{
 "jurisdiction_id": "IE",
 "jurisdiction": "Ireland",
 "url": "https://dataprotection.gi/jurisdictions/ireland/",
 "generator": "render_jid v13-gdpri-1.0.0",
 "date_modified": "2026-08-05",
 "schema_version": "gdpri-v2",
 "counts": {
  "categories": 10,
  "claims": 40,
  "sub_modules": 57,
  "source_register": 24
 },
 "categories": [
  {
   "code": "regulator_and_framework",
   "name": "Regulator & Framework",
   "traffic_light": "green",
   "sub_modules": [
    "act_and_instruments",
    "material_scope",
    "regulator_and_authority",
    "regulator_registration_and_filing",
    "territorial_scope"
   ],
   "url": "https://dataprotection.gi/jurisdictions/ireland/#regulator-and-framework-regulator-framework",
   "traffic_light_rationale": "Comprehensive, fully in-force omnibus framework with an active, well-resourced regulator and clear statutory authority.",
   "claims": [
    {
     "statement": "The Data Protection Commission (DPC), established under Section 10 of the Data Protection Act 2018, is Ireland's supervisory authority responsible for the purposes of the GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/sites/default/files/ie_sa_gdpr_art_97questionnaire.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Data Protection Act 2018 gives further effect to the GDPR and, having commenced on 25 May 2018, repealed the Data Protection Acts of 1988 and 2003 except for provisions relating to processing for national security, defence, and international relations of the State.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance / OneTrust",
     "source_url": "https://legacy.dataguidance.com/jurisdiction/ireland",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The GDPR pursues a two-fold objective in Ireland's material scope: protecting the fundamental rights of natural persons regarding personal data, and allowing the free flow of personal data and digital-economy development.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/sites/default/files/ie_sa_gdpr_art_97questionnaire.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "GDPR Article 3(2) extends application to controllers/processors not established in the Union where processing relates to offering goods or services to, or monitoring, data subjects in the Union, thereby extending Irish/EU jurisdiction extraterritorially.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/system/files/documents/files/file1/edpb_guidelines_3_2018_territorial_scope_after_public_consultation_en_1.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Data controllers and processors are required to publish their DPO's contact details and communicate them to the DPC (and other relevant supervisory authorities), in lieu of a general controller-registration filing regime post-GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance / OneTrust",
     "source_url": "https://legacy.dataguidance.com/jurisdiction/ireland",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "lawful_processing_and_special_data",
   "name": "Lawful Processing & Special Data",
   "traffic_light": "green",
   "sub_modules": [
    "consent_thresholds",
    "lawful_bases",
    "pseudonymisation_and_anonymisation",
    "special_categories"
   ],
   "url": "https://dataprotection.gi/jurisdictions/ireland/#lawful-processing-and-special-data-lawful-processing-special-data",
   "traffic_light_rationale": "Core lawful-basis and special-category rules are fully in force and well documented; the pseudonymisation/anonymisation sub-module lacks a directly retrieved DPC-specific source in this run.",
   "claims": [
    {
     "statement": "Processing is lawful under GDPR Article 6(1)(b) where necessary for performance of a contract to which the data subject is party, or to take steps at the data subject's request prior to entering a contract.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Data Protection Commission",
     "source_url": "https://www.dataguidance.com/sites/default/files/fundamentals_for_a_child-oriented_approach_to_data_processing_final_en.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Ireland has set the age of digital consent under Article 8 GDPR, read with the Data Protection Act 2018, at 16 years, meaning online service providers generally cannot rely on a child's own consent below that age.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Data Protection Commission",
     "source_url": "https://www.dataguidance.com/sites/default/files/fundamentals_for_a_child-oriented_approach_to_data_processing_final_en.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Data Protection Act 2018 introduced a lawful processing ground permitting health data to be processed where necessary for insurance, health-insurance, occupational pension, retirement annuity, or property-mortgaging purposes.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/ireland-data-protection-bill/",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "data_subject_rights",
   "name": "Data Subject Rights",
   "traffic_light": "amber",
   "sub_modules": [
    "access_right",
    "data_portability",
    "deadlines_and_response_windows",
    "rectification_and_erasure",
    "restriction_and_objection"
   ],
   "url": "https://dataprotection.gi/jurisdictions/ireland/#data-subject-rights-data-subject-rights",
   "traffic_light_rationale": "Access/erasure/rectification and deadline mechanisms are well evidenced; restriction, objection and portability sub-modules rely on the general GDPR baseline without a directly retrieved DPC-specific source.",
   "claims": [
    {
     "statement": "The DPC's 2024 case-study report addresses recurring issues in handling subject access requests, alongside deletion and rectification requests.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/key-takeaways-from-ireland-s-dpc-annual-report",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "DPC case studies published alongside the 2024 Annual Report specifically address rectification and erasure ('right to be forgotten') requests as a recurring compliance theme.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/key-takeaways-from-ireland-s-dpc-annual-report",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under Section 109 of the Data Protection Act 2018, the DPC takes steps to arrange or facilitate amicable resolution of complaints where there is a reasonable likelihood of the parties reaching resolution within a reasonable time, offering data subjects a comparatively fast route to vindication of rights.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/sites/default/files/ie_sa_gdpr_art_97questionnaire.pdf",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "controller_processor_duties",
   "name": "Controller/Processor Duties",
   "traffic_light": "amber",
   "sub_modules": [
    "accountability_and_dpia",
    "breach_notification",
    "dpo_requirements",
    "joint_controller_arrangements",
    "retention_and_disposal",
    "ropa_requirements",
    "security_measures"
   ],
   "url": "https://dataprotection.gi/jurisdictions/ireland/#controller-processor-duties-controller-processor-duties",
   "traffic_light_rationale": "DPO, accountability/DPIA, security and breach-notification sub-modules are strongly evidenced by enforcement activity; ROPA, joint-controller and retention sub-modules rely on the unevidenced general GDPR baseline.",
   "claims": [
    {
     "statement": "Under Article 39 GDPR, appointed Data Protection Officers must monitor internal compliance, act as contact point for data subjects exercising rights, and liaise with the supervisory authority; the DPC has reported more than 1,500 new DPOs appointed in Ireland following the GDPR's introduction.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/irish-dpc-discusses-role-dpos",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DPC has been particularly active in issuing guidance on Data Protection Impact Assessments and other accountability topics such as cookies and breach notification.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance / OneTrust",
     "source_url": "https://legacy.dataguidance.com/jurisdiction/ireland",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Following an inquiry into City of Dublin Education and Training Board, the DPC ordered the controller to bring its processing into compliance with the security requirements of the GDPR.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/news/irish-sa-imposes-eu125000-administrative-fine-following-inquiry-into-city-of-dublin-education_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DPC found CDETB infringed Article 33(1) GDPR by failing to notify the DPC of a personal data breach without undue delay, and Articles 34(1) and 34(4) GDPR by failing to notify affected data subjects when required.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/news/irish-sa-imposes-eu125000-administrative-fine-following-inquiry-into-city-of-dublin-education_en",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "cross_border_and_adequacy",
   "name": "Cross-Border & Adequacy",
   "traffic_light": "amber",
   "sub_modules": [
    "adequacy_granted",
    "adequacy_received",
    "data_localisation",
    "sccs_and_bcrs",
    "transfer_impact_assessment",
    "transfer_mechanisms"
   ],
   "url": "https://dataprotection.gi/jurisdictions/ireland/#cross-border-and-adequacy-cross-border-adequacy",
   "traffic_light_rationale": "Transfer-mechanism enforcement (TikTok, Meta) and adequacy-received status are strongly evidenced; adequacy-granted and data-localisation sub-modules are EU-level/absent for this JID.",
   "claims": [
    {
     "statement": "The DPC, as lead supervisory authority for TikTok, found that TikTok's transfers of EEA user data to China infringed Article 46(1) GDPR because it failed to verify, guarantee and demonstrate that SCCs and supplementary measures were effective to ensure a level of protection essentially equivalent to that guaranteed within the EU.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/news/news/2025/irish-supervisory-authority-fines-tiktok-eu530-million-and-orders-corrective_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DPC imposed administrative fines totalling €530 million on TikTok, comprising €45 million for the Article 13(1)(f) transparency infringement and €485 million for the Article 46(1) transfer infringement.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/news/news/2025/irish-supervisory-authority-fines-tiktok-eu530-million-and-orders-corrective_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "As an EU Member State, Ireland benefits from the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework, adopted 10 July 2023, allowing personal data to flow from the EEA to the U.S. without further conditions or authorisations.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/european-commission-adopts-eu-u-s-adequacy-decision",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DPC's decision against Meta found that the substantial supplementary measures Meta layered on top of SCCs did not compensate for deficiencies in U.S. law identified in Schrems II, reinforcing the requirement for a documented transfer impact assessment before relying on SCCs for EU-to-US transfers.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/meta-fined-gdpr-record-1-2-billion-euros-in-data-transfer-case",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "sectoral_watch",
   "name": "Sectoral Watch",
   "traffic_light": "amber",
   "sub_modules": [
    "credit_and_scoring",
    "education",
    "employment_data",
    "financial_sector_overlay",
    "health_sector_overlay",
    "insurance",
    "telecoms_and_eprivacy"
   ],
   "url": "https://dataprotection.gi/jurisdictions/ireland/#sectoral-watch-sectoral-watch",
   "traffic_light_rationale": "Telecoms/ePrivacy, education and insurance overlays are evidenced; financial-sector and credit-scoring sub-modules lack substantive DPC-specific sourcing in this run.",
   "claims": [
    {
     "statement": "The DPC has functions and powers under S.I. No. 336 of 2011 (European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations), which implements the ePrivacy Directive and governs cookies and electronic marketing in Ireland.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance / OneTrust",
     "source_url": "https://www.dataguidance.com/notes/ireland-data-protection-overview",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DPC's inquiry into City of Dublin Education and Training Board (CDETB), an education-sector public body, resulted in a reprimand and €125,000 in administrative fines for GDPR security and breach-notification failures.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/news/irish-sa-imposes-eu125000-administrative-fine-following-inquiry-into-city-of-dublin-education_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Data Protection Act 2018 permits processing of health data without explicit consent where necessary for insurance, health-insurance, occupational pension, retirement-annuity, or property-mortgaging purposes, creating a sector-specific overlay for insurance and financial services.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/ireland-data-protection-bill/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Employment-context data processing in Ireland is addressed through general GDPR derogations rather than extensive DPA 2018 elaboration, with practitioner guidance covering collection, processing and retention of employee data including health data.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "DataGuidance / OneTrust",
     "source_url": "https://legacy.dataguidance.com/jurisdiction/ireland",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "adtech_and_commercial_privacy",
   "name": "AdTech & Commercial Privacy",
   "traffic_light": "amber",
   "sub_modules": [
    "clean_rooms_and_dcr",
    "cookies_and_trackers",
    "cross_context_advertising",
    "dark_patterns",
    "direct_marketing",
    "opt_out_signals"
   ],
   "url": "https://dataprotection.gi/jurisdictions/ireland/#adtech-and-commercial-privacy-adtech-commercial-privacy",
   "traffic_light_rationale": "Cookies, direct marketing and cross-context (behavioural) advertising are well evidenced through enforcement; dark patterns, opt-out signals and clean rooms lack retrieved sourcing.",
   "claims": [
    {
     "statement": "Under S.I. No. 336 of 2011, websites must make information available about cookie usage; the DPC historically clarified that this does not impose a need for explicit separate consent for standard third-party analytics services such as Google Analytics.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/2011-10-24-commissioner-clarifies-directive-implementation/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DPC's 2024 enforcement activity included prosecutions of a gym, clinic, fast-food company and Google for sending unsolicited marketing SMS messages.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/key-takeaways-from-ireland-s-dpc-annual-report",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DPC fined Meta Ireland €390 million after finding Meta could not rely on the 'contract' legal basis under Article 6 GDPR for delivering behavioural/personalised advertising on Facebook and Instagram.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/irish-dpc-fines-meta-390m-euros-over-legal-basis-for-personalized-ads",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "algorithmic_biometric_and_surveillance_governance",
   "name": "Algorithmic, Biometric & Surveillance Governance",
   "traffic_light": "amber",
   "sub_modules": [
    "ai_risk_assessments",
    "automated_decision_making_transparency",
    "biometric_regime",
    "genetic_data",
    "profiling_restrictions",
    "state_surveillance_carveouts"
   ],
   "url": "https://dataprotection.gi/jurisdictions/ireland/#algorithmic-biometric-and-surveillance-governance-algorithmic-biometric-surveill",
   "traffic_light_rationale": "Profiling restrictions and state-surveillance carve-outs are evidenced; ADM transparency, biometric regime and genetic data sub-modules lack directly retrieved DPC-specific sourcing.",
   "claims": [
    {
     "statement": "The DPC's finding that Meta's 'contract' legal basis was invalid for behavioural-advertising profiling activities constrains how controllers may justify profiling-based ad personalisation absent valid consent.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/irish-dpc-fines-meta-390m-euros-over-legal-basis-for-personalized-ads",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DPC's 2024 Annual Report highlights its evolving role under the EU Artificial Intelligence Act and other digital laws, reflecting growing overlap between GDPR enforcement and AI governance obligations.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Probable",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/key-takeaways-from-ireland-s-dpc-annual-report",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Data Protection Act 2018 preserved provisions of the repealed 1988/2003 Acts specifically relating to processing of personal data for national security, defence, and international relations purposes, carving these out from the Act's general repeal.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance / OneTrust",
     "source_url": "https://legacy.dataguidance.com/jurisdiction/ireland",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "children_and_vulnerable_groups",
   "name": "Children & Vulnerable Groups",
   "traffic_light": "amber",
   "sub_modules": [
    "age_verification",
    "dependent_adults",
    "education_settings",
    "minor_profiling_bans",
    "parental_consent"
   ],
   "url": "https://dataprotection.gi/jurisdictions/ireland/#children-and-vulnerable-groups-children-vulnerable-groups",
   "traffic_light_rationale": "Age-of-consent and education-setting guidance are strongly evidenced; minor-profiling-ban and dependent-adult sub-modules lack directly retrieved DPC-specific sourcing.",
   "claims": [
    {
     "statement": "The GDPR permits Member States to set the age of digital consent for information society services between 13 and 16 years, and Ireland elected the maximum permissible age of 16.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/system/files/documents/files/file1/edpb_guidelines_3_2018_territorial_scope_after_public_consultation_en_1.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Ireland's Data Protection Act 2018 sets the age of digital consent at 16 years under Article 8 GDPR, requiring parental consent for information-society-service processing of children's data below that age.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "Data Protection Commission",
     "source_url": "https://www.dataguidance.com/sites/default/files/fundamentals_for_a_child-oriented_approach_to_data_processing_final_en.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DPC published its finalised guidance, 'Fundamentals for a Child-Oriented Approach to Data Processing,' on 17 December 2021, covering data processing in offline educational, sporting, social and health/support settings likely to be accessed by children.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance / OneTrust",
     "source_url": "https://legacy.dataguidance.com/jurisdiction/ireland",
     "source_tier": null,
     "observed_at": null
    }
   ]
  },
  {
   "code": "enforcement_and_redress",
   "name": "Enforcement & Redress",
   "traffic_light": "green",
   "sub_modules": [
    "collective_redress_and_class_actions",
    "enforcement_activity_index",
    "private_right_of_action",
    "recent_developments_180d",
    "regulator_funding_and_capacity",
    "regulator_powers_and_penalties"
   ],
   "url": "https://dataprotection.gi/jurisdictions/ireland/#enforcement-and-redress-enforcement-redress",
   "traffic_light_rationale": "Enforcement powers, penalty scale, and recent developments are extensively evidenced through primary regulator decisions and secondary reporting.",
   "claims": [
    {
     "statement": "The DPC concluded four large-scale cross-border inquiries in 2024, resulting in administrative fines totalling more than €652 million.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/key-takeaways-from-ireland-s-dpc-annual-report",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Irish SA imposed administrative fines totalling €530 million on TikTok for infringements of Articles 13(1)(f) and 46(1) GDPR relating to transfers of EEA user data to China.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/news/news/2025/irish-supervisory-authority-fines-tiktok-eu530-million-and-orders-corrective_en",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In 2024 the DPC concluded 2,357 formal complaints and resolved a further 8,418 cases through amicable means.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/key-takeaways-from-ireland-s-dpc-annual-report",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The DPC's headcount has grown to nearly 300 staff, up from 27 in 2014, though Commissioner Sweeney noted in 2026 that growth has plateaued with only some active hires continuing.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/new-irish-data-protection-commissioner-niamh-sweeney-addresses-scrutiny-over-her-appointment-shares-agency-priorities",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "Under Irish law, DPC administrative fines must be confirmed by the courts before they can be collected; as of 2026 the DPC has 13 of its 15 large concluded investigations in litigation and over 40 active court cases.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/new-irish-data-protection-commissioner-niamh-sweeney-addresses-scrutiny-over-her-appointment-shares-agency-priorities",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "The Data Protection Act 2018 enables a data subject to mandate a not-for-profit body to lodge a complaint with the DPC or bring a judicial action on the data subject's behalf, though such representative court actions cannot result in an award of material or non-material damages -- only an injunction or declaration.",
     "regulatory_stage": "in_force",
     "is_binding": true,
     "confidence": "Confirmed",
     "source_publisher": "DataGuidance",
     "source_url": "https://www.dataguidance.com/ireland-data-protection-bill/",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "In January 2026 the EDPB published an updated version (2.0) of its EU-U.S. Data Privacy Framework FAQ for European individuals, reflecting continued monitoring of the adequacy decision governing EU-to-US personal data transfers relevant to Irish controllers.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "European Data Protection Board",
     "source_url": "https://www.edpb.europa.eu/system/files/2026-01/edpb_dpf_faq-for-individuals_v2_en.pdf",
     "source_tier": null,
     "observed_at": null
    },
    {
     "statement": "At the IAPP Global Summit 2026, newly appointed DPC Commissioner Niamh Sweeney (whose five-year term began 13 October 2025) outlined 2026 enforcement priorities, including ongoing litigation with TikTok over data transfers to China and continued reliance on corrective measures alongside fines.",
     "regulatory_stage": null,
     "is_binding": false,
     "confidence": "Confirmed",
     "source_publisher": "IAPP",
     "source_url": "https://iapp.org/news/a/new-irish-data-protection-commissioner-niamh-sweeney-addresses-scrutiny-over-her-appointment-shares-agency-priorities",
     "source_tier": null,
     "observed_at": null
    }
   ]
  }
 ]
}