All insightsTopic

Data protection, the DPC, and the data you already hold

The GDPR is eight years old here and it is still the regulation that produces the Irish enforcement decisions you can read.

The AI Act gets the attention. The GDPR gets the decisions. Every published Irish enforcement action against an ordinary small business in the last five years has come from the Data Protection Commission, and the pattern in them is consistent: the incident is what starts the investigation, and the paperwork is what the fine is for.

These articles are about the parts of that an Irish SME actually touches. Whether a DPIA is mandatory rather than merely advisable. What a privacy notice has to say and when it has to be given. Whether a US supplier can lawfully receive your data. What happens in the first seventy two hours after a breach.

The Irish specifics matter more here than in most of European data protection law, because the DPC has published a binding list of processing that requires a DPIA, an Irish age of digital consent, and a separate regime for health research that catches private companies as well as universities.

8 articles on this

GDPR

Health research in Ireland: explicit consent, and the way around it

The regulations are written around the activity rather than the institution, so a commercial medtech is inside them on the same terms as a hospital.

8 minute read6 sources

GDPR

You have had a data breach. What the first 72 hours require

The 72 hours runs from when you became aware, not from when you finished investigating. That is the sentence most people get wrong on the day.

9 minute read4 sources

GDPR

Cookie banners in Ireland, and what the DPC actually said

Scrolling is not consent, pre-ticked boxes are not consent, and the six month rule everybody quotes is softer than they think.

9 minute read5 sources

GDPR

Sending personal data to the US from Ireland, in 2026

Yes, and with conditions. The Framework holds, the checks are specific, and the part people skip is whether the particular company is actually on the list for the particular data.

11 minute read7 sources

GDPR

Do you need a DPIA? Ireland has its own list, and it is specific

Most guidance answers this with European criteria. Ireland has a published list of its own, and it is the one that decides the question here.

10 minute read5 sources

GDPR

An SEO plugin updated itself, and the DPC found three separate failures

The interesting part is not the breach. It is that once the DPC looked, the record of processing and the processor agreement failed too.

7 minute read3 sources

GDPR

Does a small Irish business website need a privacy notice?

We fetched 82 Irish business websites in one week. Thirty-four had no privacy notice at any of the usual addresses, and three had one that nothing on the site linked to.

9 minute read3 sources

GDPR

AI in hiring: the rule that is already in force

Article 22 has applied since May 2018. If software rejects candidates and no person really decides, the rules that bite are the data protection ones.

10 minute read8 sources

What we do about this

Talk to us

Other topics