1. Policy Statement Glór na nÓg Childcare is fully committed to safeguarding the privacy and fundamental data rights of all children, parents, legal guardians, staff members, and volunteers. We acknowledge the high level of trust families place in our service when sharing sensitive personal information. This document outlines our institutional protocols for collecting, processing, securing, disclosing, and archiving data in alignment with Irish and European data protection laws alongside Tusla regulatory benchmarks. 


2. Scope

This operational policy governs all data processing activities undertaken by Glór na nÓg Childcare, encompassing: 

  • Executive management, administrative personnel, and data controllers.
  • Early years educators, support practitioners, relief staff, and student placement participants.
  • All physical documentation, central filing arrays, digital infrastructure, and third-party childcare management applications.

 3. Core Data Protection Principles

In strict adherence to Article 5 of the GDPR, all personal data handled by Glór na nÓg is processed according to these principles: 

  1. Lawfulness, Fairness, and Transparency: Processing occurs transparently under a valid legal basis.
  2. Purpose Limitation: Information is gathered exclusively for specified, explicit, and legitimate early childhood care and education and full day care operations.
  3. Data Minimization: Collection is restricted to data strictly necessary for child welfare, safety, and regulatory compliance.
  4. Accuracy: Regular reviews ensure records remain current and accurate.
  5. Storage Limitation: Data retention is bound strictly to statutory operational timelines.
  6. Integrity and Confidentiality: Technical and organizational security measures protect data against unauthorized or unlawful processing, accidental loss, destruction, or damage.

 4. Categories of Data Collected 

To execute our educational duties and administer state-backed subvention models (e.g., National Childcare Scheme [NCS], ECCE), we gather: 

  • Child Records: Legal name, date of birth, residential address, Personal Public Service (PPS) number, emergency medical details, immunization milestones, allergy logs, developmental tracking journals, and daily attendance/incident logs.
  • Parent/Guardian Records: Contact details, designated authorized collectors, emergency communication pathways, and financial or billing histories.
  • Personnel Records: Curriculum vitae, verified references, National Vetting Bureau (Garda Vetting) disclosures, professional certifications, contracts, and payroll files.

 5. Consent Framework 

  • Media & Promotional Usage: Specific, granular, and opt-in consent is sought upon initial enrolment regarding photography. Visual media of children will never be published on public channels or promotional brochures without explicit secondary authorization.
  • Right of Withdrawal: Parents retain the unconditional right to revoke media consent at any point by submitting a formal written notice to the Service Manager.

 6. Information Security and Storage Architecture 

  • Physical Security: Paper-based records are filed within secure, lockable cabinetry housed in restricted administrative zones. Access is restricted to authorized personnel on a strict need-to-know basis.
  • Digital Security: Software applications, cloud platforms, and local terminals are secured via multi-factor authentication, enterprise-grade encryption, and role-based access permissions. Unattended workstations are auto locked.
  • Operational Displays: Sensitive medical or dietary notices are displayed discreetly preventing general public visibility while remaining instantly accessible to designated room educators for emergency management.

 7. Data Subject Rights 

  • Subject Access Requests (SAR): Parents/guardians may request complete copies of personal records concerning themselves or their minor child under GDPR provisions. Applications must be directed to management and will be processed within one calendar month at zero cost.
  • Third-Party Record Limits: Parents are authorized to view information explicitly concerning their own child. Staff are bound by strict non-disclosure rules prohibiting cross-family data sharing during daily parent handovers.
  • Data Correction: Requests to rectify or amend inaccurate data files are executed immediately upon verification.

 8. Disclosure and Information Sharing Protocols Data remains confidential unless disclosure is mandated or permitted via narrow legal exemptions: 

  1. Safeguarding Mandates (Tusla & An Garda Síochána): Under the Children First Act 2015, all staff act as mandated persons. Bona fide child protection or welfare concerns bypass standard confidentiality boundaries and are reported directly to Tusla. Child welfare supersedes all data privacy restrictions.
  2. Statutory Audits and Inspections: Files are presented upon request to authorized inspectors from Tusla, Pobal, or the Department of Education during regulatory reviews.

 9. Statutory Data Retention Schedule Data lifecycle management balances GDPR minimization tenets against Irish statutory obligations: 

Record ClassificationMandatory Retention PeriodGoverning Authority / Legislation
Enrollment, Attendance, Accident & Medical Logs2 Years post-departure of the childChild Care Act 1991 (Early Years Services) Regs 2016
Safeguarding & Child Protection FilesRetained indefinitely / per Tusla directivesChildren First National Guidelines
Financial, ECCE, and NCS Subsidy Records7 YearsRevenue Commissioners & DCEDIY Compliance
Staff Employment and Vetting Files7 Years post-cessation of employmentIrish Employment Legislation & Revenue Rules

 10. Breaches and Staff Code of Conduct

  • Induction Commitments: Personnel, volunteers, and students execute signed confidentiality covenants prior to active classroom engagement.
  • Misconduct Sanctions: Unauthorized data exposure, loose talk concerning families, or transmission of service information via unapproved personal messaging tools constitutes gross misconduct, triggering disciplinary measures up to dismissal.
  • Breach Notification: Confirmed data incidents are logged immediately. High-risk security breaches are escalated to the Data Protection Commission (DPC) within a 72-hour window.

 11. Whistleblowing and Protected Disclosures Glór na nÓg Childcare is committed to the highest standards of integrity, openness, and accountability. We provide secure pathways for both personnel and service users to report genuine concerns regarding wrongdoing or safety failures without fear of retaliation, victimization, or adverse consequences. 

11.1 Scope of Wrongdoing A protected report or disclosure refers to raising a reasonable belief that a relevant wrongdoing or risk has occurred, is occurring, or is likely to occur within the service. This includes: 

  • Child Safeguarding Failures: Failures to comply with legal child protection mandates or systemic breaches of Tusla regulations.
  • Non-Compliance: Breaches of financial regulations, health and safety standards, or data protection laws.
  • Concealment: Intentional destruction or concealment of information relating to any of the above.

 11.2 Confidentiality and Information Sharing

  • All disclosures will be treated with the strictest confidentiality. The identity of the whistleblower and the details of the report will only be shared on a strict need-to-know basis with Tusla, relevant law enforcement, or other statutory regulatory bodies to facilitate a proper investigation or fulfil legal obligations.

 11.3 Protections for Staff and Workers In accordance with the Protected Disclosures Act 2014 (as amended): 

  • Scope: Applies to executive management, early years practitioners, relief staff, volunteers, and students on placement.
  • Protection from Penalization: Glór na nÓg strictly prohibits any form of penalization, discrimination, or adverse treatment against any worker who makes a disclosure in good faith. Any reprisal by colleagues or management will trigger immediate disciplinary action up to dismissal.
  • Identity Safeguards: The identity of the worker will be protected as far as legally practicable, except where disclosure is mandated by law (e.g., during criminal investigations).

 11.4 Protections for Parents and Guardians Glór na nÓg extends full whistleblowing protection to parents, legal guardians, and family members who flag serious regulatory breaches or child welfare issues: 

  • Protection Against Service Withdrawal: The service explicitly guarantees that no child will face discrimination, exclusion, targeting, or termination of their placement as a consequence of their parent or guardian raising a genuine regulatory, safety, or safeguarding concern in good faith.
  • Legal Shield for Child Protection Reports: Under the Protections for Persons Reporting Child Abuse Act 1998, any parent who communicates a child safeguarding concern to Tusla or An Garda Síochána in good faith is legally immune from civil liability.
  • Anonymity and Data Privacy: All parent-initiated complaints or risk escalations are treated with the highest degree of confidentiality. Record-keeping regarding complaints will be partitioned away from the child's daily educational files.

 11.5 External Escalation Pathways While internal resolution via the Glór na nÓg Complaints Framework is supported, both parents and staff maintain an absolute legal right to bypass management, and report concerns directly to external statutory bodies: 

  • Tusla Early Years Inspectorate: For operational, regulatory, or staffing ratio violations, reports can be made directly to Tusla Quality Assurance via ey.concerns@tusla.ie.
  • Tusla Social Work Services: For immediate child welfare or abuse concerns, a direct report should be filed with the local duty social work office.
  • The Data Protection Commission (DPC): For systemic, unaddressed data breaches or GDPR violations

Policy Lifecycle Review 

This policy is evaluated annually—or immediately following updates to national legislative standards or Tusla compliance directives. 

Last updated 10th March 2026     




Closed-Circuit Television (CCTV) Policy

Policy Statement 

Glór na nÓg Childcare utilizes a Closed-Circuit Television (CCTV) system. The primary objectives are ensuring the safety and security of children, staff, and visitors, safeguarding property, and assisting in child protection monitoring. This system is operated in strict compliance with the GDPR, the Data Protection Act 2018, and Irish Data Protection Commission guidance.  Purpose and Lawful Basis The processing of personal data via CCTV is based on our legitimate interests (Article 6(1)(f) of GDPR) and our statutory obligations to ensure child welfare under the Child Care Act 1991.

 The system is strictly used for: 

  • Promoting the safety, health, and welfare of children in our care.
  • Protecting the premises and assets of Glór na nÓg against theft, vandalism, or trespass.
  • Supporting child safeguarding investigations and verifying incident/accident logs.
  • Assisting with formal internal investigations regarding serious incidents, safety breaches, or severe misconduct, ensuring an objective, evidence-based review of operational events.
  • Recording audio data strictly within the main reception area to ensure the safety of frontline staff and visitors, deter verbal abuse or aggressive behaviour, and maintain a secure access-controlled entry point. This localized audio capture is necessary and proportionate to fulfil our duty of care and security at the primary public interface of the facility.

 This policy was updated 12th August 2026