The Central Statistics Office (CSO) is Ireland’s national statistical institute. We are responsible for collecting, analysing, and publishing data about our people, society, and economy. As a trusted source of Official Statistics, we play a vital role in supporting informed decision-making across government, business, and society, while also enabling meaningful comparisons with other countries.
Our statistics offer valuable insights into how people live and work in Ireland. They foster understanding, encourage informed public debate, and underpin evidence-based decisions. Access to reliable, independently produced information is fundamental to a healthy democracy and an informed society.
To deliver these insights, we use a range of data collection methods. Each year, thousands of individuals, households, and businesses participate in our surveys. We also draw on secondary data sources including public administrative data and data from publicly available and privately held sources.
Alongside producing Official Statistics, our role is evolving to include coordination of data standards across the civil and public service. By promoting the use of consistent, agreed standards, we ensure that data is defined, measured, and presented in a uniform way. This improves efficiency, reduces costs and enhances the overall quality of Ireland’s national data ecosystem.
As the State’s data steward, we are committed to ethical and responsible creation, collection, management, and use of data. Our goal is to ensure that data serves the public good and benefits the entire community of data users.
High-quality data is also essential for research and policy development. By improving data quality through the National Data Infrastructure and providing access to robust datasets, we support the grounding of Ireland’s policies and decisions in sound evidence.
The primary objective of the CSO in providing access to data is to support researchers and policymakers, ensuring that the data collected is used to its fullest potential. This approach promotes evidence-based decision-making, reduces the cost of research, and helps avoid unnecessary duplication in data collection efforts and lowers response burden.
This policy sets out the principles, procedures, and safeguards that govern access to our data for research purposes. It ensures that all access is compliant with legal, ethical, and security standards.
The policy covers the following key areas:
This policy applies to all external researchers requesting access to data held by the CSO, including academic institutions, public bodies and third-party research partners. It also applies to research work carried out by our staff outside the performance of their duties as Officers of Statistics, e.g. in connection with the pursuit of an academic qualification.
The CSO is committed to enabling responsible data sharing for research that serves the public interest, while protecting the confidentiality, integrity, and availability of our data assets.
All data access must comply with applicable laws and regulations, including the General Data Protection Regulation (GDPR), the Data Protection Act, 2018 (the ‘2018 Act’), and the Statistics Act, 1993 (the ‘Act’).
Only the minimum necessary data will be shared to achieve the research objectives.
Data must only be used for the approved research purpose.
Appropriate technical and organisational measures must be in place to protect data.
All data access decisions and activities must be documented and auditable.
Data access must serve the public good and contribute to societal benefit.
Access must not compromise our core statistical production or financial resources.
All eligible, bona fide researchers must be treated fairly and have equal opportunity to access data.
The CSO is committed to upholding the highest standards of confidentiality and data protection in all research activities. This commitment is grounded in both national and EU law, particularly the GDPR and the Act. Researchers accessing our data must adhere to strict legal and procedural safeguards to ensure the protection of personal data and the confidentiality of statistical information.
Researchers and institutions must comply with all GDPR obligations and relevant national legislation, under the oversight of the Data Protection Commission. We enforce strict safeguards throughout the application and research process to ensure compliance with both data protection laws and the confidentiality provisions of the Act.
All information supplied to the CSO is treated as strictly confidential. In relation to this policy, it is important to note that researchers only have access to de-identified or pseudonymised data.
The Act sets out strict confidentiality standards, ensuring that no details related to an identifiable person or business are divulged to any other person or body (government or private). We only publish aggregate statistical data, meaning that no individual or business can be identified from the published information. As the issue of confidentiality is of paramount importance to our work, a Code of Practice on statistical confidentiality has been published and is strictly enforced.
We collect and manage a wide range of data to support statistical analysis, research, and public policy. This data is processed and made available in different formats. Each format is governed by specific standards to ensure privacy, transparency, and accessibility.
When we receive data from surveys or administrative sources, all identifiable information is either removed or transformed into a pseudonymised format. This results in pseudonymised data that cannot be directly linked to an individual without the use of additional information (such as a key or code). This additional information is stored separately and protected by technical and organisational safeguards to prevent re-identification.
Unlike anonymised data, pseudonymised data is still considered personal data under the GDPR and remains subject to its provisions. Pseudonymisation enables safer data sharing and research while maintaining a degree of privacy protection. Pseudonymised data is used for research, with additional safety measures detailed below.
Anonymised Microdata Files (AMFs) are datasets prepared for statistical or research purposes in such a way that individuals or entities cannot be identified – either directly (e.g. names) or indirectly (e.g. through unique combinations of characteristics). These files typically undergo additional anonymisation techniques such as top-coding (e.g. converting specific ages into age ranges).
The Central Statistics Office (CSO) supports research and evidence-based policy-making by providing access to high-quality AMFs through trusted national and international channels. These arrangements ensure secure, well-documented, and reusable data access in line with governance and public interest requirements.
The following AMFs are currently available through national and international access channels:
Census Anonymised Microdata Files (household 10% sample): A 10% anonymised random household sample representing each county for each of the recent censuses are made available via the Integrated Public Use Microdata Series (IPUMS) website, which includes details on how to apply for access to the data. IPUMS is dedicated to collecting and distributing census microdata from around the world, for social science and health research purposes.
Several other CSO AMFs are available through the Irish Social Science Data Archive (ISSDA), which facilitates access for researchers. ISSDA’s mission is to promote access to quantitative social science data and support international comparative studies of Irish society and the economy. These datasets are accompanied by comprehensive metadata, documentation, and are delivered in preferred formats to ensure they are fully understandable and reusable. We also provide these anonymised datasets under the Data Governance Act (DGA), which supports public sector bodies’ secure sharing of pseudonymised or anonymised data for public interest purposes.
These AMFs are also available on the forementioned Public Service Data Catalogue with details how to request them.
An AMF of cross-sectional SILC data is available via the Luxembourg Income Study Database (LIS). These files have a high degree of statistical disclosure control applied and access is granted via the LIS Data Centre.
Published statistical data refers to the results of analyses conducted by CSO staff following data collection. This data is publicly available and can be accessed directly through our website.
Open (Government) Data includes information collected, produced, or funded by public service bodies (PSBs) and made freely available for reuse. CSO open data, including open data from a number of other public sector bodies and High Value Datasets under the ‘Statistics’ thematic category of the Commission Implementing Regulation (EU) 2023/138, can be found on our PxStat Open Data Platform. This type of data is non-personal and supports transparency, accountability, and evidence-based policy and decision-making.
Additional open data resources can be accessed through platforms such Ireland’s Open Data Portal.
We provide a range of secure services to support access to data for research, policy development and infrastructure planning. These services are governed by legislation, data protection standards, and robust governance protocols. Such requested are received in the CSO via the Researcher On-line System for applications (ROSA).
While not all data can be made available due to legal, ethical, or confidentiality constraints, the policy ensures fairness and transparency. Once a dataset is approved and made available to an individual researcher, it becomes accessible to all eligible researchers under the same conditions. This approach promotes equity of access and supports collaborative research while safeguarding sensitive information.
RMFs are unit record datasets made available, where approved, for statistical research1. While RMFs do not contain direct identifiers, there remains a risk of indirect identification. As such, access to RMFs and the management of related research projects are strictly controlled. RMFs are not statistical products; they are not aggregated or published for general public use. A current list of available RMFs is in our RMF Register.
The CSO can grant researchers access to the General Register Office (GRO) microdata on births, marriages and deaths for research purposes under specific conditions:
A CSO-GRO Memorandum of Understanding provides a specific mechanism for the CSO to produce RMFs to maximise the use of data for researchers (in the context of related Vital Statistics Act of 1952 and 1972 which allows the Minister of Health to grant consent to release data to persons engaged in medical or social research).
The CSO, in collaboration with the Office of the Government Chief Information Officer, operates VDRs to provide PSBs with secure access to high-quality data and analytical tools.
VDRs enable PSBs to apply for access to matched pseudonymised data from civil and public service sources, as well as primary data we have collected. Access is granted exclusively to PSBs working in partnership with us for statistical purposes. Only a sample of the matched data is provided to researchers to ensure risk of identification remains low.
An agreement is signed between the CSO and the requesting PSB outlining access terms and conditions.2 All PSB staff involved in the project are appointed as Officers of Statistics and must adhere to our security protocols. If a PSB wishes to include its own data, that we do not already hold, in a VDR, it may be requested3 or in exceptional cases volunteered.4
The HRDC is a specialised facility dedicated to health-related research. It operates in compliance with the Act, the Health Research Regulations, 2018, the 2018 Act, and the GDPR’s provisions regarding special categories of personal data.5
Due to the sensitive nature of health data, researchers must obtain approval from their local ethics committee and, where applicable, the Health Research Consent Declaration Committee (HRCDC). HRCDC approval is not required if data subjects’ explicit consent has already been obtained.
To ensure appropriate oversight, the CSO has established a Research Data Governance Board (RDGB). This board reviews, screens, and prioritises applications, drawing on expertise in secondary data analysis, our protocols, and best practices in data governance. Once RDGB approval is granted, the standard RMF approval process is followed before access is provided.
As the Competent body, under Data Governance Act, CSO provides anonymisation and pseudonymisation service, further supporting secure and privacy-preserving data sharing. In connection with this service, the PSB remains the controller in respect of its data.
In this role, we act as an intermediary to support PSBs’ own secure sharing of protected data, such as personal or commercially sensitive information.
As mentioned earlier we also provide our own AMFs, as a PSB, under this Act. The Public Service Data Catalogue details available AMFs and how to request them.
The CSO is committed to designing and maintaining researcher access pathways that align with the core principles of this policy: lawfulness, data minimisation, purpose limitation, security, transparency, public interest, protection of core CSO production and financing, and equality of access. There are two differentiating factors between the various services involving secondary data access.
To ensure the sustainability and quality of these services, it is important to acknowledge that more resource-intensive access options—such as those involving matched datasets, pseudonymisation, or bespoke analytical support—require significant investment in technical infrastructure, governance, and staff expertise. VDRs are substantially funded in respect of these costs by the OGCIO for public sector analysts. Financial contributions from research institutions, funding bodies, and public service partners are essential to support the expansion and enhancement of these services while safeguarding the CSO’s core statistical production. From an equity perspective, it is preferable that these contributions are paid on behalf of similar groups of researchers rather than by the individual researchers themselves.
Secondly, independent public interest tests inform our provision of HRDC and VDR access, which are very supportive for the provision of secondary data for research purposes. A broader independent consideration of the public interest for research purposes would help CSO in prioritising requests for secondary data access.
We will continue to monitor demand, assess feasibility, and engage with stakeholders to ensure that access services remain equitable, secure, and responsive to evolving research needs.
Access to CSO data is governed by a structured, multi-stage process to ensure legal compliance, data protection, and responsible use. The process is outlined below in alignment with the high-level overview in Figure 2.6
Researchers must:
To be approved for data access, researchers must successfully complete assigned training modules. This training outlines the legal obligations that apply to all Officers of Statistics. We maintain a detailed register of all individuals appointed under this designation.
Note: Access to CSO research data is restricted to bona fide researchers physically located within the Republic of Ireland. Requests for access from outside the jurisdiction will not be facilitated.
Applicants must submit a detailed proposal including:
Data minimisation principles are embedded throughout the process, meaning:
To reduce disclosure risk, researchers must work with samples rather than full population datasets. The default sample size is 10%, with justified increases subject to approval by the Management Board or Director General. The CSO may rerun models on larger samples or full datasets and share outputs with the research team, but without the underlying data.
For data access requests the proposal (or application) is received in the CSO and reviewed for completeness or returned if further detail required. If review successful, the application is progressed to the approval stages as part of the governance process.
Following initial review, applications will need approval. In the case of:
Single RMF applications, approval needed by:
Multi-RMFs applications (in the case of requests for multiple RMFs as part of the same project application) involving several Statisticians (data custodians), the following additional steps are involved:
VDR project applications will be required to be reviewed and the steps involved are:
Only bona fide researchers who are registered researchers and employed by a registered research organisation (i.e., registered for the purposes of ROSA as part of governance process) are eligible to engage with these services i.e., RMF, VDR and HRDC.
As referenced previously final approval is granted by the Director General. Approved researchers sign a declaration of secrecy and are appointed as Officers of Statistics, as well as signing a Standard Agreement in the case of RMF applications. Additional approvals may be required for specific services or sensitive data:
Officers of Statistics are legally bound to protect the confidentiality of research data. Applicants must demonstrate knowledge of SDC and apply these methods to all outputs intended for dissemination. Discussions of data must be limited to Officers of Statistics working on the same project only. The CSO may apply additional SDC measures before data is released or before outputs are published. Researchers remain responsible for applying SDC, and failure to do so may result in sanctions.
Once approved:
Once analysis is complete:
Responsibility for maintaining confidentiality in all research outputs—such as reports, publications, presentations, and articles—rests with the individual researcher appointed as an Officer of Statistics.8
Researchers may only remove non-confidential aggregate data from the CSO environment. These aggregates must be reviewed and approved by the relevant Statistician or Senior Statistician to ensure they do not risk disclosure.
Note: Applicants should be aware that the approval process is detailed and can take time, particularly when multiple datasets are requested. Each application undergoes rigorous review to ensure compliance with legal, ethical, and security standards. This may involve coordination across several governance bodies and data owners, which can extend timelines. Setting realistic expectations at the outset helps researchers plan their projects effectively and avoid delays. Similarly, consideration should be given to the lead-in time required for the processing of researchers' output requests, in particular where a large volume of material is to be reviewed for SDC requirements. Adequate planning and notice are required to facilitate the timeliness of the SDC review performed by the Statistician.
Additional Terms and Conditions: All outputs must be shared with the CSO as a condition of the access approval where required by CSO. We reserve the right to publish outputs if the researcher does not do so. Research data remains the property of the CSO at all times. All analysis must align with the approved purpose for which access was granted and must comply with the statistical disclosure control set out in the original application
Once research project is fully approved, access is facilitated via the Researcher Data Portal (RDP)—a locked-down system designed to prevent data extraction without explicit CSO approval. All data remains on CSO-managed secure data storage at all times. The system does not provide email or internet access, further safeguarding data integrity, and was developed in alignment with the Five Safes Framework:
Access to the RDP is subject to following conditions:
Researchers must ensure they log off the system when it is not in use, that unattended screens are locked, and that data is not visible to unauthorised persons. Login credentials must never be stored, shared, or communicated. Additional, Recording, photographing, screen-sharing, copying, or transferring data from the RDP is strictly prohibited. Any breach must be reported immediately to the CSO Researcher Coordination Unit. Upon completion of the research or termination of the Officer of Statistics designation, access to the RDP will be revoked.
Failure to comply with this policy may have implications for researchers and the institutions with which they work. The Act sets out offences and penalties. Sanctions in this connection include, but are not limited to:
In relation to this policy, the following responsibilities arise:
This policy will be reviewed annually, if needed reviews may be completed more frequently.
1 S.20(c) Statistics Act 1993, 2 S.11 Statistics Act 1993, 3 S.30 Statistics Act 1993, 4 S.24 Statistics Act 1993, 5 Data Protection Act, 2018 (the ‘2018 Act’), General Data Protection Regulation (GDPR), 6 This process does not apply to the DGA Anonymisation Service, 7 S.11 Statistics Act 1993, 8 S.32 and S.33 Statistics Act 1993– Statistics Act, 1993