Skip to content
Enforcement · Data Protection Authority of Ireland EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

Limerick City and County Council: Insufficient fulfilment of data subjects rights

The Irish DPA has fined Limerick City and County Council EUR 110,000.

€110,000 Fine
Limerick City and County Council
IRELAND
Art. 13 GDPR Art. 12 GDPR Art. 15 GDPR

Full text 2 findings

Paragraphs carrying a topic or an applied provision show those connections inline
§

The Irish DPA has fined Limerick City and County Council EUR 110,000. As part of an investigation, the DPA conducted an audit of the processing of personal data by the council or on its behalf using video surveillance systems, automatic license plate recognition, body-worn cameras and other technologies that can be used to monitor individuals. In doing so, it found that the Council had violated a number of data protection laws in its use of the technologies. However, the fine was issued due to GDPR violations. The DPA found that the Council violated Art. 13 GDPR in relation to the processing of data by traffic cameras. The Council had failed to provide information on the identity of the data controller, the contact details of the data protection officer, the purposes of the processing and the bodies from which further information required under Art. 13 GDPR may be obtained. In addition, the Council failed to provide this information in an easily accessible manner such as on signs near the cameras.

§

Further, the DPA concluded that the Council failed to post a video surveillance policy in an clear and plain language as well as in an easily accessible area of the Council's website. The DPA thus found an infringement of Art. 12 GDPR. Lastly, the Council has denied requests for access to personal data processed by surveillance cameras used in traffic management. For this reason, the DPA found that the Council violated Art. 15 GDPR. GDPR Articles: Art. 13 GDPR, Art. 12 GPDR, Art. 15 GDPR Industry: Public Sector and Education

How it connects

2 of 2 paragraphs apply legislation or carry a topic — see them in the full text ↓
C-487/21 Österreichische Datenschutzbehörde v CRIF C-487/21 (Österreichische Datenschutzbehörde) CJEU Oct 26, 2023 Right of Access Right to Restriction Personal Data
C-203/22 CK v Magistrat der Stadt Wien In Case C-203/22, the Court of Justice of the European Union interpreted Article 15(1)(h) of the GDPR in response to a preliminary ruling from the Verwaltungsgericht Wien… CJEU ·First Chamber Feb 27, 2025 Profiling Automated Decision-Making Marketing
2016 IEHC 323 High Court examines DPA inquiry into Meta's refusal of raw data access and portability On 25 May 2018, Michael Veale, the data subject, submitted an access and data portability request to Meta Platforms Ireland Limited (MPIL) (then Facebook Ireland Limited), the… Aug 21, 2026 Data Portability Supervisory Authorities Personal Data
C-422/24 Case C-422/24 - AB Storstockholms Lokaltrafik. A new page has been created with the following information: "" CJEU Jan 7, 2026 Personal Data Fairness & Transparency Controllers
2 A 165/24 OVG Saarlouis - 2 A 165/24 The data subject was an employee, the controller was the employer. On 14 January 2022, the data subject requested access to personal data from the controller under Article 15… May 13, 2025 Right of Access Personal Data Right to Restriction