Skip to content
Content type · 45 documents in this view · 3,811 in total

Enforcement

Regulatory actions, fines, warnings, and enforcement decisions

Country: Ireland (45) Clear filter
1–45 of 45 sort newestlargest fineoldest
€403M Google Ireland Limited: Insufficient legal basis for data processing The Irish Data Protection Commission (DPC) fined Google Ireland Limited €403 million on September 21, 2026, following an inquiry into the company's processing of personal data… DPC ·Art. 5, 6, 12 +1 ·Insufficient legal basis for data processing Legitimate Interest Personal Data Supervision Sep 21, 2026
€300,000 Midlands Regional Hospital Tullamore, County Offaly: Insufficient technical and organisational measures to ensure information security The Data Protection Authority of Ireland fined Midlands Regional Hospital Tullamore €300,000 for failing to implement sufficient technical and organizational measures to ensure… Ireland ·DPC ·Art. 5, 28, 30 +2 Integrity and Confidentiality Principle Notification Obligation Data Breaches Jun 11, 2026
€277,500 Permanent TSB: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined Permanent TSB €277,500 on 2026-05-08 for: Insufficient technical and organisational measures to ensure information security. Ireland ·DPC ·Art. 5, 32, 33 Integrity and Confidentiality Principle Notification Obligation Data Breaches May 8, 2026
€277,500 Permanent TSB plc: Insufficient technical and organisational measures to ensure information security The Data Protection Authority of Ireland fined Permanent TSB plc €277,500 for failing to implement sufficient technical and organisational measures to ensure information security,… Ireland ·DPC ·Art. 5, 32, 33 Notification Obligation Data Breaches Supervision Apr 30, 2026
€98,000 University of Limerick: Insufficient technical and organisational measures to ensure information security Data Protection Authority of Ireland fined University of Limerick €98,000 on 2025-12-10 for: Insufficient technical and organisational measures to ensure information security. Ireland ·DPC ·Art. 5, 30, 32 +2 Security Supervisory Authorities Education Dec 10, 2025
€125,000 City of Dublin Education and Training Board: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 125,000 on the City of Dublin Education and Training Board. The controller suffered a data breach due to insufficient technical and… IRELAND ·DPC ·Art. 5, 32, 33 +1 Data Breaches Controllers Security Jun 23, 2025
€550,000 Ministerie van Sociale Zekerheid: Onvoldoende wettelijke basis voor gegevensverwerking. 550.000 euro boete - Ierse Autoriteit voor Gegevensbescherming. IRELAND ·DPC ·Art. 5, 6, 9 +2 Types of Special Categories of Personal Data Personal Data Controllers Jun 12, 2025
€550,000 Departement of Social Security: Insufficient legal basis for data processing The Irish DPA imposed a fine of EUR 550,000 on the Departement of Social Security. The controller uses the so called SAFE 2 registration process for anyone applying for a Public… IRELAND ·DPC ·Art. 5, 6, 9 +2 DPIA Types of Special Categories of Personal Data Controllers Jun 12, 2025
€530M TikTok Technology Limited: Insufficient legal basis for data processing The Irish DPA (DPC) has fined TikTok EUR 530 million. In its decision, the DPC found, that TikTok infringed Art. 13 (1) f) GDPR and Art. 46 (1) GDPR due to the unlawful transfer… DPC ·Art. 13, 46 Processing Agreement International Transfer Personal Data May 2, 2025
€251M Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security The Irish Data Protection Commission (DPC) has fined Meta Platforms Ireland Limited EUR 251 million. The fine was imposed for data protection violations related to a data breach… DPC Notification Obligation Data Breaches Controllers Dec 17, 2024
€40,000 Maynooth University: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 40,000 on Maynooth University. The controller failed to implement adequate technical and organisational measures, resulting in an… IRELAND ·DPC ·Art. 5, 32, 33 Security Controllers Supervisory Authorities Nov 22, 2024
€29,500 Sligo County Council: Non-compliance with general data processing principles The Irish DPA has imposed a fine of EUR 29,500 on the Sligo County Council. The controller used video surveillance but failed to ensure compliance with the GDPR. They failed to… IRELAND ·DPC ·Art. 5, 13, 24 +3 Security Controllers Supervisory Authorities Nov 13, 2024
€310M LinkedIn: Insufficient legal basis for data processing The Irish DPA (DPC) has fined LinkedIn EUR 310 million. This decision is related to an investigation following a complaint in 2018 from the French NGO 'La Quadrature Du Net'. In… DPC ·Art. 60 Consent Supervisory Authorities Social Media Oct 24, 2024
€91M Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has imposed a fine of EUR 91 million on Meta Platforms Ireland Limited (MPIL). The DPC had initiated an investigation after MPIL reported that user passwords… DPC Data Breaches Encryption Security Sep 27, 2024
€345M TikTok Limited: Non-compliance with general data processing principles The Irish DPA (DPC), has imposed a fine of EUR 345 million on TikTok Limited. The DPC conducted an investigation primarily focused on the processing of personal data between July… IRELAND ·DPC ·Art. 5, 12, 13 +2 Privacy by Design & Default Processing Personal Data Sep 1, 2023
06/SIU/2018 The Irish DPC started an own volition inquiry into processing operations carried out by the Galway County Council (the controller), focusing mainly into the surveillance… 06/SIU/2018 ·Ireland ·DPC Monitoring DPIA Accountability Aug 22, 2023
€22,500 Irish Departement of Health: Non-compliance with general data processing principles The Irish DPA (DPC) has fined the Irish Department of Health EUR 22,500. The DPA launched an investigation into the department following public allegations that the department… IRELAND ·DPC ·Art. 5, 6, 9 Retention Period Healthcare Personal Data Jun 16, 2023
€1,200M Meta Platforms Ireland Limited: Insufficient legal basis for data processing The Irish DPA (DPC) has fined Meta Platforms Ireland Limited EUR 1.2 billion. This is the highest fine imposed to date under the GDPR. In its decision, the DPC found that Meta had… DPC ·Art. 46 Processing Agreement International Transfer Supervision May 12, 2023
€750,000 Bank of Ireland 365: Insufficient technical and organisational measures to ensure information security The Irish DPA has fined Bank of Ireland 365 EUR 750,000. The bank had notified the DPA of 10 data breaches linked to the bank's app. Unauthorized persons had managed to gain… DPC ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Security Personal Data Data Breaches Feb 27, 2023
€460,000 Centric Health Ltd.: Non-compliance with general data processing principles The Irish DPA has imposed a fine of EUR 460,000 on Centric Health Ltd.. The controller suffered a ransomware attack in which personal data such as name, date of birth and contact… IRELAND ·DPC ·Art. 5, 32 Security Controllers Personal Data Jan 23, 2023
€5.5M WhatsApp Ireland Ltd.: Insufficient legal basis for data processing The Irish DPA (DPC) has fined WhatsApp Ireland Ltd. EUR 5.5 million. The Austrian organization 'None of Your Business' (NOYB) had filed a complaint with the DPA on behalf of an… DPC ·Art. 6, 12, 13 ·Insufficient legal basis for data processing Fairness & Transparency Consent Personal Data Jan 19, 2023
€50,000 DPC (Ireland) reprimands Kildare County Council over surveillance tech and CCTV compliance This case involves an own-volition investigation conducted by the Irish DPA (DPC) into Kildare County Council, the controller. In June 2018, Officers from the Special… Art. 2, 5, 6 +5 Legitimate Interest Controllers Personal Data Jan 16, 2023
€390M Meta Platforms Ireland Limited: Non-compliance with general data processing principles The Irish DPA (DPC) has fined Meta Platforms Ireland Limited EUR 390 million. The DPA has imposed a fine of EUR 210 million for violations related to the provision of its Facebook… DPC Transparency Supervision Supervisory Authorities Jan 4, 2023
€15,000 A&G Couriers Limited T/A Fastway Couriers (Ireland): Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has fined A&G Couriers Limited T/A Fastway Couriers (Ireland) EUR 15,000. During a changeover of its IT systems, the controller had suffered a cyberattack in… DPC ·Art. 32 ·Insufficient technical and organisational measures to ensure information security Security Controllers Right of Access Dec 30, 2022
€100,000 VIEC Limited: Non-compliance with general data processing principles The Irish DPA has imposed a fine of EUR 100,000 on the nursing home operator VIEC Limited. The controller had notified the DPA of a data breach pursuant to Art. 33 GDPR. The… IRELAND ·DPC ·Art. 5, 32 Integrity and Confidentiality Principle Data Breaches Security Dec 22, 2022
€265M Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security The Irish DPA has fined Meta Platforms Ireland Limited EUR 265 million. The DPA had launched an investigation against Meta in 2021 after media reports indicated that a dataset… DPC Privacy by Design & Default Security Personal Data Nov 25, 2022
€405M Meta Platforms, Inc.: Non-compliance with general data processing principles The Irish DPA (DPC) has imposed a fine of EUR 405,000,000 on Meta Platforms, Inc. (Instagram). Following the investigation, the DPC submitted a draft decision under Art. 60 GDPR… IRELAND ·DPC ·Art. 5, 6, 12 +3 Supervision Supervisory Authorities Processing Sep 5, 2022
€463,000 Bank of Ireland: Insufficient technical and organisational measures to ensure information security The Irish DPA has fined the Bank of Ireland EUR 463,000. The bank had reported 22 data breaches to the DPA under Article 33 GDPR. As part of its investigation, the DPA found that… DPC ·Art. 32, 33, 34 ·Insufficient technical and organisational measures to ensure information security Data Breaches Notification Obligation Security Apr 5, 2022
€17M Meta Platforms Ireland Limited: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has imposed a fine of EUR 17 million on Meta Platforms Ireland Limited (former Facebook Ireland Limited). The decision is based on twelve notifications of data… DPC ·Art. 5, 24 Accountability Supervision Security Mar 15, 2022
€5,000 Slane Credit Union Ltd.: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 5,000 on Slane Credit Union Ltd. The controller had notified the DPA of a data breach in 2018. Due to an error in a search engine… IRELAND ·DPC ·Art. 5, 24, 28 +2 Controllers Processors Security Jan 26, 2022
€110,000 Limerick City and County Council: Insufficient fulfilment of data subjects rights The Irish DPA has fined Limerick City and County Council EUR 110,000. As part of an investigation, the DPA conducted an audit of the processing of personal data by the council or… IRELAND ·DPC ·Art. 12, 13, 15 Right of Access Personal Data Controllers Dec 9, 2021
€60,000 Irish Teacher Council: Insufficient technical and organisational measures to ensure information security The Irish DPA has imposed a fine of EUR 60,000 on the Irish Teaching Council. The Council notified the DPA of a data breach under Art. 33 of the GDPR. Accordingly, two employees… IRELAND ·DPC ·Art. 5, 32, 33 Data Breaches Personal Data Security Dec 2, 2021
Facebook Ireland Limited: Insufficient fulfilment of information obligations The organization 'None of your business' (NOYB) published a draft decision of the Irish DPA (DPC) on October 13, 2021, which indicates that it proposes a fine between EUR 28… DPC ·Art. 5, 12, 13 ·Insufficient fulfilment of information obligations Supervisory Authorities Personal Data Information Provision Modalities and Communication Methods Oct 6, 2021
€1,400 Vodafone Ireland Limited: Insufficient fulfilment of data subjects rights The Irish DPA has fined Vodafone Ireland Limited EUR 1,400. Vodafone had in several cases sent marketing SMS and emails and made telephone calls without the consent of the data… DPC ·Art. 21 ·Insufficient fulfilment of data subjects rights Direct Marketing Personal Data Marketing Sep 7, 2021
€225M WhatsApp Ireland Ltd.: Insufficient fulfilment of information obligations The Irish DPA (DPC) has imposed a fine of EUR 225,000,000 on WhatsApp Ireland Ltd. The DPA had started extensive investigations into the messaging service's compliance with… DPC ·Art. 5, 12, 13 +1 ·Insufficient fulfilment of information obligations Transparency Information Provision Modalities and Communication Methods Fairness & Transparency Sep 2, 2021
€1,500 MOVE Ireland: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has fined the organization MOVE (Men Overcoming Violence) EUR 1,500. MOVE is a charity working in the field of domestic violence. The organization aims to… DPC ·Art. 5, 32 ·Insufficient technical and organisational measures to ensure information security Data Breaches Security Personal Data Aug 20, 2021
€90,000 Irish Credit Bureau DAC: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) has imposed a fine of EUR 90,000 on Irish Credit Bureau (ICB). The fine follows a data breach reported by the controller to the DPA on August 31, 2018. The… IRELAND ·DPC ·Art. 5, 24, 25 Controllers Security Data Breaches Mar 23, 2021
€70,000 University College Dublin: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) fined University College Dublin (UCD) EUR 70,000 due to seven personal data breaches. Unauthorized third parties were able to access UCD e-mail accounts, and… IRELAND ·DPC ·Art. 5, 32, 33 Data Breaches Notification Obligation Security Dec 17, 2020
€450,000 Twitter International Company: Insufficient fulfilment of data breach notification obligations The Irish DPA (DPC) fined Twitter International Company EUR 450,000 for violating Art. 33 (1) GDPR and Art. 33 (5) GDPR for failing to notify the DPA in a timely manner of a data… IRELAND ·DPC ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Dec 15, 2020
€65,000 Cork University Maternity Hospital: Insufficient technical and organisational measures to ensure information security The „Data Protection Authority of Ireland“ imposed a fine on Cork University Maternity Hospital (CUMH) after the personal data of 78 patients was discovered disposed of in a… IRELAND ·DPC ·Art. 5, 32 Personal Data Security Health Data Aug 18, 2020
€85,000 Tusla Child and Family Agency: Insufficient technical and organisational measures to ensure information security The Irish DPA (DPC) fined Tusla Child and Family Agency EUR 85,000. The controller had reported 71 data breaches to the Irish DPA that occurred between May 25 and November 16,… IRELAND ·DPC ·Art. 32 Security Controllers Personal Data Aug 12, 2020
€40,000 Tusla Child and Family Agency: Insufficient fulfilment of data breach notification obligations The organization sent a letter with abuse allegations to a third party who then uploaded it to social networks. IRELAND ·DPC ·Art. 33 Notification Obligation Data Breaches Notified Body Reporting and Notification Obligations Jun 30, 2020
€75,000 Tusla Child and Family Agency: Insufficient legal basis for data processing The company has erroneously disclosed personal data, including information about children, to unauthorized persons. In one case, the contact and location data of a mother and a… IRELAND ·DPC ·Art. 5, 6 Personal Data Processing Public Authority May 17, 2020