Skip to content
Case Law · High Court ·2016 IEHC 323 EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

High Court examines DPA inquiry into Meta's refusal of raw data access and portability

On 25 May 2018, Michael Veale, the data subject, submitted an access and data portability request to Meta Platforms Ireland Limited (MPIL) (then Facebook Ireland Limited), the controller.

Status Not cited by any decision here yet

Original title: High Court - 2016 IEHC 323

Judgment

Holding

The High Court dismissed the controller's action. The Court held that neither the GDPR nor the Data Protection Act 2018 establishes the limitation alleged by the controller. Although a complaint under Article 77 GDPR must concern an alleged infringement of the complainant's personal data rights, this does not prevent the complaint from raising systemic issues where the complainant is personally affected. The Court distinguished the origin and scope of an inquiry from the corrective powers available to the DPA. A complaint-based inquiry is defined by the subject matter of the complaint, whereas an own-volition inquiry is defined by the DPA itself. However, this procedural distinction does not limit the corrective powers available once an infringement within the scope of the complaint has been identified. Consequently, the fact that an inquiry originated from an individual complaint did not require the DPA to disregard broader or systemic implications of the infringement. Addressing such implications did not convert the proceedings into an own-volition inquiry. Systemic corrective measures and administrative fines The Court noted that Articles 57 and 58 GDPR confer broad enforcement powers on supervisory authorities and do not distinguish between complaint-based and own-volition inquiries regarding the corrective measures available. Where an infringement is established, Article 58(2) GDPR requires the DPA to consider appropriate corrective measures. These may include orders bringing processing operations into compliance and administrative fines under Article 83 GDPR. Such measures are not necessarily confined to restoring the individual complainant's position and may address systemic deficiencies identified through the inquiry. In particular, the Court considered that Article 83 GDPR itself requires factors such as the nature, gravity and duration of the infringement and the number of affected data subjects to be considered when determining an administrative fine. Therefore, the broader impact of an infringement may legitimately influence a fine even when the underlying inquiry originated from one individual complaint. The Court consequently held that a complaint-based inquiry may result in system-wide corrective measures and administrative fines informed by systemic considerations, provided that these measures arise from infringements established within the subject matter of the complaint. The Court did not, however, determine whether the controller had actually infringed Articles 12, 15 or 20 GDPR or whether the proposed €360–€430 million fine was appropriate. Those findings and measures remained provisional within the DPA's ongoing decision-making procedure. Fair procedures The Court also rejected the controller's argument that the DPA had breached its right to fair procedures by expanding the inquiry after the investigative stage. The controller had been informed from the beginning that findings of infringement could result in the exercise of the DPA's corrective powers under Article 58 GDPR, including administrative fines. Moreover, throughout the inquiry, the controller had itself addressed the operation of Hive and its general approach to access requests across its user base. The systemic implications were therefore inherent in the issues under examination rather than introduced as a new subject matter at the decision-making stage. The Court further noted that the regulatory procedure had not yet concluded. The controller retained the opportunity to make submissions on the PDD before the Article 60 GDPR cooperation procedure and could subsequently challenge any legally binding final decision. Consequently, no procedural unfairness warranting judicial review had been established. Legitimate expectations The Court equally rejected the controller's claim that it had a legitimate expectation that any corrective measures would be confined to the individual data subject. Neither the DPA's guidance, its previous practices nor its correspondence with the controller contained a sufficiently precise and unconditional assurance that systemic corrective measures could only be adopted through an own-volition inquiry. On the contrary, the controller had repeatedly been informed that the DPA retained its corrective powers under Articles 58 and 83 GDPR. The Court therefore held that no legitimate expectation arose that the consequences of a complaint-based inquiry would be restricted to an individual remedy for the complainant. Accordingly, the Court found no unlawful expansion of the inquiry, breach of fair procedures or violation of legitimate expectations and dismissed the judicial-review proceedings.

From GDPRhub’s case note — a summary of the decision, not its own words. Read it in the text ↓

Summary

He requested access to all personal data concerning him stored in the controller's internal "Hive" data warehouse under Article 15 GDPR, including the data in raw form and information on its processing. He also requested relevant personal data in a structured, commonly used and machine-readable format under Article 20 GDPR. On 19 July 2018, the controller refused to provide the raw Hive data. Among other grounds, it relied on Article 12(5) GDPR, Article 15(4) GDPR and Article 20(4) GDPR. The data subject subsequently lodged a complaint with the Data the DPA arguing that the controller had failed to comply with his rights under Articles 15 and 20 GDPR and had unjustifiably relied on restrictions to those rights. On 27 July 2018, the DPA opened a complaint-based inquiry under Section 110(1) Data Protection Act 2018. The inquiry examined the controller's compliance with its obligations concerning the data subject's request. During the investigation, the controller explained that its approach to Hive data was generally applicable to its users and argued, inter alia, that extracting user-specific log-level data from Hive was computationally unfeasible. In August 2023, the DPA issued its Final Inquiry Report. The investigator considered that the controller had failed to provide the data subject with information required under Article 15(1)(a), (d) and (g) GDPR. On 10 October 2025, the DPA issued a preliminary draft decision (PDD). It provisionally found that the controller had infringed Article 15(1) and (3) GDPR by refusing access to and a copy of relevant personal data; Article 15(1)(a), (d) and (g) GDPR by providing inadequate information; Article 20(1) GDPR by refusing to provide relevant portable data; and Article 12(3) and (4) GDPR by failing to comply with the applicable time limits. The DPA also proposed a reprimand, a compliance order concerning the controller's general access and portability practices and administrative fines totalling between €360 million and €430 million. In determining the proposed corrective measures, the DPA took into account that the practices identified through the individual complaint potentially affected millions of users. The controller challenged the PDD before the High Court. It argued that the DPA had unlawfully transformed an inquiry concerning a single complaint into a systemic, EEA-wide own-volition inquiry. According to the controller, the DPA acted ultra vires by proposing systemic corrective measures and fines based on broader effects on other users. It also alleged breaches of fair procedures and legitimate expectations.

Full text 195 paragraphs

Machine translation of the decision, via GDPRhub — not the official text. Read the original

Paragraphs carrying a topic or an applied provision show those connections inline

THE HIGH COURT JUDICIALREVIEW [2026] IEHC

§

323 Record No. 2025/1876 JR BETWEEN METAPLATFORMS IRELAND LIMITED APPLICANT -AND- DATAPROTECTION COMMISSION RESPONDENT st JUDGMENT of Ms. Justice Siobhán Phelan, delivered on the 21 day of May, 2026 1TABLE OF CONTENTS INTRODUCTION.................................................................................................................................2 BACKGROUNDAND CHRONOLOGY...........................................................................................4 PROCEEDINGS.................................................................................................................................32 COMMISSION GUIDANCEAND EDPB GUIDELINES..............................................................35 LEGALFRAMEWORK....................................................................................................................36 Overview...........................................................................................................................................36 Regulation EU 2016/679 - GDPR.....................................................................................................37 Data Protection Act, 2018.................................................................................................................48 ANALYSISAND DECISION.............................................................................................................56 Prematurity.......................................................................................................................................56 Statutory Vires...................................................................................................................................60 Fair Procedures................................................................................................................................80 Legitimate Expectations....................................................................................................................85 CONCLUSION ...................................................................................................................................95 INTRODUCTION 1.

§

In these proceedings the Applicant, Meta Platforms Ireland Limited (MPIL)(formerly Facebook Ireland Limited), seeks to challenge the draft of the Preliminary Draft Decision (PDD) issued by the Data Protection Commission (the Commission) in its capacity as Lead SupervisoryAuthority (LSA) on the 10 of October, 2025, in Inquiry IN-18-7-1 (“the Inquiry”). 2. The Inquiry began in July, 2018, following a single user complaint (“the Complaint”). The Complaint concerned access and portability rights underArticles 12, 15 and 20 of Regulation (EU) 2016/679 of the European Parliament and of the Council of the 27 of th April, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation)(GDPR) relating to MPIL’s “Hive” data warehouse. 3. In the terms of its draft PDD, the Commission signals an intention to make findings of infringement of Articles 12, 15 and 20 of the GDPR and to direct corrective measures 2 to include a reprimand, a compliance order affecting MPIL’s general data access practices (not just the Complainant’s data access) and administrative fines totalling €360–€430 million due to the significant impact of the said practices on millions on users. 4.

§

Thecentral legal issuearising onthepleadings is thescopeofthe Commission’s powers to direct corrective measures and impose administrative fines on foot of a single user complaint. MPIL’s position is that the Inquiry was expressly complaint-based and limited to the Complainant’s access and portability request. It maintains that the Commission has unlawfully expanded the inquiry after the investigation stage concluded into a systemic, EEA-wide assessment. It is contended that by doing so, the Commission effectively converted the Inquiry into an “own-volition inquiry”, thereby acting ultra vires its powers under the GDPR and the Data Protection Act, 2018 (hereinafter “the 2018 Act”). It is further contended that this broadening of scope or conversion is in breach of the requirements of fair procedures and due process and MPIL’s legitimate expectations based on the Notice of Commencement, Draft Inquiry Report and Final Inquiry Report and established practices as evidenced by official publications and the practice in other cases. 5.

§

While the Commission maintained in pleadings and written submissions that the proceedings are premature because the PDD is simply a “draft of a draft”, it further contends that there has been no conversion of the Inquiry and that it has not only a power but is also obliged to consider systemic effects in the context of deciding on appropriate corrective measures once a finding of infringement is made. Notwithstanding its prematurity plea, the Commission now asks the Court to determine this issue. It relies on its broad discretion to impose effective, proportionate, and dissuasive corrective measures and fines under Articles 58 and 83 of the GDPR, whether in complaint-based inquiries or own-volition inquiries. 6. In essence, the question for determination is whether the Commission can, within a complaint-based GDPR inquiry, impose systemic corrective orders and fines based on a finding of an infringement which also affects the wider user base, or whether doing so unlawfully exceeds its powers as the Inquiry’s scope is limited by the terms of the individual complaint investigated.

§

The determination of this primary vires issue bears 3 on the secondary questions of fair procedures and breach of legitimate expectation also arising. BACKGROUNDAND CHRONOLOGY 7. TheComplainant (oneMichaelVeale)madeaGDPR datasubject access andportability request directed to MPIL by email on the 25 of May, 2018. The emailed request was made within hours of the GDPR becoming legally effective. The Complainant sought full access to his personal data stored in Facebook Ireland Limited’s (hereinafter “Facebook”) “Hive” data warehouse, not just the data made available via Facebook’s standard user tools. Specifically, he sought access to personal data underArticle 15 of the GDPR by requesting a copy of all personal data relating to him that Facebook processed and stored in its internal data warehouse known as “Hive”. He requested the data in raw or original format, not merely summaries or curated extracts.

§

He also requested sufficient contextual information to understand how and why the data was processed. 8. By way of data portability request underArticle 20 of the GDPR, the Complainant also sought the provision of his personal data in a structured, commonly used, machine-readable format, enabling independent analysis and reuse. He explained that access was required to the raw Hive data to allow him to determine whether, and how, third-party websites he had used (including sites relating to medical products) had shared browsing or interaction data with Facebook. He contended that without raw-level access, he could not meaningfully assess whether Facebook held or inferred potentially sensitive or special-category data about him, or whether his GDPR rights were being respected. Emphasis is attached in these proceedings to the fact that his request related to his personal data and was directed to data relating to him and on Facebook’s compliance in handling his specific request. 9.

§

By reply dated the 19 of July, 2018, Facebook refused to provide raw Hive data, relying on GDPR limitations (including proportionality and restrictions under Articles 12(5), 15(4) and 20(4) of the GDPR). 410. On foot of this reply, the Complainant made the Complaint to the Commission on the th 20 of July, 2018. He complained, inter alia, that Facebook had unlawfully refused to th respect his GDPR rights in responding to his data request made on the 25 of May, 2018, by its failure to provide access to personal data (Article 15 of the GDPR), its failure to comply with data portability rights (Article 20 of the GDPR) and unlawful reliance on GDPR restrictions. 11. As regards his personal access rights, the Complainant maintained in his complaint that Facebook did not provide him with all personal data relating to him stored in Facebook’s internal “Hive” data warehouse and that the data Facebook made available through its user-facing tools was incomplete and insufficient to satisfy Article 15.

§

He contended that access to raw Hive data was necessary to meaningfully understand what data Facebook held about him. 12. In terms of the alleged failure to comply with data portability rights, the Complainant maintained that Facebook refused to provide his personal data in a machine-readable, portable format and that this refusal prevented him from independently analysing or re-using his data, undermining the purpose ofArticle 20. 13. The Complainant disputed Facebook’s entitlement to rely on GDPR restrictions in reliance onArticle 12(5) relating to manifestly unfounded or excessive requests,Article 15(4) relating to the rights and freedoms of others andArticle 20(4) relating to adverse effect on rights and freedoms. He maintained that Facebook applied these restrictions too broadly and without adequate justification, effectively nullifying his rights. 14. In the terms of the Complaint submitted, the Complainant maintained that inability to assess third-party data sharing and sensitive inferences nullified his rights because without access to Hive data he could not determine whether third-party websites he had used had shared data with Facebook and whether Facebook had processed or inferred potentially sensitive or special-category data about him (e.g. relating to health).

§

He argued that this lack of transparency undermined the core GDPR objectives of accountability and data subject control. 515. In submitting the Complaint, the Complainant expressly pointed out that the issues raised by the Complaint had wider societal significance, particularly in relation to large-scale behavioural data processing and opacity of internal data systems stating: “I would like the DPC, as lead supervisory authority, to investigate this issue, whichIbelieveis of great societal importancegiventherecent revelations about microtargeting, and the extent of tracking on the internet today.” 16. On foot of the Complaint, the Commission formally opened the Inquiry pursuant to s. 110(1) of the 2018 Act, which empowers it to conduct a statutory inquiry where a complaint has been made, by issuing a Notice of Commencement of Inquiry dated the 27 of July, 2018. The Notice of Commencement of Inquiry stated: “The purpose of this letter (the "Notice") is to notify Facebook that the DPC has commenced an inquiry under and in accordance with section 110(1) of the Act (the "Inquiry").

§

Pursuant to section 110(2) of the Act, the DPC reserves its right, whereit considers it appropriateto doso, to causeany of its powers under Chapter 4 of Part 6 of the Act (excluding section 135 of the Act) to be exercised and/or cause an investigation under Chapter 5 of Part 6 of the Act to be carried out for the purpose of the Inquiry.” 17. From the Notice of Commencement of Inquiry, the Inquiry was stated to be for the purposeofinvestigating whetherFacebookhaddischargedits obligations in connection with the subject matter of the Complaint and whether any provisions of the GDPR and/or the 2018 Act had been contravened in that context. The Complaint was summarised as follows: “In general terms, the Complaint concerns the refusal by Facebook to provide information identified by the Complainant and related to his use of the Face book service which is contained in Facebook's "Hive" database in raw format, 6 to the Complainant pursuant to Article 15 of the GDPR (Right of access by the data subject) and Article 20 of the GDPR (Right to data portability).

§

The Complainant notes that this refusal may not be justified with reference to the grounds on which Facebook has refused access to the specified information i.e. Articles 12(5), 15(4) and 20(4) GDPR and the principle of proportionality developed in the case law of the Court of Justice of the European Union.” 18. As regards scope, the Notice of Commencement of Inquiry stated: “Scope of Inquiry 7. The Inquiry commenced by this Notice will examine whether or not Facebook has discharged its obligations in connection with the subject matter of the Complaint and determine whether or not any provision(s) of the Act and/or the GDPR has been contravened by Facebook in that context.” 19. As regards the outcome of the Inquiry, the Notice of Commencement of Inquiry expressly stated: “Outcomes of the Inquiry 12. In the event that DPC determines at the conclusion of the Inquiry that there has been a contravention of the Act and/or the GDPR, the DPC may exercise any of its powers as provided for under the Act and the GDPR including but not limited to powers conferred on the DPC by Article 58(2) of the GDPR which may include the imposition of an administrative fine on Facebook.” 20.

§

Notice was also given of a right to appeal to the Circuit Court or the High Court pursuant to s. 150(5) of theAct within 28 days of notification of a decision. 21. In response to the service on it of a Notice of Commencement of Inquiry, Facebook sought clarification and by letter dated the 14 th of August, 2018, it wrote to the 7 Commission raising procedural queries about the nature of the Inquiry, how it would be conducted and its statutory basis under the new 2018 Act. In particular, Facebook sought information in relation to “the full substance” of the Complaint which had been summarised “in general terms” in the Notice of Commencement of Inquiry, but a copy of which had not been provided. 22. By letter dated the 31 of August, 2018, the Commission replied (enclosing a copy of the Complaint), reaffirming that the Inquiry was a complaint-based statutory inquiry. In this letter, the Commission identified Concerned Supervisory Authorities (CSAs) then declared across fourteen other Member States.

§

The process was further outlined and it was confirmed that the Commission would provide any information acquired from the Complainant and/or any third-party sources to the extent that such information was relied upon by the Commission in the course of the Inquiry. 23. As regards the requirement under s. 109(2) of the Act in respect of its power to take steps to arrange or facilitate “amicable resolution”, the Commission explained that on an initial assessment the Commission did not consider there to be a reasonable likelihood of an amicable resolution within a reasonable timeframe referring specifically to the nature of the objection raised by the Complainant and the fact that the Complainant called on the Commission to: “…investigate the Complaint and indicated that the Complaint is of "great societal importance"…..” 24. During the Inquiry, the Commission issued three requests for information, all of which Facebook answered.

§

The first request for information was appended to the Notice of Commencement and was responded to on the 17 of August, 2018. In responding to the question as to how Facebook complies with Article 15 of the GDPR in respect of personal data processed in the Hive database, it was stated, inter alia, that: “…it is clear that Facebook is under no legal obligation to provide access to the underlying technical data stored in the Hive system…….As explained in our 8 previous submissions, it is computationally difficult in the extreme to provide targeted peruser responses to each and every subject access request we receive. As a result, Facebook ensures that the purpose of the right of access is met by providing its users with best-in-class access to their data with tools like Access Your Information and Ads Preferences. In other words, while users cannot access the raw technical information (which is meaningless to most users), they are given easy access to up-leveled and intelligible information, such as their inferred interests, which are provided clearly in Ads Preferences.” 25.

§

In support of their position that the right of access needs to be applied in a proportionate fashion, Facebook stated: “Retrieving log-level data stored in the Hive system for each and every user exercising their right of access would greatly exceed the total computer processing power of the Facebook group. We have explained this in greater detail in the various submissions we have sent to your Office, in particular with respect to the specific figures and technical details around the volume of data stored in the Hive system and the computing power it would require to run a search. Given theexcessiveburdenof retrieving log-level data storedin the Hive system and the nominal value of this information in this format to the user, we are of the view that providing users with production data ([some of which also exists in Hive] and that is actually used to power the Facebook site), as accessible through our various tools, is the best way to reflect the information in the Hive system in an intelligible and easily accessible form.

§

We are therefore satisfied that we comply withArticle 15 of the GDPR in respect of personal data processed in the Hive system.” 26. The second request for information issued on the 14 of September, 2018 and was responded to on the 19 th of October, 2018. This response included Facebook’s substantive explanation of why it refused to provide raw Hive data. In the cover letter, certain information was given over which a claim of commercial sensitivity was 9 subsequently made. The information in question might be summarised as a general estimation of the amount of data held in the Hive (in terms of petabytes); the amount of time (in terms of central processing unit (“CPU”) seconds) it takes to search one gigabyte of data in the Hive; the amount of time (in terms of CPU seconds/hours/days) it would take to search all the data held in the Hive; and the volume of servers that would be required to search and respond to access requests relating to the Hive.

§

Whilst careful not to interfere with the claim for commercial sensitivity made, it bears note for present purposes that the response sought to explain just how much work would be involved in providing users more generally with access to Hive in the form sought by the Complainant, asserting that it would be “impossible” to do so. 27. In the substance of its detailed response contained in an appendix to the letter of the 19 of October, 2018, Facebook stated: “Because data in Hive is stored and organised chronologically, there is no efficient way to extract all log entries corresponding to a particular user account. To extract all data specific to a user fromHive would require searching all partitions of all tables for all dates from the current date back to the date that a user’s account was created for a particular user’s identifier (i.e. their Facebook user ID (“UID”) or Replacement ID (“RID”)).

§

Given this, it is not computationally feasible to access the log-level data which could be linked to a given Facebook user in Hive and to offer access to that data (see question 14 below for further detail in this regard). This position was confirmed by your Office’s technical experts in their report annexed to the 2012 Report of Re-Audit (see Appendix 1).” 28. The third request for information issued on the 20 of December, 2018 and concerned Facebook’s main establishment / LSA status. This was responded to on the 11 of th January, 2019. 10 th 29. On the 8 of November, 2018, the Complainant made written submissions to the Commission elaborating on why access to Hive data was necessary and why Facebook’s refusal, in his view, breachedArticles 12, 15 and 20 of the GDPR. 30. Thereafter, by letter dated the 22 ndof March, 2019, the then lead investigator (Ms. Nicola Bayly) wrote to Facebook stating she was in the final stages of considering the Complaint, indicating that a draft inquiry report would issue shortly and explaining the upcoming submission process before finalising the report.

§

Facebook was asked to identify any commercially sensitive material in the file. Facebook responded to this th request by letter dated the 4 of April, 2019, identifying certain elements of its reply th letter of the 19 of October, 2018, as commercially sensitive. 31. There followed a period of apparent inactivity between 2019 – mid-2021, coinciding in significant part with the Covid-19 Pandemic. Over this extended period spanning more than two years, no draft inquiry report issued. During this period, responsibility for the Inquiry changed hands between investigators within the Commission more than once. th 32. By letter dated the 29 of July, 2021, the new lead investigator (Alan Fitzgerald) wrote to Facebook indicating he had taken over as lead investigator and stating that work on the draft inquiry report was ongoing and nearing completion. By letter dated the 11 th of August, 2021, Facebook’s solicitors wrote to the Commission formally noting significant delay in the Inquiry and requesting disclosure of all materials submitted by the Complainant. 33.

§

By letter dated the 11 of January, 2022, the Commission was advised that Facebook Ireland Limited had changed its name to Meta Platforms Ireland Limited (“MPIL”) effective from the 5 of January, 2022. 34. Finally, on the 25 of January, 2022, a new investigator, Ms. Monica Cappelletti, issued the Draft Inquiry Report to MPIL’s solicitors. The accompanying letter confirmed that the Inquiry had been conducted on foot of the Complaint and the investigator had examined facts within the scope defined by the Notice of Commencement. It was stated: 11 “In the course of the investigative phase of the Inquiry, the DPC, through the relevant Investigator, has sought to establish the facts considered to be relevant to the issues under examination within the scope of the Inquiry, i.e. the issues identified in the Notice of Commencement of the Inquiry dated 27 July 2018. The Draft Inquiry Report sets out the body of factual material collated and interrogated by the DPC in this regard to date; it also sets out a provisional analysis of that material by reference to relevant provisions of the GDPR.

§

In undertaking that provisional analysis, consideration has been given as to whether the facts, as they are now understood to be, may be said to indicate that one or more infringements of any identified provision(s) of the GDPR has occurred, or are occurring. It is important to note, however, that, whilst it sets out certain provisional views of the Investigator in relation to potential infringements of the GDPR, and the factual bases on which those provisional views have been formed, the Draft Inquiry Report does not make any determination or finding with respect to the matters under examination. In that regard, and for the avoidance of any doubt, no action will be taken by the DPC pursuant to the views expressed on a provisional basis in the Draft Inquiry Report. You will be aware from previous correspondence that the DPC’s decision‐ making function as it relates to the issues which are the subject of the Inquiry is reserved to the DPC decision‐maker (in this case the Commissioner for Data Protection), who will undertake an independent review of all relevant materials, to include the Inquiry report (once finalised), before taking steps in order to prepare a draft decision under and in accordance Section 113 of the Data Protection Act 2018 and Article 60 of the GDPR.” 35.

§

MPIL was invited to make submissions before the report was finalised for the decision-making stage. The Draft Inquiry Report (85 pages long) enclosed with the Commission’s letter referred to the scope of the Inquiry (paras. 23 and 24) into the Complainant’sArticle 15 and 20 rights stating: “A.3.Scope of Inquiry 12 23. This Inquiry focuses on the Complainant's Article 15 and 20 rights with respect to the Hive data and whether FIL has discharged its obligations as the controller in connection with the subject matter of the Request. The text of the relevant articles of the GDPR is set out at Appendix 1. 24. This section describes the documents provided in the course of the Inquiry, provides an overview of Hive (given its centrality to the factual issues which form the backdrop to the matters under consideration in this Inquiry}, sets out the temporal scope of the Inquiry and describes the focus of the legal issues considered in this Inquiry.” 36.

§

Under a separate heading, the temporal scope was expressed as restricted to the date of the Complaint as follows (at para. 40): “This Inquiryfocuses onFIL's practices as of the dateof theComplaint:25 May 2018. While FIL provided information to the DPC during the course of this Inquiry indicating changes that had been made to its Tools (a term which is defined in section B.1 below and discussed therein) since the time of the Complaint, these changes are outside the temporal scope of this Inquiry.” 37. Of note, the Draft Inquiry Report referred in some detail to general information obtained in relation to Hive, applicable to all users, largely informed by Facebook’s responses and submissions. The focus of the Inquiry was defined at para. 41 by reference to the Complainant’s Data Request insofar as it related to theArticle 15 right of access, the Article 20 right to data portability, restrictions and Article 12-15 modalities.

§

In the Draft Inquiry Report, the Investigator’s provisional view was recorded (at para. 240) as: “It is the provisional view of the Investigator that FIL did not comply with Article 15(1) (a), (b), (c), (d), (e), and (h) and Article 15(2) of the GDPR as it did not provide the Complainant with the necessary information relating to the 13 processing of the personal data carried out by FIL, prescribed under those provisions.” 38. Facebook provided written submissions in respect of the Draft Inquiry Report on the 25 ofMarch,2022. Thesesubmissionsaddressedtheinvestigator’sprovisionalfactual findings and legal analysis, emphasised that the Inquiry was complaint-based and should remain confined to the Complainant’s individual Article 15 and 20 GDPR Request. Objection was taken to any findings or reasoning that, in Facebook’s view, exceeded the scope of the complaint or the Notice of Commencement. 39.

§

In its submissions, Facebook stressed that the lawful scope of the Inquiry was defined by the content of the Complaint and by the scope set out in the Notice of Commencement of Inquiry. Facebook contended that the Inquiry must be limited to the specific Article 15 (access) and Article 20 (portability) request made by the Complainant and the processing identified in that request, namely data relating to him, at the relevant time in 2018. It was stressed that as the Complainant had not exercised Article 15 in full but only sought information under Article 15(1)(a), (d) and (g), compliancewith otherlimbs ofArticle15(1), orwithbroaderdata-processingpractices, did not fall within scope. Specifically, in the cover letter enclosing submissions, it was stated under the heading “Scope of the Inquiry”: “3.1 As noted in the Notice of Commencement of Inquiry dated 27 July 2018, this Inquiry has been conducted on foot of a complaint.

§

As such, the Inquiry should be based on and limited to: (A) the processing identified in the complaint dated 20 July 2018 arising from the handling of an Article 15 and 20 request (the “Complaint”); and (B) the GDPR compliance concerns raised in the Complaint, specifically, whether Meta Ireland was in compliance with Articles 15 and 20 GDPR in respect of the processing referenced in the Complaint. 143.2 The importance of ensuring the scope of the Inquiry is limited to the parameters of theComplaint ishighlightedbytheEDPBGuidelines onRelevant and Reasoned Objections: “… a distinction must be made between, on one hand, own-volition inquiries and, on the other hand, investigations triggered by complaints or by reports on potential infringements shared by concerned supervisory authorities. In procedures based on a complaint or on an infringement reported by a CSA, the scope of the procedure (i.e. those aspects of data processing which are potentially the subject of a violation) should be defined by the content of the complaint or of the report shared by the CSA: in other words, it should be defined by the aspects addressed by the complaint or report.

§

In own-volition inquiries, the LSA and 9 Adopted CSAs should seek consensus regarding the scope of the procedure (i.e. the aspects of data processing under scrutiny) prior to initiating the procedure formally.” 3.3 Therefore, the final inquiry report should not go beyond the issues of access and portability with respect to the processing set out in the Complaint. 3.4 In particular, and as explained in section 8.21 of the Submission, Article 15 GDPR is within the scope of the Inquiry only to the extent that it was engaged in the context of the data subject request dated 25 May 2018 (the “Data Subject Request”) and subsequently formed part of the Complaint. It is evident that the Complainant did not in fact exercise all of his rights under Article 15(1) or Article 15(2) GDPR in the Data Subject Request. The Data Subject Request was for a copy of the Complainant’s data under Article 15(3) GDPR and specific categories of information under Article 15(1) GDPR as follows: ■ the lawful basis for each category of data held in the Hive database; ■ all processing purposes for the data held within the Hive database; ■ storage limitation information or criteria relating to such data; and ■ where such data were not collected from the Complainant, the source from which they originate. 15 3.5 In circumstances where the request specifically only related to Article 15(1)(a),(d), and (g) GDPR it is inappropriate for the Inquiry Team to provisionally find that Meta Ireland did not comply with Articles 15(1)(b),(c),(e),(h) or 15(2) GDPR.

§

Meta Ireland submits that the provisional views reached by the Inquiry Team in this regard should be removed from the final inquiry report. 3.6 Moreover, Meta Ireland objects to any attempt to expand the scope of the investigation beyond that identified in theNotice of Commencement of Inquiry.” 40. It was clear from the submissions the Commission received that Facebook objected to any findings, reasoning oranalysis that went beyondthesubject matterofthe complaint or departed from the scope described in the Notice of Commencement. Additional st th submissions were made by letter dated the 31 of March, 2022, the 11 ofApril, 2022, th rd th the 17 of April, 2022, (enclosing an expert report), the 3 of May, 2022 and the 15 of March, 2023 (with regard to redactions in response to a letter from the Commission dated the 8 of March, 2023). th 41. An update was provided by letter dated the 16 of March, 2023, in which the Commission acknowledged that Facebook had argued the Inquiry was complaint-based and scope-limited and had objected to any expansion beyond the complaint.

§

While acknowledging this argument and without signalling any concluded position in respect of this case, the Commission expressly reserved the right to expand the scope of the Inquiry, subject to fair procedures stating: “5. Scope of the Inquiry 5.1. Whilst the substance of the point made in your letter will be examined in the context of our considerationof your client’s submissions in responseto theDraft Inquiry Report, the DPC considers that the scope of the Inquiry fairly and accurately reflects the complaint made by the Complainant and that it has the necessary authority to examine the issues presently under examination. 16 5.2. For the avoidance of doubt, the DPC reserves its right to expand the scope of the inquiry, subject to its obligation to apply fair procedures. The DPC is satisfied that the procedures applied to date are indeed fair.” 42. The Final Inquiry Report issued in August, 2023, under cover of a letter dated the 21 st ofAugust, 2023.

§

As regards the scope of the Inquiry, paragraph 23 of the Draft Inquiry Report was replicated. In substance, the content of the Final Inquiry Report was largely in the same terms as the draft report with the important exception that Facebook’s argument that the Complainant had only requested information falling under Article 15(1)(a), (d) and (g) and not the full suite ofArticle 15 rights was taken on board. The Final Inquiry Report accepted this submission by removing references to non- compliance with Article 15(1)(b), (c), (e), (f) and Article 15(2) from the Final Inquiry Report stating (at paras. 254-256): “254. In its Submissions on the Draft Inquiry Report, FIL submits that the Complainant, in his Request, did not seek to exercise each of his rights under Article 15(1) and (2) but rather requested only the specific information set out at paragraph 254 above, namely the information required to be provided under Article 15(1)(a), (d) and (g).

§

FIL therefore submits that it is inappropriate to make findings with respect to compliance with Article 15(1)(b), (c), (e), and (f) and 15(2). 255. In this regard, the Investigator agrees that the Complainant did not specifically request information under Article 15 other than that as set out at paragraph 254 above, and therefore compliance with Article 15(1)(b), (c), (e), and (f) and 15(2) should not fall within the scope of this Inquiry Report and is not considered further herein. 256. In light of this, FIL’s Response to the Complainant dated 19 July 2018 has to beassessed in order to verifywhetheror not suchresponsewas in compliance with the information obligation as required in Articles 15(1)(a), (d) and (g) of the GDPR.” 1743. It was urged on me on behalf of MPILthat no proposed findings were made in the Final Inquiry Report about Facebook’s general practices, impacts on other users or systemic non-compliance beyond the Complainant’s individual data request.

§

It is fair to note, however, that the Final Inquiry Report did set out information obtained during the Inquiry in relation to data on the Hive system as it affects each user or users generally. Nonetheless, I agree with MPIL that the emphasis or focus of the Inquiry as apparent from the Report (at para. 43) was directed to the terms of the Complainant’s Request and the infringements which the investigator considered to have been established related to the Complainant’s personal data. In this regard it was stated, referrable to the Complaint, that: “43. The key issues that fall to be considered for the purpose of this Inquiry are as follows: • Whether, and to what extent, the Hive data constitute personal data within the meaning of Article 4(1); • Article 15 – Right of Access: Whether FIL complied with its obligations as a controller under Article 15 in respect of the Request (both in terms of access to personal data and providing the information requested by the Complainant under this article); • Article 20 – Right to Data Portability: Whether FIL complied with its obligations as a controller under Article 20 in respect of the Request; • Restrictions: Whether there are any restrictions on the right of access or right of portability and FIL’s associated obligations as a controller, in respect of the Request, on which FIL was entitled to rely to refuse the Request; • Article 12 and 15 – Modalities: Whether FIL complied with its obligations in respect of relevant timeframes applicable to the Request pursuant to Article 12, and whether FIL complied with its obligations to provide information pursuant to Article 15(a), (d), and (g) as requested by the Complainant.” 1844.

§

The Final Inquiry Report proceeded to record the investigator’s views regarding compliance with obligations underArticle 15(1)-(2) in some detail (at paras. 249-278) proposing findings of breaches of Article 15(1)(a) of the GDPR in relation to the provision of information to the Complainant on foot of his Request (at para. 269 of the Final Inquiry Report), non-compliance with Article 15(1)(d) of the GDPR in referring the Complainant to generic and inaccurate information on storage limitation and failure to provide the Complainant with information required byArticle 15(1)(g) of the GDPR (at para. 277), stating: “It is the view of the Investigator that FIL did not comply with Article 15(1) (a), (d), or (g) of the GDPR as it did not provide the Complainant with the necessary information relating to the processing of the personal data carried out by FIL, as requested by the Complainant, prescribed under those provisions.” 45.

§

The infringement findings suggested by the investigator were thus limited to the failure to provide information to the Complainant and the Inspector did not record any view as to whether there had been an infringement of any other person’s rights. 46. The Final Inquiry Report marked the end of the investigative phase and the handover of the file to the Commission decision-maker. By letter dated the 21 ofAugust, 2023, the Commission confirmed that the Inquiry was now entering the decision-making stage. It was explained that if the decision-maker concluded that there had been an infringement of a relevant enactment as defined by s. 105(1) of the 2018 Act by the controller or processor to which an inquiry related, then a decision to this effect would be made. It was added: “I am required, in addition, to make a decision as to whether or not a corrective power should be exercised in respect of the controller or processor concerned, and, if so, the corrective power that is to be exercised.

§

The corrective powers that may be exercised are set out in Article 58(2) of Regulation (EU) 2016/679 (General Data Protection Regulation) (“the GDPR”) and section 115 of the 2018 Act.” 1947. The procedural steps that would follow next were set out and MPIL was advised that the Commission would prepare a draft PDD and that draft would be provided to MPIL (taking over from Facebook) and the Complainant, to allow them to make submissions. It was confirmed that after considering those submissions, the Commission would next preparea draftdecision forcirculationunderArticle60 ofthe GDPR to otherconcerned supervisory authorities. 48. Following the close of the investigative stage, with the exception of some additional correspondence regarding confidential and commercially sensitive material and proposed redactions to the Final Inquiry Report and some updates in relation enhancements on the Facebook service, there was a further long period spanning more than two years in which no draft PDD issued and no further requests for information were made.

§

In a letter dated the 2 of May, 2024, the Commission broke its silence and repeated that where its preliminary view was that there had been an infringement, it would also be necessary to consider whether any corrective action (including the possible imposition of an administrative fine) might be warranted. In this letter, the Commission advised MPIL’s solicitors as follows: “In this regard, Article 83 of the GDPR (interpreted in the light of Recital 150) envisages that administrative fines should be imposed on ‘undertakings’, rather than data controllers or processors. This is clear from Articles 83(4) and (5), which set out the maximum fines that may be imposed, in any given case, by reference to whether or not the respondent concerned is an “undertaking”. Recital 150 clarifies that “(w)here administrative fines are imposed on an undertaking, an undertaking should be understood to be an undertaking in accordance with Articles 101 and 102 TFEU for those purposes”.

§

Thus, in any case where the DPC might be minded towards the possible imposition of a fine, the DPC must consider the respondent’s status as an “undertaking”, by reference to how that term is understood in a competition law context…… In the context of the GDPR, the application of the concept of ‘undertaking’ means that, while a finding of infringement will be made as against the 20 respondent data controller or processor, any consequent fine must be imposed on the ‘undertaking’ concerned. This means that, in a case where there is another entity, such as a parent company, that is in a position to exercise decisive influence over the controller/processor’s behaviour on the market then both parent and subsidiary will together constitute a single economic entity and a single undertaking. Consequently, the relevant fining “cap”, for the purpose of Articles 83(4) and (5) will be calculated by reference to the turnover of the undertaking as a whole, rather than the turnover of the respondent data controller or processor.

§

As set out above, such an outcome does not involve, or necessitate the making of, any finding that the parent company was directly involved in the conduct giving rise to the finding of infringement.” 49. This letter elicited a detailed response from MPIL’s solicitors dated the 16 of May, 2024, in which issue was taken with the Commission’s approach to the concept of the undertaking concerned, with an emphasis being placed on liability resting with the data controller rather than any ultimate parent company. 50. Separately, by further letter dated the 20 thof December, 2024, the Complainant responded to an invitation to address the damage caused by the alleged infringements. In this letter he set out the damage – both material and non-material – he alleged arising from the breach of his data rights. In his submission, he again referred to the systemic importance of his case, stating under the heading “Concluding Statements” as follows: “I understand this case may be difficult to assign a penalty to because, unlike data breach cases, it appears to relate only to a single individual.

§

I have noted above significant non material damages relating to loss of control and denial of rights, as well as clear special damages of forgone income over this period caused by the need to understand what has happened both before and after this complaint, without the support of the data controller that literally holds all of this information, and with no follow-up communication from them around this data. However, the situation above is mirrored in countless individuals who feel they have no power in this situation, and should have been informed of the 21 opportunities to exercise their data rights and effectively facilitated in doing so by the data controller. I am in a privileged position of having access to individuals to help meunderstandthelaw.Othersarenot, andmayhaveto incur more costs and time trying to understand the situation. This is not a data breach case. If anything, it is more serious, more corrosive, and more societally damaging — a total disregard for the rule of law, and what it stands for in Ireland and in Europe.” 51.

§

Finally, on the 10 ofOctober, 2025,theCommission issuedthe draftPDD. Inits cover letter, the Commission stated that the purpose of the draft PDD was to outline the Commission’s provisional views as to whether or not, in the context of the Inquiry, an infringement had occurred or was occurring and whether or not a corrective power should be exercised in respect of MPIL and, if so, the corrective power that should be exercised. It was stressed that the provisional views were preliminary only, and were subject to such change as might be necessary to take account of any submissions MPIL might wish to make. It was stated that the Article 60 process would commence once amendments following consultation were made to the draft PDD. It was indicated that at that stage a copy of the amended PDD would be sent to MPIL for information purposes. 52. In its terms, the draft PDD confirms that the Inquiry had been conducted on foot of a complaint.

§

The issues raised in the Complaint are described in the draft PDD as having “general” or “systemic” application stating (at para. 7): “In overview, the Inquiry examines the compliance of Meta Ireland with the requirements of Articles 12, 15, and 20 of Regulation (EU) 2016/679 (“GDPR”), in the circumstances giving rise to the Complaint, which concerned the refusal by Meta Ireland of a request by the Complainant, a user of the Facebookservice, for acopyof personal data relating to himthatwas processed by Facebook in its data system known as the ‘Hive’. Although the inquiry has been conducted on foot of a single complaint, the issues raised by the complaint are of general application.” 2253. The scope of the Inquiry is summarised in the draft PDD (at paras. 48-49) as: “D. SCOPE OF THE INQUIRY D.1. Material scope 48. The scope of the Inquiry concerns the rights of the Complainant under Article 12, 15 and 20 GDPR with regard to the Request made by the Complainant to Meta Ireland for personal data relating to him that was processed by Facebook in the Hive, and whether Meta Ireland has discharged its obligations as thecontroller in connectionwiththeRequest.Asset out above, while the inquiry has been conducted on foot of a single complaint, the issues raised by the complaint are of general application and accordingly those issues of general application fall within the material scope of the inquiry.

§

D.2. Temporal scope 49. Thetemporal scopeoftheInquiryisconcernedwithMeta Ireland’s practices at the date of the Request made by the Complainant to Meta Ireland on 25 May 2018 and the Reply by Meta Ireland on 19 July 2018.” 54. The draft PDD, as circulated in October, 2025, identifies the issues for determination as follows (at para. 50): “50. The issues (“Issues”) for determination in this PDD are the following: 50.1. The DPC will determine which personal data of the Complainant fell within the scope of the Request under Article 15 GDPR. 50.2. The DPC will determine whether Meta Ireland complied with its obligations under Article 15 GDPR, including: 50.2.1. The right of the Complainant to access to, and a copy of, his personal data under Article 15(1) and Article 15(3) GDPR. 23 50.2.2. Whether it was lawful for Meta Ireland to restrict the right of the Complainant of access to, and a copy of, his personal data under Article 15(4) GDPR. 50.2.3.

§

Whether it was lawful for Meta Ireland to refuse to act on the Request by the Complainant for access to, and a copy of his personal data, under Article 12(5) GDPR. 50.2.4. The right of the Complainant to the information specified in Article 15(1)(a), (d), and (g) GDPR, and whether the Complainant was provided with that information. 50.3. The DPC will determine which personal data of the Complainant fell within the scope of the Request under Article 20 GDPR. 50.4. The DPC will determine whether Meta Ireland complied with its obligations under Article 20 GDPR, including: 50.4.1. The right of the Complainant under Article 20(1) GDPR. 50.4.2. Whether it was lawful for Meta Ireland to restrict the right of the Complainant to receive personal data concerning them under Article 20(4) GDPR; 50.4.3. Whether it was lawful for Meta Ireland refuse to act on the Request by the Complainant for access to, and a copy of his personal data, under Article 12(5) GDPR. 50.5.

§

The DPC will determine whether Meta Ireland complied withArticle12(3) and Article 12(4) GDPR in the context of the Request. 50.6. The DPC will determine (i) whether or not an infringement of the GDPR hasoccurredorisoccurringand(ii)ifaninfringementisfoundtohaveoccurred or to be occurring, whether a corrective power will be exercised in respect of Meta Ireland as the controller concerned, and the corrective power that will be exercised. An infringement of a relevant enactment, for this purpose, means an infringement of the GDPR or an infringement of a provision of, or regulation under, the 2018 Act, which gives further effect to the GDPR.” 2455. It is contended on behalf of MPIL that para. 50.6, quoted above, introduces a new element with the intention of enlarging the scope of the process. It is contended that it is deliberately formulated in this way, “untethered” from a finding in respect of the Complainant’s personal data.

§

TheCommission does not accept this contentionpointing out that 50.6 is tied to the preceding paragraphs and any infringement found within the terms of 50.6 would be an infringement of the distinct element(s) of the Complaint. It was only upon a finding of infringement that the Commission would then move to consider the question of corrective measures. 56. The Commission observed in the draft PDD (para. 161) that the Complainant required the data sought in order to ascertain whether several websites he had used, including websites selling medicinal products, had shared his browsing history with MPIL in a manner which could reveal special category data about him. The Commission stated: “the DPC notes as a matter of general application that similar considerations could arise for many other Facebook users, having regard to the characteristics of the processing at issue.” 57. Accepting that the Complaint related to Article 15(1)(a), (d) and (g) of the GDPR, the provisional view of the Commission as indicated in the draft PDD is that there should be no findings of infringement regarding Article 15(1)(b), (c), (h) or 15(2).

§

The draft PDD proposed preliminary findings of infringement, however, of Articles 15(1)(a)(d) and (g), 20(1) and 12(3) and 12(4). It is noted (at para. 286) that the Commission considered the approach of the Investigator appropriate in taking into account the wider cohort of affected Facebook users recording: “The DPC considers that these users were not able, in a similar manner to the Complainant, to exercise their GDPR rights or exercise control over their personal data. As previously noted in paragraph 7 of this PDD, although this inquiry has been conducted on foot of a single complaint, the issues addressed are of general application.” 2558. It is contended on behalf of MPIL that this statement represents an impermissible attempt to broaden the scope of the process because the Investigator did not refer to a broader cohort of users in the Final Inquiry Report. A review of the terms of the Final Inquiry Report, however, demonstrates findings of general application pertaining to access to data in the Hive warehouse generally (e.g. the finding that the extent of the controller obligation to comply with a data subject’s exercise of their right of access pursuant to Article 15 is not restricted to only providing personal data that is in a meaningful or intelligible format (p. 65); a controller is required under Article 15 to give access to all personal data concerning the requesting data subject but must do so by providing context to those data which would render the data meaningful and intelligible (p. 65); the data controller is not permitted to restrict the data thatit provides to the data subject on the basis that it takes the view that the data, if provided, would not be meaningful and intelligible to the data subject (p. 65); and Hive data consisting of observed personal data fall within the scope of application of the rights of a data subject underArticle 20 of the GDPR (p. 66)). 59.

§

The draft PDD summarised its preliminary findings of infringement of GDPR at G, para. 396, four in number, namely: I. MPIL infringed Article 15(1) and (3) GDPR by refusing to comply with the Request by the Complainant for access to and a copy of the relevant (Access) data; II. MPIL infringed Article 15(1)(a), (d) and (g) GDPR by providing inadequate information by way of reply to the Complainant’s Request; III. MPILinfringedArticle 20(1) GDPR by refusing to comply with the Request by the Complainant for the Relevant (Portability) Data; IV. MPIL infringed Article 12(3) and Article 12(4) GDPR when dealing with the Complainant’s Request by failing to comply with the time limits set out therein. 2660. It is clear from the foregoing that each infringement related to the treatment of the Complainant’s Request and no finding of an infringement was made with regard to anyone else’s data rights. 61.

§

The draft PDD then proceeded to set out the Commission’s preliminary decision on the exercise of corrective powers stating: “398. This Inquiry is a complaint-based inquiry conducted by the DPC under Section 110(1) of the 2018 Act, which provides that, whether for the purpose of Section 109(5)(e), Section 113(2), or of its own volition, the DPC may, in order to ascertain whether an infringement has occurred or is occurring, cause such inquiry as it thinks fit to be conducted for that purpose. 399. Section 113(2)(a) provides that, where the DPC is the lead supervisory authority for a complaint, it shall make a draft decision in respect of the complaint (or, as the case may be, part of the complaint) and, where applicable, as to the envisaged action to be taken in relation to the controller or processor concerned. 400. Section 113(3)(a) provides that, in making a draft decision under Section 113(2)(a), the Commission shall, where applicable, have regard to the information obtained by the Commission in its examination of the complaint, including, where an inquiry has been conducted in respect of the complaint, the information obtained in the inquiry. 401.

§

Section 113(2)(b) provides for the adoption by the DPC of its decision in respect of the complaint or, as the case may be, part of the complaint in accordance with Article 60 GDPR, and, where appropriate, Article 65 GDPR. 402. Section 113(4) provides that where the Commission adopts a decision under Section 113(2)(b) to the effect that an infringement by the controller or processor concerned has occurred or is occurring, it shall, in addition, make a decision, where an inquiry has been conducted in respect of the complaint, as to whether a corrective power should be exercised in respect of the controller or processor concerned, and, where it decides to so exercise a corrective power, the corrective power that is to be exercised. 27 403. This PDD is a draft of the draft decision that will be submitted by the DPC to other concerned supervisory authorities pursuant to Article 60 GDPR. Therefore, the remaining questions for determination in this PDD are whether any of the infringements found by the DPC merit the exercise of any of the corrective powers set out in Article 58(2) and, if so, which corrective powers the DPC should appropriately exercise. 404.

§

Article 58(2) GDPR sets out the corrective powers that supervisory authorities may exercise in respect of non-compliance by a controller or processor. Recital 129 of the GDPR states that: “[…] each measure should be appropriate, necessary and proportionate in view of ensuring compliance with this Regulation, taking into account the circumstances of each individual case […]” 405.ThecorrectivepowerswhichtheDPCproposestoexercise,andthereasons for the proposed exercise of those powers, are set out below on a provisional basis, and subject to further submissions from the parties in response to the PDD. Therefore, like the preliminary findings set out above, the following reflects the preliminary view of the DPC regarding the corrective powers it proposes to exercise.” 62. The draft PDD refers to the need, when considering the appropriateness, nature and form of proposed corrective measures, to provide an effective remedy to the Complainant and, in view of the general and systemic non-compliance identified, the need to ensure that MPIL complies with requests made by all data subjects pursuant to Articles 15 and 20 of the GDPR.

§

MPIL objects to the inclusion of this reference to general and systemic non-compliance because there was no finding of systemic infringement and the infringements found were limited to the Complainant’s data Request. 63. Corrective powers proposed to be exercised identified in the draft PDD (referred to by the Commission as the “draft of the draft”), include a reprimand underArticle 58(2)(b), corrective orders under Article 58(2)(d) of the GDPR and an administrative fine under Article 58(2)(i) of the GDPR calculated applying the criteria in Article 83(2) of the 28 GDPR. Each of these measures were set out sequentially, with individual reasoning. The proposed corrective orders are directed at MPIL’s general practices. The administrative fine proposed is said to be calculated by reference to the EEAuser base (235 million monthly active users of Facebook as of August, 2018). Mirroring the language of the GDPR, the Commission stated that it considered the proposed order appropriate and necessary to ensure compliance with GDPR, to provide an effective remedy to the Complainant and to protect all relevant data subjects (para. 415). 64.

§

In the reasoning apparent in the draft PDD, the Commission cited the systemic connotations and importance of the position adopted by MPIL in its response to the Complainant’s request which is described as having the “character of a complete or blanket, refusal.” Reference was made to the millions of data users both concretely and potentially affected (see paras. 412, 436, 445, 450 and 484 of the draft PDD). 65. In considering the question of an administrative fine, the draft PDD referred to Article 58(2)(i) of the GDPR and reflected that the purpose of administrative fines, as recognised in Recital 148 of the GDPR, is to strengthen the enforcement of the rules of the GDPR stating (at para. 420): “Fines sanction non-compliance and seek to re-establish compliance with GDPR.” Throughout the text of the draft PDD, the infringement(s) considered were the infringements of the Complainant’s data rights but the scope of the processing relating to the infringements was described as characterized by both the number of users of Facebook and the description provided by MPIL as to the extent of the personal data processed in Hive.

§

The EDPB Fining Guidelines were quoted in relation to consideration of the number of data subjects and the link between a high number of data users affected (even if they have not made a complaint or report) and “systemic” connotations (para. 53(b)(iv)ofGuidelines 04/2022 onthecalculationofadministrative fines quoted at para. 435 of the draft PDD). The Commission concluded that while the present Inquiry related to the Complainant’s personal data, the position adopted by MPILin its Reply and the way it responded to the Request reflected a “general policy” 29 of MPIL such that requests for personal data stored in Hive would “generally be refused” (at para. 436). 66. In providing the draft PDD to MPIL in October, 2025, the Commission advised this was its: “final opportunity to put forward any arguments or views … prior to the commencement of the Article 60 process”. 67. MPIL objected to the draft PDD by letter dated the 5 of November, 2025, contending that the Commission had improperly expanded the scope of the Inquiry after the investigativestageand that thetextof the draft PDDunlawfully departed from theFinal Inquiry Report.

§

In essence, it was contended that the Commission had unlawfully expanded the scope of a long-running complaint-based inquiry into an effective own-volition inquiry. It was pointed out that the Inquiry arose from a single complaint by an individual (July 2018) about MPIL’s response to a specific Article 15 and 20 of the GDPR access/portability request concerning data held in Facebook’s Hive Data Warehouse. 68. It was further contended that the scope of the process was consistently defined in the Notice of Commencement, Draft Inquiry Report (2022) and Final Inquiry Report (2023) as limited to that Complaint but had been improperly expanded in the (draft) PDD by the treatment of the Complaint as raising issues of general application, proposing corrective orders relating not just to the Complainant, but to general data access and portability practices of Facebook; and administrative fines of €360–€430 million, calculated by reference to alleged systemic effects on Facebook users across the EEA. 69.

§

It was argued that the Commission has no power under the 2018 Act or the GDPR to expand a complaint-based inquiry into systemic matters without formally opening an own-volition inquiry. It was contended that the distinction between a complaint-based inquiry and an own-volition inquiry was recognised in Irish law, the Commission’s own 30 guidance and EDPB guidelines. It was also argued that late expansion of scope in this way was both in breach of the requirements of procedural fairness and legitimate expectations in a process which had been ongoing for some seven years. In consequence, the case made was that the draft PDD was ultra vires. The Commission was requested to withdraw the draft PDD and to issue a revised version strictly limited to the original complaint. MPIL’s solicitors warned that if the Commission refused to withdraw the draft PDD, MPIL would seek judicial review. 70. By letter dated the 9 of December, 2025, the Commission rejected those objections and refused to withdraw or revise the draft PDD stating: “….there is no substance to your client’s complaint that the DPC has expanded the scope of its inquiry, or that, through the approach adopted in the PDD, it has “converted” its inquiry into an own-volition inquiry.

§

To the contrary, it is clear that the scope of the DPC’s analysis as set out in the PDD is fully consistent with the notice by which your client was first informed of the commencement of the within inquiry, and with such statements of position as were subsequently articulated by the DPC as the inquiry progressed. In particular, it is noted that, in the context of the above-referenced commencement notice, the DPC cautioned that if it “determines at the conclusion of the Inquiry that there has been a contravention of the Act and/or the GDPR, the DPC may exercise any of its powers as provided for under the Act and the GDPR including but not limited to thepowers conferred on the DPC by Article 58(2) of the GDPR … Each of the corrective measures now proposed is clearly and properly grounded in the powers conferred on the DPC by that provision. It follows that it is not accepted that the DPC has acted (or is acting) ultra vires its powers under the GDPR and the Data Protection Act, 2018, or otherwise unlawfully.

§

The true position is that, consistent with (i) its obligation to enforce the application of the GDPR; and (ii) the margin of appreciation it enjoys as the national data protection supervisory authority for Ireland and acting as Lead Supervisory Authority for the EU in relation to this matter, the DPC has 31 determined - on a provisional basis, and pending receipt and consideration of any submissions your client wishes to make in response to the PDD - that, on foot of the shortcomings it has found in your client’s response to Mr Veale’s requests, it is both necessary and appropriate that it would adopt the particular corrective measures now proposed. The DPC considers that the adoption of those measures is necessary to order to ensure a consistent and high level of protection of personal data through the strong and effective enforcement of the rules comprised within Articles 12, 15 and 20 of the GDPR.

§

The DPC is also satisfied that the proposed corrective measures take due account of the circumstances of Mr Veale’s specific complaint, whilst also ensuring that they are effective, proportionate and dissuasive in order to address the infringements identified and to ensure that the relevant provisions of the GDPR are fully and properly enforced. We emphasise that the proposed corrective measures remain provisional at this pointandyourclientnow hasafullopportunityto makesubmissionsinresponse to the PDD.” 71. Following on from the refusal to withdraw or revise the draft PDD, MPIL commenced these judicial review proceedings in December, 2025. PROCEEDINGS 72. The Statement of Grounds and verifyingAffidavit of GráinneVarian on behalf of MPIL were filed in the Central Office of the High Court on the 12 of December, 2025. 73. The legal grounds advanced in the Statement of Grounds make three broad complaints. 74.

§

Firstly, a complaint is pleaded that the measures proposed in the draft PDD are ultra vires the Commission’s powers under the GDPR and the 2018 Act which distinguish between complaint-based inquiries (scope defined by the complaint), and own-volition inquiries (scope defined by the Commission) but the Commission has unlawfully extended from one into the other. 3275. Secondly, it is contended that this expansion of the scope of the Inquiry is in breach of legitimate expectations deriving from representations as to the scope of the Inquiry variously through the Notice of Commencement, correspondence during the Inquiry, the Draft and Final Inquiry Reports, and the Commission’s published guidance and the Annual Report2018 which were all to the effect that theInquiry wouldremainconfined to the Complainant and his request. 76. Finally, it is pleaded that the PDD violates Irish constitutional fair-procedures guarantees, Article 6 of the European Convention on Human Rights (hereinafter “ECHR”), and Articles 47–50 of the Charter of Fundamental Rights of the European Union (hereinafter“EUCharter”)as MPILhas neverbeeninvestigated,heardin respect of or permitted to defend itself against the systemic allegations now relied upon. 77.

§

In her grounding affidavit, Ms. Varian sets out the factual and procedural foundation for the case, exhibiting relevant material and explains why MPIL says the inquiry changed character after it ended and contends that the draft PDD is ultra vires and procedurally unfair. Specifically,sheclaims that thedraft PDD forthefirst timeframed the inquiry as involving MPIL’s “general” or “systemic” practices, proposed corrective orders going beyond the Complainant and contemplated very substantial administrative fines (€360–€430 million) calculated by reference to MPIL’s EEA user base. She contended that this represented a fundamental departure from the Notice of Commencement, the entire investigative process and the Draft and Final Inquiry Reports. th 78. On the 15 of December, 2025, the High Court granted leave to proceed by way of judicial review (Gearty J.). The Court also granted a stay ex parte preventing the Commission from progressing toArticle 60 of the GDPR or finalising the decision.

§

An originating Notice of Motion was filed on the 17 of December, 2025, returnable to the 12 of January, 2026. 79. By further order made on the 19 of January, 2026, by consent, directions were made in relation to the delivery of opposition papers and time was fixed for any further replying affidavit and written submissions. Itwas orderedthat theproceedings belisted for hearing commencing on the 21 ofApril, 2026 and that the stay granted ex parte be continued until determination of these proceedings, with liberty to apply in the event of 33 a reference to the CJEU pursuant toArticle 267 of the Treaty on the Functioning of the European Union (hereinafter “TFEU”). 80. The Commission’s Statement of Opposition was filed on the 10 of February, 2026, verified by an affidavit of one Diarmuid Goulding sworn on the 9 of February, 2026. The Statement of Opposition characterizes the proceedings as premature, misconceived and an improper attempt to halt an ongoing statutory process before any final decision has been made.

§

It was pleaded out that the PDD circulated for submissions is not a final decision and MPIL has ongoing and adequate opportunities to make submissions on the PDD through participation in the Article 60 GDPR cooperation process and a statutory appeal against any final decision. 81. Reliance was also pleaded onArticles 58 and 83 of the GDPR under which supervisory authorities (SAs) must adopt effective, proportionate and dissuasive measures where infringements are found and such measures may, and often must, take account of the scale and gravity of the infringement and its impact on other data subjects, even if the inquiry began with a single complaint. The premise for the proceedings is opposed on the basis that limiting remedies to the Complainant alone would undermine GDPR enforcement. 82. In his affidavit, Mr. Goulding defends the legality of the Commission’s approach, deniesany unlawful expansion orconversionofthe Inquiry; emphasises the provisional nature of the PDD circulated and frames MPIL’s challenge as a premature interference with an ongoing statutory process.

§

He explains that where an infringement is found, the Commission is obliged under Articles 58 and 83 of the GDPR to impose measures that are effective, proportionate, and dissuasive and that such measures may properly consider the scale and impact of the infringement, including effects on other data subjects, even if the inquiry originated with a single complaint. 83. There followed a further exchange of affidavits with a replying affidavit of Ms. Varian th swornonthe24 ofFebruary,2026andafurtherAffidavitofDiarmuidGouldingsworn th on the 10 of March, 2026. th 84. Written submissions were filed on behalf of MPIL on the 16 of March, 2026 and th replying submissions on behalf of the Commission were filed on the 8 ofApril, 2026. 34COMMISSION GUIDANCEAND EDPB GUIDELINES 85. Reliance is placed by MPIL on certain publications by the Commission and European Data Protection Board Guidelines to support the interpretation of the GDPR that they advocate in these proceedings.

§

Given the reliance on an alleged departure from guidance published by the Commission in documents such as the Annual Report for 2018, the Guide to Statutory Inquiries (May 2019); DPC Inquiries Committee Terms of Referenceand DPC Inquiry IN-20-8-1(own-volitioninquiryprecedent) and Guidelines published by the European Data Protection Board Guidelines (including Guidelines 09/2020 on relevant and reasoned objection under Regulation 2016/679, Version 2.0 Adopted on 09 March 2021, Guidelines 02/2022 Guidelines on Article 60 GDPR and Guidelines 04/2022 (Fining Guidelines)) in relation to the alleged expansion of a complaint-based inquiry into an “own-volition inquiry”, it is appropriate to record the limited extent to which these documents say anything on distinct and different processes under the legal framework of the GDPR and the 2018Act. 86. Firstly, as regards the Commission’s own documents, I was specifically referred to Guidance issued by the Commission in respect of Statutory Inquiries and the Annual Report for 2018 in which reference is made in very similar terms to the fact that under the 2018 Act, the Commission may conduct two different types of statutory inquiry under s.110 in order to establish whether an infringement of the GDPR or the 2018Act has occurred.

applies Art. 60
§

These are referred to as a complaint-based inquiry or an inquiry of the Commission’s “own-volition”. 87. On behalf of MPIL, I was also referred to para. 27 of In the EDPB Guidelines 09/2020 which provide: “In some circumstances, an objection could go as far as identifying gaps in the draft decision justifying the need for further investigation by the LSA. For instance, if the investigation carried out by the LSA unjustifiably fails to cover some of the issues raised by the complainant or resulting from an infringement reported by a CSA, a relevant and reasoned objection may be raised based on the failure of the LSA to properly handle the complaint and to safeguard the rights of the data subject. In this regard, a distinction must be made between, on 35 one hand, own-volition inquiries and, on the other hand, investigations triggered by complaints or by reports on potential infringements shared by the CSAs.

§

In procedures based on a complaint or on an infringement reported by a CSA, the scope of the procedure (i.e. those aspects of data processing which are potentially the subject of a violation) should be defined by the content of the complaint or of the report shared by the CSA: in other words, it should be defined by the aspects addressed by the complaint or report. In own-volition inquiries, theLSAandAdoptedCSAsshouldseekconsensus regarding thescope of the procedure (i.e. the aspects of data processing under scrutiny) prior to initiating the procedure formally. The same applies in cases where a SA dealing with a complaint or report by another SA takes the view that an own-volition inquiry is also necessary to deal with systematic compliance issues going beyond the specific complaint or report.” 88. It seems to me that these documents do little more than acknowledge that inquiries are commenced in different ways but that the terms of reference for the Inquiry should be clear before an inquiry is formally initiated.

§

I have not been referred to any passage in these documents which support the contention that the power to direct corrective measures and impose administrative fines in a complaint-based inquiry is considered to be, or represented to be, limited to measures for the benefit of the Complainant personally only. These documents do not in terms support the proposition that the GDPR should be interpreted as providing that broader measures directed at matters of systemic or general concern may only be directed in own-volition inquiries. LEGALFRAMEWORK Overview 89. Regulation (EU) 2016/679 of the European Parliament and of the Council of the 27 ofth April, 2016, on the protection of natural persons with regard to the processing of personal data and on the free movement of such data, and repealing Directive 95/46/EC (General Data Protection Regulation - GDPR) came into from the 25 of May, 2018. It is binding in its entirety and directly applicable in all Member States. 3690.

§

Further effect has been given to the GDPR in the State by the provisions of the 2018 Act which must be given a conforming interpretation in the event of any ambiguity. 91. Other relevant provisions in the field of operation of data law deriving in very large part from the requirements of EU law include the EU Charter (specific reliance placed in this case on Articles 41, 47, 48, 49, 50); the ECHR (Article 6(1); Article 1 Protocol 1); the ECHRAct, 2003 and the TFEU. In its pleadings theApplicant requests a reference for a preliminary ruling pursuant to Article 267 of the TFEU, although this relief was not pursued in any substantive fashion in either written submissions or oral argument). 92. In common with the thrust of the argument advanced before me, my primary focus on this judgment is on the provisions of the GDPR and the 2018Act. Given the centrality of vires to the case made on behalf of MPILand bearing in mind that the Commission’s powers and functions derive directly from the GDPR as given further effect to by the 2018 Act, it is appropriate to set out in some detail what they provide in material part before proceeding to make any findings on the legal argument advanced in this case.

§

Regulation EU 2016/679 - GDPR 93. The GDPR is a human rights instrument with the protection of natural persons in relation to the processing of personal data building on Article 8(1) of EU Charter and Article 16(1) of the TFEU, as its objective. As expressed in Recital 4 to the GDPR, the right to the protection of personal data under the GDPR is not an absolute right; it must be considered in relation to its function in society and be balanced against other fundamental rights, in accordance with the principle of proportionality. 94. Recital 4 to the GDPR places the right to an effective remedy in respect of infringements of the GDPR as central to the raison d’être of the GDPR. In this regard, I was also referred to Recitals 141 and 142 which provide for a right to lodge a complaint with a single supervisory authority (hereinafter “SA”) and the right to an effective judicial remedy in accordance withArticle 47 of the EU Charter together with the right to mandate a not-for-profit body, organisation or association to lodge a complaint on his or her behalf.

§

Where a complaint is made by a body on a data subject's 37 behalf independently of the data subject's mandate, however, that body may not be allowed to claim compensation. 95. The provisions of the GDPR relevant to the issues arising in these proceedings include Articles 12, 15, 57, 58, 60, 65 and 77–83. 96. Article 12 requires data controllers to take appropriate measures to provide transparent information, communication and modalities for the exercise of the rights of the data subject. Article 12(5) envisages the charging of a fee or the refusal to act on a request only where the request is manifestly unfounded or excessive, in particular because of their repetitive character but the burden is on the controller to demonstrate the manifestly unfounded or excessive character of the request. MPIL sought to rely on Article 12(5) to justify its refusal of the Complainant’s request in this case. 97.

§

Article15isoneoftwoprovisionsoftheGDPRattheheartoftheComplainant’saccess request. Article 15 provides: “1. The data subject shall have the right to obtain from the controller confirmationastowhetherornotpersonaldataconcerninghimorherarebeing processed, and, where that is the case, access to the personal data and the following information: (a) the purposes of the processing; (b) the categories of personal data concerned; (c) the recipients or categories of recipient to whom the personal data have been or will be disclosed, in particular recipients in third countries or international organisations; (d) where possible, the envisaged period for which the personal data will be stored, or, if not possible, the criteria used to determine that period; (e) the existence of the right to request from the controller rectification or erasure of personal data or restriction of processing of personal data concerning the data subject or to object to such processing; 38 (f) the right to lodge a complaint with a supervisory authority; (g) where the personal data are not collected from the data subject, any available information as to their source; (h) the existence of automated decision-making, including profiling, referred to in Article 22(1) and (4) and, at least in those cases, meaningful information about the logic involved, as well as the significance and the envisaged consequences of such processing for the data subject. 2.

§

Where personal data are transferred to a third country or to an international organisation, the data subject shall have the right to be informed of the appropriate safeguards pursuant to Article 46 relating to the transfer. 3. The controller shall provide a copy of the personal data undergoing processing. For any further copies requested by the data subject, the controller may charge a reasonable fee based on administrative costs. Where the data subject makes the request by electronic means, and unless otherwise requested by the data subject, the information shall be provided in a commonly used electronic form. 4. Theright to obtain a copyreferredto in paragraph 3shall not adverselyaffect the rights and freedoms of others.” 98. Of these provisions, the data Request and subsequent Complaint invoked Articles 15(1)(a), (d) and (g), albeit in the draft Inquiry Report, reference was also made to potential infringement of other elements of Article 15 not directly arising on the terms oftheComplaint.

§

Theseweresubsequentlyremovedfrom theInquiryReportfollowing submissions on behalf of MPIL. 99. Article 20 provides for a right to data portability which requires the data controller to provide the data subject with his or her personal data in a structured, commonly used and machine-readable format and the right to transmit said data to another controller without hindrance from the controller to which the personal data has been provided. 39100. Article 51 of the GDPR requires each Member State to provide for one or more independent public authorities to be responsible for monitoring the application of this Regulation, in order to protect the fundamental rights and freedoms of natural persons in relation to processing and to facilitate the free flow of personal data within the Union to be referred to as the supervisory authority (SA). SAs are expected to contribute to the consistent application of GDPR and to this end, to cooperate with each other and the Commission. 101.

§

Article 57 prescribes the tasks of each SA on its territory. It provides in relevant part as follows: “Article 57 Tasks 1. Without prejudice to other tasks set out under this Regulation, each supervisory authority shall on its territory: (a) monitor and enforce the application of this Regulation; (b)…; (c)…; (d)...; (e)…; (f) handle complaints lodged by a data subject, or by a body, organisation or association in accordance with Article 80, and investigate, to the extent appropriate, the subject matter of the complaint and inform the complainant of the progress and the outcome of the investigation within a reasonable period, in particular if further investigation or coordination with another supervisory authority is necessary; (g)…; (h) conduct investigations on the application of this Regulation, including on the basis of information received from another supervisory authority or other public authority; (i)…; (j)…; (k)…; (l) …; (m) …; (n) …; (o)…; (p)…; (q)…; (r)…; (s) …; (t) …; (u) …; (v) ...” 40 The fact that the first task identified is the monitoring and enforcement of GDPR sets the tone for the balance of Article 57 and the SA’s functions.

§

Relevant to construing the scope of the powers vested in the Commission it is fundamental to approach the interpretative exercise on the basis that under the GDPR, it falls on the SA to ensure compliance with GDPR within its territory using the powers vested in it for this purpose. 102. Article 58 of the GDPR is addressed to the powers of each SAand provides separately for investigative and corrective powers. Investigative powers are provided for under Article 58(1) as follows: “1. Each supervisory authority shall have all of the following investigative powers: (a) to order the controller and the processor, and, where applicable, the controller's or the processor's representative to provide any information it requires for the performance of its tasks; (b) to carry out investigations in the form of data protection audits; (c) to carry out a review on certifications issued pursuant to Article 42(7); (d) to notify the controller or the processor of an alleged infringement of this Regulation; (e) to obtain, from the controller and the processor, access to all personal data and to all information necessary for the performance of its tasks; (f)to obtain access to anypremises of thecontroller andtheprocessor,including to any data processing equipment and means, in accordance with Union or Member State procedural law.” 41103.

§

Article 58(2) of the GDPR is addressed to corrective powers and provides for a power variously to: “2.Eachsupervisoryauthorityshallhaveallofthefollowingcorrectivepowers: (a) to issue warnings to a controller or processor that intended processing operations are likely to infringe provisions of this Regulation; (b) to issue reprimands to a controller or a processor where processing operations have infringed provisions of this Regulation; (c) to order the controller or the processor to comply with the data subject's requests to exercise his or her rights pursuant to this Regulation; (d) to order the controller or processor to bring processing operations into compliance with the provisions of this Regulation, where appropriate, in a specified manner and within a specified period; (e) to order the controller to communicate a personal data breach to the data subject; (f) to impose a temporary or definitive limitation including a ban on processing; (g) to order the rectification or erasure of personal data or restriction of processing pursuant to Articles 16, 17 and 18 and the notification of such actions to recipients to whom the personal data have been disclosed pursuant to Article 17(2) and Article 19; (h) to withdraw a certification or to order the certification body to withdraw a certification issued pursuant to Articles 42 and 43, or to order the certification body not to issue certification if the requirements for the certification are not or are no longer met; (i) to impose an administrative fine pursuant to Article 83, in addition to, or instead of measures referred to in this paragraph, depending on the circumstances of each individual case; (j) to order the suspension of data flows to a recipient in a third country or to an international organisation.” 42104.

§

The exercise of powers underArticle 58 is subject to appropriate safeguards including an effective judicial remedy. In this judgment, I attach importance to the fact that there is no distinction drawn by the language of Article 58 in relation to the exercise of the powerbasedonthenatureoftheinvestigationandnothingtosuggestthatvestedpowers were limited or unavailable in a complaint-based inquiry. It bears emphasis too that the power to impose an administrative fine is expressly stated to be “in addition to” or “instead of” other measures referred to inArticle 58 and there is nothing to suggest that an administrative fine cannot be imposed on foot of a complaint-based inquiry. Indeed, the use of the mandatory “shall” confirms that authorities must have these powers available to exercise “on the circumstances of each individual case”. From this, the powers must be available in all cases, albeit whether and how to exercise them remains a matter of some discretion, albeit guided by the GDPR. 105.

§

Article 60 provides for cooperation between the LSA (in this case the Commission) and the other SAs concerned. The purpose of the cooperation procedure is to facilitate the conclusion of decisions based on consensus between the LSA and any Concerned Supervisory Authorities (“CSAs”) (as defined by Article 4(22) of the GDPR). The Article 60 Process enables the CSAs to share their views with the LSA, including by way of a “relevant and reasoned objection”. Where such an objection is raised to the LSA’s draft decision during theArticle 60 consultation period, the LSAmust, if it does not “follow”theobjection oris of theopinionthatit is not relevant andreasoned,submit the matter to the European Data Protection Board (the “EDPB”) for determination pursuant to theArticle 65 GDPR dispute resolution process. 106. The EDPB is established under Article 68 of the GDPR and, in addition to issuing binding decisions under Article 65, is vested with further tasks under Article 70 which include the monitoring and ensuring the correct application of the Regulation and the issuance of guidelines, recommendations and best practices on procedures on prescribed subject matter including underArticle 68(1)(g) on establishing personal data breaches and Article 68(1)(k) on the application of investigation and corrective measures and the setting of administrative fees pursuant toArticle 83. 43107.

§

Key to the determination of the arguments advanced in these proceedings on behalf of MPIL,Article 77 of the GDPR provides for the right to lodge a complaint with the SA. Article 77 provides for an individual complaint in the following terms: “77(1). Without prejudice to any other administrative or judicial remedy, every data subject shall have the right to lodge a complaint with a supervisory authority, in particular in the Member State of his or her habitual residence, place of work or place of the alleged infringement if the data subject considers that the processing of personal data relating to him or her infringes this Regulation. (2). The supervisory authority with which the complaint has been lodged shall inform the complainant on the progress and the outcome of the complaint including the possibility of a judicial remedy pursuant to Article 78.” 108. Article 77 is relied upon by MPILto argue for a narrow construction of the powers of inquiry required under the GDPR on the basis that any inquiry on foot of a complaint is limitedtoinvestigationofanallegedinfringement oftheComplainant’s personal data rights and does not extend to matters of general or systemic concern.

§

This argument is based on the fact that a complaint underArticle 77 may only be made by a data subject who alleges a breach of their personal data rights. The Commission, on the other hand, contend that Article 77 lays a “threshold” requirement in respect of an individual complainant requiring an alleged infringement of their data rights to invoke jurisdiction but in no way limits or circumscribes the powers of the SA to secure enforcement and compliance of the GDPR by means of corrective measures in respect of systemic or general matters arising from the Complaint. 109. Article 78 in turns sets out the right to an effective remedy against an SA specifying inArticle 78(2) that without prejudice to: “any other administrative or non-judicial remedy, each data subject shall have the right to a an effective judicial remedy where the supervisory authority which 44 is competent pursuant to Articles 55 and 56 does not handle a complaint or does not inform the data subject within three months on the progress or outcome of the complaint lodged pursuant to Article 77.” 110.

§

Article 79 of the GDPR provides for a right to an effective judicial remedy directly against a controller or processor and Article 80 provides for a right to mandate a not- for-profit body, organisation or association to lodge a complaint on behalf of a data subject. 111. Article 82 vests a person who has suffered material or non-material damage because ofan infringement ofthe GDPR to a right to receivecompensation. The right to receive compensation is limited to a data subject who has suffered a breach of their personal data rights. This is in distinction to Article 83 which requires the existence of a power to impose administrative fines in respect of data infringement, whether an individual has brought a complaint and sought compensation or not, stressing the need to ensure that any fine imposed in an individual case is “effective, proportionate and dissuasive”. 112. Article 83 warrants being set out in full: “83(1).

§

Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article in respect of infringements of this Regulation referred to in paragraphs 4, 5 and 6 shall in each individual case be effective, proportionate and dissuasive. (2). Administrative fines shall, depending on the circumstances of each individual case, be imposed in addition to, or instead of, measures referred to in points (a) to (h) and (j) of Article 58(2). When deciding whether to impose an administrativefineanddecidingontheamountoftheadministrativefinein each individual case due regard shall be given to the following: (a) the nature, gravity and duration of the infringement taking into account the nature scope or purpose of the processing concerned as well as the number of data subjects affected and the level of damage suffered by them; 45(b) the intentional or negligent character of the infringement; (c) any action taken by the controller or processor to mitigate the damage suffered by data subjects; (d) the degree of responsibility of the controller orprocessor taking into account technical and organisational measures implemented by them pursuant to Articles 25 and 32; (e) any relevant previous infringements by the controller or processor; (f) the degree of cooperation with the supervisory authority, in order to remedy the infringement and mitigate the possible adverse effects of the infringement; (g) the categories of personal data affected by the infringement; (h) the manner in which the infringement became known to the supervisory authority, in particular whether, and if so to what extent, the controller or processor notified the infringement; (i) where measures referred to in Article 58(2) have previously been ordered against the controller or processor concerned with regard to the same subject- matter, compliance with those measures; (j) adherence to approved codes of conduct pursuant to Article 40 or approved certification mechanisms pursuant to Article 42; and (k) any other aggravating or mitigating factor applicable to the circumstances of the case, such as financial benefits gained, or losses avoided, directly or indirectly, from the infringement.

§

(3). If a controller or processor intentionally or negligently, for the same or linked processing operations, infringesseveral provisions of thisRegulation,the total amount of the administrative fine shall not exceed the amount specified for the gravest infringement. (4). Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to 10 000 000 EUR, or in the case of an undertaking, up to 2 % of the total worldwide annual turnover of the preceding financial year, whichever is higher: 46(a) the obligations of the controller and the processor pursuant to Articles 8, 11, 25 to 39 and 42 and 43; (b) the obligations of the certification body pursuant to Articles 42 and 43; (c) the obligations of the monitoring body pursuant to Article 41(4). (5). Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to 20 000 000 EUR, or in the case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher: (a) the basic principles for processing, including conditions for consent, pursuant to Articles 5, 6, 7 and 9; (b) the data subjects' rights pursuant to Articles 12 to 22; (c) the transfers of personal data to a recipient in a third country or an international organisation pursuant to Articles 44 to 49; (d) any obligations pursuant to Member State law adopted under Chapter IX; (e) non-compliance with an order or a temporary or definitive limitation on processing or thesuspension of data flows bythesupervisoryauthoritypursuant to Article 58(2) or failure to provide access in violation of Article 58(1).

§

(6). Non-compliance with an order by the supervisory authority as referred to in Article 58(2) shall, in accordance with paragraph 2 of this Article, be subject to administrative fines up to 20 000 000 EUR, or in the case of an undertaking, up to 4 %of thetotal worldwide annual turnover ofthe preceding financial year, whichever is higher. 4 (7). Without prejudice to the corrective powers of supervisory authorities pursuanttoArticle58(2),eachMemberStatemaylaydowntherulesonwhether and to what extent administrative fines may be imposed on public authorities and bodies established in that Member State. (8). The exercise by the supervisory authority of its powers under this Article shall be subject to appropriate procedural safeguards in accordance with Union and Member State law, including effective judicial remedy and due process. 47 (9). Where the legal system of the Member State does not provide for administrative fines, this Article may be applied in such a manner that the fine is initiated by the competent supervisory authority and imposed by competent national courts, while ensuring that those legal remedies are effective and have an equivalent effect to the administrative fines imposed by supervisory authorities.

§

In any event, the fines imposed shall be effective, proportionate and dissuasive. Those Member States shall notify to the Commission the provisions of their laws which they adopt pursuant to this paragraph by 25 May 2018 and, without delay, any subsequent amendment law or amendment affecting them.” Accordingly, on their express terms, both Articles 82 and 83 provide for hybrid remedies/penalties for a GDPR breach. They are not mutually exclusive. The approach taken to the capping of fines referrable to the turnover of the undertaking as opposed to the data controller/processor in question is significant in the context of the requirement to ensure that fines are effective, proportionate and dissuasive. It reflects an understanding that fines imposed may be very significant. Data Protection Act, 2018 113. The Commission is established under s. 10 of the 2018 Act and designated as SA within the meaning of the GDPR by s. 11 of that Act. 114.

§

Sections107–113ofthe2018Actgivesfurthereffecttotherequirementsof theGDPR in the State insofar as enforcement is concerned. Unsurprisingly, the definitions prescribed under s. 107 are closely aligned with requirements of the GDPR, using mirror language. 115. The power vesting in the Commission to handle complaints contained in s. 109 is expressed as follows: 48“109. (1) For the purposes of section 108(2)(a), the Commission shall examine the complaint and shall, in accordance with this section, take such action in respect of it as the Commission, having regard to the nature and circumstances of the complaint, considers appropriate. (2) The Commission, where it considers that there is a reasonable likelihood of the parties concerned reaching, within a reasonable time, an amicable resolution of the subject matter of the complaint, may take such steps as it considers appropriate to arrange or facilitate such an amicable resolution.

§

(3) Where the parties concerned reach an amicable resolution of the subject matter of the complaint, the complaint shall, from the date on which the amicable resolution is reached, be deemed to have been withdrawn by the complainant concerned. (4) Where the Commission considers that an amicable resolution cannot be reached by the parties within a reasonable time, it shall proceed— (a) in the case of a complaint to which section 113 applies, to comply with section 113(2), or (b) in the case of any other complaint, to take an action specified in subsection (5). (5) The actions referred to in subsection (4)(b) include one or more than one of the following: (a) rejection of the complaint; (b) dismissal of the complaint; (c) provision to the complainant of advice in relation to the subject matter of the complaint; (d) serving on the controller or processor concerned of an enforcement notice, requiring it to do one or more than one of the following: (i) comply with the data subject’s request to exercise his or her rights pursuant to a relevant enactment; 49 (ii) where the enforcement notice is given to the controller, communicate a personal data breach to the data subject; (iii) rectify or erase personal data or restrict processing pursuant to Article 16, 17 or 18, and, in respect of that action, to comply with Article 19 and, where applicable, Article 17(2); (da) where the Commission considers the processing of personal data the subject of the complaint infringes a relevant enactment, issuing a reprimand to the controller or processor concerned; (e) causing of such inquiry as the Commission thinks fit to be conducted in respect of the complaint; (f) taking of such other action in respect of the complaint as the Commission considers appropriate.

§

(6) The Commission shall, as soon as practicable after taking an action referred to in subsection (5) (other than paragraph (e) of that subsection), give the complainant a notice in writing informing the complainant of the action taken.” 116. It is immediately apparent that s. 109 of the 2018 Act, consistent with the GDPR, reflects an imperative on the Commission to examine and act on a complaint. A broad power is vested in the Commission to this end to cause such inquiry as the Commission “thinks fit” and to take such action as the Commission considers “appropriate”. The power to conduct an inquiry is not a tightly constrained power as apparent from the open, permissive language. 117. Separately, under s. 110, the Commission is empowered to conduct an inquiry into a suspected infringement whether for the purpose of section 109(5)(e), section 113(2), or of its own volition, to ascertain whether an infringement has occurred or is occurring, cause such inquiry as it thinks fit to be conducted for that purpose.

§

No distinction is drawn as between an inquiry on foot of a complaint, a complaint to which Article 60 relates or an own-volition inquiry for this purpose. 50118. Section 111 refers to a decision on foot of an own-volition inquiry as follows: “111. (1) Where an inquiry has been conducted of the Commission’s own- volition, the Commission, having considered the information obtained in the inquiry, shall— (a) if satisfied that an infringement by the controller or processor to which the inquiry relates has occurred or is occurring, make a decision to that effect, and (b) if not so satisfied, make a decision to that effect. (2)Where the Commission makes a decision under subsection (1)(a), it shall, in addition, make a decision— (a) as to whether a corrective power should be exercised in respect of the controller or processor concerned, and (b) where it decides to so exercise a corrective power, the corrective power that is to be exercised.

§

(3) The Commission, where it makes a decision referred to in subsection (2)(b), shall exercise the corrective power concerned.” 119. Section 113 is addressed to cross-border complaints to whichArticle 60 applies, such as the subject complaint in this case, as follows: “113. (1)This section applies to acomplaint in respect of whichtheCommission is the lead supervisory authority. (2) Where section 109(4)(a) applies, the Commission shall— (a) in accordance with subsection (3), make a draft decision in respect of the complaint (or, as the case may be, part of the complaint) and, where applicable, as to the envisaged action to be taken in relation to the controller or processor concerned, and (b) in accordance with Article 60 and, where appropriate, 51Article 65, adopt its decision in respect of the complaint or, as the case may be, part of the complaint. (3) In making a draft decision under subsection (2)(a), the Commission shall, where applicable, have regard to— (a) the information obtained by the Commission in its examination of the complaint, including, where an inquiry has been conducted in respect of the complaint, the information obtained in the inquiry, and (b) any draft for a decision that is submitted to the Commission by a supervisory authority in accordance with Article 56(4).

§

(4) Where the Commission adopts a decision under subsection (2)(b) to the effect that an infringement by the controller or processor concerned has occurred or is occurring, it shall, in addition, make a decision— (a) where an inquiry has been conducted in respect of the complaint— (i) as to whether a corrective power should be exercised in respect of the controller or processor concerned, and (ii) where it decides to so exercise a corrective power, the corrective power that is to be exercised, or (b) where an inquiry has not been conducted in respect of the complaint— (i) as to whether an action specified in subsection (6) should be taken in respect of the controller or processor concerned, and (ii) where it decides to take such an action, the action that is to be taken. (5) The Commission, in making its decision under subsection (4), shall have due regard to the decision as to the envisaged action to be taken in relation to the controller or processor included in the Commission’s draft decision under subsection (2)(a) or, as the case may be, its revised draft decision under Article 60.

§

(6) The actions referred to in subsection (4)(b) include any or all of the following: 52 (a) the serving on the controller or processor concerned of an enforcement notice, requiring it to do one or more than one of the following: (i) comply with the data subject’s request to exercise his or her rights pursuant to a relevant enactment; (ii) where the enforcement notice is given to the controller, communicate a personal data breach to the data subject; (iii) rectify or erase personal data or restrict processing pursuant to Article 16, 17 or 18, and, in respect of that action, to comply with Article 19 and, where applicable, Article 17(2); (aa) the issuing of a reprimand to the controller or processor concerned; (b) the taking of such other action in respect of the complaint as the Commission considers appropriate. (7) The Commission— (a) where it makes a decision referred to in subsection (4)(a)(ii), shall exercise the corrective power concerned, and (b) where it makes a decision referred to in subsection (4)(b)(ii), shall take the action concerned.” 120.

§

Section 115 provides for the exercise by the Commission of corrective powers as follows: “115. (1) For the purposes of exercising a corrective power under section 111, 112 or 113, the Commission may do either or both of the following: (a) subject to Chapter 6, decide to impose an administrative fine on the controller or processor concerned; (b) exercise any other corrective power specified in Article 58(2). (2) Without prejudice to the generality of subsection (1)(b), the Commission may, for the purposes of exercising a power referred to in that provision, serve 53 on the controller or processor concerned an enforcement notice requiring it to take such steps as the Commission considers necessary for those purposes.” 121. In providing for the exercise of corrective powers, s. 115 (like Article 58(2) which it givesfurthereffectto)makesnodistinctionbetweenwhethertheinquirywasconducted by the Commission on its own-volition or on foot of a complaint.

§

The absence of any distinction between the different inquiry types when it comes to the exercise of corrective powers is key to conclusions I reach later in this judgment. 122. Other provisions of the 2018 Act which were not the focus of oral argument before me, but which are identified as relevant on the papers, include the provision in Chapter 6 for the administrative fines power of the Commission. To the end of giving effect to the power prescribed in the GDPR to impose administrative fines, s.141 of the 2018 Act provides: “141(1) The Commission, in considering— (a) whether to make a decision to impose an administrative fine, and (b) where applicable, the amount of such a fine, shall act in accordance with this section and Article 83. (2) …. (3) …. (4) Where the Commission decides to impose an administrative fine on a controller or processor that— (a) is a public authority or a public body, but (b) is not a public authority or a public body that acts as an undertaking within the meaning of the Competition Act 2002, the amount of the administrative fine concerned shall not exceed €1,000,000.

§

(5) The Commission, as soon as practicable after— (a) a decision to impose an administrative fine is confirmed under section 142(3)(a) or 143(2), or 54 (b) the court decides, under section 142(3)(b), to impose a different fine, shall give the controller or processor concerned a notice in writing, requiring the controller or processor to pay the amount of the fine concerned to the Commission within the period of 28 days commencing on the date of the notice. (6)…. (7).... (8) In this section and section 142, a reference to a decision to impose an administrative fine shall be construed as a reference to a decision by the Commission, under section 111, 112, 113 or 133 (9), to impose such a fine.” 123. It is also relevant to note that s. 142 of the 2018Act provides for an appeal against an administrative fine within 28 days from the date on which notice of the decision concerned was given to either the Circuit or High Court based on the quantum of the fine.

§

Under s. 142(2), the court, on hearing an appeal under subsection (1), may consider any evidence adduced or argument made by the controller or processor concerned, whether already adduced or made to an authorised officer or the Commission or not. Section 142(3) provides that the court may, on the hearing of an appeal under subsection (a) confirm the decision the subject of the appeal, (b) replace the decision with such other decision as the court considers just and appropriate, including a decision to impose a different fine or no fine, or (c) annul the decision. In making a decision under s. 142(3), however, the Court is similarly bound to act in accordance withArticle 83. 124. Under the scheme of the 2018 Act, even where there is no appeal against the administrative fine imposed by the Commission, it is necessary for a Court to confirm a decision to impose an administrative fine as provided in s. 143(1) of the 2018 Act.

§

Under s. 143(2), the Circuit Court may refuse to confirm an administrative fine where it sees good reason not to do so. 125. The right to appeal to a court (concurrent jurisdiction conferred on Circuit and High Court under s. 150(9)) conferred under the 2018 Act is not limited to the case of administrative fines and s. 150(5) provides for a full right of appeal for any person affected by a legally binding decision of the Commission under Chapter 2 or 3 (defined 55 as including a decision to exercise a corrective power), within 28 days from the date on which notice of the decision is received. A further appeal lies under s. 150(11) on a point of law. ANALYSISAND DECISION 126. Notwithstanding the relief sought in reliance on Article 267 of the TFEU in the proceedings as drafted, in argument MPIL has framed this case on traditional judicial review grounds of ultra vires, fair procedures, legitimate expectations and an application of settled EU law, not its uncertain interpretation.

§

Reliance is placed on the legal framework (both EU and domestic), the case law of both the Irish courts and the CJEU (and indeed other courts) and the issues are presented as clear, without requiring CJEU intervention at this stage, a position which appears to me to be correct. 127. Four separate issues arise on the pleadings which I now propose to address in turn, albeit no one ground is entirely insulated from the others and there is a significant interconnection between the different legal issues which require to be determined by this Court. Prematurity 128. Prematurity was a very important part of a preliminary objection to the maintenance of these proceedings advanced on behalf of the Commission in pleadings and in written submissions. In opening the case for the Commission, however, senior counsel stated nd (Transcript of Proceedings, Day 2, 22 ofApril, 2026, p. 5, lines 3-23): “Judge, just at the outset, may I make clear that in this particular case, we will not contend that the vires issue is premature.

§

And we do, therefore, respectfully suggest that the Court must decide the issue…..so, in this case, I’m absolutely urging theCourt to decideit,we’renot advancing theprematurityargument qua vires, but it’s not to be taken as a concession for other cases.” 56129. Conscious of my role in ensuring the proper exercise of my discretion in judicial review proceedings, it nonetheless seems to me that I should not proceed to determine the issues in these proceedings without being properly satisfied myself that it is appropriate to do so, despite an identified and identifiable prematurity issue, albeit in circumstances whereprematurityis nolongerbeingpressed andtakingthisinto account as a relevant consideration. 130. I have been referred by both parties to a series of relevant decisions in this regard, most notably, Facebook Ireland Ltd v. Data Protection Commission [2021] IEHC 336 (which is separately considered below for other purposes at paras. 186-187) and Rowland v. An Post [2017] 1 IR 355; [2017] IESC 20.

§

Whereas the general rule, acknowledged in these authorities, is that courts do not intervene prematurely where a statutory process is ongoing, especially where alternative remedies (such as an appeal or the possibility of a final decision challenge by way of judicial review) exist, it is also accepted that mid-process intervention may rarely be appropriate, albeit only in exceptional circumstances. 131. The judgment in Facebook Ireland Limited v. Data Protection Commission established that a preliminary draft decision is amenable to judicial review and a controller can challenge the procedures of the Commission before the process is complete and even though the Commission decision is provisional in circumstances where the preliminary views will likely carry through to the final stages unless successfully challenged. Similarly, in Rowland v. An Post the Supreme Court accepted that judicial review can be brought mid-process where it is clear the process has “gone irremediably wrong”. 132.

§

By not standing over the prematurity plea in this case despite having developed the argument in considerable detail in its written submissions, there is at least an implicit acknowledgment on the part of the Commission that it is desirable and in the interests oftheprocess thattheissueofstatutoryviresbedeterminedbeforetheprocessadvances further. I note that the Commission’s formal position in correspondence has extended beyond an invitation to MPIL to make submissions, consistent with it having an open mind on the question of vires and the matter remaining to be determined. Rather, in its 57 letter dated the 9 of December, 2025, the Commission clearly stated that there was no substance to the complaint that it had extended the scope of the Inquiry and that it was: “clear that the scope of the DPC’s analysis as set out in the PDD is fully consistent with the notice by which your client was first informed of the commencement of the within inquiry…….each of the corrective measures now proposed is clearly and properly grounded in the powers conferred on the DPC by that provision [Article 58(2) of GDPR].

§

It follows that it is not accepted that the DPC has acted (or is acting) ultra vires its powers under the GDPR and the Data Protection Act, 2018, or otherwise unlawfully”. 133. On any reading, the Commission’s position as formally communicated in this letter reflects a settled view on the law and the parameters of its statutory powers and their proper exercise. The Commission’s settled view, which does not accord with MPIL’s, will likely carry through to the final stages of the process. The issue is clearly fundamental to the lawfulness of the process. If MPIL is correct in its arguments, the letter expressing a concluded view on vires signals a departure which has lasting implications for the direction of the process. Furthermore, the next and final stages of the process involve cooperation with other concerned supervisory authorities in accordance with Article 60 of the GDPR, introducing a cross-border layer of complexity to the process which may make the rectification of an error in the process by an Irish court less straightforward. 134.

§

Theadditionallayerofcomplexityincludesapotentialfurtherrevisionoralternatively adoption of the PDD, without apparent opportunity for further submissions from MPIL, or the potential engagement of the consistency mechanism referred to in Article 63 in the event of a relevant and reasoned objection from a CSA which the Commission, as LSA, does not accept. In addition, the potential application of the dispute resolution mechanism under Article 65 pursuant to which the EDPB (established pursuant to Article 68 of the GDPR) shall adopt a binding decision arises (a recent example of this occurring is seen in DPC Inquiry Reference: In-20-8-1 in own-volition inquiry under s. 110 of the 2018Act involving the same parties as this case). When this occurs, MPIL 58 will have a final opportunity to make submissions directed to a decision which will be required but in circumstances where Article 65(6) of the GDPR requires the Commission to adopt its final decision “on the basis of” the EDPB’s decision within one month after notification of the EDPB’s decision 135.

§

In the absence of any authority directly on point on the vires question and having regard to the fact that both sides are now desirous of the vires issue being determined, it seems to me, that by reason of a combination of factors summarised above, it is appropriate to determine the question arising in respect of the lawful parameters of the process at this point of the process. 136. Although the Commission has resiled from its prematurity plea in respect of the vires argument for the purpose of this application, its position is more ambiguous as regards the balance of the case advanced in reliance on fair procedures and legitimate expectation arguments. As there is a significant interconnection or circularity to the case made on behalf of MPIL in advancing a three-pronged challenge, I am satisfied that it would be artificial and an inefficient use of court time to carve up the case and determine some legal grounds selectively and not others in reliance on asserted prematurity. 137.

§

Ultimately, for reasons which I elaborate upon below, the statutory vires question is determinative of each of the issues arising on this case. If the Commission is correct as to its vires to proceed in the way it has, then the unfairness alleged from a perceived enlargement of the process is not established quite simply because no unlawful or impermissible enlargement or extension of scope has occurred and MPIL has at all times been aware of the scope of the Inquiry and the parameters of the Commission’s powers to impose corrective measures, including administrative fines. 138. Similarly, where the process is at all times referred to in representations to MPIL in a manner which aligns with the prescribed legal process and that process provides for mandatory consideration of corrective measures in the case of infringement having regard to systemic implications, the proposition that MPILis entitled to a process other than that prescribed in law based on the doctrine of legitimate expectation is almost 59 untenable.

§

This is because the process followed has, always, been tied to the applicable legal provisions. 139. The extent to which the vires argument is integral to the other grounds of challenge advanced support me in my view that it is appropriate that I should deal with all issues now. This is the most efficient approach and best used of court time. Statutory Vires 140. MPIL’s point of departure in these proceedings is that the measures proposed in the PDD are ultra vires the Commission’s powers under the GDPR and the 2018 Act because both the GDPR and the 2018 Act distinguish between complaint-based inquiries (scope defined by the complaint) and own-volition inquiries (scope defined by the SA or LSA and CSA). MPIL’s case is constructed on the proposition that the Commissionis limited ina complaint-based inquiryto measures whichreflect aremedy for the individual Complainant and are not calibrated by reference to the fact that any infringement found impacts other users.

§

It is accepted on behalf of MPIL that the Commission has jurisdiction in respect of systemic matters of general application but it is contended that such general or systemic matters may only be investigated by the Commission in an own-volition inquiry process in which it is clear from the scope of the inquiry notified by the Commission that issues of systemic and general application are under investigation. 141. Based on this dichotomy in the Commission’s powers of investigation and the route to making findings and adopting a decision, it is contended on behalf of MPIL that the Commission has unlawfully extended from one process into the other in the terms of the PDD and corrective measures proposed. For MPIL to succeed on this argument, however, it must substantiate the claim that the GDPR and the 2018Act limit the scope of a complaint-based inquiry by excluding from the scope of such inquiry systemic or general issues of concern and require that such issues are only investigated in an own- volition process by referenceto thetextoftheselegal measures, theirstatutoryintention and purpose. 60142.

§

I have carefully scrutinised the provisions of both the GDPR and the 2018 Act identified by both parties. The material scope of the GDPR, which the Commission is required to enforce, is widely drawn by the terms of Article 2, consistent with its purpose and intention in providing robust protection for the personal data of data subjects. The Commission’s role is not limited to vindicating the GDPR rights of those data subjects who make complaints, but this is a part of its functions. 143. As the rights of data subjects and the data subject’s ability to ensure respect for those rights as established under the GDPR are dependent on the availability of transparent information in relation to the processing of personal data relating to the data subject, the requirement for transparency established under Articles 12 and 15 is central to the effectiveness of the GDPR. Similarly, Article 20, by providing for a right to data portability which means that the data subject is entitled to receive their own personal data in a structured, commonly used and machine-readable format, is also central to the enforcement of personal data rights. 144.

§

These gateway rights provisions are at the heart of the subject Complaint. The fact that the entire system for enforcement of data protection rights is reliant on information being available in respect of the personal data processed requires little explanation. It can readily beunderstood whyinfringement oftheseaccess andportabilityrights would be treated as grave, core as they are to the functioning of the safeguards provided under the GDPR. 145. While complainants have a right to access, to complain and to object which relate to their own personal data, under the general scheme of the GDPR as further implemented by the 2018Act, enforcement of the GDPR is the responsibility of the competent SAin each State. As apparent from the review of the legal framework above, tasks assigned to the Commission by application of Article 57 of the GDPR include monitoring and enforcing the application of the GDPR, handling complaints and conducting investigations.

§

It is the function of the Commission, under the terms of the GDPR and the 2018 Act, to monitor the application of the GDPR in relation to the processing of data in Ireland (Article 51 of the GDPR and s. 11 of the 2018Act). 61146. In both SCHUFA Holding Case C-26/22 and Case C-64/22 and TR v. Land Hessen Case C-768/21, the CJEU emphasised that in the context of the power of the SA to impose corrective measures that it should be borne in mind that, in accordance with Article 8(3) of the EU Charter andArticle 51(1) andArticle 57(1)(a) of the GDPR, the national supervisory authorities are responsible for monitoring compliance with the EU rules concerning the protection of natural persons with regard to the processing of personal data. In particular, under Article 57(1)(f) of the GDPR, each SA is required on its territory to handle complaints which, in accordance with Article 77(1) of that Regulation, any data subject is entitled to lodge where that data subject considers that the processing of personal data relating to him or her infringes that Regulation, to investigate,to theextent appropriate,thesubject matterofthecomplaint.

§

In monitoring the enforcement of the GDPR, it is a matter of special concern to the SA that data subjects generally should have access to information in relation to their personal data. This is the immediate context in which the Complaint in this case falls to be considered. 147. Turning then to consider the contention made on behalf of MPIL as to the bifurcated nature of the inquiry power and its implications for the imposition of corrective measures, I note that separate provision is indeed made under the legal framework for an inquiry on foot of an individual complaint as well as an own-volition inquiry, albeit the words “own-volition” do not appear in the text of the GDPR. While the words “own-volition” are not used in the GDPR, the concept of SAs having powers to initiate investigations themselves (under Article 57 and Article 58 powers), even without a complaint is clearly enshrined in GDPR as part of the SA’s task to monitor and enforce the GDPR.

§

This is manifest, for example, from Article 57(1)(h) of the GDPR which provides in express terms that SAs shall conduct investigations on the application of the GDPR, including on the basis for information received from another SA or other public authority. The Commission undoubtedly, therefore, has powers, as LSA or SA, under the GDPR and the 2018 Act to initiate an inquiry leading to the imposition of corrective measures without a complaint of data breach being made to it by or on behalf of any individual. 148. As set out above, the language of the GDPR and the 2018Act respectively provide for a very broad and extensive inquiry power with an emphasis on the Commission qua SA taking such action as it considers “appropriate” to examine issues of GDPR 62 compliance. It is striking that in prescribing broad powers of inquiry/investigation, neither the GDPR nor s. 109(1) of the 2018Act distinguishes between complaint-based inquiries or own-volition inquiries.

§

Notably, in prescribing different inquiries under s. 109(5)(e), s. 113(2) or of its own-volition, the Legislature makes identical provision using the same language for Commission’s powers of investigation, regardless of the type of inquiry. In each case, the Legislature has prescribed a broad power to cause such inquiry as the Commission “thinks fit” to be conducted. Accordingly, the claimed narrower scope of inquiry in complaint-based inquiries as compared to own-volition inquiries contended for on behalf of MPIL finds no support in the text of the relevant provisions of the 2018 Act on the plain meaning of the words used. The words used are to all material effect identical. 149. As defined in both the GDPR (Article 77) and the 2018Act (s. 107), a complaint may be made by a data subject who considers the processing of personal data relating to him or her infringes a relevant enactment. While the scope of the individual inquiry is properly rooted in the complaint and a threshold (or standing) requirement for an individual making a complaint is the identification of an alleged infringement of the complainant’s personal data right(s), there is no impediment in the language of Article 77 of the GDPR or s. 107 of the 2018 Act to an individual complainant making a complaint which properly raises systemic issues, so long as the complainant is also personally affected by those issues. 150.

§

MPIL’s contention that Article 77 supports their position that a power of inquiry on foot of a complaint is limited to investigation of an alleged infringement of the Complainant’s data rights and does not extend to matters of general or systemic concern, is not supported by the language of Article 77 because no such limitation is stated in terms, nor does it flow from the words used. I have also reflected on whether it is supported by Article 77 having regard to its context and purpose and the context and purpose of the GDPR as a whole. 151. In considering MPIL’s argument based on the requirement for a personal data breach to ground a complaint underArticle 77, it is useful to recall whereArticle 77 is situated in the overall scheme of the GDPR. Specifically, not only is it preceded byArticles 57 and 58, which are directed to securing compliance with the GDPR, but it is followed 63 by Articles 78, 79, 80, 82 and 83, all of which are concerned with the right to an effective remedy for individual breaches, combined with penalty powers whether individual data breaches are in play or not. 152.

§

The role (or “task”) of the Commission, as confirmed in Article 57(1)(a), (f) and (h) of the GDPR includes to monitor and enforce the application of the GDPR (Article 57(1)(a)), to investigate “to the extent appropriate” the “subject matter” of complaints received (Article 57(1)(f)) and “to conduct investigations on the application of this Regulation, including on the basis of information received from another supervisory authority or other public authority” (Article 57(1)(h)). 153. Insofar as Article 57(1)(f) of the GDPR requires the SA to handle complaints lodged by adatasubject, orby abody, thispowerfalls to beexercisedin pursuit oftheobjective of enforcing compliance with the GDPR, the first task of the SA. Similarly, insofar as Article 57(1)(h) requires the SA to conduct investigations on the application of this Regulation, including based on information received from another SA or other public authority, it is a power exercised in securing the faithful application of the requirements of the GDPR. 154.

§

The Commission in its role as SA is vested by the terms of Article 58(1) with wide- ranging investigatory powers and with corrective powers as set out in Article 58(2). Article 58 does not distinguish between whether infringement findings are made in a complaint-based inquiry or an own-volition inquiry when it comes to the exercise of corrective powers. At para. 33 of its judgment in TR v. Land Hessen, the CJEU stated: “in order to handle complaints thus lodged, Article 58(1) of the GDPR confers extensive investigative powers on each supervisory authority. Where, following its investigation, such an authority finds an infringement of the provisions of that regulation, it is required to react appropriately in order to remedy the shortcoming found, and each measure should, as specified in recital 129 of that regulation, in particular be appropriate, necessary and proportionate in view of ensuring compliancewiththat regulation,takingintoaccount thecircumstances of each individual case.

§

To that end, Article 58(2) of that regulation lists the various corrective measures that the supervisory authority may adopt (see, to 64 that effect, judgment of 7 December 2023, SCHUFA Holding (Discharge from remaining debts), C-26/22 and C-64/22, EU:C:2023:958, paragraph 57 and the case-law cited). 34 Thus, under Article 58(2) of the GDPR, the supervisory authority has the power, inter alia, to issue reprimands to a controller or a processor where processing operations have infringed provisions of that regulation (point (b)), to order the controller or the processor to comply with the data subject’s requests to exercise his or her rights pursuant to that regulation (point (c)), to order the controller or processor to bring processing operations into compliance with the provisions of that regulation, where appropriate, in a specified manner and within a specified period (point (d)), or to impose an administrativefinepursuant toArticle83oftheGDPR,in additionto, orinstead of the measures referred to in Article 58(2), depending on the circumstances of each individual case (point (i)).” 155.

§

When the investigatory powers vested under Articles 57 and 58(1) of the GDPR are construed in the light of the SA’s function in ensuring compliance with GDPR generally and on a systemic basis including through the exercise of corrective powers, it surely follows that where the subject matter of a complaint (be that an individual complaint or a complaint referred by a recognised body or an own motion inquiry) raises issues of systemic concern, it is for the Commission to investigate those concerns “to the extent appropriate” with due regard to systemic concerns arising. Where infringements are found, the Commission, in its capacity as SA, must, in accordance with Article 58(2), next consider appropriate corrective measures. 156. Corrective powers prescribed under Article 58(2) are not limited to requiring the processing of data in an individual complainant’s case but extend to orders required to “bring processing operations into compliance with the provisions” of the GDPR (Article58(2)(d)) and to imposeanadministrativefinepursuant toArticle83 depending on the circumstances of each individual case (Article 58(2)(i)).

§

The GDPR does not distinguish between complaint-based inquiries or own-volition inquiries when it comes to the duty and powers of the SA in relation to corrective measures. There is nothing in the GDPR to suggest that there is any jurisdictional impediment to such measures 65 being directed following investigation and a finding of infringement in respect of an individual complaint. Corrective measures available under Article 58(2) include measures plainly directed to the issue of systemic concern or systemic practices. Nothing inArticle 58(2) suggests that they can only imposed on foot of an own motion investigation. 157. In deciding on corrective action, be that in a complaint based or own-volition investigation/inquiry,Article58(2)makesitclearthattheSAmustbevestedwithpower to impose corrective measures. Furthermore, when considering the exercise of those powerstheSAis not onlyentitledto but shouldconsiderbroadersystemicissues having regard to its tasks monitoring and enforcing the application of the GDPR underArticle 57.

§

The language of s. 115 of the 2018 Act, in giving effect to the requirement under GDPR to vest theCommissionwith correctivepowers,expresslyenvisages theexercise of a corrective power in respect of complaint-based inquiries, own-volition inquiries and cross-border inquiries alike and without distinction, in keeping with the fact that the GDPR envisages corrective powers being widely available both in aid of enforcing the application of the GDPR and/or responding to complaints. 158. Article 77 of the GDPR, relied upon by MPIL, derives meaning both from the language used, its context (including location with the GDPR) and the legislative intention. The general and systemic nature and thrust of the provisions of Articles 57 and 58 are significant in terms of context and intention and are an important interpretative aid toArticle 77. 159. The language of Articles 77, 78 and 79 is addressed to the individual and securing individual remedies in the case of injury to a natural person’s data rights.

§

These provisions read together and in context demonstrate that the right to a remedy is not limited to the right to make a complaint. A person whose rights under the GDPR have been infringed is entitled to a judicial remedy as against the controller or processor in respect of the said breach (Article 78). The person is also entitled to compensation for said injury. This right to a judicial remedy and to compensation under Article 82, is limited to a person who has suffered a breach of his or her GDPR rights. To that extent, MPILis correct that some remedies provided under the GDPR require individual harm to be demonstrated by a data subject to ground an entitlement to a prescribed remedy. 66 However, this does not mean that the power to require corrective measures is similarly constrained. 160. It is significant, for example, that it is envisaged under Article 80(2), that Member States may permit a not-for-profit body, organisation or association to lodge a complaint, even without mandate from the affected data subject, if it considers that the rights of a data subject have been infringed.

§

To be entitled to compensation under Article 82, one must be a person who has suffered damage because of GDPR infringement but a complaint requiring investigation of an alleged breach of subject data rights may be referred without that person’s involvement. In such cases, the objective is not to secure compensation in respect of individual harm suffered but to secure compliance with the requirements of the GDPR. 161. While the representative action envisaged under Article 80 requires the data subject who joins in that action to have met the threshold requirement of complaining that their personaldatarightsareinfringed,nothinginthelanguageofArticle80canbeconstrued as meaning that any ensuing investigation or decision-making process is confined to the individual complaints comprised in the representative action. The contrary conclusion sits more comfortably with the fact that Article 80(2) expressly envisages a complaint from a permitted body where it considers that the rights of a data subject under the GDPR have been infringed because of data processing, without any mandate or authority from the data subject concerned.

§

Such a power, untethered from the affected individual, fits far better with a legislative intention that the ensuing inquiry be concerned with matters of general or systemic concern (rather than individual concern) in terms of compliance with and enforcement of the GDPR. 162. Similarly, although compensation under Article 82 is only due to a data subject who has suffered an infringement of rights under the GDPR, nothing in Articles 58(2)(i) or 83 of the GDPR relating to the power to impose administrative fines in respect of prescribed breaches (including infringements of Articles 12 to 20 under Article 83(5)(b)), limits the power to impose a corrective measure (including fine) by reference to a subject complaint only. The mandatory language of Article 83 makes clear that while an administrative fine need not be imposed in every case, when imposing a fine in any case of infringement of Articles 12 to 22, the SA must ensure that the 67 administrative fine is “effective, proportionate and dissuasive” and is subject to a cap calculated by reference to the turnover of the undertaking, as opposed to the data controller/processor.

§

This is irrespective of whether the case is on foot of an inquiry in respect of an individual complaint or an own-volition inquiry. The factors to be considered in deciding on whether to impose an administrative fine as sanction and the amount of the sanction are not optional. The SA is obliged to follow the mandate set by the words “shall ensure” that the decision is informed by the prescribed criteria which include the number of data subjects affected. 163. The fact that a wider lens applies in respect of corrective measures including administrative fines than in an Article 82 compensation claim is underscored by the requirement under Article 83 to have regard to factors such as the nature, gravity and duration of the infringement and the number of data subjects affected when deciding whether to impose an administrative fine. Manifestly, when requiring regard to the number of data subjects affected,Article 83(2)(a) does not limit this to consideration of affected data subjects who have made a data request and been refused access.

§

Such limiting words are not used, although they could have been if this were the legislative intent. Indeed, it is no part of MPIL’s case that an administrative fine could not be imposed in an own-volition process, absent participation of any individual, injured party. This must mean (and I do not understand it to be disputed) that power to impose a sanction is not tied to complaint cases. If it is not intended as a remedy for an injured party, however, it logically follows that it must be directed instead to securing general compliance with GDPR. 164. The detailed consideration given to the proper exercise of the power to impose an administrative fine underArticle 83 byAdvocate General Emiliou in his Opinion dated 4 of May, 2023, in NVSC Case C-683/21 supports a conclusion that the power to impose an administrative fine underArticle 83 of the GDPR is available for exercise as a corrective measure having regard to any finding of infringement of GDPR.

§

In his opinion, he stated thatArticle 83 provides a two-tier sanction system, depending on the specific type of provision infringed as follows (at paras.56-57): 68 “Whereas the first tier, defined in Article 83(4) of that regulation, applies to situations where a controller or processor breaches the general obligations to which they are subject, as well as certain specific obligations, the second tier is reserved, as Article 83(5) of the GDPR indicates, for more serious infringements, such as infringements of, inter alia, the basic principles for processing, the data subjects’ rights, and the rules relating to the transfer of personal data to a recipient in a third country or an international organisation. For both tiers, the competent national authorities must, after they have established that a particular provision of the GDPR has been infringed, perform two assessments. First, they must determine whether a fine should be imposed and, second, where they have so determined, they must set the amount of that fine.

§

Those assessments must be carried out in each individual case, in the light of various factors listed in Article 83(2) of the GDPR. Among those factors is the ‘intentional or negligent character of the infringement’ (Article 83(2)(b) thereof).” 165. It was further noted in the Opinion of Advocate General Emilou in the NVSC Case that the wording of Article 83(2) of the GDPR itself indicates that it is not mandatory in all cases to impose an administrative fine but that that provision requires the SA to take account, in each individual case, of various factors when deciding whether to impose an administrative fine. He observed (at paras. 68-69): “Those factors are circumstances – which may be aggravating or mitigating – that influence the decision of the supervisory authority, such as the nature, gravity and duration of the infringement, but also circumstances relating to the conduct of the controller, such as whether the infringement was committed intentionally or negligently.

§

In that context, the second and third sentences of recital 148 seem to me to be relevant for the purposes of interpreting Article 83(2) of the GDPR, in so far as they give indications as to the characteristics which should be taken into account in reaching a decision. The recital introduces the concept of a ‘minor infringement’, which has significant consequences for the administrative practice of the supervisory authority.” It 69 states, inter alia, that ‘in a case of a minor infringement or if the fine likely to be imposed would constitute a disproportionate burden to a natural person, a reprimand may be issued instead of a fine’”. 166. I am satisfied that it is settled as a matter of EU law that administrative fines may be imposed following the finding of an infringement in any inquiry process under the GDPR conducted in accordance with the requirements of due process but in deciding on imposing such a sanction, the SA is obliged to consider the factors identified in Article 83(2) of the GDPR.

§

To recap on those factors, in deciding on the amount of the administrative fine “in each individual case,” the SA is required (denoted using mandatory language of “shall”) to consider, inter alia, the “number of data subjects affected” (Article 83(2)(a)) and to identify an upper cap on the amount of the fine referrable to the turnover of the undertaking as a whole. In this regard, no distinction is drawn between the inquiry on foot of an individual complaint or an own-volition inquiry. 167. I am satisfied that when it comes to corrective measures, the GDPR plainly does not restrict consideration to the individual data subject in deciding on the appropriate measure but requires a broader approach in which regard is had to systemic considerations as encapsulated in the prescribed factors which must be considered. As noted above, there is no ambiguity in s. 115 of the 2018 Act in this regard either.

§

The powers of the Commission in imposing a corrective measure are identical whether exercised under ss. 111, 112 or 113 of the 2018Act. 168. When one broadens the lens from Article 77 and the right to make an individual complaint and the right to an effective judicial remedy inhering in a complainant to consider the role of the Commission as SA or LSA under the GDPR, the fundamental premise for these proceedings does not hold. This is because the right of an individual to pursue a complaint is tied to an alleged infringement of personal data rights but the duty of the Commission under the GDPR, having established infringements of a systemic nature, extends beyond imposing corrective action limited to the individual case. Having established locus standi to bring a complaint as a person affected, the relief the Commission may order in the individual’s case is not limited to a finding or 70 direction binding only as regards the individual litigant.

§

Instead, it may properly proceed to require steps to be taken to ensure compliance and/or to impose a sanction to support the effectiveness of the GDPR. This entails a power to impose a sanction by way of an administrative fine which should be both proportionate and dissuasive. In the context of large processors or controllers, it can readily be appreciated that a dissuasive fine may need to be a very significant fine. As referred to above, the extent of the power to impose a very significant fine to meet the requirements of effectiveness, proportionality and dissuasiveness is acknowledged by the applicable cap prescribed underArticle 83(5) of the GDPR. 169. Contrary to MPIL’s submission, neither the GDPR nor the 2018Act limit the scope of any ensuing process in a complaint-based inquiry to requiring a corrective act in respect of an individual breach only, even where systemic issues are identified on the facts established in the investigation conducted.

§

The absence of such a limitation is not surprising given that the main thrust of the GDPR and the 2018Act is directed towards the creation of expansive enforcement powers designed to promote compliance with prescribedprotectionofpersonaldata. Thisisapparentfromthelanguageoftherecitals to the GDPR which recognise that effective protection of personal data requires the strengthening of the rights of data subjects and the vesting of powers for monitoring and ensuring compliance with the rules of the protection of personal data and sanctions for infringements (see, for example, Recital 11). It would be impermissible as a matter of legal interpretation to construe Article 57 by reference to a restriction not provided for in express terms and not otherwise apparent from the words used in the GDPR, when such construction would have the effect of undermining the overarching obligation on the SA to ensure effective implementation of the GDPR. 170.

§

MPIL’s argument that the jurisdiction of the Commission deriving from Article 77 is only to investigate and make findings of a breach in the individual case and to make corrective orders directed to the individual infringement is not supported by the wording used or the purpose and intention served by the GDPR and constitutes a reading into Article 77 of a limitation on the powers of the Commission which has not been provided for under EU law. In its language and statutory context, the purpose and effect of Article 77 is clear. The intention is to provide an individual who alleges infringement of their data rights an effective remedy in respect of that breach. By 71 providing in black and white terms for such a remedy, nothing in the language of the Article77 otherwiselimits orcircumscribesthepowersoftheSAto secureenforcement and compliance of GDPR by means of corrective measures in respect of systemic or general matters arising from the Complaint which are of broader concern than the individual data breach alleged. 171.

§

The overarching or broad nature of these powers to secure enforcement of the GDPR is in distinction to the right to an effective judicial remedy which vests in the individual data subject under Article 79 and is directly tied to the data infringement personal to the data subject. 172. The provisions of the GDPR vesting the Commission with powers, as SAor LSA, are giveneffect(orfurthereffect)throughtheprovisionsofthe2018Actinthisjurisdiction. As set out above, the 2018 Act is entirely consistent with the GDPR insofar as it does not limit the power of investigation to a complaint-based inquiry by excluding findings of systemic significance or to which systemic significance attaches from the scope of such inquiry. The Inquiry commenced on foot of the Complaint was rooted in s. 110(1) of the 2018 Act. It is clear from s. 110(2) of the 2018 Act that the Commission had at its disposal all the powers it considered appropriate under Chapters 4 (except s. 135) and 5 of Part 6 of the 2018Act for the purpose of the Inquiry.

§

Under s. 110 of the 2018 Act, no distinction is drawn between the powers available to the Commission on an “own-volition” investigation, as opposed to a complaint-based inquiry. This legal fact is not reconcilable with MPIL’s contention in these proceedings that the Commission hasnopowertoimposecorrectivemeasuresinformedbythesystemicconcernsbecause the inquiry originated on foot of an individual complaint. 173. Any lingering doubt which may be harboured in this regard is dispelled by the fact that where the Commission is satisfied that an infringement of the GDPR has been established, whether on foot of an investigation of individual complaint or of an investigation commenced of the Commission’s own-volition, the Commission may exercise any of its powers as provided for under the 2018Act and the GDPR, including powers conferred on the Commission by Article 58(2) of the GDPR and provided for in s. 115 of the 2018 Act.

§

The requirement to consider corrective action arises in just the same way whether the infringement is found in an own-volition inquiry (s. 111(2)) 72 or an inquiry on an individual complaint (s. 112(2)) or an inquiry in respect of a cross- border complaint (s. 113(4)). Section 115 of the 2018 Act is expressed as applying in identical terms to the exercise of a corrective power whether under ss. 111, 112 or 113. In other words, there is no difference as between each of the three different types of inquiry when it comes to the statutory scaffolding provided for the exercise of a corrective power. The statutory vires of the Commission in each case is expressed in substantively identical terms. 174. Specifically, insofar as the power to impose an administrative sanction is concerned, Article 58(2)(i), which applies to inquiries whether under ss. 111, 112 or 113, provides permissively in like manner for the imposition of such a sanction but, where an administrative sanction is being applied, the Commission is required to apply Article 83 of the GDPR.

§

Article 83 is in turn expressed in very clear, mandatory language and requires consideration of prescribed factors including the number of data subjects affected when the power to impose an administrative fine is being exercised. The requirement to consider the number of data subjects affected by the breach when imposing an administrativefineis thesamewhethertheinvestigationwhich has yielded the finding of a breach was conducted under ss. 111, 112 or 113. There is no difference in this regard between an own-volition inquiry and an inquiry based on an individual complaint. 175. In short, no matter what the basis for the inquiry, the Commission is obliged when making an infringement finding to proceed to next consider the question of corrective measures which include administrative sanctions, such administrative sanctions to be considered in accordance withArticles 58 and/or 83 of the GDPR. 176.

§

The language of the separate provisions creating different powers of inquiry does not support the contended for distinction between complaint-based inquiries and so-called own-volition inquiries insofar as the imposition of corrective measures is concerned. I see nothing in the legal framework of the GDPR and the 2018 Act to support MPIL’s contention that the Commission’s powers regarding corrective measures are any different referrable to the type of underlying inquiry which resulted in the infringement finding. 73177. While the processes of investigation or inquiry are distinct and one requires a complainant, personally affected and the other does not, whether an investigation/inquiry originates in an original complaint or an own-volition inquiry, the power of the Commission is identical save that the terms of reference for the inquiry to be conducted have different sources. In the case of a complaint-based inquiry, an inquiry is rooted in a complaint by an affected party that their data rights have been infringed and the terms of reference for the inquiry are fixed by the terms of the complaint.

§

On the other hand, in an own-volition inquiry, there is no necessity for an individual complainant to come forward to assert a breach of his or her data rights and terms of reference are fixed by the SA and, in a cross border context, by consensus between the LSAand the SAprior to initiating the procedure formally or where the SA takes the view that an own-volition inquiry is also necessary to deal with systematic compliance issues going beyond the specific complaint or report (as expanded upon in EDPB Guidelines 09/2020, at para. 27). 178. Insofar as reliance is placed on the EDPB’s Guidelines and the Commission’s guidance provided in public documents to support MPIL’s interpretation of the Commission’s powers as restricted to requiring corrective measures or imposing administrative fines in complaint-based inquiries in a manner which precludes regard being had to systemic implications of breaches found, I cannot identify any such support in those documents.

§

While the documents recognise the different source of the inquiry power which is established by the GDPR and the 2018Act themselves, they do not support a conclusion that there is any limitation onArticles 58 powers, exercised in accordance with Article 83, when it comes to the obligation to require corrective measures or impose administrative sanctions. Nothing in these documents supports a different interpretation of these powers referrable to whether the findings are made in an individual case in which findings with systemic implications are made or an own- volition inquiry initiated by the SA. The distinction is procedural, not substantive and most importantly does not limit corrective powers. 179. I am satisfied that the position articulated by the EDPB through the relevant Guidelines is entirely consistent with the existence of broad powers of investigation for the purpose of securing compliance with the GDPR and an acknowledgement that these powers must be exercised in accordance with requirements of fair procedures such that 74 the controller or processor is entitled to know the parameters of the investigation from the outset.

§

In the case of a complaint-based inquiry, the inquiry is fixed by the terms of the complaint but in the case of an own-volition investigation, the terms of reference require to be fixed by the SA (by consensus when several authorities involved) and formally communicated at the outset. 180. The existence of differently sourced inquiry powers in both the GDPR and the 2018 Act is consistent with and in furtherance of the objective of effective enforcement of GDPR protections by ensuring that monitoring and enforcement is not dependent on theexistenceofanindividualcomplainant. Theonlymaterialdistinctionwhichappears to arise as between an individual complaint and an own-volition complaint insofar as the consequences of a finding that an infringement has occurred is concerned relates to the payment of compensation. In this regard, Article 82 of the GDPR provides for a right of compensation for a person who has suffered material or non-material damage because of an infringement of the Regulation and clearly vests a right to compensation in an injured party.

§

There is nothing to suggest, however, that the consequences of a data infringement found in an investigation on foot of an individual complaint are limited to the requirement to compensate. 181. I am satisfied that a single complaint by an individual data subject which results in an infringement on facts which raise broader systemic issues can, in tandem with the right to compensation vesting in the individual data subject who brought the complaint, also result in the data processor/controller being the subject of sanction in the form of corrective action directed in accordance with Article 58(2) of the GDPR and s. 115 of the 2018Act. Nowhere inArticle 58(2) or in s. 115 of the 2018Act is it suggested that corrective measures must be tailored in the case of a complaint-based inquiry to the infringement of the complainant data subject’s rights. Instead, the entire thrust of the GDPR and the 2018 Act is that the SA is empowered to impose the most appropriate penalties depending on the circumstances of the individual case having regard to the need to ensure that the GDPR is fully enforced.

§

As confirmed by the CJEU, the objective is to ensure a consistent and high level of protection of personal data through strong enforcement of the rules (see Hessen, paras. 38 and 40). 75182. Given the broadly based powers of the SA and the purpose of the GDPR, I find no support in the legal framework for the contention made that an individual complaint cannot lead to the imposition of a requirement to take corrective measures or to pay a fine having regard to the systemic nature of the breach found by the Commission following inquiry in the language of either the GDPR or the 2018Act. MPILidentifies not a single authority of the CJEU or the Irish courts which supports the limitation contended for. In the case of findings of infringement made in an inquiry on foot of an individual complaint, nothing in the language of Article 83 of the GDPR ties the SA’s powers to require corrective measures or impose administrative sanctions to the provision of a remedy for that individual complainant.

§

Rather, the SAis obliged by the mandatory language of Article 83 of the GDPR to consider the circumstances of the case, specifically the nature, gravity and duration of the infringement found, taking account of the nature and purpose of the processing concerned and the number of data subjects affected when considering an administrative sanction. 183. I am mindful that in other cases the Commission has, in some well-known instances, maintained investigations into individual complaints in tandem with “own-volition” investigations (see, for example, Meta Platforms Ireland Ltd v. Data Protection Commission [2024] IEHC 75 and Facebook Ireland Ltd v. Data ProtectionCommission [2021] IEHC 336 both of which concern the same dual process of a complaint based inquiryandanown-volitioninquiry). Asapparent fromthejudgmentinMetaPlatforms Ireland Ltd v Data Protection Commission (Quinn J.) which was addressed to the joinderofan individual complainant(Mr.Schrems)as noticepartyin proceedings taken by Meta in respect of an own-volition inquiry commenced by the Commission, two inquiries were in train at the same time.

§

The complaint made by Mr. Schrems was first in timeand was referred to in thejudgment as “the Complaints BasedInquiry”. Atpara. 90 of his judgment, Quinn J. described the complaints-based inquiry in issue as addressed to the transfer of Mr. Schrems’ personal data. The separate “Own-Volition Inquiry”, in which reference was made to the transfers of “personal data relating to individuals who are in the European Union / European Economic Area,” was described in the judgment as applying: 76 “to all those who use or access Facebook, which of course includes Mr. Schrems, whereas the Complaints Based Inquiry is stated to be particular to Mr. Schrems’own personal data.” 184. It might be observed that there was a particular history to Mr. Schrems complaint- based inquiry which was delayed by no less than two separate preliminary references to the CJEU and predated the own-volition inquiry by several years.

§

The own-volition inquiry was separately subject to challenge in Facebook Ireland Limited v. The Data Protection Commissioner & Ors. wherein Facebook unsuccessfully sought to impugn the decision to commence the separate own-volition investigation. 185. I read the decisions in cases such as Facebook Ireland Limited v. The Data Protection Commissioner & Anor. and Meta Platforms Ireland Ltd v Data Protection Commission as confirmatory oftheCommission’s jurisdiction orcompetenceto investigatesystemic issues and to elect to do so by way of an own-volition inquiry rather than within the confines of a complaint-based inquiry, in tandem with the complaint-based inquiry. By way of example, such a course of action might be prompted by the fact that certain potential infringements are not squarely identified within the scope of the individual complaint e.g. in this case it appears to be accepted that potential infringements of Article 15(1)(b), (c), (e), (f) and 15(2) highlighted in the Draft Inquiry Report fall outside the scope of the current complaint based inquiry. 186.

§

In his decision in Facebook Ireland Limited v. The Data Protection Commissioner & Anor., Barniville J. (as he then was) considered both ss. 110 and 111 of the 2018 Act and found that under s. 110(1), the Commission (at para. 158): “is entitled to commence an inquiry and that it has a wide discretion in terms of the nature and extent of that inquiry. It is entitled to “cause such inquiry as it thinks fit to be conducted” for the purpose envisaged by the section. Section 12(8) makes clear that subject to the 2018 Act, the DPC is entitled to “regulate its own procedures”. 77187. The decision in Facebook Ireland Limited v. The Data Protection Commissioner & Anor. is clear authority for the proposition that in the absence of prescribed requirements for an inquiry under s. 110, it is open to the Commission to gather information in a variety of ways, subject at all times to the overriding requirement of fair procedures as well as the other requirements contained in the GDPR concerning the need for expedition and due diligence. 188.

§

Nothing in either judgment precludes the investigation of systemic issues which properly arise in connection with a complaint-based inquiry. The fact that the Commission has elected to conduct own-volition inquiries in tandem with individual complaint-based inquiries in the past does not mean that where systemic issues arise on the facts of an individual complaint, they must always do so. The inquiry route adopted is simply the procedure by which the complaint is investigated. The inquiry powers are the same in respect of both investigation/inquiry processes. The corrective powers available are also the same. 189. I am satisfied that the fact that the Commission has adopted dual procedures in the past whether that be for reasons of expediency or otherwise, does not mean that it is bound to do so in all cases in which systemic concerns arise. I see nothing in the judgments referred to which indicate a finding that systemic issues may only be investigated in the context of an own-volition inquiry.

§

The fact that it was open to the Commission to commence an own-volition investigation/inquiry in tandem with the complaint-based inquiry in this case but has elected not to do so, instead addressing systemic issues as they arise from the individual complaint, does not render the process unlawful. The Commission is simply pursuing a different process or option equally open to the Commission, without duplicating the process unnecessarily. 190. The fact that the Commission has exercised a power to conduct own-volition inquiries in other cases and that the power to exercise an own-volition inquiry may be triggered during the investigation of an individual complaint when conduct comes to light which either falls outside the scope of the individual complaint or which for reasons of expediency or other considerations is considered to be best addressed in a separate process, does not mean that the Commission is obliged to convene an own-volition inquiry in any case where potential infringements having systemic implications are 78 identified on the basis of an individual complaint before proceeding to require correctivemeasures orimposeanadministrativesanctionreferrableto thesaid systemic implications. 191.

§

I am satisfied that the restriction which MPIL contends for on the powers of the CommissionasSAisonewhichdependsonreadinginalimitationoncorrectivepowers including powers of administrative sanction which is not supported by the language of the GDPR or the 2018Act and is inconsistent with its purpose of effective enforcement of GDPR rights. The contention that the Commission lacks statutory vires to impose corrective measures or an administrative fine referrable to the number of data subjects affected, other than the individual complainant, following inquiry on foot of an individual complaint has not, in my view, been substantiated. 192. Ihaveconcluded that the contention thatthe Commission has convertedthe individual complaint process into an own-volition process is based on MPIL’s misunderstanding of the powers of the Commission as SA or LSA under the GDPR and in accordance with the 2018 Act in identifying proposed appropriate corrective measures and proposing to impose an administrative fine having found an infringement of data rights.

§

The ongoing process is rooted in and remains a process under s. 113 of the 2018 Act based on an individual complaint in which it is proposed to make findings, require corrective measures and impose sanctions informed by the systemic nature of the infringements found on foot of the individual complaint, just as the GDPR envisages. 193. Acomplaint-based inquiry can lawfully lead to system-wide corrective measures and large fines having regard to the requirements of Articles 58 (broad corrective powers) and 83 (fines referable to the number of data subjects affected) GDPR and the Commission’s role in enforcing GDPR generally. There has been no conversion of the Inquiry because this was and is always open in such an inquiry. The fact that it originates in an individual complaint does not impact of the SA’s powers to make corrective orders. 194. Where a controller adopts a uniform, organisation-wide practice in response to data subject requests, a finding that such practice infringes the GDPR in the case of one data subject necessarily entails that the same practice will operate in the same way vis-à-vis other data subjects.

§

In such circumstances, the infringement, though identified through 79 an individual complaint, has systemic implications. The fact that the Commission is considering the systemic implications of the conduct established in the Inquiry, as it must (no matter what type of inquiry is in train), does not change the nature of the Inquiry. Broad corrective powers may be exercised in either complaint based or own- volition inquiries alike. 195. The vires case as constructed on behalf of MPIL is simply not properly grounded on the provisions underlying and providing for the powers exercised. Fair Procedures 196. MPIL contends for a high level of fair procedures by reason of the very serious consequences of infringement findings under the GDPR. I am referred in this regard to provisions of the EU Charter and decisions of the ECtHR, including the decision in Grande Stevens v. Italy (Application No. 18640/10) and other cases where the degree of severity of the penalty to which the person concerned is a priori liable may be considered penal in nature requiring a high degree of procedural fairness.

§

I do not understand the contention that a high level of fair procedures and protection of rights of defence apply in the current context to be disputed by the Commission at a level of principle, albeit it is not accepted that the process is criminal in nature. 197. In this case, however, the argument that there has been a breach of fair procedures is inextricably linked with the case made that the process has transmuted into something other than what it was from the outset with the consequence that MPIL have been deprived of rights of defence because it was not on notice that it could be exposed to corrective measures or administrative fines of the order envisaged by the Commission and was deprived of the opportunity to order its defence of the claim in the light of general and systemic concerns with such significant potential consequences. The strength of this argument relies on whether MPILhave grounds for contending that they were not on notice of the potential severity of corrective measures or administrative sanctions which might be imposed on foot of this complaint-based inquiry.

§

I am satisfied that they have not established such grounds. 80198. Having regard to the applicable legal framework, consistently cited in all formal communications, it was or should have always been clear to MPILthat the Commission would be required to consider corrective measures in accordance with Articles 58, whichcouldincludeadministrativefinesmeasuredwithdueregardtoprescribedfactors under Article 83(2) in the event of an infringement finding on foot of the complaint in this case. For a fine to be effective and dissuasive as required underArticle 83, it must be of sufficient moment that the undertaking will be incentivised to change its practices to come into compliance with the requirements of GDPR. Given the express reliance on the legal framework at all stages of this process and the clarity with which Articles 58 and 83 operate to require consideration of corrective measures including an administrative fine, the complaint that there has been a want of fair procedures in the conduct of the Commission process loses most of its substance.

§

As a matter of law, MPIL fully legally advised as to the legal framework, was clearly on notice that an inquiry was in train giving rise to corrective measures not limited to the individual case, including a potential administrative sanction, in the event that an infringement was found. 199. Quite apart from the legal framework and the expert legal advice available to MPIL, the evidence demonstrates that at each stage of the process and from the outset, MPIL was reminded of the Commission’s powers to impose a requirement for corrective measures. As early as the Notice of Commencement of Inquiry, MPILwas specifically referred to possible outcomes and the Commission’s powers under Article 58(2) and the fact that this could include administrative fines. It was clear even from the terms of the Complaint, furnished to MPIL at an early stage in the process, that it was being squarely maintained that the complaint raised concerns of great societal concern.

§

Indeed, as set out above, in the letter dated the 31 of August, 2018, the Commission replied to a request for clarification from Facebook reaffirming that the inquiry was a complaint-based statutory inquiry involving a significant number of CSAs from other Member States of the EU and the nature of the Complaint and the fact that the Complainant had identified it as giving rise to issues of “great societal importance” were highlighted as factors which led the Commission to conclude that there was no reasonable likelihood of an amicable resolution within a reasonable timeframe. 81200. It bears emphasis that the request for information issued by the Commission and the responsesto those requests by Facebook related in largepartto how Facebookcomplies withArticle 15 of the GDPR in respect of personal data processed in the Hive database generally. Facebook adopted a global or overarching position that it was not under an obligation to provide access to the underlying data stored in the Hive system but instead provides users with tools likeAccess Your Information andAds Preferences.

§

It is clear from the voluminous material generated in the statutory Inquiry that Facebook always acknowledged and never sought to deny that users are not provided with access to the raw technical information stored on Hive. 201. It was manifest from the terms of the responses made by Facebook that refusal of access at the material time was not personal to the Complainant and was systematic, albeit that the data in question was described by Facebook as “meaningless to most users”. From the terms of the Facebook response across the submissions filed over the timespan of the Inquiry, Facebook addressed its attention to the burden of providing access to “each and every user exercising their right of access” relying on identified tools which provide “users with production data.” It is clear from this that Facebook itself did not treat the Inquiry as connected only with the data access rights of the Complainant and the burden of providing his personal data to him.

§

In its several responses to the Commission during the Inquiry, Facebook stressed the amount of time and the extent of the search required to respond to access requests relating to the Hive. The work described was that involved in providing users more generally with access to Hive in the form sought by the Complainant and was not limited to his request. 202. As noted above, the Draft Inquiry Report also referred in some detail to general information obtained in relation to Hive, applicable to all users, largely informed by Facebook’s responses and submissions. It was stressed by the Commission in furnishing the Draft Inquiry Report that no determination had yet been made and that the decision-making function as it related to the issues which were the subject of the Inquiry was reserved to theCommission decision‐maker(inthis casetheCommissioner for Data Protection), who would undertake an independent review of all relevant materials in order to prepare a draft decision under and in accordance s.113 of the 2018 Act andArticle 60 of the GDPR. 82203.

§

Upon commencement of the decision making phase, by letter dated the 21 ofAugust, 2023, it was explained that the decision-maker was required not only to make findings on infringements of the GDPR but also to make a decision as to whether or not a corrective power should be exercised in respect of the controller or processor concerned, and,ifso, thecorrectivepowerthatis tobeexercised.Itwas expresslystated thatthecorrectivepowersthatmaybeexercisedaresetoutinArticle58(2)oftheGDPR and s. 115 of the 2018Act. 204. I cannot accept in the circumstances of this case that MPIL failed to understand the nature of the Inquiry in train and the potential consequences of a finding of an infringement of GDPR. It certainly approached its response to the Complaint fully cognisant that the issues arising were of a general nature, defending the Complaint based on information which explained why it was not required to provide information sought to any user.

§

The Commission’s letter in May, 2024, following the delivery of the Final Inquiry Report could not have been clearer in spelling out the obligation on the Commission to consider corrective measures, including administrative fines, in the event that an infringement was found and in referring specifically to Article 83 of the GDPR. 205. While it might be possible to ground a complaint of breach of fair procedures referrable to assurances given in the process, as more fully addressed below within the rubric of the claim for breach of legitimate expectation, I am satisfied that no assurance was given or representation made that corrective measures and administrative sanctions referrable to the broader or systemic implications of an infringement finding would not beimposed on footof an individualcomplaint based at any time in the process followed in this case such as could be said to result in unfairness. 206.

§

There is nothing on the evidence of what transpired during the process to suggest that had MPIL been aware that corrective measures would be considered having regard to systemicissues, it wouldhaveput different ormoreinformation beforethe Commission and no such information has been identified for the purpose of these proceedings. 207. I am satisfied that MPIL were on notice from the early stages of the process that corrective powers underArticles 58 and 83 could be applied to them in this complaint- based process and that administrative fines were also possible. MPIL defended 83 general/systemic issues during the Inquiry. The requirement to observe fair procedures applies in both investigation/inquiry processes – complaint-based and own-volition. Where, by law, the potential consequences are the same, the requirement to observe fair procedures in the process is not less in a complaint-based process relied on to lead to corrective measures, including significant administrative fines of the type in issue in these proceedings.

§

Those requirements were met by notifying MPILfrom the outset of the particulars of what was alleged, identifying the potential consequences and affording opportunities to respond and set out their defence throughout the process. 208. Indeed, it should be emphasised in the context of the fair procedures case advanced on behalf of MPIL, that the process is not yet concluded. These proceedings were taken in the face of a further opportunity to make submissions in respect of the PDD in advance of the Article 60 process and notwithstanding the existence of a full right of appeal against any ultimate decision under s. 141 in respect of the imposition of an administrative fine and s. 150 in respect of corrective measures generally. The final decision of the Commission must be taken in accordance with Article 60 of the GDPR and, where appropriate, Article 65, with the result that because of the cross-border nature of the complaint, the Commission may not proceed unilaterally in requiring corrective measures or imposing administrative sanctions in respect of the Complaint.

§

In the case of any administrative fine ultimately imposed by the Commission, such an administrative fine would require to be confirmed by application to the Circuit Court to be effective and the Circuit Court may refuse to do so where satisfied that there is good reason to refuse. 209. In sum, multiple opportunities arise within the ongoing process to address any fair procedures issues properly identified. Noprocedural unfairness warrantingintervention by way of judicial review has been demonstrated. The MPILwas fully on notice of the case it had to meet at all material times. In circumstances where the underlying conduct under examination concerned general organisational practices affecting all users, the potential for broader regulatory consequences was inherent in this case from the outset. There was no change in the legal character of the Inquiry. The systemic character of the issue arising from the Complaint is supported by MPIL’s evidence from which it was clear that it applied the same approach uniformly to all users. 84Legitimate Expectations 210.

§

MPILcontends that there has been a breach of a legitimate expectation that corrective actions proposed in respect of any infringement finding on the Complaint would be limited to the data rights of the Complainant and would not be extended to address systemic issues arising. The parties rely on authorities such as Glencar Exploration plc v. Mayo County Council (No. 2) [2002] 1 IR 84; [2002] IESC 1, Murphy v. Revenue Commissioners & DPP [2023] IECA 110, Facebook Ireland Limited v. Commission & Anor (cited above) and Ryan v. Data Protection Commission [2024] IECA 152 in relation to the question of legitimate expectation. I was also referred to ZF v. European Commission Case T-605/18 and Myland Ireland Ltd v. European Commission Case T-1181/23. 211. It is settled as a matter of EU case-law, as it is in Irish domestic law, that the right to rely on the principle of the protection of legitimate expectations presupposes the fulfilment of cumulative conditions.

§

From the EU case-law, there are three cumulative conditions to establish a legitimate expectation. Firstly, precise, unconditional and consistent assurances originating from authorised and reliable sources must have been given to the person concerned by the administration. Secondly, those assurances must be such as to give rise to a legitimate expectation on the part of the person to whom theyareaddressed.Thirdly,theassurancesgivenmustcomplywiththeapplicablerules. 212. MPIL relies, inter alia, on the scope of the Inquiry based on an individual complaint, the statutory framework (GDPR and 2018Act), EDPB guidelines (defining procedural scope), Commission publications (forming the factual basis of alleged representations) as well as the precedent of Commission practice in other cases (specifically several documented in reported court decisions) and formal communications in the course of the Inquiry process to contend for an assurance given as to the narrow or limited scope of the Inquiry, tied to the individual breach of data rights.

§

Having considered the material relied upon to ground the asserted representations, I am satisfied that the claim advanced based on a breach of legitimate expectation must fail. 213. The extracts identified from the Commission Guidance documents and the EDPR Guidelines recognise the distinct origins of inquiry power and how the parameters of 85 an inquiry power are established. They do not provide that systemic issues may only be addressed through an own-volition inquiry process as contended on behalf of MPIL. On an objective, fair and reasonable reading of the published documentation, where a relevant individual complaint has beenmade,a furtherown-volitioninquiry wouldonly be necessary where the systematic compliance issues go beyond the parameters of the specific complaint, bringing them beyond the scope of an inquiry already in train. I note in this regard that in Facebook Ireland Limited v. Commission, Barniville J. considered a similar argument based on a legitimate expectation as to the procedure to be followed deriving from the 2018 Annual Report having applied the well-known principles developed in Glencar, Lett & Co Ltd v. Wexford Borough Council [2012] 2 IR 198; [2012] IESC 14 and in Cromane Seafoods Ltd. v. Minister for Agriculture [2017] 1 I.R. 119. 214.

§

Addressing the legitimate expectation argument at length (from para. 188 of his judgment) in Facebook Ireland Limited, Barniville J. observed that: “it is quite clear from the terms of the 2018 Annual Report that the inquiry phases set out on pp. 28 and 29 are illustrative only and are not binding on the DPC. In maintaining that they are, FBI has sought to airbrush out completely the qualifying language contained in the Report.” 215. Barniville J. likewise rejected the argument, also advanced in this case, that the fact that a particular practice has been followed in some inquiries in the past gives rise to a legitimate expectation that the same procedure would be used in all other cases. It is noted that in Facebook Ireland Limited, Meta Platforms Ireland Limited and Ryan v. Data Protection Commission, the Courts were concerned with decisions of the Commission to continue an own-volition inquiry in tandem with a complaint-based inquiry. 216.

§

In terms of its previous practices and in circumstances where MPILrelied on previous instances of own-volition inquiry powers being exercised in respect of systemic issues, even where an individual complaint was also under investigation, several cases were 86 cited on behalf of the Commission in the papers to demonstrate a practice of ordering corrective measures of general application on foot of individual complaint-based inquiries. 217. While there is clear precedent for the imposition of systemic corrective orders in complaint-based inquiries, no previous case was identified in which significant administrative fines were imposed in a complaint-based inquiry only. At a level of principle, however, the foundations upon which this case was advanced on behalf of MPIL, namely, that systemic issues fall outside the vires of an individual complaint- based inquiry and have been treated thus by the Commission, is not borne out by the practice of the Commission.

§

Evidence as to the practice of the Commission does not demonstrate a fixed practice applied as a rule in dealing with systemic matters only through own-volition inquiries. Instead, the practice established in evidence is consistent with the fact that the Commission may elect to exercise a power to conduct an own-volition inquiry, but it may also elect to impose corrective measures of broader application in a complaint-based inquiry. Both options are open if there is compliance with the requirements of fair procedures in the process. 218. The legitimate expectation argument in this case does not rest on the contents of official publications or what occurred in other cases but is also advanced very specifically with reference to the formal correspondence which issued in the process. It has therefore been necessary to consider this correspondence in some detail but, having done so, I am satisfied that in correspondence with MPIL in the context of the Inquiry, MPIL has, throughout the process, been referred by the Commission to the Complaint and the applicable statutory provisions and legal framework.

§

The Commission has never represented that systemic compliance issues arising from findings made within the scope of the individual complaint, would not be considered by the Commission in its decision and would not have a bearing on ensuing enforcement measures adopted. Instead, the Commission has squarely relied on the applicable statutory provisions to establish the parameters of its power to impose corrective measures. 219. As established by the Court ofAppeal in Murphy v. Revenue Commissioners & DPP, it is appropriate to give objective meaning to language used in formal correspondence. 87 I am satisfied that at all stages of the process the language used in the formal correspondence in this case was carefully aligned to the applicable statutory provisions. What was intended to be conveyed and was clearly conveyed was a decision-making process in conformity with the requirements of the GDPR and in the proper exercise of powers set out in the 2018Act.

§

I can see no other meaning or representation supported by the language used in any of the formal documents relied upon by MPIL. Quite correctly, the Commission never sought to fetter or curtail any of these powers by representing that corrective powers would be narrowly focussed on the individual infringement of GDPR it found to have been established. I see nothing in the formal correspondence which could reasonably have misled MPIL in this regard. 220. Specifically, as summarised above, it was apparent even from the terms of the Complaint submitted in which the Complainant expressly pointed out that the issues he raised in respect of the processing of his personal data had wider societal significance “given the recent revelations about microtargeting, and the extent of tracking on the internet today,” that this was a complaint which might have ramifications beyond the personal data breach involving the Complainant. 221.

§

In notifying the opening of the Inquiry in the terms of the formal notice served, the Commission clearly rooted the Inquiry in s. 110(1) of the 2018 Act. The Notice of Commencement of Inquiry expressly pointed out that s. 110(2) of the Act permitted it to exercise all the powers it considered appropriate under Chapters 4 (except s. 135) and 5 of Part 6 of the 2018 Act to be carried out for the purpose of the Inquiry and the Commission stated that it was reserving the right to do so. Nothing in this language could be construed as inferring a restricted process in the conduct of the investigation. Indeed, thereferenceto s. 110 immediatelysignalledthattheCommission hadavailable to it the same powers that it would have in an own-volition investigation because this is what is provided for in s. 110(1) of the 2018Act. 222. From the Notice of Commencement of Inquiry, the purpose of the inquiry was stated to be to examine whether Facebook had discharged its obligations in connection with the subject matter of the complaint, and whether any provisions of the GDPR and/or the 2018 Act had been contravened in that context.

§

In my view, the reference to the discharge of obligations “in connection with” “the subject matter” of the Complaint 88 squarely brought within the parameters of the Inquiry the refusal by Facebook to provide identified information contrary to the requirements ofArticles 15 and 20 of the GDPR. The repeated characterisation of the inquiry as complaint-based does not, of itself, bear the meaning which MPIL seeks to attribute to it. Properly understood, that description relates to the origin and subject matter of the Inquiry, namely that it was initiated by a complaint concerning the alleged infringement of an individual data subject’s rights. It does not constitute, either expressly or by necessary implication, a representation that the Commission would limit its response, in the event of an infringement being established, to measures confined to the individual complainant. 223. It bears particular emphasis that the language used in the Notice was not limiting language which could be said to infer that the Commission was not concerned by systemic implications of any data infringements found based on systemic practices or practices of general application involved by Facebook in responding to the data request or in information provided during the Inquiry.

§

Indeed, the Notice of Commencement of Inquiry expressly alerted MPIL to the possible outcome of the Inquiry and specifically, in the event that the Commission were to determine at the conclusion of the Inquiry that there has been a contravention of the Act and/or the GDPR, then the Commission could exercise any of its powers as provided for under the Act and the GDPR including but not limited to powers conferred on the DPC by Article 58(2) of the GDPR. 224. MPIL places particular reliance on the terms of the Draft and Final Inquiry Reports, noting that the findings proposed therein were framed exclusively by reference to the Complainant’s personal data. That is so. However, those reports formed part of the investigative phase of the process. They did not purport to address, still less to determine, the question of the appropriate corrective measures to be adopted in the eventofafindingofinfringement.Thatquestionarisesatadistinctstageofthestatutory process and is governed by separate legal considerations.

§

The absence of reference to systemic consequences in the investigative reports cannot be construed as a representation that such consequences would not be addressed at the decision-making stage. 89225. Thus, while no express reference was made to s. 141 of the 2018 Act providing for administrative fines, Facebook (now MPIL) were informed in black and white, stark terms that this “may include the imposition of an administrative fine on Facebook” (in line withArticles 58(2) and 83 of the GDPR). In my view, a data controller reading the NoticeofInquiryandawareofthetermsoftheRequest as wellas theresponseprovided totheRequestandtheComplaint,couldbeundernomisapprehension astothepotential scope and ramifications of the Inquiry thus commenced, including the potential exposure to a sanction by way of administrative fine and how this would be measured. 226. The fact that the corrective measures which could flow from the Inquiry was in no way limited to the data breach affecting just one person remained clear throughout the process.

§

There was no doubt from the outset that the Complaint raised systemic issues. The Complainant spelt this out in his complaint and the Commission expressly referenced the Complainant’s position in early correspondence. 227. When the Draft Inquiry Report issued on the 25 of January, 2022, MPIL was again expressly referred to the statutory provisions governing the process. The express reference to s. 113 of the 2018Act in the Draft Inquiry Report served (or ought to have served) as a clear reminder to Facebook/MPIL that where the Commission decision- maker adopts a decision to the effect that a data infringement has occurred or is occurring, there flows from this an obligation on the Commission under s. 113(4) of the 2018 Act to consider the exercise of corrective powers. The Commission has no discretion in this regard. It is mandated as a matter of law to consider the exercise of corrective powers, albeit that it has a discretion ultimately as to what, if any corrective powers, it considers it appropriate to exercise (provided its decision in this regard is reconcilable with its obligations under EU law). 228.

§

It bears further emphasis that the exercise of corrective powers under s. 113(4) necessarily engages s. 115 of the 2018 Act which expressly empowers the imposition of administrative sanctions and any other corrective power specified in Article 58 of the GDPR. Even a fleeting familiarity withArticle 58 identifies the range of corrective powers available to the Commission to ensure compliance with the GDPR, including the possible imposition of administrative sanctions. However, insofar as the power to impose an administrative sanction is concerned,Article 58(2)(i) requires an application 90 of Article 83 of the GDPR when considering imposing such a sanction. This in turn mandates (through the repeated use of the word “shall” in Article 83) consideration of the number of data subjects affected. 229. In the circumstances, the proposition that MPIL was led to understand through communications during the statutory process that the Commission was only concerned with a single instance data breach in the Complainant’s case and would not have regard to the broader concerns arising from the subject matter of the complaint leading to the imposition of an administrative fine referrable to these systemic concerns assessed in accordance withArticle 83(2) criteria is simply untenable. 230.

§

It was urged on me on behalf of MPILthat no findings were made in the Final Inquiry Report about Facebook’s general practices, impacts on other users or systemic non-compliance beyond the Complainant’s individual data request and they relied on this as confirmation of the limited scope of the inquiry process. This approach to the Final Inquiry Report is incomplete and self-serving in circumstances where the Final Inquiry Report plainly set out information obtained during the Inquiry in relation to data on the Hive system as it affects each user or users generally. st 231. Uponcommencement of thedecision-making phase,byletterdatedthe 21 ofAugust, 2023, it was explained that the decision-maker was required not only to make findings on infringements of the GDPR but also to make a decision as to whether or not a corrective power under Article 58(2) of the GDPR or s. 115 of the 2018Act should be exercised in respect of the controller or processor concerned, and, if so, the corrective power that is to be exercised.

§

I am at a loss to see how MPIL contends that it could read this as consistent with their contended for representation that systemic issues were beyond the scope of the process. 232. This contention is all the more difficult to comprehend when regard is had to the letter nd dated the 2 of May, 2024, from the Commission in which it repeated that where its preliminary view was that there had been an infringement, it would be necessary to consider whether or not any corrective action (including the possible imposition of an administrative fine) might be warranted. This correspondence was directed towards establishing the undertaking concerned in circumstances where Article 83 of the GDPR (interpreted in the light of Recital 150) envisages that administrative fines should be 91 imposed on ‘undertakings’, rather than data controllers or processors, noting the significance of this question in identifying the relevant fining “cap”, which for the purpose of Articles 83(4) and (5) falls to be calculated by reference to the turnover of the undertaking as a whole, rather than the turnover of the respondent data controller or processor.

§

It was pointed out in this letter that MPIL is a wholly owned subsidiary of Facebook International Operations Limited which is ultimately owned and controlled by Meta Platforms Inc. and it was assumed, that Meta Platforms Inc. was similar to a sole owner as regards its power to exercise a “decisive influence over the conduct of MPIL.” This was described as a “rebuttable presumption”. Aresponse was invited in this regard. nd 233. It is noteworthy that although the letter of the 2 of May, 2024, elicited a detailed response from MPIL’s solicitors dated the 16 of May, 2024, in which issue was taken with the Commission’s approach to the concept of the undertaking concerned but in this letter it was not contended that in considering corrective action, including the imposition of administrative sanctions, there had been any enlargement of the scope of the process. While it is true that this correspondence did not alert MPIL to the scale of the proposed measures, insofar as matters of scope are concerned, it was not then disputed that a legal basis existed for the imposition of corrective measures including administrative fines.

§

As a matter of law (and never suggested otherwise by the Commission) where administrative fines are concerned, the Commission is not at large but must approach the question in the light of the factors identified in Article 83(2) of the GDPR. 234. In this case, the Complaint and the response it elicited brought systematic compliance issues within the scope of the individual inquiry insofar as they related to infringements ofArticle15(1)(a), (d) and (g). In contrast, the Commission has signalledthatit accepts that systemic compliance issues relating to Article 15(1)(b), (c), (e), (f) and Article 15(2) fell outside the scope of the Inquiry and are not relied upon in the draft PDD. In all its communications throughout the process, the Commission has proceeded with clear reference to its statutory powers. It has never sought to dilute those powers and nothing it has said could be construed as diminishing those powers.

§

The Commission is obliged when making an infringement finding to consider the question of corrective measures and administrative sanctions in accordance with Articles 58 and/or 83. Not 92 only is the Commission not entitled to resile from this obligation as this would constitute an impermissible abdication of its functions, but I see no evidence that it ever sought to in making any representation which could have been interpreted as limiting the scope of the Commission’s inquiry and decision making function on the Complaint. 235. Thematters relieduponbyMPILto establishlimitationsona complaint-basedprocess which are not prescribed by the legislative scheme and would appear to cut across it, fall far short of the type of statement or representation required to give rise to a legitimate expectation considered in the caselaw. The Commission never represented, let alone clearly represented, that the process in train would not permit consideration of systemic issues arising in terms of corrective action flowing from a finding of infringement.

§

Nor could it be said that the Commission had “committed” in its publications to only investigate systemic issues in the context of an own-volition inquiry in terms necessary to support a claim for legitimate expectation. Not only have MPIL failed to establish a representation or assurance as to the process in train upon which they relied to their detriment in concluding that the Commission would not have regard to systemic implications of any infringement findings on foot of an individual complaint and/or without conduct an own-volition inquiry but, in fact, the evidence shows that MPIL deployed significant resources (including evidence from an expert andcomprehensivewrittensubmissions)torespondtothesystemicimplicationsarising in connection with the induvial complaint made. It is unclear, therefore, what detriment MPIL says arises to them by reason of the process followed. 236. The fact that the Commission squarely invoked its statutory powers at all times in the process means that it could not be said to be “unfair or inconsistent with good administration” (in the words of Lord Fraser in Attorney General of Hong Kong cited by Barniville J. in Facebook Ireland Limited the Commission & Anor.) or that is would be “unjust to permit the public authority to resile from it” (in the words of Fennelly J. in Glencar which were followed and approved in several of the subsequent cases, includingCromane,also consideredinsomelengthbyBarnivilleJ.in FacebookIreland Limited the Commission & Anor.) to conclude that where vires is established on foot of the provisions identified, no unfairness or injustice flows from taking steps in accordance with the process provided for in the legal framework.

§

In this regard, I am satisfied that MPILwerenot entitledto expect thatit wouldnot beexposedto corrective 93 measures of general application in the inquiry process as these are only imposed in own-volition inquiries. Such an expectation runs directly contrary to the statutory regimeand it is notsupported byevidenceas to thepracticewhichshowsboth measures of general application in own-volition and complaint-based inquiries. 237. I harbour significant doubts that the Commission could ever legitimately represent that it would restrict the exercise of its powers in a manner inconsistent with the requirements of the GDPR as given further effect to by the 2018 Act in the manner contended on behalf of MPIL. I echo the views of Barniville J. in addressing similar arguments in Facebook Ireland Limited v. the Commission & Anor. when he stated (at para. 224) that: “a legitimate expectation of the type which FBI has sought to have recognised andenforcedwould,inmyview,beinconsistentwiththe Commission’s“freedom to exercise properly a statutory power” (being the phrase used by Fennelly J. in his statement of the test in Glencar).” 238.

§

I further note Barniville J.’s finding that even if, contrary to his primary findings, a legitimate expectation had been established based on the published procedures and/or the practice followed by the Commission in other previous inquiries, it would nonetheless be open to the Commission to depart from the procedures referred to and to adopt a different procedure for its inquiry, provided that in doing so it complied with fair procedures and with the Commission’s obligations under the 2018 Act and the GDPR. Even the existence of longstanding practices (which those identified on behalf of MPIL are not) does not give rise to any legitimate expectation that that practice will not change, albeit in some instances may require that a change of practice will only occur with reasonable notice being given. Those considerations do not arise in this case because it was at all times made clear to MPIL that the statutory process was being followed and there has been no deviation from this.

§

Evidence as to practice shows that no hardand fast practice ofakind which could groundasuccessful claim to alegitimate expectation existed. 94239. It is my view that, as with the fair procedures argument advanced, MPIL’s claim based on a legitimate expectation is dependent on its interpretation of the vires of the Commission, which I have found to be wrong in law. On a proper approach to the exercise of the Commission’s powers under Article 58 and 83 of the GDPR, as further given effect through the provisions of the 2018Act, the Commission could not lawfully limit its consideration of prescribed matter when it comes to the exercise of its statutory powers. Nor did it. I am satisfied that the process pursued by the Commission is entirely in line with the applicable provisions. It was never in doubt but that were an infringement found, the Commission would proceed to consider Articles 58 and 83 of the GDPR, as it is mandated by law to do. 240.

applies Art. 58
§

MPIL was not entitled to infer from the fact that the process was initiated on foot of an individual complaint that the consequences of any adverse findings would be limited to a remedy appropriate to the infringement of the Complainant’s rights only, with no enforcement action taken regarding systemic matters. No such limitation exists within the statutory regime applying and the Commission as SAor LSAis obliged to consider corrective action having regard to the circumstances of the individual case, including any general or systemic issues arising. No representation was ever made that remedies would be limited to the individual complainant and all communications reflected the statutory framework which clearly allowed broader measures. 241. I am satisfied that the Commission did not make any representation, whether express or implied, that it would restrict the scope of its corrective powers in the manner contended for, nor did it adopt a practice capable of giving rise to such an expectation.

§

The process followed was, at all times, consistent with the statutory framework governing the Commission’s functions. The ground of challenge based on legitimate expectations must therefore fail. CONCLUSION 242. The case made that the draft PDD is ultra vires on the basis that the GDPR and the 2018 Act distinguish between complaint-based and own-volition inquiries such that complaint-based inquiries are limited to remedies for the individual complainant, whereas systemic issues may only be addressed through own-volition inquiries, is not 95 borne out by the legislative framework. The contention made on behalf of MPIL that the architecture and structure of the GDPR and the 2018 Act requires the Commission to address systemic issues only within the rubric of an own-volition inquiry is not legally sound. 243. TheGDPRestablishesabroadsystemofenforcementinwhichsupervisoryauthorities are tasked with monitoring and ensuring compliance.

§

Articles 57 and 58 confer wide investigative and corrective powers, including the obligation to investigate complaints “to theextent appropriate”andto takemeasures necessary to ensurecompliance.These provisions do not differentiate between complaint-based and own-volition inquiries in terms of the extent of powers of investigation or the nature of corrective measures available. 244. While a complaint must be grounded in an alleged infringement of the complainant’s personal data rights, there is nothing in Article 77 or the 2018 Act that prevents such a complaint from raising systemic issues, provided the complainant is personally affected. Nor is there any textual or purposive basis for limiting an ensuing investigation or decision to the individual circumstances of the complainant. 245. Where an infringement is found, the SA is required to consider corrective measures under Article 58(2), which include orders to bring processing operations into compliance and the imposition of administrative fines under Article 83.

§

These powers are not confined to addressing the individual complainant’s position but may extend to systemic deficiencies identified during the inquiry. Article 83 mandates consideration of factors such as the nature, gravity and duration of the infringement and the number of data subjects affected if imposing an administrative fine, confirming that sanctions are directed at ensuring general compliance rather than providing an individual remedy. 246. The 2018 Act reflects the same broad scheme as the GDPR. It confers identical corrective powers regardless of whether an inquiry is commenced on foot of a complaintorontheCommission’sowninitiative.Theonlymaterialdistinctionbetween these processes lies in their origin: a complaint-based inquiry is defined by the subject matter of the complaint, whereas an own-volition inquiry is defined by the authority itself(ormorethanoneauthority). Thisproceduraldistinctiondoesnotaffecttheextent 96 of the Commission’s powers either to investigate within the parameters of a complaint or agreed terms of reference/scope of inquiry or to impose corrective measures once an infringement has been established. 247.

§

Accordingly, a complaint-based inquiry may lawfully address systemic issues arising onthefactsandmayresultinsystem-widecorrectivemeasuresincludingadministrative fines informed by systemic considerations. This does not convert a complaint-based inquiry into an own-volition process but reflects the Commission’s overarching obligation to ensure effective enforcement of the GDPR when infringements are found. 248. MPIL’s contention that the Commission’s powers are confined in a complaint-based inquiry to remedies for the individual complainant depends on reading into the GDPR and the 2018 Act a limitation that is not supported by their text, context, or purpose. The legal framework instead supports the conclusion that the same corrective powers apply irrespective of how an inquiry is initiated, and that those powers may properly be exercised by reference to the broader impact of the infringement identified. 249.

§

There has been no impermissible extension of the process from an individual complaint process to an own-volition process and nobreachofrights of fair procedures. The applicable legal framework, consistently referenced throughout the process, made clear that any infringement finding would require consideration of corrective measures under Article 58, including administrative fines assessed in accordance with Article 83. Those provisions plainly contemplate sanctions that are effective, proportionate and dissuasive, taking into account factors such as the scale and impact of the infringement irrespective of the source of the process. 250. MPILwasonnoticefromtheoutsetthatcorrectivemeasures(includingadministrative fine) were possible and were not confined to the individual complainant. This is borne out by the procedural record. Furthermore, the course and substance of the process of inquiry further reinforced its systemic dimension.

§

Requests for information and MPIL’s responses addressed its general approach to compliance with Article 15, particularly in respect of the Hive database. MPIL defended a uniform position applicable to all users, acknowledging that certain categories of data were not made accessible in raw form. Its submissions addressed the burden of responding to access requests at scale, demonstrating that it understood the issues to extend beyond the 97 individual complainant. Having engaged extensively with systemic issues during the Inquiry, MPIL does not point to any unfairness in the process in terms of a different approach it might have taken if it were not mistaken as to the scope of the process. 251. The claim in reliance on legitimate expectation also fails as no assurances were ever given by the Commission that corrective measures directed to systemic issues would not be made in this case. The various materials relied upon by MPIL (guidelines, prior practice and correspondence) do not objectively support the existence of a representation that the Inquiry would be limited in scope.

applies Art. 15
§

The correspondence and formal notices issued during the inquiry repeatedly signalled that the Commission retained the full scope of its powers, including the possibility of imposing broad corrective measures and fines at that stage of the statutory process. In addition, the statutory framework under the GDPR and the 2018 Act clearly empowers, and indeed obliges, the Commission to consider the full range of corrective measures, including thoseofgeneral application andadministrativefines, onceaninfringement is identified. Throughout the process, the Commission consistently referred to these statutory powers, and at no point sought to limit or fetter them. 252. Nor does past practice support MPIL’s position as there is clear evidence that systemic corrective measures have previously been imposed in complaint-based inquiries (albeit not fines of the order now proposed). There is no rule of practice or law that systemic issues can only be addressed through own-volition investigations. 253.

§

In view of my findings above, I will make an order dismissing the proceedings and will hear the parties in relation to any consequential matters, if required. This matter will be listed following the expiry of fourteen days from the electronic delivery of this judgment for the purpose of finalising orders. 98

How it connects

190 of 195 paragraphs apply legislation or carry a topic — see them in the full text ↓