis, you may withdraw it at any time using the unsubscribe link in the message or by contacting us. Withdrawal does not affect processing that occurred before withdrawal.

Every electronic marketing message sent on IRDG's behalf includes a clear opt-out. IRDG retains the minimum suppression information needed to prevent further marketing to an address that has opted out.

Zoho Campaigns records whether a marketing email is delivered or opened and whether links in it are clicked. This tracking is explained in the email and is used to understand delivery and engagement and improve future communications.

Most routine membership and service messages are necessary communications — for example, membership administration, renewal administration, confirmations and changes relating to a booking, information needed to take part in a requested course or event, and responses to a support request. Optional newsletters, general promotion of future events or programmes and other promotional messages are treated separately and require the relevant marketing permission.

IRDG does not promote a partner's services as partner marketing and does not provide contact details to a partner for that partner's own marketing. This does not prevent IRDG from giving information about a programme or event that IRDG is itself delivering or co-delivering, where that communication is covered by the person's service request or marketing choice.

IRDG does not conduct telephone marketing.

9. Cookies and similar technologies

We use essential cookies or similar technologies where they are necessary for the website, security or a service you request to work.

No optional analytics, preference or marketing technologies currently operate on this site. If any are introduced, we will ask for consent before they operate, provide a cookie-settings control on every page, and make withdrawing consent as easy as giving it.

A Cookie Notice identifying each technology's provider, purpose, category and duration will be published alongside any such introduction.

10. Who receives personal data

We disclose personal data only where it is necessary for a stated purpose, permitted by law or required by a legal obligation. Depending on the service, recipients may include:

  • authorised IRDG staff and contractors;
  • website hosting, content-delivery, security and technical-support providers;
  • Zoho services used for forms, CRM, bookings, events and communications;
  • event, booking and learning platforms;
  • Stripe for card-payment processing and IRDG's bank for payments made by electronic funds transfer;
  • venues or caterers receiving the minimum dietary or allergy information needed to provide food safely;
  • programme, course, awarding and certification providers;
  • Skillnet Ireland and authorised funding, compliance, evaluation and attendance-verification providers;
  • an employer, where attendance or a CPD certificate is provided for employer-arranged or funded training;
  • event or programme partners where their involvement is necessary and has been explained;
  • research or survey providers;
  • the Department of Finance, the Department of Enterprise, Tourism and Employment, the Department of Further and Higher Education, Research, Innovation and Science, Enterprise Ireland and IDA Ireland for the policy and representation purposes explained in section 5;
  • accountants, auditors, insurers, legal advisers and other professional advisers; and
  • regulators, law-enforcement bodies, courts or public authorities where disclosure is required or permitted by law.

Some recipients process data only on IRDG's documented instructions and under an appropriate contract. Others determine their own purposes and act as independent controllers. Where another organisation is a controller, it is responsible for its own processing and its privacy notice also applies.

Card payments are processed through Stripe. IRDG receives the transaction and administrative information needed to reconcile the payment but cannot access the customer's full card details. Stripe may act as a processor for payment instructions and as a controller for some regulated, security and fraud-prevention activities; the Stripe Privacy Center provides further information and its notice should also be linked at checkout. Where a person pays by electronic funds transfer, the payment is made directly to IRDG's bank account and IRDG receives the ordinary bank-statement and remittance information needed to identify and reconcile it.

IRDG does not circulate general attendee or delegate lists, disclose contacts for a partner's own marketing or share an identifiable policy contribution without the contributor's express permission.

11. International transfers

Some providers may process personal data outside the European Economic Area. Where this occurs, IRDG will use a legally recognised transfer mechanism, such as:

  • a European Commission adequacy decision;
  • for an eligible and currently certified US organisation, the EU–US Data Privacy Framework; or
  • approved Standard Contractual Clauses together with any additional safeguards required following an assessment of the transfer.

You may contact us for information about the safeguards relevant to your personal data and, where applicable, how to obtain a copy.

12. How long we keep personal data

We retain personal data only for as long as necessary for the relevant purpose, including any period required for legal, accounting, funding, audit, complaint or claims purposes. We then delete or irreversibly anonymise it, subject to proportionate backup-retention arrangements.

This schedule is in force. It is reconciled with contracts, statutory obligations and system deletion controls through the supplier and data-flow register, which Mary Byrne maintains alongside this notice.

Retention schedule
Record categoryMaximum retention or rule
General enquiries and unsuccessful membership enquiries24 months after the matter is closed, unless a shorter period is appropriate or a live dispute requires a hold
Core membership, contract and account recordsFor the membership relationship and 6 years after it ends; ordinary contact details not needed for that record should be removed sooner
Member-support, mentoring, diagnostic and Funding cases3 years after the case closes; information of greater sensitivity should be removed within 12 months unless continued retention is necessary and documented
Non-Skillnet event and programme records24 months after completion; certificate, finance or contract records may follow the applicable longer rule
Skillnet information in SonraíSkillnet Ireland's publicly available Trainee Privacy Statement, last revised April 2024, says prescribed trainee and reaction data is retained for 3 years from the end of the calendar year after course completion and is anonymised after 2 years; that statement is the operative rule for the Skillnet record
IRDG's separate Skillnet administrative copyNo longer than 2 years after course completion, then delete or irreversibly anonymise; retain only the minimum non-identifying funding or audit record for any longer period required by the Network Agreement
Online event and programme recordings, including Zoom recordings12 months after the event or programme, then delete from active storage, subject to any documented backup cycle
Dietary or allergy informationDelete as soon as the catering and immediate event-safety purpose has ended and no later than 30 days after the event
Event photographs and permission recordsKeep selected images only for the stated communications or archive purpose; review continued use at least every 3 years; retain the permission record while the image remains in use
Newsletter subscription and consent evidenceWhile subscribed and for up to 3 years after withdrawal or last use where needed to evidence the permission; retain a minimal suppression record for as long as necessary to honour the opt-out
Research, survey and consultation response-level data24 months after the project closes, then delete or irreversibly anonymise; aggregated or anonymised outputs may be retained. Delete an Innovation Index email supplied only for the report and webinar within 3 months after the last promised report or webinar communication, unless the person separately subscribes to marketing
Finance, invoice and tax records6 years after the end of the relevant accounting period, subject to finance and legal confirmation
Security and technical logsUp to 12 months, unless needed for an active security incident, investigation or legal hold
Failed-form fallback emailsReview monthly and delete from the active mailbox after successful routing or resolution; the destination record follows its category rule
Rights requests, complaints and incidents3 years after closure, unless a longer period is needed for a legal claim or regulatory matter
BackupsA maximum of 90 days after deletion from the live system, unless an isolated legal or security hold applies

We may retain a relevant record for longer where necessary for a legal claim, investigation or binding legal requirement. A litigation or regulatory hold will be limited to relevant information and reviewed when the hold ends.

13. Security

We use appropriate technical and organisational measures designed to protect personal data against accidental or unlawful loss, alteration, access, disclosure or destruction. Measures include restricting access according to role, securing transmission and systems, managing suppliers, maintaining backups and responding to security incidents.

No method of transmission or storage is completely secure. We review our measures in light of the nature of the data, the risks, available technology and the cost of implementation.

14. Your rights

Depending on the circumstances and subject to legal conditions and exceptions, you may have the right to:

  • receive information about how your personal data is used;
  • access your personal data and receive a copy;
  • correct inaccurate or incomplete data;
  • ask us to erase personal data;
  • ask us to restrict its use;
  • receive certain data in a structured, commonly used and machine-readable format;
  • object to processing based on legitimate interests; and
  • withdraw consent at any time where processing is based on consent.

You may object to direct marketing at any time. If you do, we will stop using your personal data for that purpose.

The right to erasure is not absolute. We may retain data where processing remains necessary to comply with a legal obligation, establish, exercise or defend legal claims, or where another exception under data-protection law applies.

To exercise a right, contact info@irdg.ie, telephone (01) 234 2401 or write to the address in section 2. We may ask for information reasonably necessary to confirm your identity. We do not normally charge a fee, although the GDPR permits a reasonable fee or refusal where a request is manifestly unfounded or excessive.

We normally respond without undue delay and within one month. If a request is complex or there are multiple requests, we may extend that period by up to two further months. If so, we will explain the extension within the first month.

Where a request concerns Skillnet Ireland or information held in Sonraí, IRDG will identify and coordinate with the relevant controller as appropriate. You may also contact Skillnet Ireland using the details in its Trainee Privacy Statement.

15. Children and automated decision-making

IRDG's services are intended for adults acting in a professional or business capacity. They are not directed at children, and IRDG does not knowingly solicit personal data directly from children. IRDG does not currently provide training or other services designed for students, apprentices or work-experience participants under 18, and it does not target under-18 event attendees or survey participants.

An attendee under 18 may exceptionally participate in an IRDG event or activity that is not directed at children. If IRDG becomes aware that it is processing personal data relating to an under-18 participant, it will limit the information used to what is necessary, provide appropriate privacy information and apply any additional safeguards or parent or guardian involvement required in the circumstances.

IRDG does not currently use solely automated decision-making, including profiling, that produces legal effects or similarly significantly affects individuals. Digital tools may support administration, analysis, segmentation or decision-making, but material decisions are subject to meaningful human involvement.

16. Complaints

You may lodge a complaint with the Data Protection Commission if you believe our use of personal data infringes data-protection law. We would welcome the opportunity to address your concern first, but this does not affect your right to complain.

Data Protection Commission
6 Pembroke Row
Dublin 2
D02 X963
Ireland
Contact the Data Protection Commission

17. Changes to this notice

We may update this notice when our services or processing activities change. We will publish the revised notice and update its effective date. Where a change materially affects how we use personal data, we will provide additional notice where appropriate.

Mary Byrne owns the annual internal review of this notice and the supporting supplier, retention and collection-point records.

Effective date: This notice takes effect on its publication at irdg.ie, replacing the notice previously in force.