EU Regulation 2016/679 - Decision Register

SUPERVISORY AUTHORITY PROFILE / IRISH DPC

Irish Data Protection Commission (DPC) GDPR Fines, Enforcement Record

The most-fined GDPR regulator by cumulative amount. Ireland is the EU establishment of choice for US Big Tech, which makes the DPC the lead supervisory authority for the largest single-issuer fines on the register.

Cumulative fines

~€3.0B+

Headline decisions

~25 indexed

Largest single fine

€1.2B (Meta 2023)

EDPB Art 65 cases

5+ since 2021

Active since

1989 (GDPR: 2018)

EDUCATIONAL ONLY

This page is a reference summary of a published regulator decision. It is not legal advice. Consult a qualified data protection lawyer for advice on your specific situation. The UK GDPR is a separate regime from the EU GDPR following Brexit. Always read the source decision in full before relying on any figure or quote.

PROFILE

Mandate and constitution

Ireland's Data Protection Commission is the supervisory authority designated under Article 51 GDPR for the territory of Ireland and, by operation of Article 56 for cross-border processing, the lead supervisory authority for any controller with its main EU establishment in Ireland. The DPC was established under the Data Protection Act 1988 (the original incorporation of Convention 108 into Irish law), reconstituted under the Data Protection Acts 1988 and 2003, and modernised under the Data Protection Act 2018 to give effect to the GDPR. The 2018 Act designates the DPC as the supervisory authority for the purposes of the GDPR and the Law Enforcement Directive, and establishes its powers, procedures and accountability framework.

The DPC reports to the Oireachtas (Irish parliament) through the Minister for Justice. Its budget, staffing and operational independence are governed by the Data Protection Act 2018 and by EU-level institutional independence requirements set out in Articles 52-54 GDPR. The DPC's headquarters are in Dublin (Fitzwilliam Square), with a satellite office in Portarlington. Staffing has grown materially during the GDPR period, from approximately 110 in 2018 to more than 230 by 2026, reflecting the scale of the Big Tech caseload.

Fining philosophy

The DPC's fining philosophy reflects the institutional reality that it handles the largest cross-border GDPR inquiries in the EU. Its decisions are characterised by long inquiry timelines (often three to five years from complaint to final decision), detailed factual analysis, careful Article 83(2) factor-by-factor weighting, and an emphasis on procedural rigour. Critics have accused the DPC of being insufficiently aggressive on fine amounts; the EDPB Article 65 mechanism has repeatedly recalibrated DPC draft fines upward, most visibly in the WhatsApp case (€30-50M draft to €225M final) and the Meta Chapter V case.

The DPC's decisions are notable for the depth of their Article 6 and Article 25 reasoning on platform-design questions, and for their treatment of cross- border one-stop-shop dynamics. The DPC has also led on Article 6 lawful-basis findings in the Meta cases (contract-as-basis rejected for personalised advertising), which have reshaped ad-tech compliance across the EU.

Headline decisions

The DPC's major decisions since 2018 include the following landmarks. In September 2021, the WhatsApp €225 million transparency decision was issued following EDPB Binding Decision 1/2021 (the first ever EDPB Article 65 binding decision). In September 2022, the Instagram €405 million children's-data decision was issued following EDPB Binding Decision 2/2022. In January 2023, two Meta Ireland decisions totalling €390 million addressed the contractual lawful basis for personalised advertising on Facebook and Instagram, again following an EDPB binding decision. In May 2023, the Meta €1.2 billion Chapter V transfer decision was issued, the largest single GDPR fine to date, following EDPB Binding Decision 1/2023. In September 2023, the TikTok €345 million children's-data decision was issued following EDPB Binding Decision 2/2023.

The 2024-2026 period has continued the pattern. In May 2025, the TikTok €530 million Chapter V (China transfers) decision was issued, the second-largest single GDPR fine to date. Throughout this period the DPC has also handled a steady stream of mid-sized national fines on Irish controllers, smaller breach notifications, and a growing volume of cross-border own-volition inquiries.

Statistical record

Cumulative DPC fines since the GDPR took effect exceed €3 billion. The distribution is highly skewed: a small number of multi-hundred-million-euro Big Tech decisions account for the bulk of the total. Median annual fine count is in the tens (not hundreds, unlike the AEPD); median fine size is in the low-millions when Big-Tech outliers are excluded. The Big Tech share of the total is approximately 95% in any year where a major decision is issued, and lower in years where no Big Tech decision concludes.

Annual reports published by the DPC provide detailed breakdowns of complaint volumes (rising steadily, exceeding 11,000 in 2024), cross-border statutory inquiries (typically 20-30 active concurrently), and Section 110 inquiries (DPC-initiated inquiries under Irish law). The most recent annual report available at the time of writing is for 2024, with the 2025 report expected in mid-2026.

How to engage as a data subject

Data subjects affected by processing carried out by an Ireland-established controller can lodge a complaint with the DPC under Article 77 GDPR. Complaints are submitted through the dataprotection.ie web portal, by post, or by email. The DPC will typically acknowledge within a defined service-level period and will engage either through the formal complaint procedure or through informal resolution depending on the nature of the matter.

For cross-border complaints (where the data subject is in another Member State but the controller is established in Ireland), the one-stop-shop mechanism allows the complaint to be lodged with the data subject's local DPA and then forwarded to the DPC as lead authority. The original DPA retains a role as a "concerned" authority through the Article 60 cooperation procedure and through any Article 65 escalation.

Recent enforcement trends

The DPC's 2024-2026 enforcement priorities, as set out in its regulatory strategy and annual reports, include children's data (continuing from the TikTok and Instagram lines), AI-system processing (under the new EU AI Act intersect with GDPR), DPIA compliance for large-scale processing, and the continued one-stop-shop relationships with concerned authorities. The DPC has published guidance on data-protection considerations in AI development and on the application of GDPR to large language model training data, which signals the direction of future inquiries.

The institutional move to a three-Commissioner structure in 2024 was partly motivated by the operational scale required to handle the concurrent inquiries and the complexity of the EDPB cooperation work. The structural change is intended to reduce single-point-of-decision bottlenecks and to allow the DPC to conclude more inquiries per year while maintaining decision quality.

FREQUENTLY ASKED

About the Irish DPC

Why does the Irish DPC issue so many large fines?
Most major US technology companies (Meta, Google, Apple, Microsoft, LinkedIn, TikTok) have their European headquarters in Ireland. Under Article 56 GDPR, the supervisory authority of the Member State where a controller has its main EU establishment acts as lead supervisory authority for cross-border processing. As a result, the Irish DPC takes the lead role on every major Big Tech inquiry, and the fines issued reflect the global revenue of those undertakings.
What is the EDPB Article 65 mechanism and why does it matter for the DPC?
Article 65 GDPR allows concerned supervisory authorities to refer a draft decision to the European Data Protection Board when the lead authority and concerned authorities cannot reach consensus through the Article 60 cooperation procedure. The EDPB then issues a binding decision. The mechanism has been invoked repeatedly in DPC inquiries, including WhatsApp (2021), Instagram (2022), Meta contractual basis (2023), TikTok (2023) and Meta Chapter V (2023). In each case the EDPB intervention materially raised the fine or sharpened the findings.
How does the DPC's decision count compare to other DPAs?
By decision count, the Spanish AEPD issues by far the most GDPR decisions of any DPA, with many small-to-mid sized fines on national-only complaints. The DPC issues a much smaller number of decisions but with much higher individual amounts due to its Big-Tech remit. By cumulative fine amount, the DPC leads.
Can the DPC enforce fines against US entities?
The lead-authority fines are imposed on the EU establishment (typically the Ireland-incorporated subsidiary), which is itself a legal person within the EU. Enforcement against the EU entity is therefore straightforward. The question of whether the parent US entity bears any direct liability is more complex and is addressed through accompanying orders (such as the suspension or deletion orders in the Meta Chapter V case) rather than through direct fines against the US parent.
Who heads the DPC?
The DPC was led by a single Commissioner (Helen Dixon, 2014-2024) for most of the GDPR period to date. Following structural reforms in 2024, the office moved to a three-Commissioner structure to reflect the scale of the workload. Des Hogan, Dale Sunderland and Niamh Sweeney were appointed as the three Commissioners.
Where can I read DPC decisions?
The DPC publishes summary decisions and press releases on dataprotection.ie. Full decision texts are usually published shortly after the announcement but may be redacted for confidentiality. EDPB binding decisions that affected DPC outcomes are published on edpb.europa.eu. Appeal-stage Irish High Court judgments are published on courts.ie.

CROSS-REFERENCES

Cases led by the DPC

DPC CASE

Meta €1.2B (2023)

Largest GDPR fine ever. Chapter V US transfers.

Open reference →

DPC CASE

TikTok €530M (2025)

Chapter V transfers to China. The second-largest single GDPR fine.

Open reference →

DPC CASE

TikTok €345M (2023)

Children's data; Article 25 by-design and by-default.

Open reference →

DPC CASE

Instagram €405M (2022)

Children's contact-details public-by-default.

Open reference →

DPC CASE

WhatsApp €225M (2021)

Articles 12-14 transparency. First EDPB Article 65 binding decision.

Open reference →

PEER DPA

French CNIL

Compare DPC's lead-authority remit with CNIL's national + cookie focus.

Open reference →

SOURCES & CITATIONS

Primary sources

Figures as of May 2026. Verified against published DPA decisions.

REGISTER UPDATED 2026-04-28