GDPR and Childcare: What Records Are You Required to Keep, and for How Long?

Every early years service in Ireland collects personal data before a child even walks through the door: names, addresses, medical details, emergency contacts, and sometimes PPS numbers for funding schemes. GDPR childcare Ireland compliance is not optional paperwork, it is a legal responsibility that sits alongside Tusla registration requirements. Combined with the specific record keeping rules set out in the Child Care Act 1991 (Early Years Services) Regulations 2016, providers need to know exactly what data they can hold, how long to keep it, and how to protect it. This article explains what GDPR means in practice for a creche or preschool, sets out how long to keep child records Ireland regulations require, and gives practical steps for building a compliant childcare privacy policy.

What Is GDPR and Why Does It Apply to Childcare Settings?

GDPR, the General Data Protection Regulation (EU) 2016/679, is EU-wide law governing how personal data is collected, used, stored, and protected. In Ireland it is implemented alongside the Data Protection Act 2018 and overseen by the Data Protection Commission.

Any organisation that holds personal information about identifiable individuals must comply, and that includes every creche, preschool, and school-age childcare provider. Childcare settings are considered particularly sensitive because they routinely handle children's data, and medical or health information is treated as a special category of data requiring an extra level of care.

What Counts as Personal Data in an Early Years Setting?

  • Child's name, date of birth, address, and photograph
  • Medical information, allergies, and immunisation details
  • Developmental records and observation or learning story notes
  • Daily attendance and collection records
  • Parent or guardian contact details
  • Staff personal, employment, and vetting records
  • CCTV footage, where a setting uses it
  • Payment and billing information

How Long to Keep Child Records in Ireland

Retention periods for early years settings are not simply a matter of preference. The Child Care Act 1991 (Early Years Services) Regulations 2016 sets specific minimum periods, which should form the backbone of your service's retention schedule:

  • Child registration records, including allergy and immunisation details: at least 2 years from the date the child leaves the service
  • Daily attendance records: 2 years from the date the child leaves
  • Medication records: 2 years
  • Accident and incident records: 2 years
  • The visitor sign-in and sign-out register: 1 year from the date it began
  • Staff references and Garda vetting documentation: 5 years from the date the staff member commences work

GDPR's own storage limitation principle means data protection early years practice should not stop at these minimum figures. Providers should document a clear retention schedule and avoid keeping personal data for longer than necessary once these periods have passed.

The Core GDPR Principles Every Creche Should Follow

  • Lawfulness, fairness and transparency: parents should know what data is collected and why.
  • Purpose limitation: data collected for one reason, such as enrolment, should not be reused for an unrelated purpose without a proper basis.
  • Data minimisation: only collect what is genuinely needed.
  • Accuracy: keep records up to date, particularly emergency contact and medical details.
  • Storage limitation: do not keep personal data longer than necessary.
  • Integrity and confidentiality: protect data with appropriate security, whether paper or digital.
  • Accountability: be able to demonstrate compliance, not just claim it.

Building a GDPR-Compliant Childcare Privacy Policy

A childcare privacy policy GDPR document should be written in plain language and cover:

  • What personal data is collected and why
  • The legal basis for processing each type of data
  • Who the data may be shared with, such as Tusla or funding bodies for schemes like the National Childcare Scheme
  • How long each type of record is retained
  • Parents' rights, including access, correction, and how to raise a complaint
  • The security measures in place to protect records
  • Contact details for data protection queries

This policy typically works alongside your enrolment paperwork. Early Years Shop's admissions and enrolment policy template is a useful starting point for settings building or updating this documentation.

Photos, Social Media and Children's Personal Data

Photographs of children require their own, separate consent from parents, distinct from general enrolment consent. This consent should be specific about how images will be used, whether for internal displays, newsletters, or public social media, and it should be easy for a parent to withdraw at any time. Where a setting uses CCTV or any biometric technology, such as fingerprint access systems, a documented data protection impact assessment is strongly recommended given the higher risk involved.

Common GDPR Mistakes in Childcare Settings

  • Having no written privacy policy, or one that has not been reviewed in years
  • Keeping records indefinitely rather than to a documented retention schedule
  • Using children's photographs without clear, specific consent
  • Storing paper files in unlocked cabinets or shared, unsecured digital folders
  • Having no clear process for handling a parent's request to see their child's records
  • Mixing staff personal data into general files that all team members can access

Practical Steps to Get GDPR Right in Your Setting

  1. Map what personal data you hold, where it is stored, and who can access it.
  2. Write or update your privacy policy and consent forms in plain language.
  3. Set a documented retention schedule that matches or exceeds Tusla's minimum requirements.
  4. Secure both physical storage, such as locked cabinets, and digital storage, such as password protection.
  5. Train staff on confidentiality and safe data handling as part of induction.
  6. Put a clear process in place for responding to a parent's access request.
  7. Review your policy and practice at least once a year, or whenever something changes.

Conclusion

GDPR compliance in childcare is not just about avoiding a fine. It is about respecting the trust families place in your service when they hand over sensitive information about their child. Aligning your data protection practice with both GDPR principles and the specific retention periods set out in the Child Care Act 1991 (Early Years Services) Regulations 2016 protects children, protects your organisation, and helps your service stand up well at inspection. Early Years Shop's records, policies and toolkits and quality and compliance ranges include templates that can help you build this documentation with confidence, and our Tusla inspection checklist covers what inspectors expect to see across your record keeping more broadly.

Frequently Asked Questions

Does GDPR apply to small preschools and childminders?

Yes. GDPR applies to any organisation that processes personal data, regardless of its size. A small sessional preschool has the same core obligations as a large full day care service.

How long must a creche keep child records in Ireland?

Under the Child Care Act 1991 (Early Years Services) Regulations 2016, most child records, including attendance, medication, and accident records, must be retained for at least 2 years after the child leaves the service. Always check the specific requirement for the record type in question.

Can parents request to see their child's records?

Yes, this is a right of access under GDPR. Settings should have a simple, documented process for handling these requests promptly.

Do childcare settings need a Data Protection Officer?

Most small and medium early years settings are not automatically required to appoint a formal Data Protection Officer, unless they carry out large-scale processing of special category data. Every setting should still have a clearly named person responsible for data protection.

What happens if a data breach occurs in a creche?

The setting must assess the breach and, where it poses a risk to individuals, notify the Data Protection Commission within 72 hours. An internal record of the breach should be kept regardless of whether notification is required.