🔒 Data Protection Regulatory Intelligence
Data Protection Monitor · dataprotection.gi
IE v13-gdpri-1.0.0
content: ai_generated legal review: never_reviewed (informational) publication gate: 0 failing21 sources retrieved model claude-sonnet-5 · 2026-07-29

Ireland

IE schema gdpri-v2 trajectory: not yet assessedregulated (omnibus)overlaps: FIM, WPM, AIC

Last updated · 10 categories · 40 claims · 42 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
40Claimsbaseline..claims[]
7Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No red categories; 18 sub-modules are flagged red.

Jurisdiction brief

Latest update · 28 September 2026

Lead Signal

The Data Protection Commission has closed out September 2026 with two material fines that together mark a period of intensified enforcement activity beyond the regime's usual cadence. On 21 September 2026, the DPC fined Google Ireland Limited EUR403 million following a six-year inquiry, opened in February 2020, into the lawfulness of location-data processing across Web & App Activity, Location History and Location Accuracy. The decision found infringements of GDPR Articles 5, 6, 12 and 13 concerning the lawfulness, fairness and transparency of that processing, and separately found an accountability-obligation infringement for Google's failure to demonstrate compliance with the lawfulness/fairness/transparency principle specifically for Location Accuracy processing. The DPC imposed a six-month compliance order alongside the fine.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive, fully in-force omnibus framework with an active, well-resourced regulator and clear statutory authority.

Primary frameworkGDPR (Regulation (EU) 2016/679) as implemented by the Data Protection Act 2018
Traffic-light rationale — GreenComprehensive, fully in-force omnibus framework with an active, well-resourced regulator and clear statutory authority.

Sub-modules (5)

Regulator And AuthorityGreen

The DPC is Ireland's independent supervisory authority for GDPR, statutorily established under Section 10 of the Data Protection Act 2018.

Claims (1):

  • The Data Protection Commission (DPC), established under Section 10 of the Data Protection Act 2018, is Ireland's supervisory authority responsible for the purposes of the GDPR.

Act And InstrumentsGreen

The Data Protection Act 2018 gives further effect to the GDPR and repealed the 1988/2003 Acts (save national-security/defence/international-relations processing carve-outs).

Claims (1):

  • The Data Protection Act 2018 gives further effect to the GDPR and, having commenced on 25 May 2018, repealed the Data Protection Acts of 1988 and 2003 except for provisions relating to processing for national security, defence, and international relations of the State.

Material ScopeGreen

The GDPR's dual objective -- protecting the fundamental right to data protection while enabling free data flow -- defines material scope of application in Ireland.

Claims (1):

  • The GDPR pursues a two-fold objective in Ireland's material scope: protecting the fundamental rights of natural persons regarding personal data, and allowing the free flow of personal data and digital-economy development.

Territorial ScopeGreen

Article 3(2) GDPR extends the Irish/EU regime extraterritorially to non-EU-established controllers targeting or monitoring EU data subjects.

Claims (1):

  • GDPR Article 3(2) extends application to controllers/processors not established in the Union where processing relates to offering goods or services to, or monitoring, data subjects in the Union, thereby extending Irish/EU jurisdiction extraterritorially.

Regulator Registration And FilingAmber

Ireland imposes no general controller-registration requirement post-GDPR; the principal filing obligation is DPO-contact-detail publication/communication to the DPC under Article 37 GDPR.

Claims (1):

  • Data controllers and processors are required to publish their DPO's contact details and communicate them to the DPC (and other relevant supervisory authorities), in lieu of a general controller-registration filing regime post-GDPR.
Category narrative69 words

Ireland's data protection regime is the EU's GDPR (Regulation (EU) 2016/679) as given further effect domestically by the Data Protection Act 2018, which commenced 25 May 2018 and established the Data Protection Commission (DPC) under Section 10 as the national supervisory authority. Ireland's status as host jurisdiction for the EU/EEA establishments of many major technology platforms makes the DPC a frequent lead supervisory authority under the GDPR's one-stop-shop mechanism.

no periodic updates on record for this sub-brief

Sources and claims (5)
  1. ConfirmedEuropean Data Protection Board — The Data Protection Commission (DPC), established under Section 10 of the Data Protection Act 2018, is Ireland's supervisory authority responsible for the purposes of the GDPR.observed
  2. ConfirmedDataGuidance / OneTrust — The Data Protection Act 2018 gives further effect to the GDPR and, having commenced on 25 May 2018, repealed the Data Protection Acts of 1988 and 2003 except for provisions relating to processing for national security, defence, and international relations of the State.observed
  3. ConfirmedEuropean Data Protection Board — The GDPR pursues a two-fold objective in Ireland's material scope: protecting the fundamental rights of natural persons regarding personal data, and allowing the free flow of personal data and digital-economy development.observed
  4. ConfirmedEuropean Data Protection Board — GDPR Article 3(2) extends application to controllers/processors not established in the Union where processing relates to offering goods or services to, or monitoring, data subjects in the Union, thereby extending Irish/EU jurisdiction extraterritorially.observed
  5. ConfirmedDataGuidance / OneTrust — Data controllers and processors are required to publish their DPO's contact details and communicate them to the DPC (and other relevant supervisory authorities), in lieu of a general controller-registration filing regime post-GDPR.observed

#

Core lawful-basis and special-category rules are fully in force and well documented; the pseudonymisation/anonymisation sub-module lacks a directly retrieved DPC-specific source in this run.

Primary frameworkGDPR Articles 6-9 as supplemented by the Data Protection Act 2018
Traffic-light rationale — GreenCore lawful-basis and special-category rules are fully in force and well documented; the pseudonymisation/anonymisation sub-module lacks a directly retrieved DPC-specific source in this run.

Sub-modules (4)

Lawful BasesGreen

Article 6(1)(b) contractual-necessity basis, among the enumerated GDPR lawful bases, applies where processing is necessary for performance of, or entry into, a contract.

Claims (1):

  • Processing is lawful under GDPR Article 6(1)(b) where necessary for performance of a contract to which the data subject is party, or to take steps at the data subject's request prior to entering a contract.

Special CategoriesAmber

The Data Protection Act 2018 created a bespoke lawful ground for processing health data necessary for insurance, pension and mortgage purposes.

Claims (1):

  • The Data Protection Act 2018 introduced a lawful processing ground permitting health data to be processed where necessary for insurance, health-insurance, occupational pension, retirement annuity, or property-mortgaging purposes.

Pseudonymisation And AnonymisationRed

No DPC-specific pseudonymisation/anonymisation guidance or safe-harbour provision was retrieved in this research pass.

Absence provenance: unavailable. Searched: unavailable.

Category narrative48 words

Lawful bases follow GDPR Article 6, with the Data Protection Act 2018 setting Ireland's age of digital consent (Article 8 GDPR) at 16 years and adding a bespoke lawful ground permitting insurance-related health-data processing. Pseudonymisation/anonymisation safe-harbour guidance specific to the DPC was not located in this research pass.

Periodic update · new data 2026-09-28

Lawful Processing & Special Data

The DPC's 21 September 2026 decision against Google Ireland Limited found infringements of GDPR Articles 5, 6, 12 and 13 in respect of the lawfulness, fairness and transparency of location-data processing carried out through Web & App Activity, Location History and Location Accuracy features. Article 5 sets out the core processing principles, Article 6 the lawful bases for processing, and Articles 12 and 13 the transparency obligations owed to data subjects at the point personal data is collected. The DPC's finding that these provisions were infringed concerns whether Google gave users an adequate legal basis and adequate transparency for processing their location data through these specific product features. The inquiry that produced this finding was opened in February 2020 and ran for approximately six and a half years before conclusion in September 2026, reflecting the scale and complexity of establishing infringement across multiple interlinked product features.

This finding sits within Ireland's broader enforcement context this cycle: the DPC's decision explicitly targets the lawful-basis and transparency dimensions of location processing, rather than, for example, a security or retention failure. The EUR403 million fine and accompanying six-month compliance order reflect a finding of substantive infringement on the lawfulness and transparency principles specifically.

Outlook

Whether Google intends to appeal the 21 September 2026 decision is understood from press reporting but has not been confirmed against a DPC or court filing this cycle. Any appeal would test the DPC's Article 5/6/12/13 findings on location-data lawfulness and transparency before the courts, and would be the clearest next signal for how durable this finding proves to be.

Sources and claims (3)
  1. ConfirmedData Protection Commission — Processing is lawful under GDPR Article 6(1)(b) where necessary for performance of a contract to which the data subject is party, or to take steps at the data subject's request prior to entering a contract.observed
  2. ConfirmedData Protection Commission — Ireland has set the age of digital consent under Article 8 GDPR, read with the Data Protection Act 2018, at 16 years, meaning online service providers generally cannot rely on a child's own consent below that age.observed
  3. ProbableDataGuidance — The Data Protection Act 2018 introduced a lawful processing ground permitting health data to be processed where necessary for insurance, health-insurance, occupational pension, retirement annuity, or property-mortgaging purposes.observed

#

Access/erasure/rectification and deadline mechanisms are well evidenced; restriction, objection and portability sub-modules rely on the general GDPR baseline without a directly retrieved DPC-specific source.

Primary frameworkGDPR Articles 12-22 as administered by the Data Protection Act 2018
Traffic-light rationale — AmberAccess/erasure/rectification and deadline mechanisms are well evidenced; restriction, objection and portability sub-modules rely on the general GDPR baseline without a directly retrieved DPC-specific source.

Sub-modules (5)

Access RightGreen

DPC 2024 case studies specifically address subject access request handling as a recurring compliance issue.

Claims (1):

  • The DPC's 2024 case-study report addresses recurring issues in handling subject access requests, alongside deletion and rectification requests.

Rectification And ErasureGreen

The same DPC case-study reporting addresses rectification and erasure ('right to be forgotten') requests.

Claims (1):

  • DPC case studies published alongside the 2024 Annual Report specifically address rectification and erasure ('right to be forgotten') requests as a recurring compliance theme.

Restriction And ObjectionRed

No DPC-specific source on restriction (Art 18) or objection (Art 21) practice was retrieved in this pass; the general GDPR baseline applies.

Absence provenance: unavailable. Searched: unavailable.

Data PortabilityRed

No DPC-specific portability (Art 20) guidance or enforcement was retrieved in this pass; the general GDPR baseline applies.

Absence provenance: unavailable. Searched: unavailable.

Deadlines And Response WindowsGreen

Section 109 DPA 2018 empowers the DPC to facilitate amicable complaint resolution within a reasonable time, offering data subjects a faster route to remedy than full statutory inquiry.

Claims (1):

  • Under Section 109 of the Data Protection Act 2018, the DPC takes steps to arrange or facilitate amicable resolution of complaints where there is a reasonable likelihood of the parties reaching resolution within a reasonable time, offering data subjects a comparatively fast route to vindication of rights.
Category narrative67 words

GDPR Articles 13-22 provide the framework for access, rectification, erasure, restriction, objection and portability rights, enforced in Ireland by the DPC. The DPC's 2024 case-study reporting highlights access, deletion and rectification requests as recurring themes, and Section 109 of the Data Protection Act 2018 provides an amicable-resolution route with a comparatively fast response window. Direct DPC-specific sourcing on restriction/objection and portability was not retrieved in this pass.

Periodic update · new data 2026-09-14

Data Subject Rights

The Data Protection Commission's draft decision found that Meta Platforms Ireland Limited infringed Articles 12, 15 and 20 GDPR in connection with the handling of data access requests. Fines in the region of EUR 360-430 million are proposed, and the High Court upheld the DPC's power to impose such a fine in a May 2026 judgment, though the final fine amount remains undetermined pending the DPC's own decision — this is a probable-confidence finding, and the matter is understood to still be subject to contestation by way of judicial review. The infringement findings concern how the company handled subject access requests and data portability requests, going to the core data-subject-rights framework under GDPR Articles 12 (transparent information), 15 (right of access) and 20 (right to data portability).

This is one of the two largest live GDPR enforcement matters affecting Ireland this cycle, and its scale — a proposed fine in the hundreds of millions of euro — places it alongside the TikTok cross-border transfer matter as evidence of the DPC's continuing willingness to pursue high-value enforcement against major technology platforms headquartered in its jurisdiction.

Outlook

The fine quantum remains the central open question: the DPC's own final determination, once issued, will resolve whether the figure lands within the proposed EUR 360-430 million range or is adjusted following further process. Judicial review avenues remain available to Meta and may extend the timeline before the matter is fully resolved.

Sources and claims (3)
  1. ProbableIAPP — The DPC's 2024 case-study report addresses recurring issues in handling subject access requests, alongside deletion and rectification requests.observed
  2. ProbableIAPP — DPC case studies published alongside the 2024 Annual Report specifically address rectification and erasure ('right to be forgotten') requests as a recurring compliance theme.observed
  3. ConfirmedEuropean Data Protection Board — Under Section 109 of the Data Protection Act 2018, the DPC takes steps to arrange or facilitate amicable resolution of complaints where there is a reasonable likelihood of the parties reaching resolution within a reasonable time, offering data subjects a comparatively fast route to vindication of rights.observed

#

DPO, accountability/DPIA, security and breach-notification sub-modules are strongly evidenced by enforcement activity; ROPA, joint-controller and retention sub-modules rely on the unevidenced general GDPR baseline.

Primary frameworkGDPR Articles 5, 24-39 as administered by the Data Protection Act 2018
Traffic-light rationale — AmberDPO, accountability/DPIA, security and breach-notification sub-modules are strongly evidenced by enforcement activity; ROPA, joint-controller and retention sub-modules rely on the unevidenced general GDPR baseline.

Sub-modules (7)

Accountability And DpiaGreen

The DPC has been particularly active in issuing DPIA and accountability guidance.

Claims (1):

  • The DPC has been particularly active in issuing guidance on Data Protection Impact Assessments and other accountability topics such as cookies and breach notification.

Dpo RequirementsGreen

Article 39 DPO obligations are in force; the DPC reports over 1,500 new DPOs appointed in Ireland post-GDPR.

Claims (1):

  • Under Article 39 GDPR, appointed Data Protection Officers must monitor internal compliance, act as contact point for data subjects exercising rights, and liaise with the supervisory authority; the DPC has reported more than 1,500 new DPOs appointed in Ireland following the GDPR's introduction.

Ropa RequirementsRed

No DPC-specific ROPA (Article 30) enforcement or guidance beyond a general reference to published Article 30 guidance was retrieved with sufficient substantive detail in this pass.

Absence provenance: unavailable. Searched: unavailable.

Joint Controller ArrangementsRed

No DPC-specific joint-controller arrangement guidance or enforcement was retrieved in this pass.

Absence provenance: unavailable. Searched: unavailable.

Security MeasuresGreen

The CDETB inquiry resulted in an order to bring processing into compliance with GDPR security-of-processing requirements.

Claims (1):

  • Following an inquiry into City of Dublin Education and Training Board, the DPC ordered the controller to bring its processing into compliance with the security requirements of the GDPR.

Breach NotificationGreen

The CDETB inquiry found infringements of Articles 33(1), 34(1) and 34(4) GDPR for failure to notify the DPC and affected data subjects of a breach without undue delay.

Claims (1):

  • The DPC found CDETB infringed Article 33(1) GDPR by failing to notify the DPC of a personal data breach without undue delay, and Articles 34(1) and 34(4) GDPR by failing to notify affected data subjects when required.

Retention And DisposalRed

No DPC-specific retention/disposal guidance or enforcement decision was retrieved in this pass.

Absence provenance: unavailable. Searched: unavailable.

Category narrative44 words

GDPR accountability, DPO, security and breach-notification duties are in force and actively enforced, illustrated by the DPC's inquiry into City of Dublin Education and Training Board (CDETB) for security and breach-notification failures. ROPA-specific, joint-controller-specific and retention-and-disposal-specific DPC sourcing was not retrieved in this pass.

Periodic update · new data 2026-09-28

Controller/Processor Duties

Alongside the lawfulness and transparency findings, the DPC's 21 September 2026 decision against Google Ireland Limited found a distinct accountability-obligation infringement: a failure to demonstrate compliance with the lawfulness, fairness and transparency principle specifically in respect of Location Accuracy processing. This is an accountability finding under the GDPR's Article 5(2) accountability principle and related controller-obligation provisions, and it is analytically distinct from the substantive lawfulness findings addressed under lawful processing — this finding concerns Google's ability to demonstrate its compliance, not solely whether the underlying processing was lawful.

The accountability infringement was found specifically in relation to the Location Accuracy feature, narrower in scope than the lawfulness findings which spanned Web & App Activity, Location History and Location Accuracy together. This distinction indicates the DPC's inquiry examined each product feature separately for both substantive lawfulness and accountability compliance, rather than reaching a single undifferentiated finding across the product suite.

Outlook

The accountability finding, being narrower and feature-specific, may be a discrete point of appeal or compliance-order focus separate from the broader lawfulness findings; whether the six-month compliance order the DPC imposed addresses the accountability gap specifically for Location Accuracy will be a marker of how the corrective order is structured.

1 earlier distinct update(s)
Periodic update · new data 2026-09-14

Controller/Processor Duties

Two active DPC matters this cycle bear directly on controller and processor security and breach-notification duties. First, the DPC adopted a final decision on 10 June 2026 following an inquiry into a ransomware attack on the laboratory information system at a Midlands Regional Hospital, citing infringements of Articles 5 (principles relating to processing), 28 (processor obligations), 30 (records of processing), 32 (security of processing) and 34 (communication of a personal data breach to the data subject) GDPR. This is a probable-confidence finding sourced from the DPC's own decisions register, and the breadth of articles cited — spanning core principles, processor governance, documentation, technical security, and breach communication — indicates a systemic security-failure finding rather than a narrow technical lapse.

Second, the DPC has commenced an inquiry following Permanent TSB's notification of a series of three data breaches relating to its Open 24 Contact Centre. This inquiry is understood to be ongoing, with no outcome yet determined this cycle; it is recorded here as an active development rather than a concluded enforcement matter.

Outlook

The Midlands Regional Hospital decision, now final, may generate follow-on guidance or precedent value for health-sector processors facing similar ransomware exposure. The Permanent TSB inquiry remains the item to watch: its outcome will indicate how the DPC treats a financial-sector processor facing a pattern of repeated breaches at a single contact-centre operation, rather than an isolated incident.

Sources and claims (4)
  1. ConfirmedIAPP — Under Article 39 GDPR, appointed Data Protection Officers must monitor internal compliance, act as contact point for data subjects exercising rights, and liaise with the supervisory authority; the DPC has reported more than 1,500 new DPOs appointed in Ireland following the GDPR's introduction.observed
  2. ConfirmedDataGuidance / OneTrust — The DPC has been particularly active in issuing guidance on Data Protection Impact Assessments and other accountability topics such as cookies and breach notification.observed
  3. ConfirmedEuropean Data Protection Board — Following an inquiry into City of Dublin Education and Training Board, the DPC ordered the controller to bring its processing into compliance with the security requirements of the GDPR.observed
  4. ConfirmedEuropean Data Protection Board — The DPC found CDETB infringed Article 33(1) GDPR by failing to notify the DPC of a personal data breach without undue delay, and Articles 34(1) and 34(4) GDPR by failing to notify affected data subjects when required.observed

#

Transfer-mechanism enforcement (TikTok, Meta) and adequacy-received status are strongly evidenced; adequacy-granted and data-localisation sub-modules are EU-level/absent for this JID.

Primary frameworkGDPR Chapter V (Articles 44-49) as administered by the DPC
Traffic-light rationale — AmberTransfer-mechanism enforcement (TikTok, Meta) and adequacy-received status are strongly evidenced; adequacy-granted and data-localisation sub-modules are EU-level/absent for this JID.

Sub-modules (6)

Transfer MechanismsAmber

The DPC's TikTok decision found infringement of Article 46(1) GDPR where SCC supplementary measures were not verified as effective for EEA-to-China transfers.

Claims (1):

  • The DPC, as lead supervisory authority for TikTok, found that TikTok's transfers of EEA user data to China infringed Article 46(1) GDPR because it failed to verify, guarantee and demonstrate that SCCs and supplementary measures were effective to ensure a level of protection essentially equivalent to that guaranteed within the EU.

Adequacy ReceivedAmber

As an EU Member State, Ireland benefits from the European Commission's EU-US Data Privacy Framework adequacy decision (10 July 2023).

Claims (1):

  • As an EU Member State, Ireland benefits from the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework, adopted 10 July 2023, allowing personal data to flow from the EEA to the U.S. without further conditions or authorisations.

Adequacy GrantedRed

Adequacy decisions are granted by the European Commission at EU level, not by Ireland individually; no Ireland-specific adequacy-granting act was identified, consistent with JID scoping discipline.

Absence provenance: unavailable. Searched: unavailable.

Sccs And BcrsAmber

The TikTok decision resulted in €530 million in fines split between transparency (Art 13(1)(f)) and unlawful-transfer (Art 46(1)) infringements tied to SCC reliance.

Claims (1):

  • The DPC imposed administrative fines totalling €530 million on TikTok, comprising €45 million for the Article 13(1)(f) transparency infringement and €485 million for the Article 46(1) transfer infringement.

Transfer Impact AssessmentAmber

The Meta decision established that supplementary measures layered on SCCs did not cure deficiencies identified in Schrems II, reinforcing the practical need for a documented transfer impact assessment.

Claims (1):

  • The DPC's decision against Meta found that the substantial supplementary measures Meta layered on top of SCCs did not compensate for deficiencies in U.S. law identified in Schrems II, reinforcing the requirement for a documented transfer impact assessment before relying on SCCs for EU-to-US transfers.

Data LocalisationRed

No Ireland-specific data-localisation mandate was identified in this research pass; Ireland relies on the GDPR's harmonised transfer regime rather than a partial or absolute localisation requirement.

Absence provenance: unavailable. Searched: unavailable.

Category narrative65 words

Ireland relies on the EU's transfer mechanisms (SCCs, BCRs, adequacy decisions, derogations) under GDPR Chapter V. The DPC's TikTok and Meta decisions are the leading Irish precedents on SCC transfer-impact-assessment adequacy, and Ireland benefits from the EU-US Data Privacy Framework adequacy decision as an EU Member State. Adequacy-granting is an EU Commission competence rather than an Irish-specific act, and no Ireland-specific data-localisation mandate was identified.

Periodic update · new data 2026-09-14

Cross-Border & Adequacy

The DPC's most consequential cross-border enforcement action this cycle is the High Court's upholding, on 30 June 2026, of a EUR 530 million administrative fine against TikTok. The DPC found infringements of Articles 46(1) (transfers subject to appropriate safeguards) and 13(1)(f) GDPR (information to be provided on transfers to third countries) concerning EEA user data being made accessible from China. This is described as the first such data-transfer fine issued by an EU Member State specifically concerning access arrangements involving China, and is a confirmed-tier finding carrying the highest materiality rating in this cycle's evidence set. A related DPC appeal was dismissed by the Supreme Court on 30 April 2026, removing one procedural obstacle to the fine's enforcement, though the ultimate outcome of TikTok's own response to the upheld fine and any associated suspension order remains pending.

Separately, on the standing transfer-mechanism-administration side, the DPC maintains an updated (January 2026) published list of approved Binding Corporate Rules for which it acts as lead supervisory authority — a lower-materiality, probable-confidence administrative fact reflecting Ireland's continuing role as lead supervisory authority for a substantial cohort of multinational BCR arrangements given the concentration of tech-sector EU headquarters in the jurisdiction.

Outlook

The TikTok matter's next milestone is the outcome of TikTok's appeal against the fine and any associated data-transfer suspension order, which remains pending. Given the DPC's demonstrated willingness to pursue and defend China-linked transfer enforcement through to High Court and Supreme Court levels, this matter is likely to remain the DPC's highest-profile cross-border case for the remainder of 2026.

1 earlier distinct update(s)
Periodic update · new data 2026-09-05

Cross-Border & Adequacy

The DPC's €530 million fine against TikTok in 2025, over the transfer of EEA user data to China, is this cycle's clearest cross-border-transfer signal. The finding is confirmed with reasonable corroboration, though TikTok is appealing the decision and no primary DPC decision text was independently retrieved this cycle. The fine sits within an established DPC enforcement pattern requiring documented Transfer Impact Assessments for every cross-border transfer mechanism relied upon by controllers and processors under DPC jurisdiction: Standard Contractual Clauses alone are treated as insufficient without a documented analysis of the receiving country's legal framework, mirroring the reasoning previously applied in the Schrems II line of cases and the earlier Meta transfer fine. For controllers relying on SCCs for transfers into jurisdictions without an adequacy decision, the TikTok fine functions as a fresh, high-value illustration of the DPC's willingness to enforce this standard even against a major global platform.

Outlook

The TikTok appeal outcome is the marker to watch: if it narrows or overturns the underlying transfer-adequacy reasoning, that would be a material development for how the DPC's Transfer Impact Assessment expectations are applied going forward; if it is dismissed or the fine substantially upheld, it reinforces the current strict-scrutiny posture for transfers to jurisdictions like China.

Sources and claims (4)
  1. ConfirmedEuropean Data Protection Board — The DPC, as lead supervisory authority for TikTok, found that TikTok's transfers of EEA user data to China infringed Article 46(1) GDPR because it failed to verify, guarantee and demonstrate that SCCs and supplementary measures were effective to ensure a level of protection essentially equivalent to that guaranteed within the EU.observed
  2. ConfirmedEuropean Data Protection Board — The DPC imposed administrative fines totalling €530 million on TikTok, comprising €45 million for the Article 13(1)(f) transparency infringement and €485 million for the Article 46(1) transfer infringement.observed
  3. ConfirmedIAPP — As an EU Member State, Ireland benefits from the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework, adopted 10 July 2023, allowing personal data to flow from the EEA to the U.S. without further conditions or authorisations.observed
  4. ConfirmedIAPP — The DPC's decision against Meta found that the substantial supplementary measures Meta layered on top of SCCs did not compensate for deficiencies in U.S. law identified in Schrems II, reinforcing the requirement for a documented transfer impact assessment before relying on SCCs for EU-to-US transfers.observed

#

Telecoms/ePrivacy, education and insurance overlays are evidenced; financial-sector and credit-scoring sub-modules lack substantive DPC-specific sourcing in this run.

Primary frameworkGDPR + sector overlays: S.I. No. 336/2011 (ePrivacy); Data Protection Act 2018 (insurance-related health-data ground)
Traffic-light rationale — AmberTelecoms/ePrivacy, education and insurance overlays are evidenced; financial-sector and credit-scoring sub-modules lack substantive DPC-specific sourcing in this run.

Sub-modules (7)

Financial Sector OverlayRed

No substantive DPC-specific financial-sector overlay content (beyond the insurance-related health-data ground captured under the insurance sub-module) was retrieved in this pass.

Absence provenance: unavailable. Searched: unavailable.

Health Sector OverlayAmber

Health-sector-specific processing is principally addressed via the DPA 2018 insurance-related health-data lawful ground; no separate general health-sector DPC guidance was retrieved.

Claims (1):

  • The Data Protection Act 2018 permits processing of health data without explicit consent where necessary for insurance, health-insurance, occupational pension, retirement-annuity, or property-mortgaging purposes, creating a sector-specific overlay for insurance and financial services.

Telecoms And EprivacyGreen

The DPC exercises functions under S.I. No. 336 of 2011, Ireland's implementation of the ePrivacy Directive, governing cookies and electronic-communications privacy.

Claims (1):

  • The DPC has functions and powers under S.I. No. 336 of 2011 (European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations), which implements the ePrivacy Directive and governs cookies and electronic marketing in Ireland.

Employment DataAmber

Employment-context processing in Ireland relies on general GDPR derogations; practitioner commentary addresses collection, processing and retention of employee (including health) data.

Claims (1):

  • Employment-context data processing in Ireland is addressed through general GDPR derogations rather than extensive DPA 2018 elaboration, with practitioner guidance covering collection, processing and retention of employee data including health data.

Credit And ScoringRed

Only a title-level reference to a historic DPC fine against an Irish credit bureau was located, without retrievable substantive content in this pass.

Absence provenance: unavailable. Searched: unavailable.

EducationAmber

The DPC's CDETB inquiry is the leading education-sector enforcement precedent, addressing security and breach-notification failures.

Claims (1):

  • The DPC's inquiry into City of Dublin Education and Training Board (CDETB), an education-sector public body, resulted in a reprimand and €125,000 in administrative fines for GDPR security and breach-notification failures.

InsuranceAmber

The Data Protection Act 2018 provides a bespoke lawful ground for insurance-related health-data processing, forming Ireland's principal insurance-sector overlay.

Claims (1):

  • The Data Protection Act 2018 permits processing of health data without explicit consent where necessary for insurance, health-insurance, occupational pension, retirement-annuity, or property-mortgaging purposes, creating a sector-specific overlay for insurance and financial services.
Category narrative56 words

Sectoral overlays in Ireland include the ePrivacy Regulations (S.I. No. 336/2011) for telecoms/electronic communications, a DPA 2018 insurance-specific health-data ground, and education-sector enforcement (CDETB). Employment-data treatment relies on general GDPR derogations rather than extensive statutory elaboration. Financial-sector-specific and credit-scoring-specific DPC sourcing beyond a title-level reference to a historic credit-bureau fine was not retrieved in this pass.

Periodic update · new data 2026-09-14

Sectoral Watch

Two sectoral matters intersect with the DPC's broader enforcement activity this cycle. In the financial sector, the DPC has commenced an inquiry into Permanent TSB following the bank's notification of a series of three data breaches relating to its Open 24 Contact Centre — a probable-confidence, ongoing matter with no outcome yet determined. In the health sector, the DPC concluded, on 10 June 2026, a final decision following an inquiry into a ransomware attack on the laboratory information system at a Midlands Regional Hospital, citing infringements across Articles 5, 28, 30, 32 and 34 GDPR.

Taken together, these two matters show the DPC's sectoral enforcement reach extending into both financial-services contact-centre operations and health-sector laboratory information systems within the same cycle, indicating that sectoral breach exposure is not confined to any single industry vertical in Ireland's current enforcement environment. Both matters derive from the DPC's own decisions and guidance register, a Tier-1 primary source.

Outlook

The Permanent TSB inquiry is the sectoral matter with the least settled outcome and is the one most likely to generate a further material development in coming cycles, given it remains an open inquiry rather than a concluded decision.

Sources and claims (4)
  1. ConfirmedDataGuidance / OneTrust — The DPC has functions and powers under S.I. No. 336 of 2011 (European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations), which implements the ePrivacy Directive and governs cookies and electronic marketing in Ireland.observed
  2. ConfirmedEuropean Data Protection Board — The DPC's inquiry into City of Dublin Education and Training Board (CDETB), an education-sector public body, resulted in a reprimand and €125,000 in administrative fines for GDPR security and breach-notification failures.observed
  3. ProbableDataGuidance — The Data Protection Act 2018 permits processing of health data without explicit consent where necessary for insurance, health-insurance, occupational pension, retirement-annuity, or property-mortgaging purposes, creating a sector-specific overlay for insurance and financial services.observed
  4. ProbableDataGuidance / OneTrust — Employment-context data processing in Ireland is addressed through general GDPR derogations rather than extensive DPA 2018 elaboration, with practitioner guidance covering collection, processing and retention of employee data including health data.observed

#

Cookies, direct marketing and cross-context (behavioural) advertising are well evidenced through enforcement; dark patterns, opt-out signals and clean rooms lack retrieved sourcing.

Primary frameworkS.I. No. 336/2011 (ePrivacy) + GDPR Article 6 (legal basis for advertising/profiling)
Traffic-light rationale — AmberCookies, direct marketing and cross-context (behavioural) advertising are well evidenced through enforcement; dark patterns, opt-out signals and clean rooms lack retrieved sourcing.

Sub-modules (6)

Cookies And TrackersAmber

S.I. No. 336/2011 requires clear cookie-usage disclosure; the DPC has historically clarified that standard analytics cookies do not require a separate explicit consent step beyond homepage-level disclosure (subject to subsequent guidance evolution).

Claims (1):

  • Under S.I. No. 336 of 2011, websites must make information available about cookie usage; the DPC historically clarified that this does not impose a need for explicit separate consent for standard third-party analytics services such as Google Analytics.

Dark PatternsRed

No DPC-specific dark-pattern enforcement or guidance was retrieved in this pass.

Absence provenance: unavailable. Searched: unavailable.

Opt Out SignalsRed

No DPC-specific Global Privacy Control / opt-out-signal guidance was retrieved in this pass.

Absence provenance: unavailable. Searched: unavailable.

Clean Rooms And DcrRed

No DPC-specific clean-room / data-collaboration-room guidance was retrieved in this pass.

Absence provenance: unavailable. Searched: unavailable.

Cross Context AdvertisingAmber

The DPC's €390 million Meta decision found Meta could not rely on the 'contract' legal basis for behavioural advertising, constraining cross-context/personalised-advertising practices.

Claims (1):

  • The DPC fined Meta Ireland €390 million after finding Meta could not rely on the 'contract' legal basis under Article 6 GDPR for delivering behavioural/personalised advertising on Facebook and Instagram.

Direct MarketingGreen

The DPC's 2024 enforcement activity included prosecutions for unsolicited SMS marketing.

Claims (1):

  • The DPC's 2024 enforcement activity included prosecutions of a gym, clinic, fast-food company and Google for sending unsolicited marketing SMS messages.
Category narrative41 words

Cookie and tracker consent is governed by S.I. No. 336/2011, with the DPC actively enforcing direct-marketing rules (2024 SMS-marketing prosecutions) and behavioural-advertising legal-basis requirements (the €390 million Meta decision). Dark-pattern, opt-out-signal and clean-room/data-collaboration-room-specific DPC sourcing was not retrieved in this pass.

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. ProbableIAPP — Under S.I. No. 336 of 2011, websites must make information available about cookie usage; the DPC historically clarified that this does not impose a need for explicit separate consent for standard third-party analytics services such as Google Analytics.observed
  2. ConfirmedIAPP — The DPC's 2024 enforcement activity included prosecutions of a gym, clinic, fast-food company and Google for sending unsolicited marketing SMS messages.observed
  3. ConfirmedIAPP — The DPC fined Meta Ireland €390 million after finding Meta could not rely on the 'contract' legal basis under Article 6 GDPR for delivering behavioural/personalised advertising on Facebook and Instagram.observed

#

Profiling restrictions and state-surveillance carve-outs are evidenced; ADM transparency, biometric regime and genetic data sub-modules lack directly retrieved DPC-specific sourcing.

Primary frameworkGDPR Article 22 + EU AI Act (Regulation (EU) 2024/1689)
Traffic-light rationale — AmberProfiling restrictions and state-surveillance carve-outs are evidenced; ADM transparency, biometric regime and genetic data sub-modules lack directly retrieved DPC-specific sourcing.

Sub-modules (6)

Profiling RestrictionsAmber

The Meta decision's invalidation of the 'contract' legal basis for behavioural advertising constrains profiling-based ad personalisation absent valid consent.

Claims (1):

  • The DPC's finding that Meta's 'contract' legal basis was invalid for behavioural-advertising profiling activities constrains how controllers may justify profiling-based ad personalisation absent valid consent.

Automated Decision Making TransparencyRed

No DPC-specific Article 22 ADM-transparency guidance or decision was retrieved in this pass.

Absence provenance: unavailable. Searched: unavailable.

Ai Risk AssessmentsAmber

The DPC's 2024 Annual Report highlights its evolving role under the EU AI Act, reflecting growing overlap between GDPR enforcement and AI governance obligations.

Claims (1):

  • The DPC's 2024 Annual Report highlights its evolving role under the EU Artificial Intelligence Act and other digital laws, reflecting growing overlap between GDPR enforcement and AI governance obligations.

Biometric RegimeRed

No DPC-specific biometric-regime (facial recognition, fingerprint, gait) guidance or enforcement was retrieved in this pass.

Absence provenance: unavailable. Searched: unavailable.

Genetic DataRed

No DPC-specific genetic-data guidance or enforcement was retrieved in this pass.

Absence provenance: unavailable. Searched: unavailable.

State Surveillance CarveoutsAmber

The Data Protection Act 2018 preserved national-security, defence and international-relations processing carve-outs from the pre-2018 Acts, exempting these from its general repeal.

Claims (1):

  • The Data Protection Act 2018 preserved provisions of the repealed 1988/2003 Acts specifically relating to processing of personal data for national security, defence, and international relations purposes, carving these out from the Act's general repeal.
Category narrative47 words

Ireland's DPC increasingly interfaces with the EU AI Act (Regulation (EU) 2024/1689) alongside its GDPR profiling/ADM remit; the Meta contract-legal-basis decision constrains profiling-based advertising. National-security/defence carve-outs preserved from pre-GDPR law remain the operative state-surveillance carve-out. Biometric-regime, genetic-data and ADM-transparency-specific DPC sourcing was not retrieved in this pass.

Periodic update · new data 2026-09-05

Algorithmic, Biometric & Surveillance Governance

Many provisions of the EU AI Act become applicable from August 2026, with some high-risk AI requirements following on later transition dates. This is confirmed as a material EU-level development arriving within this cycle's window, converging with existing GDPR transparency and automated-decision-making obligations for controllers using AI systems in Ireland. No Irish-specific DPC enforcement action was identified alongside this development this cycle, and it is not yet confirmed whether the DPC has issued Ireland-specific coordination guidance for the August 2026 applicability date — that remains an evidentiary gap rather than an asserted absence.

Outlook

Watch for DPC guidance specifically addressing the AI Act/GDPR interface as the August 2026 applicability date approaches, and for the first enforcement actions or investigations that treat AI Act compliance and GDPR automated-decision-making obligations as a combined compliance question rather than two separate regimes.

Sources and claims (3)
  1. ConfirmedIAPP — The DPC's finding that Meta's 'contract' legal basis was invalid for behavioural-advertising profiling activities constrains how controllers may justify profiling-based ad personalisation absent valid consent.observed
  2. ProbableIAPP — The DPC's 2024 Annual Report highlights its evolving role under the EU Artificial Intelligence Act and other digital laws, reflecting growing overlap between GDPR enforcement and AI governance obligations.observed
  3. ConfirmedDataGuidance / OneTrust — The Data Protection Act 2018 preserved provisions of the repealed 1988/2003 Acts specifically relating to processing of personal data for national security, defence, and international relations purposes, carving these out from the Act's general repeal.observed

#

Age-of-consent and education-setting guidance are strongly evidenced; minor-profiling-ban and dependent-adult sub-modules lack directly retrieved DPC-specific sourcing.

Primary frameworkGDPR Article 8 as implemented by the Data Protection Act 2018
Traffic-light rationale — AmberAge-of-consent and education-setting guidance are strongly evidenced; minor-profiling-ban and dependent-adult sub-modules lack directly retrieved DPC-specific sourcing.

Sub-modules (5)

Age VerificationGreen

GDPR permits Member States to set the digital-consent age between 13 and 16; Ireland elected the maximum permissible age of 16.

Claims (1):

  • The GDPR permits Member States to set the age of digital consent for information society services between 13 and 16 years, and Ireland elected the maximum permissible age of 16.

Minor Profiling BansRed

No DPC-specific minor-profiling-ban guidance or enforcement was retrieved in this pass.

Absence provenance: unavailable. Searched: unavailable.

Education SettingsGreen

The DPC published finalised guidance on child-oriented data processing covering offline educational, sporting, social and health/support settings likely to be accessed by children.

Claims (1):

  • The DPC published its finalised guidance, 'Fundamentals for a Child-Oriented Approach to Data Processing,' on 17 December 2021, covering data processing in offline educational, sporting, social and health/support settings likely to be accessed by children.

Dependent AdultsRed

No DPC-specific dependent-adult (elderly, mentally incapacitated) protections guidance was retrieved in this pass.

Absence provenance: unavailable. Searched: unavailable.

Category narrative52 words

Ireland set the GDPR Article 8 age of digital consent at 16 years -- the maximum permitted under the GDPR's 13-16 range -- and the DPC published dedicated child-oriented processing guidance ('Fundamentals for a Child-Oriented Approach to Data Processing', December 2021). Minor-profiling-ban and dependent-adult-specific DPC sourcing was not retrieved in this pass.

no periodic updates on record for this sub-brief

Sources and claims (3)
  1. ConfirmedEuropean Data Protection Board — The GDPR permits Member States to set the age of digital consent for information society services between 13 and 16 years, and Ireland elected the maximum permissible age of 16.observed
  2. ConfirmedData Protection Commission — Ireland's Data Protection Act 2018 sets the age of digital consent at 16 years under Article 8 GDPR, requiring parental consent for information-society-service processing of children's data below that age.observed
  3. ConfirmedDataGuidance / OneTrust — The DPC published its finalised guidance, 'Fundamentals for a Child-Oriented Approach to Data Processing,' on 17 December 2021, covering data processing in offline educational, sporting, social and health/support settings likely to be accessed by children.observed

#

Enforcement powers, penalty scale, and recent developments are extensively evidenced through primary regulator decisions and secondary reporting.

Primary frameworkData Protection Act 2018, Part 6 (Sections 109-141) + GDPR Articles 77-84
Traffic-light rationale — GreenEnforcement powers, penalty scale, and recent developments are extensively evidenced through primary regulator decisions and secondary reporting.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The DPC's 2024 cross-border inquiries produced fines exceeding €652 million; the TikTok decision alone imposed €530 million.

Claims (2):

  • The DPC concluded four large-scale cross-border inquiries in 2024, resulting in administrative fines totalling more than €652 million.
  • The Irish SA imposed administrative fines totalling €530 million on TikTok for infringements of Articles 13(1)(f) and 46(1) GDPR relating to transfers of EEA user data to China.

Enforcement Activity IndexGreen

In 2024 the DPC concluded 2,357 formal complaints and resolved a further 8,418 cases through amicable means.

Claims (1):

  • In 2024 the DPC concluded 2,357 formal complaints and resolved a further 8,418 cases through amicable means.

Regulator Funding And CapacityGreen

DPC headcount has grown to nearly 300 staff from 27 in 2014, though Commissioner Sweeney noted in 2026 growth has plateaued.

Claims (1):

  • The DPC's headcount has grown to nearly 300 staff, up from 27 in 2014, though Commissioner Sweeney noted in 2026 that growth has plateaued with only some active hires continuing.

Collective Redress And Class ActionsAmber

Fines require court confirmation before collection, generating substantial litigation volume including judicial review and Article 65 annulment actions.

Claims (1):

  • Under Irish law, DPC administrative fines must be confirmed by the courts before they can be collected; as of 2026 the DPC has 13 of its 15 large concluded investigations in litigation and over 40 active court cases.

Private Right Of ActionAmber

DPA 2018 enables not-for-profit bodies to bring representative complaints/actions on behalf of data subjects, though damages are unavailable in such actions.

Claims (1):

  • The Data Protection Act 2018 enables a data subject to mandate a not-for-profit body to lodge a complaint with the DPC or bring a judicial action on the data subject's behalf, though such representative court actions cannot result in an award of material or non-material damages -- only an injunction or declaration.

Recent Developments 180DGreen

Within the last 180 days, the EDPB issued an updated EU-US DPF FAQ (January 2026) and Commissioner Sweeney publicly outlined 2026 enforcement priorities at the IAPP Global Summit, including ongoing TikTok transfer litigation.

Claims (2):

  • In January 2026 the EDPB published an updated version (2.0) of its EU-U.S. Data Privacy Framework FAQ for European individuals, reflecting continued monitoring of the adequacy decision governing EU-to-US personal data transfers relevant to Irish controllers.
  • At the IAPP Global Summit 2026, newly appointed DPC Commissioner Niamh Sweeney (whose five-year term began 13 October 2025) outlined 2026 enforcement priorities, including ongoing litigation with TikTok over data transfers to China and continued reliance on corrective measures alongside fines.
Category narrative72 words

The DPC is among the most active GDPR enforcers globally, concluding four large-scale cross-border inquiries in 2024 with fines exceeding €652 million, and headline decisions against TikTok (€530m) and Meta (€1.2bn; €390m). Irish law requires court confirmation of fines before collection, driving substantial litigation volume; the DPA 2018 provides for representative (non-damages) actions by qualified not-for-profit bodies. Recent 2026 developments include continued EU-US Data Privacy Framework monitoring and Commissioner Sweeney's public priority-setting.

Periodic update · new data 2026-09-28

Enforcement & Redress

September 2026 produced two material DPC fines within a single month, a pace of enforcement activity that stands out against the regime's usual cadence. On 2 September 2026, the DPC fined the Health Service Executive EUR645,000 following an inquiry into personal data contained in paper records stored externally across twelve HSE facilities, with the order combining the financial penalty with a reprimand and corrective orders. Nineteen days later, on 21 September 2026, the DPC fined Google Ireland Limited EUR403 million following a six-year inquiry into location-data processing, with a six-month compliance order attached.

The two decisions differ sharply in scale and subject matter — a domestic public health body's paper-records handling on one hand, and a multinational technology company's digital location-data processing architecture on the other — but their proximity in time is itself the material signal: it indicates the DPC's current enforcement output is not concentrated in any single sector or case type, and that multiple substantial inquiries were reaching conclusion within the same reporting window. The Google fine, in particular, followed an inquiry opened in February 2020, meaning its September 2026 conclusion reflects the closing of a multi-year investigation rather than a newly-initiated action.

Outlook

Whether Google intends to appeal the 21 September 2026 decision is understood from press reporting but has not been confirmed against a DPC or court filing this cycle; an appeal would be the clearest next-step development in that specific matter. More broadly, whether this cluster of two fines within a month represents a genuine step-change in DPC enforcement tempo, or the coincidental conclusion of two independently-timed inquiries, is a distinction that a further enforcement action within the next reporting period would help resolve.

2 earlier distinct update(s)
Periodic update · new data 2026-09-14

Enforcement & Redress

Ireland's enforcement scale, viewed in aggregate, is the dominant fact of this cycle's data-protection picture. The DPC has issued EUR 4.04 billion in GDPR fines since May 2018 — a confirmed-tier finding — almost four times more than second-placed France, and including the largest single European GDPR fine of 2025, the EUR 530 million fine against TikTok. The DPC holds 8 of the top 10 GDPR fines ever issued anywhere in the EU, a further confirmed-tier finding underscoring the concentration of major GDPR enforcement activity in Ireland relative to every other Member State.

This aggregate enforcement picture sits alongside, and is substantially driven by, the two largest live matters tracked elsewhere in this cycle's brief: the upheld TikTok cross-border transfer fine and the pending Meta data-access-rights fine. Ireland's enforcement posture continues to intensify materially, with these two matters together representing the two largest live GDPR enforcement matters in the EU this cycle, a confirmed-confidence judgment reflecting the DPC's sustained trajectory as the bloc's dominant GDPR enforcer.

Outlook

The aggregate fine total will move further once the Meta fine is finally quantified and once any adjustment to the TikTok fine following its appeal process is resolved. Ireland's position as the EU's leading GDPR enforcer by fine volume is unlikely to be displaced in the near term given the concentration of major technology-platform EU headquarters within its jurisdiction.

Periodic update · new data 2026-09-05

Enforcement & Redress

The DPC's cumulative GDPR fine total since 2018 stands at approximately €4.04 billion, the largest of any EU supervisory authority, confirmed via secondary aggregation reporting drawing on the DLA Piper January 2026 Data Breach Survey. Set against that headline figure, only approximately €20 million — about 0.5 percent — has actually been collected, with the balance suspended, under appeal, or in litigation, including the €1.2 billion Meta fine and the €746 million Amazon fine. The Amazon fine was annulled on procedural grounds by the Luxembourg Administrative Court in March 2026, though most of the underlying substantive violations were confirmed notwithstanding that procedural annulment — an important distinction between a fine being vacated and the underlying finding being vindicated. This cycle's most significant new enforcement data point is the €530 million TikTok fine issued in 2025 over EEA-to-China data transfers, now under appeal, which is confirmed via corroborated secondary reporting though no primary DPC decision text was independently retrieved.

Outlook

The persistently low fine-collection rate means headline enforcement totals should be read with caution when assessing near-term realised regulatory pressure; the TikTok appeal and the broader pattern of Meta- and Amazon-scale fines facing years of litigation both suggest that the practical deterrent effect of DPC enforcement lags materially behind its nominal scale.

Sources and claims (8)
  1. ConfirmedIAPP — The DPC concluded four large-scale cross-border inquiries in 2024, resulting in administrative fines totalling more than €652 million.observed
  2. ConfirmedEuropean Data Protection Board — The Irish SA imposed administrative fines totalling €530 million on TikTok for infringements of Articles 13(1)(f) and 46(1) GDPR relating to transfers of EEA user data to China.observed
  3. ConfirmedIAPP — In 2024 the DPC concluded 2,357 formal complaints and resolved a further 8,418 cases through amicable means.observed
  4. ConfirmedIAPP — The DPC's headcount has grown to nearly 300 staff, up from 27 in 2014, though Commissioner Sweeney noted in 2026 that growth has plateaued with only some active hires continuing.observed
  5. ConfirmedIAPP — Under Irish law, DPC administrative fines must be confirmed by the courts before they can be collected; as of 2026 the DPC has 13 of its 15 large concluded investigations in litigation and over 40 active court cases.observed
  6. ConfirmedDataGuidance — The Data Protection Act 2018 enables a data subject to mandate a not-for-profit body to lodge a complaint with the DPC or bring a judicial action on the data subject's behalf, though such representative court actions cannot result in an award of material or non-material damages -- only an injunction or declaration.observed
  7. ConfirmedEuropean Data Protection Board — In January 2026 the EDPB published an updated version (2.0) of its EU-U.S. Data Privacy Framework FAQ for European individuals, reflecting continued monitoring of the adequacy decision governing EU-to-US personal data transfers relevant to Irish controllers.observed
  8. ConfirmedIAPP — At the IAPP Global Summit 2026, newly appointed DPC Commissioner Niamh Sweeney (whose five-year term began 13 October 2025) outlined 2026 enforcement priorities, including ongoing litigation with TikTok over data transfers to China and continued reliance on corrective measures alongside fines.observed
No categories match.

Filters combine as OR inside a group and AND across groups.

Publication gate

No failing checks.

schema_validpass
min_t1_per_instrument_metpass
min_quoted_text_presentwaived — floor 0%
translation_provenance_recordedn/a — no subject in this jurisdiction
egress_verifiedpass
source_tier_integrity_okpass
jurisdiction_source_floor_metpass
tier_a_b_national_primary_pct33.33
aggregator_only_jurisdiction_count0
manual_override

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Ireland
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewerno reviewer on record
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-10-02. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 40 claim(s) (40 category placement(s)), 42 source(s) in the cumulative register.

Think something on this page is wrong? Report an error.

GDPR article map

Cross-reference: which category/sub-module covers each UK GDPR article (38 mapped).

Show article map
GDPR article to category mapping
ArticleCategorySub-module
Art. 5Controller/Processor Dutiesaccountability and dpia
Art. 6Lawful Processing & Special Datalawful bases
Art. 7Lawful Processing & Special Dataconsent thresholds
Art. 9Lawful Processing & Special Dataspecial categories
Art. 13Data Subject Rightsaccess right
Art. 14Data Subject Rightsaccess right
Art. 15Data Subject Rightsaccess right
Art. 16Data Subject Rightsrectification and erasure
Art. 17Data Subject Rightsrectification and erasure
Art. 18Data Subject Rightsrestriction and objection
Art. 19Data Subject Rightsrestriction and objection
Art. 20Data Subject Rightsdata portability
Art. 21Data Subject Rightsrestriction and objection
Art. 22Algorithmic, Biometric & Surveillance Governanceautomated decision making transparency
Art. 25Controller/Processor Dutiesaccountability and dpia
Art. 28Controller/Processor Dutiesjoint controller arrangements
Art. 30Controller/Processor Dutiesropa requirements
Art. 32Controller/Processor Dutiessecurity measures
Art. 33Controller/Processor Dutiesbreach notification
Art. 34Controller/Processor Dutiesbreach notification
Art. 35Controller/Processor Dutiesaccountability and dpia
Art. 37Controller/Processor Dutiesdpo requirements
Art. 38Controller/Processor Dutiesdpo requirements
Art. 39Controller/Processor Dutiesdpo requirements
Art. 44Cross-Border & Adequacytransfer mechanisms
Art. 45Cross-Border & Adequacyadequacy received
Art. 46Cross-Border & Adequacysccs and bcrs
Art. 47Cross-Border & Adequacysccs and bcrs
Art. 48Cross-Border & Adequacytransfer mechanisms
Art. 49Cross-Border & Adequacytransfer mechanisms
Art. 77Enforcement & Redressprivate right of action
Art. 78Enforcement & Redressprivate right of action
Art. 79Enforcement & Redressprivate right of action
Art. 80Enforcement & Redresscollective redress and class actions
Art. 81Enforcement & Redressregulator powers and penalties
Art. 82Enforcement & Redressprivate right of action
Art. 83Enforcement & Redressregulator powers and penalties
Art. 84Enforcement & Redressregulator powers and penalties

Self-audit

regulator_and_framework, lawful_processing_and_special_data (partial), cross_border_and_adequacy, and enforcement_and_redress modules are anchored predominantly on T1/T2 sources (DPA 2018, GDPR, EDPB decision notices, EDPB Art 97 questionnaire). data_subject_rights, controller_processor_duties, sectoral_watch, adtech_and_commercial_privacy, algorithmic_biometric_and_surveillance_governance and children_and_vulnerable_groups rely on a mix of T2 (EDPB/DPC guidance) and T3 (IAPP/DataGuidance) secondary reporting, with several sub-modules (pseudonymisation/anonymisation, restriction/objection, portability, ROPA, joint-controller, retention/disposal, dark patterns, opt-out signals, clean rooms, ADM transparency, biometric regime, genetic data, minor profiling bans, dependent adults, adequacy-granted, data-localisation, financial-sector overlay, credit-and-scoring) carrying explicit absent_field_provenance because no DPC-specific T1/T2/T3 source was retrieved in this research pass.

Unresolved questions (5):

  • Does current DPC cookie-consent guidance (post-2020) still permit the 2011-era analytics-cookie exemption cited in this run, or has it been superseded by later formal guidance?
  • What is the DPC's current designated role (if any) as an AI Act market surveillance authority for specific high-risk AI system categories in Ireland?
  • Are there DPC-specific ROPA (Article 30), joint-controller, or retention/disposal enforcement decisions not surfaced in this search pass?
  • Is there an Irish credit-and-scoring-sector-specific DPC enforcement pattern beyond the single historical credit-bureau fine reference located?
  • What is the current precise effective/decision date for the TikTok and Meta fine decisions cited (exact dates were not fully resolved in retrieved sources)?

Escalate to primary-source review: yes