Ireland flag

Ireland

Ireland Data Privacy Laws: GDPR, DPC Enforcement & Your Rights (2026)

By Recording Law Editorial TeamReviewed July 20, 202628 min read
Ireland Data Privacy Laws: GDPR, DPC Enforcement & Your Rights (2026)

Frequently Asked Questions

Why does Ireland regulate data privacy for Meta, Google, Apple, and TikTok?

Under the GDPR's one-stop-shop mechanism in Article 60, the supervisory authority in the country where a company has its main EU establishment becomes the lead regulator for the entire EU. Because Meta, Google, Apple, Microsoft, TikTok, and LinkedIn established their European headquarters in Dublin, Ireland's Data Protection Commission serves as their primary GDPR regulator, overseeing data protection compliance for over 450 million European users. The concentration reflects Ireland's 12.5% corporate tax rate, its English-speaking workforce, and its status as the only English-speaking EU member state after Brexit.

Who leads the Data Protection Commission?

The DPC has three commissioners. Dr Des Hogan has been chairperson and Commissioner for Data Protection since February 2024 and is also the organisation's chief executive. Dale Sunderland was appointed commissioner in February 2024, and Niamh Sweeney became the third commissioner in September 2025. The three-member structure replaced the former single-commissioner model.

How much has the Irish DPC fined companies under the GDPR?

The DPC has imposed over 4 billion euros in GDPR fines since May 2018, more than any other EU supervisory authority. Major fines include 1.2 billion euros against Meta for EU-US data transfers (May 2023), 530 million euros against TikTok for transfers to China (May 2025), 405 million euros against Instagram for children's data defaults (September 2022), 345 million euros against TikTok for children's privacy (September 2023), 310 million euros against LinkedIn for unlawful advertising legal basis (October 2024), 251 million euros against Meta for a 2018 data breach (December 2024), 225 million euros against WhatsApp for transparency failures (September 2021), and 91 million euros against Meta for password security failures (September 2024). A large proportion of these fines remain subject to legal challenge and have not been collected.

What is the digital age of consent in Ireland?

Ireland set the digital age of consent at 16 under the Data Protection Act 2018 (Number 7 of 2018), the highest age permitted by Article 8 of the GDPR (which allows member states to set it anywhere between 13 and 16). Online service providers must make reasonable efforts to verify parental consent before processing personal data of children under 16. Processing a child's personal data for direct marketing, profiling, or micro-targeting is also a criminal offence under Irish law, separate from and in addition to any GDPR administrative fine.

What is the constitutional basis for privacy rights in Ireland?

The Irish Constitution does not enumerate a specific right to privacy. However, Irish courts have recognised privacy as an unenumerated personal right protected under Article 40.3 of the Constitution, which requires the State to protect and vindicate citizens' personal rights. The foundational case is Kennedy and Arnold v Attorney General [1987] IR 587, where Hamilton P held that the right to privacy was violated by unlawful State phone tapping of journalists. This constitutional foundation coexists with Article 8 of the European Convention on Human Rights, which became part of Irish domestic law under the European Convention on Human Rights Act 2003.

What is the EU-US Data Privacy Framework and is it still valid?

The EU-US Data Privacy Framework (DPF), adopted by the European Commission on 10 July 2023 (Implementing Decision (EU) 2023/1795), provides the current adequacy mechanism for EU-to-US personal data transfers. It replaced the Privacy Shield framework, which was invalidated by the CJEU in Schrems II (Case C-311/18, July 2020). Companies certified under the DPF may receive EU personal data without additional transfer safeguards. In September 2025, the EU General Court dismissed a legal challenge to the DPF (Case T-132/23), ruling that the Commission's adequacy decision was valid. The claimant has appealed to the CJEU. The DPF remains in force as of mid-2026.

What does the EU AI Act mean for organisations in Ireland?

The EU AI Act (Regulation (EU) 2024/1689) applies in Ireland as EU law. Prohibited AI practices (including social scoring, subliminal manipulation, and real-time biometric identification for law enforcement) have been banned since 2 February 2025. Requirements for high-risk AI systems apply from August 2026. Ireland's DPC is designated as a competent authority for AI systems that process personal data. Organisations using AI in employment, health, law enforcement, or financial services must assess whether their systems qualify as high-risk and prepare for conformity assessment requirements.

Do I need a Data Protection Officer in Ireland?

Under Article 37 GDPR, a DPO is mandatory for public authorities and bodies, for organisations whose core activities require regular and systematic monitoring of individuals on a large scale, and for organisations whose core activities involve large-scale processing of special categories of data (health, biometric, racial or ethnic origin, etc.). The DPO must have expert knowledge of data protection law, must be independent, and may not receive instructions regarding their tasks. Contact details must be published and notified to the DPC. Voluntary appointment is also permitted and may be beneficial for other organisations.

What happens if the DPC and other EU regulators disagree on a case?

When the DPC issues a draft decision in a cross-border case, other EU supervisory authorities may raise relevant and reasoned objections within four weeks. If consensus cannot be reached, the matter goes to the EDPB for a binding dispute resolution decision under Article 65 GDPR. The EDPB has overruled the DPC in the WhatsApp, Meta (transfers), Instagram, and Meta (advertising legal basis) cases, resulting in higher fines and broader compliance orders. In January 2025, the EU General Court confirmed the EDPB has full authority to direct the DPC to take specific investigative and decisional steps.

How do I file a data protection complaint in Ireland?

Contact the organisation first and allow one month for a response. If you are unsatisfied, file a complaint with the DPC at dataprotection.ie, free of charge, using its online webform. The DPC must provide an update or outcome within three months and attempt amicable resolution before deploying its corrective powers. The DPC does not award compensation to complainants. For damages, you can bring a data protection action under section 117 of the Data Protection Act 2018 in the Circuit Court or High Court, and damage includes non-material damage such as distress. You also retain the right under Article 79 GDPR to go to court independently of any DPC complaint.

Updates

Refresh: confirmed the DPC's three commissioners (Dr Des Hogan chairing since February 2024, Dale Sunderland, and Niamh Sweeney since September 2025), verified the Meta and TikTok transfer fines against DPC announcements, expanded coverage of the ePrivacy Regulations (S.I. No. 336/2011), and linked the new step-by-step DPC complaint guide.

Full audit-and-evolve refresh: added constitutional basis section, legal bases for processing, DPO and DPIA requirements, EU AI Act overlay, expanded cross-border transfers with September 2025 General Court ruling on the EU-US Data Privacy Framework, added Meta 91M and Meta AI training decisions, X inquiry, 2024 DPC annual report statistics, and expanded business compliance section. Word count expanded from 3,150 to approx. 6,200.

Initial publication covering DPC structure, major fines through early 2025, one-stop-shop mechanism, and data subject rights.

Sources and References

  1. Data Protection Commission - Official Website(dataprotection.ie).gov
  2. Data Protection Commission - Who We Are (Commissioners)(dataprotection.ie).gov
  3. Data Protection Legislation - DPC(dataprotection.ie).gov
  4. Data Protection Act 2018 - Irish Statute Book(irishstatutebook.ie).gov
  5. Data Protection Act 2018, section 117 (judicial remedy and compensation)(irishstatutebook.ie).gov
  6. S.I. No. 336/2011 (ePrivacy Regulations) - cookies and electronic marketing(irishstatutebook.ie).gov
  7. Data Protection Act 2018 - gov.ie(gov.ie).gov
  8. Data Protection and the GDPR - Department of Enterprise(enterprise.gov.ie).gov
  9. Overview of the GDPR - Citizens Information(citizensinformation.ie).gov
  10. Your Rights under the GDPR - DPC(dataprotection.ie).gov
  11. Breach Notification - DPC(dataprotection.ie).gov
  12. Data Protection Officers - DPC(dataprotection.ie).gov
  13. Data Protection Impact Assessments - DPC(dataprotection.ie).gov
  14. Guidance on Legal Bases for Processing - DPC(dataprotection.ie).gov
  15. DPC Instagram Inquiry Decision(dataprotection.ie).gov
  16. DPC Meta Ireland Data Transfers Decision (1.2bn euro fine, May 2023)(dataprotection.ie).gov
  17. DPC TikTok Children Fine(dataprotection.ie).gov
  18. DPC fines TikTok 530 million euros over EEA-China transfers (May 2025)(dataprotection.ie).gov
  19. DPC LinkedIn Fine(dataprotection.ie).gov
  20. DPC Meta 251 Million Fine(dataprotection.ie).gov
  21. DPC Meta 91 Million Fine (Sept 2024)(dataprotection.ie).gov
  22. WhatsApp Ireland Decision - DPC(dataprotection.ie).gov
  23. DPC X (Twitter) AI Training Inquiry (April 2025)(dataprotection.ie).gov
  24. DPC Statement on Meta AI Training (May 2025)(dataprotection.ie).gov
  25. DPC 2024 Annual Report(dataprotection.ie).gov
  26. EDPB Binding Decision on Meta 1.2B Fine(edpb.europa.eu).gov
  27. EDPB Record Fine for Instagram(edpb.europa.eu).gov
  28. EDPB TikTok Ireland Fine(edpb.europa.eu).gov
  29. EDPB Statement on DPAs Role in AI Act Framework(edpb.europa.eu).gov
  30. EU AI Act - Department of Enterprise, Trade and Employment(enterprise.gov.ie).gov
  31. Ireland AI Act Implementation Roadmap (March 2025)(enterprise.gov.ie).gov
  32. Right of Access - DPC(dataprotection.ie).gov
  33. Right to Erasure - DPC(dataprotection.ie).gov
  34. Workplace Surveillance - Citizens Information(citizensinformation.ie).gov
Share: