Last updated · 10 categories · 40
claims · 21 sources in the cumulative register
10Categoriesbaseline.[]
57Sub-modulesbaseline..sub_modules{}
40Claimsbaseline..claims[]
0Tier-1 sourcesrun_metadata.t1_source_count
Traffic-light mix(sums to 10 rendered categories; click to filter)
No categories are currently flagged red.
Jurisdiction brief
Lead Signal
Ireland's Data Protection Commission has closed out a run of cross-border enforcement decisions that reset the practical boundaries of transatlantic data transfers and behavioural advertising. The DPC, as lead supervisory authority for TikTok, found that the platform's transfers of EEA user data to China infringed Article 46(1) GDPR because TikTok failed to verify that its standard contractual clauses and supplementary measures were actually effective, and imposed €530 million in fines split between a €45 million penalty for Article 13(1)(f) transparency failures and €485 million for the Article 46(1) transfer failure. In a separate decision, the DPC found that Meta's supplementary measures layered on top of SCCs did not cure the deficiencies identified in Schrems II, reinforcing that a documented transfer impact assessment is now the operative expectation rather than an optional accountability exercise. The DPC also fined Meta Ireland €390 million after concluding that Meta could not rely on the "contract" legal basis under Article 6 GDPR to justify behavioural and personalised advertising. Set against this enforcement record, a challenger-level review of the underlying EU-US Data Privacy Framework adequacy decision has corrected an earlier overstatement: the adequacy finding permits EEA-to-US transfers only where the receiving US organisation has self-certified and maintains DPF compliance, and transfers to non-certified recipients still require SCCs or other Article 46 safeguards -- it is not an unconditional adequacy finding for the United States as a whole. That same review flags that the adequacy decision, while formally in force, faces a live supersession risk via the pending CJEU appeal in Latombe v Commission and a June 2026 noyb letter arguing that a US Supreme Court ruling undermines the FTC's independence, a pillar of the adequacy finding.
Other Developments
Ireland's baseline supervisory architecture remains unchanged and fully in force: the DPC continues to operate as Ireland's GDPR supervisory authority under Section 10 of the Data Protection Act 2018, which gives further effect to the GDPR domestically and repealed the earlier 1988/2003 Acts while preserving carve-outs for national-security, defence and international-relations processing. In the education sector, the DPC ordered the City of Dublin Education and Training Board to bring its processing into line with GDPR security-of-processing requirements after finding infringements of Articles 33(1), 34(1) and 34(4) for failing to notify a breach without undue delay, concluding that inquiry with a reprimand and a €125,000 fine. On direct marketing, the DPC pursued prosecutions in 2024 against a gym, a clinic, a fast-food company and Google over unsolicited marketing SMS messages. The DPC's 2024 annual reporting also surfaces recurring case-study themes in subject access requests and in rectification and erasure ("right to be forgotten") handling, alongside commentary on the DPC's evolving role under the EU AI Act as GDPR enforcement and AI governance increasingly overlap. On capacity, the DPC has grown to nearly 300 staff from 27 in 2014, though new Commissioner Niamh Sweeney has noted that this growth trajectory has plateaued. Structurally, Irish law requires DPC administrative fines to be confirmed by the courts before they can be collected, and as of 2026, 13 of the 15 large concluded DPC investigations are in litigation, with more than 40 active court cases pending -- a feature of the Irish enforcement pathway not shared by every GDPR supervisory authority. Overall, the DPC concluded four large-scale cross-border inquiries in 2024 resulting in fines exceeding €652 million, closed 2,357 formal complaints, and resolved a further 8,418 cases through amicable means.
Cross-Monitor Connections
The DPC's 2024 annual reporting flags a growing overlap between GDPR enforcement and the EU AI Act, including implications for how the Meta advertising decision constrains profiling-based ad personalisation; AI-Act-specific governance analysis of this overlap is routed to the artificial-intelligence monitor, with this monitor retaining the data-protection angle on profiling restrictions. Separately, the bespoke lawful ground the Data Protection Act 2018 creates for processing health data in insurance, pension and mortgage contexts carries a potential financial-crime and AML data-sharing overlap that is flagged at a general level for the financial-integrity monitor, without original financial-crime analysis performed here.
Outlook
Ireland's enforcement posture into the remainder of 2026 looks set to remain tightening rather than settling: Commissioner Sweeney has outlined enforcement priorities at the IAPP Global Summit that include continued reliance on corrective measures alongside fines and ongoing TikTok transfer litigation, against a backdrop of an EDPB-updated EU-US Data Privacy Framework FAQ (Version 2.0) published in January 2026. The most consequential open question for cross-border transfer practice is whether the DPF adequacy decision itself survives the pending Latombe appeal and the FTC-independence challenge raised by noyb -- a live risk vector that warrants closer monitoring than a straightforward "in force" reading would suggest. Several GDPRI sub-modules for Ireland -- including pseudonymisation and anonymisation practice, restriction and objection rights, data portability, joint-controller arrangements, dark patterns, and biometric and genetic data -- remain without DPC-specific sourcing in this research pass; that is recorded here as a coverage gap rather than as evidence of regulatory inactivity in those areas.
trust tier: ai_unverified
Regulatory Status
Ireland's Data Protection Commission, established under Section 10 of the Data Protection Act 2018, remains the GDPR's most consequential national enforcer given its lead-authority role over numerous multinational technology companies headquartered in Dublin. In 2024-2026 the DPC concluded four large-scale cross-border inquiries yielding fines exceeding €652 million, including €530 million against TikTok for Article 13(1)(f) transparency and Article 46(1) transfer failures, and €390 million against Meta for relying on an invalid 'contract' legal basis for behavioural advertising. A separate Meta decision found that supplementary transfer measures layered on SCCs did not cure Schrems II deficiencies. Ireland has also pursued education-sector enforcement, ordering the City of Dublin Education and Training Board to remedy security-of-processing and breach-notification failures under Articles 33 and 34 GDPR. On children's data, Ireland has set the GDPR Article 8 age of digital consent at 16, the maximum permitted, and published dedicated child-oriented processing guidance in December 2021. Structurally, Irish law requires DPC fines to be confirmed by the courts before collection, driving substantial litigation volume, while the Data Protection Act 2018 permits representative not-for-profit actions without a damages remedy.
Outlook
The most consequential open question for Ireland's cross-border transfer role is whether the EU-US Data Privacy Framework adequacy decision survives the pending CJEU Latombe appeal and a noyb challenge to FTC independence; the decision is formally in force but permits transfers only to DPF-self-certified US recipients, not an unconditional US adequacy finding. New Commissioner Niamh Sweeney has signalled continuity in enforcement priorities into 2026, including ongoing TikTok transfer litigation, against a backdrop of plateauing regulator headcount growth. Several sub-modules -- including pseudonymisation, restriction/objection, portability, joint-controller practice, dark patterns, and biometric/genetic data -- remain without DPC-specific sourcing this cycle and are carried forward as coverage gaps rather than signals of inactivity.
10 of 10 categories
Signal
Density
Selections OR within a group, AND across groups. Press / to search.
Traffic-light rationale — GreenComprehensive, fully in-force omnibus framework with an active, well-resourced regulator and clear statutory authority.
Sub-modules (5)
Regulator And AuthorityGreen
The DPC is Ireland's independent supervisory authority for GDPR, statutorily established under Section 10 of the Data Protection Act 2018.
Claims: CLM-IE-a1b2c301
Act And InstrumentsGreen
The Data Protection Act 2018 gives further effect to the GDPR and repealed the 1988/2003 Acts (save national-security/defence/international-relations processing carve-outs).
Claims: CLM-IE-b2c3d402
Material ScopeGreen
The GDPR's dual objective -- protecting the fundamental right to data protection while enabling free data flow -- defines material scope of application in Ireland.
Claims: CLM-IE-c3d4e503
Territorial ScopeGreen
Article 3(2) GDPR extends the Irish/EU regime extraterritorially to non-EU-established controllers targeting or monitoring EU data subjects.
Claims: CLM-IE-d4e5f604
Regulator Registration And FilingAmber
Ireland imposes no general controller-registration requirement post-GDPR; the principal filing obligation is DPO-contact-detail publication/communication to the DPC under Article 37 GDPR.
Claims: CLM-IE-e5f60705
Category narrative69 words
Ireland's data protection regime is the EU's GDPR (Regulation (EU) 2016/679) as given further effect domestically by the Data Protection Act 2018, which commenced 25 May 2018 and established the Data Protection Commission (DPC) under Section 10 as the national supervisory authority. Ireland's status as host jurisdiction for the EU/EEA establishments of many major technology platforms makes the DPC a frequent lead supervisory authority under the GDPR's one-stop-shop mechanism.
No periodic updates recorded against this sub-brief.
Sources and claims (5)
ConfirmedEuropean Data Protection Board — The Data Protection Commission (DPC), established under Section 10 of the Data Protection Act 2018, is Ireland's supervisory authority responsible for the purposes of the GDPR.
ConfirmedDataGuidance / OneTrust — The Data Protection Act 2018 gives further effect to the GDPR and, having commenced on 25 May 2018, repealed the Data Protection Acts of 1988 and 2003 except for provisions relating to processing for national security, defence, and international relations of the State.
ConfirmedEuropean Data Protection Board — The GDPR pursues a two-fold objective in Ireland's material scope: protecting the fundamental rights of natural persons regarding personal data, and allowing the free flow of personal data and digital-economy development.
ConfirmedEuropean Data Protection Board — GDPR Article 3(2) extends application to controllers/processors not established in the Union where processing relates to offering goods or services to, or monitoring, data subjects in the Union, thereby extending Irish/EU jurisdiction extraterritorially.
ConfirmedDataGuidance / OneTrust — Data controllers and processors are required to publish their DPO's contact details and communicate them to the DPC (and other relevant supervisory authorities), in lieu of a general controller-registration filing regime post-GDPR.
Core lawful-basis and special-category rules are fully in force and well documented; the pseudonymisation/anonymisation sub-module lacks a directly retrieved DPC-specific source in this run.
Primary frameworkGDPR Articles 6-9 as supplemented by the Data Protection Act 2018
Traffic-light rationale — GreenCore lawful-basis and special-category rules are fully in force and well documented; the pseudonymisation/anonymisation sub-module lacks a directly retrieved DPC-specific source in this run.
Sub-modules (4)
Lawful BasesGreen
Article 6(1)(b) contractual-necessity basis, among the enumerated GDPR lawful bases, applies where processing is necessary for performance of, or entry into, a contract.
Claims: CLM-IE-f6070816
Consent ThresholdsGreen
Ireland set the Article 8 GDPR age of digital consent at 16 years, the maximum permitted under the GDPR's 13-16 range.
Claims: CLM-IE-070817a7
Special CategoriesAmber
The Data Protection Act 2018 created a bespoke lawful ground for processing health data necessary for insurance, pension and mortgage purposes.
Claims: CLM-IE-0708186b
Pseudonymisation And AnonymisationRed
No DPC-specific pseudonymisation/anonymisation guidance or safe-harbour provision was retrieved in this research pass.
Absence provenance: not recorded. Searched: not recorded.
Category narrative48 words
Lawful bases follow GDPR Article 6, with the Data Protection Act 2018 setting Ireland's age of digital consent (Article 8 GDPR) at 16 years and adding a bespoke lawful ground permitting insurance-related health-data processing. Pseudonymisation/anonymisation safe-harbour guidance specific to the DPC was not located in this research pass.
No periodic updates recorded against this sub-brief.
Sources and claims (3)
ConfirmedData Protection Commission — Processing is lawful under GDPR Article 6(1)(b) where necessary for performance of a contract to which the data subject is party, or to take steps at the data subject's request prior to entering a contract.
ConfirmedData Protection Commission — Ireland has set the age of digital consent under Article 8 GDPR, read with the Data Protection Act 2018, at 16 years, meaning online service providers generally cannot rely on a child's own consent below that age.
ProbableDataGuidance — The Data Protection Act 2018 introduced a lawful processing ground permitting health data to be processed where necessary for insurance, health-insurance, occupational pension, retirement annuity, or property-mortgaging purposes.
Access/erasure/rectification and deadline mechanisms are well evidenced; restriction, objection and portability sub-modules rely on the general GDPR baseline without a directly retrieved DPC-specific source.
Primary frameworkGDPR Articles 12-22 as administered by the Data Protection Act 2018
Traffic-light rationale — AmberAccess/erasure/rectification and deadline mechanisms are well evidenced; restriction, objection and portability sub-modules rely on the general GDPR baseline without a directly retrieved DPC-specific source.
Sub-modules (5)
Access RightGreen
DPC 2024 case studies specifically address subject access request handling as a recurring compliance issue.
Claims: CLM-IE-1819192c
Rectification And ErasureGreen
The same DPC case-study reporting addresses rectification and erasure ('right to be forgotten') requests.
Claims: CLM-IE-19192a3d
Restriction And ObjectionRed
No DPC-specific source on restriction (Art 18) or objection (Art 21) practice was retrieved in this pass; the general GDPR baseline applies.
Absence provenance: not recorded. Searched: not recorded.
Data PortabilityRed
No DPC-specific portability (Art 20) guidance or enforcement was retrieved in this pass; the general GDPR baseline applies.
Absence provenance: not recorded. Searched: not recorded.
Deadlines And Response WindowsGreen
Section 109 DPA 2018 empowers the DPC to facilitate amicable complaint resolution within a reasonable time, offering data subjects a faster route to remedy than full statutory inquiry.
Claims: CLM-IE-2a3d4b5e
Category narrative67 words
GDPR Articles 13-22 provide the framework for access, rectification, erasure, restriction, objection and portability rights, enforced in Ireland by the DPC. The DPC's 2024 case-study reporting highlights access, deletion and rectification requests as recurring themes, and Section 109 of the Data Protection Act 2018 provides an amicable-resolution route with a comparatively fast response window. Direct DPC-specific sourcing on restriction/objection and portability was not retrieved in this pass.
No periodic updates recorded against this sub-brief.
Sources and claims (3)
ProbableIAPP — The DPC's 2024 case-study report addresses recurring issues in handling subject access requests, alongside deletion and rectification requests.
ProbableIAPP — DPC case studies published alongside the 2024 Annual Report specifically address rectification and erasure ('right to be forgotten') requests as a recurring compliance theme.
ConfirmedEuropean Data Protection Board — Under Section 109 of the Data Protection Act 2018, the DPC takes steps to arrange or facilitate amicable resolution of complaints where there is a reasonable likelihood of the parties reaching resolution within a reasonable time, offering data subjects a comparatively fast route to vindication of rights.
DPO, accountability/DPIA, security and breach-notification sub-modules are strongly evidenced by enforcement activity; ROPA, joint-controller and retention sub-modules rely on the unevidenced general GDPR baseline.
Primary frameworkGDPR Articles 5, 24-39 as administered by the Data Protection Act 2018
Traffic-light rationale — AmberDPO, accountability/DPIA, security and breach-notification sub-modules are strongly evidenced by enforcement activity; ROPA, joint-controller and retention sub-modules rely on the unevidenced general GDPR baseline.
Sub-modules (7)
Accountability And DpiaGreen
The DPC has been particularly active in issuing DPIA and accountability guidance.
Claims: CLM-IE-4b5c6d70
Dpo RequirementsGreen
Article 39 DPO obligations are in force; the DPC reports over 1,500 new DPOs appointed in Ireland post-GDPR.
Claims: CLM-IE-3d4b5c6f
Ropa RequirementsRed
No DPC-specific ROPA (Article 30) enforcement or guidance beyond a general reference to published Article 30 guidance was retrieved with sufficient substantive detail in this pass.
Absence provenance: not recorded. Searched: not recorded.
Joint Controller ArrangementsRed
No DPC-specific joint-controller arrangement guidance or enforcement was retrieved in this pass.
Absence provenance: not recorded. Searched: not recorded.
Security MeasuresGreen
The CDETB inquiry resulted in an order to bring processing into compliance with GDPR security-of-processing requirements.
Claims: CLM-IE-5c6d7e81
Breach NotificationGreen
The CDETB inquiry found infringements of Articles 33(1), 34(1) and 34(4) GDPR for failure to notify the DPC and affected data subjects of a breach without undue delay.
Claims: CLM-IE-6d7e8f92
Retention And DisposalRed
No DPC-specific retention/disposal guidance or enforcement decision was retrieved in this pass.
Absence provenance: not recorded. Searched: not recorded.
Category narrative44 words
GDPR accountability, DPO, security and breach-notification duties are in force and actively enforced, illustrated by the DPC's inquiry into City of Dublin Education and Training Board (CDETB) for security and breach-notification failures. ROPA-specific, joint-controller-specific and retention-and-disposal-specific DPC sourcing was not retrieved in this pass.
No periodic updates recorded against this sub-brief.
Sources and claims (4)
ConfirmedIAPP — Under Article 39 GDPR, appointed Data Protection Officers must monitor internal compliance, act as contact point for data subjects exercising rights, and liaise with the supervisory authority; the DPC has reported more than 1,500 new DPOs appointed in Ireland following the GDPR's introduction.
ConfirmedDataGuidance / OneTrust — The DPC has been particularly active in issuing guidance on Data Protection Impact Assessments and other accountability topics such as cookies and breach notification.
ConfirmedEuropean Data Protection Board — Following an inquiry into City of Dublin Education and Training Board, the DPC ordered the controller to bring its processing into compliance with the security requirements of the GDPR.
ConfirmedEuropean Data Protection Board — The DPC found CDETB infringed Article 33(1) GDPR by failing to notify the DPC of a personal data breach without undue delay, and Articles 34(1) and 34(4) GDPR by failing to notify affected data subjects when required.
Transfer-mechanism enforcement (TikTok, Meta) and adequacy-received status are strongly evidenced; adequacy-granted and data-localisation sub-modules are EU-level/absent for this JID.
Primary frameworkGDPR Chapter V (Articles 44-49) as administered by the DPC
Traffic-light rationale — AmberTransfer-mechanism enforcement (TikTok, Meta) and adequacy-received status are strongly evidenced; adequacy-granted and data-localisation sub-modules are EU-level/absent for this JID.
Sub-modules (6)
Transfer MechanismsAmber
The DPC's TikTok decision found infringement of Article 46(1) GDPR where SCC supplementary measures were not verified as effective for EEA-to-China transfers.
Claims: CLM-IE-7e8f90a3
Adequacy ReceivedAmber
As an EU Member State, Ireland benefits from the European Commission's EU-US Data Privacy Framework adequacy decision (10 July 2023).
Claims: CLM-IE-90a1b2c5
Adequacy GrantedRed
Adequacy decisions are granted by the European Commission at EU level, not by Ireland individually; no Ireland-specific adequacy-granting act was identified, consistent with JID scoping discipline.
Absence provenance: not recorded. Searched: not recorded.
Sccs And BcrsAmber
The TikTok decision resulted in €530 million in fines split between transparency (Art 13(1)(f)) and unlawful-transfer (Art 46(1)) infringements tied to SCC reliance.
Claims: CLM-IE-8f90a1b4
Transfer Impact AssessmentAmber
The Meta decision established that supplementary measures layered on SCCs did not cure deficiencies identified in Schrems II, reinforcing the practical need for a documented transfer impact assessment.
Claims: CLM-IE-a1b2c3d6
Data LocalisationRed
No Ireland-specific data-localisation mandate was identified in this research pass; Ireland relies on the GDPR's harmonised transfer regime rather than a partial or absolute localisation requirement.
Absence provenance: not recorded. Searched: not recorded.
Category narrative65 words
Ireland relies on the EU's transfer mechanisms (SCCs, BCRs, adequacy decisions, derogations) under GDPR Chapter V. The DPC's TikTok and Meta decisions are the leading Irish precedents on SCC transfer-impact-assessment adequacy, and Ireland benefits from the EU-US Data Privacy Framework adequacy decision as an EU Member State. Adequacy-granting is an EU Commission competence rather than an Irish-specific act, and no Ireland-specific data-localisation mandate was identified.
No periodic updates recorded against this sub-brief.
Sources and claims (4)
ConfirmedEuropean Data Protection Board — The DPC, as lead supervisory authority for TikTok, found that TikTok's transfers of EEA user data to China infringed Article 46(1) GDPR because it failed to verify, guarantee and demonstrate that SCCs and supplementary measures were effective to ensure a level of protection essentially equivalent to that guaranteed within the EU.
ConfirmedEuropean Data Protection Board — The DPC imposed administrative fines totalling €530 million on TikTok, comprising €45 million for the Article 13(1)(f) transparency infringement and €485 million for the Article 46(1) transfer infringement.
ConfirmedIAPP — As an EU Member State, Ireland benefits from the European Commission's adequacy decision for the EU-U.S. Data Privacy Framework, adopted 10 July 2023, allowing personal data to flow from the EEA to the U.S. without further conditions or authorisations.
ConfirmedIAPP — The DPC's decision against Meta found that the substantial supplementary measures Meta layered on top of SCCs did not compensate for deficiencies in U.S. law identified in Schrems II, reinforcing the requirement for a documented transfer impact assessment before relying on SCCs for EU-to-US transfers.
Telecoms/ePrivacy, education and insurance overlays are evidenced; financial-sector and credit-scoring sub-modules lack substantive DPC-specific sourcing in this run.
Traffic-light rationale — AmberTelecoms/ePrivacy, education and insurance overlays are evidenced; financial-sector and credit-scoring sub-modules lack substantive DPC-specific sourcing in this run.
Sub-modules (7)
Financial Sector OverlayRed
No substantive DPC-specific financial-sector overlay content (beyond the insurance-related health-data ground captured under the insurance sub-module) was retrieved in this pass.
Absence provenance: not recorded. Searched: not recorded.
Health Sector OverlayAmber
Health-sector-specific processing is principally addressed via the DPA 2018 insurance-related health-data lawful ground; no separate general health-sector DPC guidance was retrieved.
Claims: CLM-IE-d4e5f609
Telecoms And EprivacyGreen
The DPC exercises functions under S.I. No. 336 of 2011, Ireland's implementation of the ePrivacy Directive, governing cookies and electronic-communications privacy.
Claims: CLM-IE-b2c3d4e7
Employment DataAmber
Employment-context processing in Ireland relies on general GDPR derogations; practitioner commentary addresses collection, processing and retention of employee (including health) data.
Claims: CLM-IE-e5f60710
Credit And ScoringRed
Only a title-level reference to a historic DPC fine against an Irish credit bureau was located, without retrievable substantive content in this pass.
Absence provenance: not recorded. Searched: not recorded.
EducationAmber
The DPC's CDETB inquiry is the leading education-sector enforcement precedent, addressing security and breach-notification failures.
Claims: CLM-IE-c3d4e5f8
InsuranceAmber
The Data Protection Act 2018 provides a bespoke lawful ground for insurance-related health-data processing, forming Ireland's principal insurance-sector overlay.
Claims: CLM-IE-d4e5f609
Category narrative56 words
Sectoral overlays in Ireland include the ePrivacy Regulations (S.I. No. 336/2011) for telecoms/electronic communications, a DPA 2018 insurance-specific health-data ground, and education-sector enforcement (CDETB). Employment-data treatment relies on general GDPR derogations rather than extensive statutory elaboration. Financial-sector-specific and credit-scoring-specific DPC sourcing beyond a title-level reference to a historic credit-bureau fine was not retrieved in this pass.
No periodic updates recorded against this sub-brief.
Sources and claims (4)
ConfirmedDataGuidance / OneTrust — The DPC has functions and powers under S.I. No. 336 of 2011 (European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations), which implements the ePrivacy Directive and governs cookies and electronic marketing in Ireland.
ConfirmedEuropean Data Protection Board — The DPC's inquiry into City of Dublin Education and Training Board (CDETB), an education-sector public body, resulted in a reprimand and €125,000 in administrative fines for GDPR security and breach-notification failures.
ProbableDataGuidance — The Data Protection Act 2018 permits processing of health data without explicit consent where necessary for insurance, health-insurance, occupational pension, retirement-annuity, or property-mortgaging purposes, creating a sector-specific overlay for insurance and financial services.
ProbableDataGuidance / OneTrust — Employment-context data processing in Ireland is addressed through general GDPR derogations rather than extensive DPA 2018 elaboration, with practitioner guidance covering collection, processing and retention of employee data including health data.
Cookies, direct marketing and cross-context (behavioural) advertising are well evidenced through enforcement; dark patterns, opt-out signals and clean rooms lack retrieved sourcing.
Traffic-light rationale — AmberCookies, direct marketing and cross-context (behavioural) advertising are well evidenced through enforcement; dark patterns, opt-out signals and clean rooms lack retrieved sourcing.
Sub-modules (6)
Cookies And TrackersAmber
S.I. No. 336/2011 requires clear cookie-usage disclosure; the DPC has historically clarified that standard analytics cookies do not require a separate explicit consent step beyond homepage-level disclosure (subject to subsequent guidance evolution).
Claims: CLM-IE-f60701aa
Dark PatternsRed
No DPC-specific dark-pattern enforcement or guidance was retrieved in this pass.
Absence provenance: not recorded. Searched: not recorded.
Opt Out SignalsRed
No DPC-specific Global Privacy Control / opt-out-signal guidance was retrieved in this pass.
Absence provenance: not recorded. Searched: not recorded.
Clean Rooms And DcrRed
No DPC-specific clean-room / data-collaboration-room guidance was retrieved in this pass.
Absence provenance: not recorded. Searched: not recorded.
Cross Context AdvertisingAmber
The DPC's €390 million Meta decision found Meta could not rely on the 'contract' legal basis for behavioural advertising, constraining cross-context/personalised-advertising practices.
Claims: CLM-IE-f60701cc
Direct MarketingGreen
The DPC's 2024 enforcement activity included prosecutions for unsolicited SMS marketing.
Claims: CLM-IE-f60701bb
Category narrative41 words
Cookie and tracker consent is governed by S.I. No. 336/2011, with the DPC actively enforcing direct-marketing rules (2024 SMS-marketing prosecutions) and behavioural-advertising legal-basis requirements (the €390 million Meta decision). Dark-pattern, opt-out-signal and clean-room/data-collaboration-room-specific DPC sourcing was not retrieved in this pass.
No periodic updates recorded against this sub-brief.
Sources and claims (3)
ProbableIAPP — Under S.I. No. 336 of 2011, websites must make information available about cookie usage; the DPC historically clarified that this does not impose a need for explicit separate consent for standard third-party analytics services such as Google Analytics.
ConfirmedIAPP — The DPC's 2024 enforcement activity included prosecutions of a gym, clinic, fast-food company and Google for sending unsolicited marketing SMS messages.
ConfirmedIAPP — The DPC fined Meta Ireland €390 million after finding Meta could not rely on the 'contract' legal basis under Article 6 GDPR for delivering behavioural/personalised advertising on Facebook and Instagram.
Profiling restrictions and state-surveillance carve-outs are evidenced; ADM transparency, biometric regime and genetic data sub-modules lack directly retrieved DPC-specific sourcing.
Primary frameworkGDPR Article 22 + EU AI Act (Regulation (EU) 2024/1689)
Traffic-light rationale — AmberProfiling restrictions and state-surveillance carve-outs are evidenced; ADM transparency, biometric regime and genetic data sub-modules lack directly retrieved DPC-specific sourcing.
Sub-modules (6)
Profiling RestrictionsAmber
The Meta decision's invalidation of the 'contract' legal basis for behavioural advertising constrains profiling-based ad personalisation absent valid consent.
Claims: CLM-IE-a90a1e11
Automated Decision Making TransparencyRed
No DPC-specific Article 22 ADM-transparency guidance or decision was retrieved in this pass.
Absence provenance: not recorded. Searched: not recorded.
Ai Risk AssessmentsAmber
The DPC's 2024 Annual Report highlights its evolving role under the EU AI Act, reflecting growing overlap between GDPR enforcement and AI governance obligations.
Claims: CLM-IE-a90a1e22
Biometric RegimeRed
No DPC-specific biometric-regime (facial recognition, fingerprint, gait) guidance or enforcement was retrieved in this pass.
Absence provenance: not recorded. Searched: not recorded.
Genetic DataRed
No DPC-specific genetic-data guidance or enforcement was retrieved in this pass.
Absence provenance: not recorded. Searched: not recorded.
State Surveillance CarveoutsAmber
The Data Protection Act 2018 preserved national-security, defence and international-relations processing carve-outs from the pre-2018 Acts, exempting these from its general repeal.
Claims: CLM-IE-a90a1e33
Category narrative47 words
Ireland's DPC increasingly interfaces with the EU AI Act (Regulation (EU) 2024/1689) alongside its GDPR profiling/ADM remit; the Meta contract-legal-basis decision constrains profiling-based advertising. National-security/defence carve-outs preserved from pre-GDPR law remain the operative state-surveillance carve-out. Biometric-regime, genetic-data and ADM-transparency-specific DPC sourcing was not retrieved in this pass.
No periodic updates recorded against this sub-brief.
Sources and claims (3)
ConfirmedIAPP — The DPC's finding that Meta's 'contract' legal basis was invalid for behavioural-advertising profiling activities constrains how controllers may justify profiling-based ad personalisation absent valid consent.
ProbableIAPP — The DPC's 2024 Annual Report highlights its evolving role under the EU Artificial Intelligence Act and other digital laws, reflecting growing overlap between GDPR enforcement and AI governance obligations.
ConfirmedDataGuidance / OneTrust — The Data Protection Act 2018 preserved provisions of the repealed 1988/2003 Acts specifically relating to processing of personal data for national security, defence, and international relations purposes, carving these out from the Act's general repeal.
Traffic-light rationale — AmberAge-of-consent and education-setting guidance are strongly evidenced; minor-profiling-ban and dependent-adult sub-modules lack directly retrieved DPC-specific sourcing.
Sub-modules (5)
Age VerificationGreen
GDPR permits Member States to set the digital-consent age between 13 and 16; Ireland elected the maximum permissible age of 16.
Claims: CLM-IE-c1d2e344
Parental ConsentGreen
Below the age-of-16 threshold, online information-society-service providers must generally obtain parental consent under Article 8 GDPR / DPA 2018.
Claims: CLM-IE-c1d2e355
Minor Profiling BansRed
No DPC-specific minor-profiling-ban guidance or enforcement was retrieved in this pass.
Absence provenance: not recorded. Searched: not recorded.
Education SettingsGreen
The DPC published finalised guidance on child-oriented data processing covering offline educational, sporting, social and health/support settings likely to be accessed by children.
Claims: CLM-IE-c1d2e366
Dependent AdultsRed
No DPC-specific dependent-adult (elderly, mentally incapacitated) protections guidance was retrieved in this pass.
Absence provenance: not recorded. Searched: not recorded.
Category narrative52 words
Ireland set the GDPR Article 8 age of digital consent at 16 years -- the maximum permitted under the GDPR's 13-16 range -- and the DPC published dedicated child-oriented processing guidance ('Fundamentals for a Child-Oriented Approach to Data Processing', December 2021). Minor-profiling-ban and dependent-adult-specific DPC sourcing was not retrieved in this pass.
No periodic updates recorded against this sub-brief.
Sources and claims (3)
ConfirmedEuropean Data Protection Board — The GDPR permits Member States to set the age of digital consent for information society services between 13 and 16 years, and Ireland elected the maximum permissible age of 16.
ConfirmedData Protection Commission — Ireland's Data Protection Act 2018 sets the age of digital consent at 16 years under Article 8 GDPR, requiring parental consent for information-society-service processing of children's data below that age.
ConfirmedDataGuidance / OneTrust — The DPC published its finalised guidance, 'Fundamentals for a Child-Oriented Approach to Data Processing,' on 17 December 2021, covering data processing in offline educational, sporting, social and health/support settings likely to be accessed by children.
Traffic-light rationale — GreenEnforcement powers, penalty scale, and recent developments are extensively evidenced through primary regulator decisions and secondary reporting.
Sub-modules (6)
Regulator Powers And PenaltiesGreen
The DPC's 2024 cross-border inquiries produced fines exceeding €652 million; the TikTok decision alone imposed €530 million.
Claims: CLM-IE-e10e10aa, CLM-IE-e10e10bb
Enforcement Activity IndexGreen
In 2024 the DPC concluded 2,357 formal complaints and resolved a further 8,418 cases through amicable means.
Claims: CLM-IE-e10e10cc
Regulator Funding And CapacityGreen
DPC headcount has grown to nearly 300 staff from 27 in 2014, though Commissioner Sweeney noted in 2026 growth has plateaued.
Claims: CLM-IE-e10e10dd
Collective Redress And Class ActionsAmber
Fines require court confirmation before collection, generating substantial litigation volume including judicial review and Article 65 annulment actions.
Claims: CLM-IE-e10e10ee
Private Right Of ActionAmber
DPA 2018 enables not-for-profit bodies to bring representative complaints/actions on behalf of data subjects, though damages are unavailable in such actions.
Claims: CLM-IE-e10e10ff
Recent Developments 180DGreen
Within the last 180 days, the EDPB issued an updated EU-US DPF FAQ (January 2026) and Commissioner Sweeney publicly outlined 2026 enforcement priorities at the IAPP Global Summit, including ongoing TikTok transfer litigation.
Claims: CLM-IE-e10e1011, CLM-IE-e10e1022
Category narrative72 words
The DPC is among the most active GDPR enforcers globally, concluding four large-scale cross-border inquiries in 2024 with fines exceeding €652 million, and headline decisions against TikTok (€530m) and Meta (€1.2bn; €390m). Irish law requires court confirmation of fines before collection, driving substantial litigation volume; the DPA 2018 provides for representative (non-damages) actions by qualified not-for-profit bodies. Recent 2026 developments include continued EU-US Data Privacy Framework monitoring and Commissioner Sweeney's public priority-setting.
No periodic updates recorded against this sub-brief.
Sources and claims (8)
ConfirmedIAPP — The DPC concluded four large-scale cross-border inquiries in 2024, resulting in administrative fines totalling more than €652 million.
ConfirmedEuropean Data Protection Board — The Irish SA imposed administrative fines totalling €530 million on TikTok for infringements of Articles 13(1)(f) and 46(1) GDPR relating to transfers of EEA user data to China.
ConfirmedIAPP — In 2024 the DPC concluded 2,357 formal complaints and resolved a further 8,418 cases through amicable means.
ConfirmedIAPP — The DPC's headcount has grown to nearly 300 staff, up from 27 in 2014, though Commissioner Sweeney noted in 2026 that growth has plateaued with only some active hires continuing.
ConfirmedIAPP — Under Irish law, DPC administrative fines must be confirmed by the courts before they can be collected; as of 2026 the DPC has 13 of its 15 large concluded investigations in litigation and over 40 active court cases.
ConfirmedDataGuidance — The Data Protection Act 2018 enables a data subject to mandate a not-for-profit body to lodge a complaint with the DPC or bring a judicial action on the data subject's behalf, though such representative court actions cannot result in an award of material or non-material damages -- only an injunction or declaration.
ConfirmedEuropean Data Protection Board — In January 2026 the EDPB published an updated version (2.0) of its EU-U.S. Data Privacy Framework FAQ for European individuals, reflecting continued monitoring of the adequacy decision governing EU-to-US personal data transfers relevant to Irish controllers.
ConfirmedIAPP — At the IAPP Global Summit 2026, newly appointed DPC Commissioner Niamh Sweeney (whose five-year term began 13 October 2025) outlined 2026 enforcement priorities, including ongoing litigation with TikTok over data transfers to China and continued reliance on corrective measures alongside fines.
No categories match.
Filters combine as OR inside a group and AND across
groups.
Editorial metadata
Provenance only. Nothing below gates publication or affects the render.
Editorial metadata for Ireland
Field
Value
trust.lawyer_review.status
never_reviewed
trust.lawyer_review.reviewer
not recorded
trust.content_source
ai_generated
Provenance and declared absence
Disclosure model: category cards load OPEN; narratives render in full; standing narratives load as a clamped teaser with an explicit “read full” control carrying the true word count. No text is hidden without disclosing how much of it there is.
Sub-modules are DP-specific nested subsections with their own real per-sub-module traffic light, rendered under each category (BRIEF section 2b.5). Neither WPM nor the crypto monitor carries this field.
Traffic-light dots are REAL data (baseline.<category>.traffic_light), not renderer-invented taxonomy, and are never suppressed -- unlike WPM, where a RAG dot would be forbidden as invented severity.
Family/accent taxonomy is renderer-level presentation config, not a JID field; it decorates the RAG dot, it does not replace it. Colour is always duplicated in text and is never the sole carrier of meaning.
Suppressed by doctrine: derived risk score; derived_scores = {}.
Band honesty: uncertainty bands are computed against a frozen build clock of 2026-08-05. A year-precision row is never promoted into a tighter band.
Envelope: baseline resolved at jurisdiction_json.baseline; 10 categories, 57 sub-module(s), 40 claim(s), 24 source(s) in the cumulative register.