Regulators
Who regulates what online in Ireland, and who will actually contact you
Most Irish businesses assume the Data Protection Commission covers all of this. It covers one regulation out of six.
By Oscar CobbeCurrent as at 9 minute read8 sources
Six regimes, six sets of powers
An ordinary Irish consumer-facing website now sits under several separate regimes at once, and they were written at different times by different institutions with different enforcement machinery behind them.
The practical question is not which regulator is in charge of the internet. It is which one will send you a letter, and that is decided by which rule you are on the wrong side of.
| The rule | The Irish body | The instrument |
|---|---|---|
| Personal data, and cookies | Data Protection Commission | GDPR and S.I. 336 of 2011 |
| Digital Services Act generally | Coimisiún na Meán, as Digital Services Coordinator | Digital Services Act 2024, section 8 |
| DSA Articles 30 to 32, online marketplaces | Competition and Consumer Protection Commission | Digital Services Act 2024, Part 3 |
| Accessibility of e-commerce and e-books | Competition and Consumer Protection Commission | S.I. 636 of 2023, Regulation 4(2)(f) and (g) |
| Accessibility of products | Competition and Consumer Protection Commission | S.I. 636 of 2023, Regulation 4(1) |
| Accessibility of electronic communications, and 112 | Commission for Communications Regulation | S.I. 636 of 2023, Regulation 4(2)(a) and (h) |
| Accessibility of consumer banking | Central Bank of Ireland | S.I. 636 of 2023, Regulation 4(2)(e) |
| AI Act, coordination and single point of contact | AI Office of Ireland | Regulation of Artificial Intelligence Act 2026 |
| AI in employment decisions | Workplace Relations Commission | EU AI Act, as designated |
The Data Protection Commission, which is the one with a record
The DPC is the Irish supervisory authority for the GDPR, and its powers also cover the ePrivacy Regulations of 2011 and the Law Enforcement Directive. It is the only Irish digital regulator with a long published record of decisions against ordinary businesses.
Its 2025 annual report records 16,160 new cases from individuals, a 45% increase on 2024, and 6,521 valid breach notifications, a 16% decrease. Almost half of those breaches were correspondence sent to the wrong recipient.
That last figure is the most useful number on this page for a small business, because it says what the risk actually looks like. It is not an attacker. It is an email.
Coimisiún na Meán, and the one active enforcement record
Section 8 of the Digital Services Act 2024 designates Coimisiún na Meán as Ireland's Digital Services Coordinator and as competent authority for the Digital Services Act other than in respect of Articles 30, 31 and 32.
It is enforcing. It opened an investigation into X in November 2025 concerning Article 20, the internal complaint-handling system. In December 2025 it opened investigations into TikTok and LinkedIn concerning Articles 16 and 25. In May 2026 it opened two investigations into Meta, in respect of Facebook and Instagram, concerning Articles 25 and 27 and the design patterns around choosing a non-profiling feed.
Every one of those is against a very large platform, and the obligations at issue are in Sections 3 and 4 of Chapter III, which are precisely the sections Articles 19 and 29 switch off for a micro or small enterprise. An Irish SME reading that enforcement record is reading about a regime it is not in.
The CCPC, which wears three hats
The Competition and Consumer Protection Commission has the broadest digital remit of any Irish body over an ordinary shop, and almost nobody associates it with any of this.
Under Part 3 of the Digital Services Act 2024 it is the competent authority for Articles 30 to 32, the online marketplace provisions. Under Regulation 4(1) of the Accessibility Regulations it is the market surveillance authority for every in-scope product. And under Regulation 4(2)(f) and (g) it is the compliance authority for e-books and for e-commerce services.
That third hat is the one that matters most. For a consumer-facing Irish website, the regulator of accessibility is the CCPC, not the National Disability Authority. The NDA's role under the Accessibility Regulations is advisory, under Regulation 4(4). Its monitoring role is under the separate public sector regime, S.I. No. 358 of 2020, and applies to public bodies.
The consumer who does not need a regulator at all
Regulation 30 of S.I. No. 636 of 2023 lets a consumer apply directly to the Circuit Court for a compliance order against a non-compliant economic operator, and Regulation 30(10) lets a representative body engage on their behalf with their approval. No regulator has to be involved and there is no compensation cap in the way there is under the Equal Status Acts. It is the sharpest practical exposure on this page.
Where there is no enforcement record, said plainly
Two of these regimes have no published Irish enforcement action that we could find as at 31 August 2026.
Under S.I. No. 636 of 2023, the Accessibility Regulations, we found no published direction, compliance notice or prosecution. The CCPC's accessibility pages carry guidance and a set of microenterprise guidelines rather than outcomes, and ComReg's information notice of June 2025 states it can take enforcement action without reporting any. The regulators are in a guidance phase.
Under the AI Act, we found no published Irish enforcement action either, which is unsurprising given the AI Office was established in July 2026 and the high-risk regime does not apply until December 2027.
In both cases that is a statement about what has been published. The Accessibility Regulations' enforcement pathway starts with a notice of proposal and fourteen days to make representations, which happens in private. None published is not none issued.
Which one will contact you
In descending order of likelihood for an ordinary Irish business with a website.
- 1The Data Protection Commission, because of a complaint from an individual or a breach you notified yourself. This is by far the most likely, and it usually starts with something you reported.
- 2A consumer, through the Circuit Court, under Regulation 30 of the Accessibility Regulations. No regulator needed and no cap.
- 3The CCPC, on accessibility of an e-commerce service, if the guidance phase turns into an enforcement phase.
- 4Coimisiún na Meán, if you actually operate an intermediary service, which most shops do not.
- 5The Workplace Relations Commission, if you use software anywhere near hiring, and specifically if it infers anything from how a candidate looks or sounds.
The useful way to hold all this
Nobody needs to memorise a table of regulators. What is worth holding is the shape: the rules that reach you follow from what your business does, and the bodies follow from the rules.
Which is why the free checks on this site are scoped by activity rather than by regulation. Answering six questions about what you actually run gets you the list of duties, and the duties name their supervisors.
For the AI side specifically, the Irish designation has a gap in it worth knowing about: the Department publishes a list of fourteen competent authorities, and four of them do not appear in the statutory instrument we could find.
Sources
- 1.Digital Services Act 2024, No. 2 of 2024 · Irish Statute Book, Office of the Attorney General
- 2.Digital Services Act, and published investigations · Coimisiún na Meán
- 3.The Digital Services Act, enforcement and regulation · Competition and Consumer Protection Commission
- 4.S.I. No. 636 of 2023, and the designation of authorities in Regulation 4 · Irish Statute Book, Office of the Attorney General
- 5.Who we are · Data Protection Commission
- 6.DPC publishes 2025 Annual Report · Data Protection Commission
- 7.European Accessibility Act · National Disability Authority
- 8.AI Office of Ireland established, Paul Byrne appointed as CEO · Department of Enterprise, Tourism and Employment
One assessment, all of the regimes
The compliance audit works out which of these actually reach a business and which do not, and says so in writing with the instrument behind each answer. For most Irish SMEs the list of what does not apply is longer than the list of what does, and that is a useful document to hold.
GDPR and AI compliance auditWho wrote this
Oscar Cobbe · Founder, FourWinds Digital
Writes and maintains the legal explainers on this site, and does the compliance work behind them. Every date and article number here is checked against the instrument itself before it is published, and corrected in place when the law moves.
More about how we work →Read next
Digital Services Act
Does the Digital Services Act apply to an Irish online shop?
The Act regulates services that carry other people's content or other people's goods. Selling your own stock is not one of them.
EU AI Act
Who regulates AI in Ireland, and which one is yours
There is no Irish AI regulator. There are more than a dozen of them, and which one is yours depends on what your business does rather than on what your software is.
European Accessibility Act
Does the European Accessibility Act apply to your website?
Two questions settle it: are you selling to consumers, and do you employ fewer than ten people. Most Irish SMEs can answer both in a minute.
Written on 31 August 2026 and accurate as at that date. This is general information about how the rules work, not legal advice on your situation. We are not solicitors and we say so when you need one.