🔒 Data Protection Regulatory Intelligence
GDPRI · dataprotection.gi
IE · run data-protection-2026-07-29 v13-gdpri-1.0.0
content: ai_generated 21 sources retrieved model claude-sonnet-5 ·

Ireland

IE schema gdpri-v2 trajectory: not recorded

Last updated · 10 categories · 40 claims · 21 sources in the cumulative register

10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
40Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix (sums to 10 rendered categories; click to filter)
No categories are currently flagged red.

Jurisdiction brief

Lead Signal

Ireland's Data Protection Commission has closed out a run of cross-border enforcement decisions that reset the practical boundaries of transatlantic data transfers and behavioural advertising. The DPC, as lead supervisory authority for TikTok, found that the platform's transfers of EEA user data to China infringed Article 46(1) GDPR because TikTok failed to verify that its standard contractual clauses and supplementary measures were actually effective, and imposed €530 million in fines split between a €45 million penalty for Article 13(1)(f) transparency failures and €485 million for the Article 46(1) transfer failure. In a separate decision, the DPC found that Meta's supplementary measures layered on top of SCCs did not cure the deficiencies identified in Schrems II, reinforcing that a documented transfer impact assessment is now the operative expectation rather than an optional accountability exercise. The DPC also fined Meta Ireland €390 million after concluding that Meta could not rely on the "contract" legal basis under Article 6 GDPR to justify behavioural and personalised advertising. Set against this enforcement record, a challenger-level review of the underlying EU-US Data Privacy Framework adequacy decision has corrected an earlier overstatement: the adequacy finding permits EEA-to-US transfers only where the receiving US organisation has self-certified and maintains DPF compliance, and transfers to non-certified recipients still require SCCs or other Article 46 safeguards -- it is not an unconditional adequacy finding for the United States as a whole. That same review flags that the adequacy decision, while formally in force, faces a live supersession risk via the pending CJEU appeal in Latombe v Commission and a June 2026 noyb letter arguing that a US Supreme Court ruling undermines the FTC's independence, a pillar of the adequacy finding.

10 of 10 categories
Signal
Density

Selections OR within a group, AND across groups. Press / to search.

#

Comprehensive, fully in-force omnibus framework with an active, well-resourced regulator and clear statutory authority.

Primary frameworkGDPR (Regulation (EU) 2016/679) as implemented by the Data Protection Act 2018
Traffic-light rationale — GreenComprehensive, fully in-force omnibus framework with an active, well-resourced regulator and clear statutory authority.

Sub-modules (5)

Regulator And AuthorityGreen

The DPC is Ireland's independent supervisory authority for GDPR, statutorily established under Section 10 of the Data Protection Act 2018.

Claims: CLM-IE-a1b2c301

Act And InstrumentsGreen

The Data Protection Act 2018 gives further effect to the GDPR and repealed the 1988/2003 Acts (save national-security/defence/international-relations processing carve-outs).

Claims: CLM-IE-b2c3d402

Material ScopeGreen

The GDPR's dual objective -- protecting the fundamental right to data protection while enabling free data flow -- defines material scope of application in Ireland.

Claims: CLM-IE-c3d4e503

Territorial ScopeGreen

Article 3(2) GDPR extends the Irish/EU regime extraterritorially to non-EU-established controllers targeting or monitoring EU data subjects.

Claims: CLM-IE-d4e5f604

Regulator Registration And FilingAmber

Ireland imposes no general controller-registration requirement post-GDPR; the principal filing obligation is DPO-contact-detail publication/communication to the DPC under Article 37 GDPR.

Claims: CLM-IE-e5f60705

Category narrative69 words

Ireland's data protection regime is the EU's GDPR (Regulation (EU) 2016/679) as given further effect domestically by the Data Protection Act 2018, which commenced 25 May 2018 and established the Data Protection Commission (DPC) under Section 10 as the national supervisory authority. Ireland's status as host jurisdiction for the EU/EEA establishments of many major technology platforms makes the DPC a frequent lead supervisory authority under the GDPR's one-stop-shop mechanism.

No periodic updates recorded against this sub-brief.

Sources and claims (5)
  1. ConfirmedEuropean Data Protection BoardThe Data Protection Commission (DPC), established under Section 10 of the Data Protection Act 2018, is Ireland's supervisory authority responsible for the purposes of the GDPR.
  2. ConfirmedDataGuidance / OneTrustThe Data Protection Act 2018 gives further effect to the GDPR and, having commenced on 25 May 2018, repealed the Data Protection Acts of 1988 and 2003 except for provisions relating to processing for national security, defence, and international relations of the State.
  3. ConfirmedEuropean Data Protection BoardThe GDPR pursues a two-fold objective in Ireland's material scope: protecting the fundamental rights of natural persons regarding personal data, and allowing the free flow of personal data and digital-economy development.
  4. ConfirmedEuropean Data Protection BoardGDPR Article 3(2) extends application to controllers/processors not established in the Union where processing relates to offering goods or services to, or monitoring, data subjects in the Union, thereby extending Irish/EU jurisdiction extraterritorially.
  5. ConfirmedDataGuidance / OneTrustData controllers and processors are required to publish their DPO's contact details and communicate them to the DPC (and other relevant supervisory authorities), in lieu of a general controller-registration filing regime post-GDPR.

#

Core lawful-basis and special-category rules are fully in force and well documented; the pseudonymisation/anonymisation sub-module lacks a directly retrieved DPC-specific source in this run.

Primary frameworkGDPR Articles 6-9 as supplemented by the Data Protection Act 2018
Traffic-light rationale — GreenCore lawful-basis and special-category rules are fully in force and well documented; the pseudonymisation/anonymisation sub-module lacks a directly retrieved DPC-specific source in this run.

Sub-modules (4)

Lawful BasesGreen

Article 6(1)(b) contractual-necessity basis, among the enumerated GDPR lawful bases, applies where processing is necessary for performance of, or entry into, a contract.

Claims: CLM-IE-f6070816

Special CategoriesAmber

The Data Protection Act 2018 created a bespoke lawful ground for processing health data necessary for insurance, pension and mortgage purposes.

Claims: CLM-IE-0708186b

Pseudonymisation And AnonymisationRed

No DPC-specific pseudonymisation/anonymisation guidance or safe-harbour provision was retrieved in this research pass.

Absence provenance: not recorded. Searched: not recorded.

Category narrative48 words

Lawful bases follow GDPR Article 6, with the Data Protection Act 2018 setting Ireland's age of digital consent (Article 8 GDPR) at 16 years and adding a bespoke lawful ground permitting insurance-related health-data processing. Pseudonymisation/anonymisation safe-harbour guidance specific to the DPC was not located in this research pass.

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ConfirmedData Protection CommissionProcessing is lawful under GDPR Article 6(1)(b) where necessary for performance of a contract to which the data subject is party, or to take steps at the data subject's request prior to entering a contract.
  2. ConfirmedData Protection CommissionIreland has set the age of digital consent under Article 8 GDPR, read with the Data Protection Act 2018, at 16 years, meaning online service providers generally cannot rely on a child's own consent below that age.
  3. ProbableDataGuidanceThe Data Protection Act 2018 introduced a lawful processing ground permitting health data to be processed where necessary for insurance, health-insurance, occupational pension, retirement annuity, or property-mortgaging purposes.

#

Access/erasure/rectification and deadline mechanisms are well evidenced; restriction, objection and portability sub-modules rely on the general GDPR baseline without a directly retrieved DPC-specific source.

Primary frameworkGDPR Articles 12-22 as administered by the Data Protection Act 2018
Traffic-light rationale — AmberAccess/erasure/rectification and deadline mechanisms are well evidenced; restriction, objection and portability sub-modules rely on the general GDPR baseline without a directly retrieved DPC-specific source.

Sub-modules (5)

Access RightGreen

DPC 2024 case studies specifically address subject access request handling as a recurring compliance issue.

Claims: CLM-IE-1819192c

Rectification And ErasureGreen

The same DPC case-study reporting addresses rectification and erasure ('right to be forgotten') requests.

Claims: CLM-IE-19192a3d

Restriction And ObjectionRed

No DPC-specific source on restriction (Art 18) or objection (Art 21) practice was retrieved in this pass; the general GDPR baseline applies.

Absence provenance: not recorded. Searched: not recorded.

Data PortabilityRed

No DPC-specific portability (Art 20) guidance or enforcement was retrieved in this pass; the general GDPR baseline applies.

Absence provenance: not recorded. Searched: not recorded.

Deadlines And Response WindowsGreen

Section 109 DPA 2018 empowers the DPC to facilitate amicable complaint resolution within a reasonable time, offering data subjects a faster route to remedy than full statutory inquiry.

Claims: CLM-IE-2a3d4b5e

Category narrative67 words

GDPR Articles 13-22 provide the framework for access, rectification, erasure, restriction, objection and portability rights, enforced in Ireland by the DPC. The DPC's 2024 case-study reporting highlights access, deletion and rectification requests as recurring themes, and Section 109 of the Data Protection Act 2018 provides an amicable-resolution route with a comparatively fast response window. Direct DPC-specific sourcing on restriction/objection and portability was not retrieved in this pass.

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ProbableIAPPThe DPC's 2024 case-study report addresses recurring issues in handling subject access requests, alongside deletion and rectification requests.
  2. ProbableIAPPDPC case studies published alongside the 2024 Annual Report specifically address rectification and erasure ('right to be forgotten') requests as a recurring compliance theme.
  3. ConfirmedEuropean Data Protection BoardUnder Section 109 of the Data Protection Act 2018, the DPC takes steps to arrange or facilitate amicable resolution of complaints where there is a reasonable likelihood of the parties reaching resolution within a reasonable time, offering data subjects a comparatively fast route to vindication of rights.

#

DPO, accountability/DPIA, security and breach-notification sub-modules are strongly evidenced by enforcement activity; ROPA, joint-controller and retention sub-modules rely on the unevidenced general GDPR baseline.

Primary frameworkGDPR Articles 5, 24-39 as administered by the Data Protection Act 2018
Traffic-light rationale — AmberDPO, accountability/DPIA, security and breach-notification sub-modules are strongly evidenced by enforcement activity; ROPA, joint-controller and retention sub-modules rely on the unevidenced general GDPR baseline.

Sub-modules (7)

Accountability And DpiaGreen

The DPC has been particularly active in issuing DPIA and accountability guidance.

Claims: CLM-IE-4b5c6d70

Dpo RequirementsGreen

Article 39 DPO obligations are in force; the DPC reports over 1,500 new DPOs appointed in Ireland post-GDPR.

Claims: CLM-IE-3d4b5c6f

Ropa RequirementsRed

No DPC-specific ROPA (Article 30) enforcement or guidance beyond a general reference to published Article 30 guidance was retrieved with sufficient substantive detail in this pass.

Absence provenance: not recorded. Searched: not recorded.

Joint Controller ArrangementsRed

No DPC-specific joint-controller arrangement guidance or enforcement was retrieved in this pass.

Absence provenance: not recorded. Searched: not recorded.

Security MeasuresGreen

The CDETB inquiry resulted in an order to bring processing into compliance with GDPR security-of-processing requirements.

Claims: CLM-IE-5c6d7e81

Breach NotificationGreen

The CDETB inquiry found infringements of Articles 33(1), 34(1) and 34(4) GDPR for failure to notify the DPC and affected data subjects of a breach without undue delay.

Claims: CLM-IE-6d7e8f92

Retention And DisposalRed

No DPC-specific retention/disposal guidance or enforcement decision was retrieved in this pass.

Absence provenance: not recorded. Searched: not recorded.

Category narrative44 words

GDPR accountability, DPO, security and breach-notification duties are in force and actively enforced, illustrated by the DPC's inquiry into City of Dublin Education and Training Board (CDETB) for security and breach-notification failures. ROPA-specific, joint-controller-specific and retention-and-disposal-specific DPC sourcing was not retrieved in this pass.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ConfirmedIAPPUnder Article 39 GDPR, appointed Data Protection Officers must monitor internal compliance, act as contact point for data subjects exercising rights, and liaise with the supervisory authority; the DPC has reported more than 1,500 new DPOs appointed in Ireland following the GDPR's introduction.
  2. ConfirmedDataGuidance / OneTrustThe DPC has been particularly active in issuing guidance on Data Protection Impact Assessments and other accountability topics such as cookies and breach notification.
  3. ConfirmedEuropean Data Protection BoardFollowing an inquiry into City of Dublin Education and Training Board, the DPC ordered the controller to bring its processing into compliance with the security requirements of the GDPR.
  4. ConfirmedEuropean Data Protection BoardThe DPC found CDETB infringed Article 33(1) GDPR by failing to notify the DPC of a personal data breach without undue delay, and Articles 34(1) and 34(4) GDPR by failing to notify affected data subjects when required.

#

Transfer-mechanism enforcement (TikTok, Meta) and adequacy-received status are strongly evidenced; adequacy-granted and data-localisation sub-modules are EU-level/absent for this JID.

Primary frameworkGDPR Chapter V (Articles 44-49) as administered by the DPC
Traffic-light rationale — AmberTransfer-mechanism enforcement (TikTok, Meta) and adequacy-received status are strongly evidenced; adequacy-granted and data-localisation sub-modules are EU-level/absent for this JID.

Sub-modules (6)

Transfer MechanismsAmber

The DPC's TikTok decision found infringement of Article 46(1) GDPR where SCC supplementary measures were not verified as effective for EEA-to-China transfers.

Claims: CLM-IE-7e8f90a3

Adequacy ReceivedAmber

As an EU Member State, Ireland benefits from the European Commission's EU-US Data Privacy Framework adequacy decision (10 July 2023).

Claims: CLM-IE-90a1b2c5

Adequacy GrantedRed

Adequacy decisions are granted by the European Commission at EU level, not by Ireland individually; no Ireland-specific adequacy-granting act was identified, consistent with JID scoping discipline.

Absence provenance: not recorded. Searched: not recorded.

Sccs And BcrsAmber

The TikTok decision resulted in €530 million in fines split between transparency (Art 13(1)(f)) and unlawful-transfer (Art 46(1)) infringements tied to SCC reliance.

Claims: CLM-IE-8f90a1b4

Transfer Impact AssessmentAmber

The Meta decision established that supplementary measures layered on SCCs did not cure deficiencies identified in Schrems II, reinforcing the practical need for a documented transfer impact assessment.

Claims: CLM-IE-a1b2c3d6

Data LocalisationRed

No Ireland-specific data-localisation mandate was identified in this research pass; Ireland relies on the GDPR's harmonised transfer regime rather than a partial or absolute localisation requirement.

Absence provenance: not recorded. Searched: not recorded.

Category narrative65 words

Ireland relies on the EU's transfer mechanisms (SCCs, BCRs, adequacy decisions, derogations) under GDPR Chapter V. The DPC's TikTok and Meta decisions are the leading Irish precedents on SCC transfer-impact-assessment adequacy, and Ireland benefits from the EU-US Data Privacy Framework adequacy decision as an EU Member State. Adequacy-granting is an EU Commission competence rather than an Irish-specific act, and no Ireland-specific data-localisation mandate was identified.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ConfirmedEuropean Data Protection BoardThe DPC, as lead supervisory authority for TikTok, found that TikTok's transfers of EEA user data to China infringed Article 46(1) GDPR because it failed to verify, guarantee and demonstrate that SCCs and supplementary measures were effective to ensure a level of protection essentially equivalent to that guaranteed within the EU.
  2. ConfirmedEuropean Data Protection BoardThe DPC imposed administrative fines totalling €530 million on TikTok, comprising €45 million for the Article 13(1)(f) transparency infringement and €485 million for the Article 46(1) transfer infringement.
  3. ConfirmedIAPPAs an EU Member State, Ireland benefits from the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework, adopted 10 July 2023, allowing personal data to flow from the EEA to the U.S. without further conditions or authorisations.
  4. ConfirmedIAPPThe DPC's decision against Meta found that the substantial supplementary measures Meta layered on top of SCCs did not compensate for deficiencies in U.S. law identified in Schrems II, reinforcing the requirement for a documented transfer impact assessment before relying on SCCs for EU-to-US transfers.

#

Telecoms/ePrivacy, education and insurance overlays are evidenced; financial-sector and credit-scoring sub-modules lack substantive DPC-specific sourcing in this run.

Primary frameworkGDPR + sector overlays: S.I. No. 336/2011 (ePrivacy); Data Protection Act 2018 (insurance-related health-data ground)
Traffic-light rationale — AmberTelecoms/ePrivacy, education and insurance overlays are evidenced; financial-sector and credit-scoring sub-modules lack substantive DPC-specific sourcing in this run.

Sub-modules (7)

Financial Sector OverlayRed

No substantive DPC-specific financial-sector overlay content (beyond the insurance-related health-data ground captured under the insurance sub-module) was retrieved in this pass.

Absence provenance: not recorded. Searched: not recorded.

Health Sector OverlayAmber

Health-sector-specific processing is principally addressed via the DPA 2018 insurance-related health-data lawful ground; no separate general health-sector DPC guidance was retrieved.

Claims: CLM-IE-d4e5f609

Telecoms And EprivacyGreen

The DPC exercises functions under S.I. No. 336 of 2011, Ireland's implementation of the ePrivacy Directive, governing cookies and electronic-communications privacy.

Claims: CLM-IE-b2c3d4e7

Employment DataAmber

Employment-context processing in Ireland relies on general GDPR derogations; practitioner commentary addresses collection, processing and retention of employee (including health) data.

Claims: CLM-IE-e5f60710

Credit And ScoringRed

Only a title-level reference to a historic DPC fine against an Irish credit bureau was located, without retrievable substantive content in this pass.

Absence provenance: not recorded. Searched: not recorded.

EducationAmber

The DPC's CDETB inquiry is the leading education-sector enforcement precedent, addressing security and breach-notification failures.

Claims: CLM-IE-c3d4e5f8

InsuranceAmber

The Data Protection Act 2018 provides a bespoke lawful ground for insurance-related health-data processing, forming Ireland's principal insurance-sector overlay.

Claims: CLM-IE-d4e5f609

Category narrative56 words

Sectoral overlays in Ireland include the ePrivacy Regulations (S.I. No. 336/2011) for telecoms/electronic communications, a DPA 2018 insurance-specific health-data ground, and education-sector enforcement (CDETB). Employment-data treatment relies on general GDPR derogations rather than extensive statutory elaboration. Financial-sector-specific and credit-scoring-specific DPC sourcing beyond a title-level reference to a historic credit-bureau fine was not retrieved in this pass.

No periodic updates recorded against this sub-brief.

Sources and claims (4)
  1. ConfirmedDataGuidance / OneTrustThe DPC has functions and powers under S.I. No. 336 of 2011 (European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations), which implements the ePrivacy Directive and governs cookies and electronic marketing in Ireland.
  2. ConfirmedEuropean Data Protection BoardThe DPC's inquiry into City of Dublin Education and Training Board (CDETB), an education-sector public body, resulted in a reprimand and €125,000 in administrative fines for GDPR security and breach-notification failures.
  3. ProbableDataGuidanceThe Data Protection Act 2018 permits processing of health data without explicit consent where necessary for insurance, health-insurance, occupational pension, retirement-annuity, or property-mortgaging purposes, creating a sector-specific overlay for insurance and financial services.
  4. ProbableDataGuidance / OneTrustEmployment-context data processing in Ireland is addressed through general GDPR derogations rather than extensive DPA 2018 elaboration, with practitioner guidance covering collection, processing and retention of employee data including health data.

#

Cookies, direct marketing and cross-context (behavioural) advertising are well evidenced through enforcement; dark patterns, opt-out signals and clean rooms lack retrieved sourcing.

Primary frameworkS.I. No. 336/2011 (ePrivacy) + GDPR Article 6 (legal basis for advertising/profiling)
Traffic-light rationale — AmberCookies, direct marketing and cross-context (behavioural) advertising are well evidenced through enforcement; dark patterns, opt-out signals and clean rooms lack retrieved sourcing.

Sub-modules (6)

Cookies And TrackersAmber

S.I. No. 336/2011 requires clear cookie-usage disclosure; the DPC has historically clarified that standard analytics cookies do not require a separate explicit consent step beyond homepage-level disclosure (subject to subsequent guidance evolution).

Claims: CLM-IE-f60701aa

Dark PatternsRed

No DPC-specific dark-pattern enforcement or guidance was retrieved in this pass.

Absence provenance: not recorded. Searched: not recorded.

Opt Out SignalsRed

No DPC-specific Global Privacy Control / opt-out-signal guidance was retrieved in this pass.

Absence provenance: not recorded. Searched: not recorded.

Clean Rooms And DcrRed

No DPC-specific clean-room / data-collaboration-room guidance was retrieved in this pass.

Absence provenance: not recorded. Searched: not recorded.

Cross Context AdvertisingAmber

The DPC's €390 million Meta decision found Meta could not rely on the 'contract' legal basis for behavioural advertising, constraining cross-context/personalised-advertising practices.

Claims: CLM-IE-f60701cc

Direct MarketingGreen

The DPC's 2024 enforcement activity included prosecutions for unsolicited SMS marketing.

Claims: CLM-IE-f60701bb

Category narrative41 words

Cookie and tracker consent is governed by S.I. No. 336/2011, with the DPC actively enforcing direct-marketing rules (2024 SMS-marketing prosecutions) and behavioural-advertising legal-basis requirements (the €390 million Meta decision). Dark-pattern, opt-out-signal and clean-room/data-collaboration-room-specific DPC sourcing was not retrieved in this pass.

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ProbableIAPPUnder S.I. No. 336 of 2011, websites must make information available about cookie usage; the DPC historically clarified that this does not impose a need for explicit separate consent for standard third-party analytics services such as Google Analytics.
  2. ConfirmedIAPPThe DPC's 2024 enforcement activity included prosecutions of a gym, clinic, fast-food company and Google for sending unsolicited marketing SMS messages.
  3. ConfirmedIAPPThe DPC fined Meta Ireland €390 million after finding Meta could not rely on the 'contract' legal basis under Article 6 GDPR for delivering behavioural/personalised advertising on Facebook and Instagram.

#

Profiling restrictions and state-surveillance carve-outs are evidenced; ADM transparency, biometric regime and genetic data sub-modules lack directly retrieved DPC-specific sourcing.

Primary frameworkGDPR Article 22 + EU AI Act (Regulation (EU) 2024/1689)
Traffic-light rationale — AmberProfiling restrictions and state-surveillance carve-outs are evidenced; ADM transparency, biometric regime and genetic data sub-modules lack directly retrieved DPC-specific sourcing.

Sub-modules (6)

Profiling RestrictionsAmber

The Meta decision's invalidation of the 'contract' legal basis for behavioural advertising constrains profiling-based ad personalisation absent valid consent.

Claims: CLM-IE-a90a1e11

Automated Decision Making TransparencyRed

No DPC-specific Article 22 ADM-transparency guidance or decision was retrieved in this pass.

Absence provenance: not recorded. Searched: not recorded.

Ai Risk AssessmentsAmber

The DPC's 2024 Annual Report highlights its evolving role under the EU AI Act, reflecting growing overlap between GDPR enforcement and AI governance obligations.

Claims: CLM-IE-a90a1e22

Biometric RegimeRed

No DPC-specific biometric-regime (facial recognition, fingerprint, gait) guidance or enforcement was retrieved in this pass.

Absence provenance: not recorded. Searched: not recorded.

Genetic DataRed

No DPC-specific genetic-data guidance or enforcement was retrieved in this pass.

Absence provenance: not recorded. Searched: not recorded.

State Surveillance CarveoutsAmber

The Data Protection Act 2018 preserved national-security, defence and international-relations processing carve-outs from the pre-2018 Acts, exempting these from its general repeal.

Claims: CLM-IE-a90a1e33

Category narrative47 words

Ireland's DPC increasingly interfaces with the EU AI Act (Regulation (EU) 2024/1689) alongside its GDPR profiling/ADM remit; the Meta contract-legal-basis decision constrains profiling-based advertising. National-security/defence carve-outs preserved from pre-GDPR law remain the operative state-surveillance carve-out. Biometric-regime, genetic-data and ADM-transparency-specific DPC sourcing was not retrieved in this pass.

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ConfirmedIAPPThe DPC's finding that Meta's 'contract' legal basis was invalid for behavioural-advertising profiling activities constrains how controllers may justify profiling-based ad personalisation absent valid consent.
  2. ProbableIAPPThe DPC's 2024 Annual Report highlights its evolving role under the EU Artificial Intelligence Act and other digital laws, reflecting growing overlap between GDPR enforcement and AI governance obligations.
  3. ConfirmedDataGuidance / OneTrustThe Data Protection Act 2018 preserved provisions of the repealed 1988/2003 Acts specifically relating to processing of personal data for national security, defence, and international relations purposes, carving these out from the Act's general repeal.

#

Age-of-consent and education-setting guidance are strongly evidenced; minor-profiling-ban and dependent-adult sub-modules lack directly retrieved DPC-specific sourcing.

Primary frameworkGDPR Article 8 as implemented by the Data Protection Act 2018
Traffic-light rationale — AmberAge-of-consent and education-setting guidance are strongly evidenced; minor-profiling-ban and dependent-adult sub-modules lack directly retrieved DPC-specific sourcing.

Sub-modules (5)

Age VerificationGreen

GDPR permits Member States to set the digital-consent age between 13 and 16; Ireland elected the maximum permissible age of 16.

Claims: CLM-IE-c1d2e344

Minor Profiling BansRed

No DPC-specific minor-profiling-ban guidance or enforcement was retrieved in this pass.

Absence provenance: not recorded. Searched: not recorded.

Education SettingsGreen

The DPC published finalised guidance on child-oriented data processing covering offline educational, sporting, social and health/support settings likely to be accessed by children.

Claims: CLM-IE-c1d2e366

Dependent AdultsRed

No DPC-specific dependent-adult (elderly, mentally incapacitated) protections guidance was retrieved in this pass.

Absence provenance: not recorded. Searched: not recorded.

Category narrative52 words

Ireland set the GDPR Article 8 age of digital consent at 16 years -- the maximum permitted under the GDPR's 13-16 range -- and the DPC published dedicated child-oriented processing guidance ('Fundamentals for a Child-Oriented Approach to Data Processing', December 2021). Minor-profiling-ban and dependent-adult-specific DPC sourcing was not retrieved in this pass.

No periodic updates recorded against this sub-brief.

Sources and claims (3)
  1. ConfirmedEuropean Data Protection BoardThe GDPR permits Member States to set the age of digital consent for information society services between 13 and 16 years, and Ireland elected the maximum permissible age of 16.
  2. ConfirmedData Protection CommissionIreland's Data Protection Act 2018 sets the age of digital consent at 16 years under Article 8 GDPR, requiring parental consent for information-society-service processing of children's data below that age.
  3. ConfirmedDataGuidance / OneTrustThe DPC published its finalised guidance, 'Fundamentals for a Child-Oriented Approach to Data Processing,' on 17 December 2021, covering data processing in offline educational, sporting, social and health/support settings likely to be accessed by children.

#

Enforcement powers, penalty scale, and recent developments are extensively evidenced through primary regulator decisions and secondary reporting.

Primary frameworkData Protection Act 2018, Part 6 (Sections 109-141) + GDPR Articles 77-84
Traffic-light rationale — GreenEnforcement powers, penalty scale, and recent developments are extensively evidenced through primary regulator decisions and secondary reporting.

Sub-modules (6)

Regulator Powers And PenaltiesGreen

The DPC's 2024 cross-border inquiries produced fines exceeding €652 million; the TikTok decision alone imposed €530 million.

Claims: CLM-IE-e10e10aa, CLM-IE-e10e10bb

Enforcement Activity IndexGreen

In 2024 the DPC concluded 2,357 formal complaints and resolved a further 8,418 cases through amicable means.

Claims: CLM-IE-e10e10cc

Regulator Funding And CapacityGreen

DPC headcount has grown to nearly 300 staff from 27 in 2014, though Commissioner Sweeney noted in 2026 growth has plateaued.

Claims: CLM-IE-e10e10dd

Collective Redress And Class ActionsAmber

Fines require court confirmation before collection, generating substantial litigation volume including judicial review and Article 65 annulment actions.

Claims: CLM-IE-e10e10ee

Private Right Of ActionAmber

DPA 2018 enables not-for-profit bodies to bring representative complaints/actions on behalf of data subjects, though damages are unavailable in such actions.

Claims: CLM-IE-e10e10ff

Recent Developments 180DGreen

Within the last 180 days, the EDPB issued an updated EU-US DPF FAQ (January 2026) and Commissioner Sweeney publicly outlined 2026 enforcement priorities at the IAPP Global Summit, including ongoing TikTok transfer litigation.

Claims: CLM-IE-e10e1011, CLM-IE-e10e1022

Category narrative72 words

The DPC is among the most active GDPR enforcers globally, concluding four large-scale cross-border inquiries in 2024 with fines exceeding €652 million, and headline decisions against TikTok (€530m) and Meta (€1.2bn; €390m). Irish law requires court confirmation of fines before collection, driving substantial litigation volume; the DPA 2018 provides for representative (non-damages) actions by qualified not-for-profit bodies. Recent 2026 developments include continued EU-US Data Privacy Framework monitoring and Commissioner Sweeney's public priority-setting.

No periodic updates recorded against this sub-brief.

Sources and claims (8)
  1. ConfirmedIAPPThe DPC concluded four large-scale cross-border inquiries in 2024, resulting in administrative fines totalling more than €652 million.
  2. ConfirmedEuropean Data Protection BoardThe Irish SA imposed administrative fines totalling €530 million on TikTok for infringements of Articles 13(1)(f) and 46(1) GDPR relating to transfers of EEA user data to China.
  3. ConfirmedIAPPIn 2024 the DPC concluded 2,357 formal complaints and resolved a further 8,418 cases through amicable means.
  4. ConfirmedIAPPThe DPC's headcount has grown to nearly 300 staff, up from 27 in 2014, though Commissioner Sweeney noted in 2026 that growth has plateaued with only some active hires continuing.
  5. ConfirmedIAPPUnder Irish law, DPC administrative fines must be confirmed by the courts before they can be collected; as of 2026 the DPC has 13 of its 15 large concluded investigations in litigation and over 40 active court cases.
  6. ConfirmedDataGuidanceThe Data Protection Act 2018 enables a data subject to mandate a not-for-profit body to lodge a complaint with the DPC or bring a judicial action on the data subject's behalf, though such representative court actions cannot result in an award of material or non-material damages -- only an injunction or declaration.
  7. ConfirmedEuropean Data Protection BoardIn January 2026 the EDPB published an updated version (2.0) of its EU-U.S. Data Privacy Framework FAQ for European individuals, reflecting continued monitoring of the adequacy decision governing EU-to-US personal data transfers relevant to Irish controllers.
  8. ConfirmedIAPPAt the IAPP Global Summit 2026, newly appointed DPC Commissioner Niamh Sweeney (whose five-year term began 13 October 2025) outlined 2026 enforcement priorities, including ongoing litigation with TikTok over data transfers to China and continued reliance on corrective measures alongside fines.
No categories match.

Filters combine as OR inside a group and AND across groups.

Editorial metadata

Provenance only. Nothing below gates publication or affects the render.

Editorial metadata for Ireland
FieldValue
trust.lawyer_review.statusnever_reviewed
trust.lawyer_review.reviewernot recorded
trust.content_sourceai_generated

Provenance and declared absence

Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.

Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.

Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.

Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.

Suppressed by doctrine: derived risk score; derived_scores = {}.

Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.

Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 40 claim(s), 24 source(s) in the cumulative register.