Selling online from Ireland

Regulators

Who regulates what online in Ireland, and who will actually contact you

Most Irish businesses assume the Data Protection Commission covers all of this. It covers one regulation out of six.

By Oscar CobbeCurrent as at 9 minute read8 sources

Six regimes, six sets of powers

An ordinary Irish consumer-facing website now sits under several separate regimes at once, and they were written at different times by different institutions with different enforcement machinery behind them.

The practical question is not which regulator is in charge of the internet. It is which one will send you a letter, and that is decided by which rule you are on the wrong side of.

The ruleThe Irish bodyThe instrument
Personal data, and cookiesData Protection CommissionGDPR and S.I. 336 of 2011
Digital Services Act generallyCoimisiún na Meán, as Digital Services CoordinatorDigital Services Act 2024, section 8
DSA Articles 30 to 32, online marketplacesCompetition and Consumer Protection CommissionDigital Services Act 2024, Part 3
Accessibility of e-commerce and e-booksCompetition and Consumer Protection CommissionS.I. 636 of 2023, Regulation 4(2)(f) and (g)
Accessibility of productsCompetition and Consumer Protection CommissionS.I. 636 of 2023, Regulation 4(1)
Accessibility of electronic communications, and 112Commission for Communications RegulationS.I. 636 of 2023, Regulation 4(2)(a) and (h)
Accessibility of consumer bankingCentral Bank of IrelandS.I. 636 of 2023, Regulation 4(2)(e)
AI Act, coordination and single point of contactAI Office of IrelandRegulation of Artificial Intelligence Act 2026
AI in employment decisionsWorkplace Relations CommissionEU AI Act, as designated

The Data Protection Commission, which is the one with a record

The DPC is the Irish supervisory authority for the GDPR, and its powers also cover the ePrivacy Regulations of 2011 and the Law Enforcement Directive. It is the only Irish digital regulator with a long published record of decisions against ordinary businesses.

Its 2025 annual report records 16,160 new cases from individuals, a 45% increase on 2024, and 6,521 valid breach notifications, a 16% decrease. Almost half of those breaches were correspondence sent to the wrong recipient.

That last figure is the most useful number on this page for a small business, because it says what the risk actually looks like. It is not an attacker. It is an email.

Coimisiún na Meán, and the one active enforcement record

Section 8 of the Digital Services Act 2024 designates Coimisiún na Meán as Ireland's Digital Services Coordinator and as competent authority for the Digital Services Act other than in respect of Articles 30, 31 and 32.

It is enforcing. It opened an investigation into X in November 2025 concerning Article 20, the internal complaint-handling system. In December 2025 it opened investigations into TikTok and LinkedIn concerning Articles 16 and 25. In May 2026 it opened two investigations into Meta, in respect of Facebook and Instagram, concerning Articles 25 and 27 and the design patterns around choosing a non-profiling feed.

Every one of those is against a very large platform, and the obligations at issue are in Sections 3 and 4 of Chapter III, which are precisely the sections Articles 19 and 29 switch off for a micro or small enterprise. An Irish SME reading that enforcement record is reading about a regime it is not in.

The CCPC, which wears three hats

The Competition and Consumer Protection Commission has the broadest digital remit of any Irish body over an ordinary shop, and almost nobody associates it with any of this.

Under Part 3 of the Digital Services Act 2024 it is the competent authority for Articles 30 to 32, the online marketplace provisions. Under Regulation 4(1) of the Accessibility Regulations it is the market surveillance authority for every in-scope product. And under Regulation 4(2)(f) and (g) it is the compliance authority for e-books and for e-commerce services.

That third hat is the one that matters most. For a consumer-facing Irish website, the regulator of accessibility is the CCPC, not the National Disability Authority. The NDA's role under the Accessibility Regulations is advisory, under Regulation 4(4). Its monitoring role is under the separate public sector regime, S.I. No. 358 of 2020, and applies to public bodies.

The consumer who does not need a regulator at all

Regulation 30 of S.I. No. 636 of 2023 lets a consumer apply directly to the Circuit Court for a compliance order against a non-compliant economic operator, and Regulation 30(10) lets a representative body engage on their behalf with their approval. No regulator has to be involved and there is no compensation cap in the way there is under the Equal Status Acts. It is the sharpest practical exposure on this page.

Where there is no enforcement record, said plainly

Two of these regimes have no published Irish enforcement action that we could find as at 31 August 2026.

Under S.I. No. 636 of 2023, the Accessibility Regulations, we found no published direction, compliance notice or prosecution. The CCPC's accessibility pages carry guidance and a set of microenterprise guidelines rather than outcomes, and ComReg's information notice of June 2025 states it can take enforcement action without reporting any. The regulators are in a guidance phase.

Under the AI Act, we found no published Irish enforcement action either, which is unsurprising given the AI Office was established in July 2026 and the high-risk regime does not apply until December 2027.

In both cases that is a statement about what has been published. The Accessibility Regulations' enforcement pathway starts with a notice of proposal and fourteen days to make representations, which happens in private. None published is not none issued.

Which one will contact you

In descending order of likelihood for an ordinary Irish business with a website.

  1. 1The Data Protection Commission, because of a complaint from an individual or a breach you notified yourself. This is by far the most likely, and it usually starts with something you reported.
  2. 2A consumer, through the Circuit Court, under Regulation 30 of the Accessibility Regulations. No regulator needed and no cap.
  3. 3The CCPC, on accessibility of an e-commerce service, if the guidance phase turns into an enforcement phase.
  4. 4Coimisiún na Meán, if you actually operate an intermediary service, which most shops do not.
  5. 5The Workplace Relations Commission, if you use software anywhere near hiring, and specifically if it infers anything from how a candidate looks or sounds.

The useful way to hold all this

Nobody needs to memorise a table of regulators. What is worth holding is the shape: the rules that reach you follow from what your business does, and the bodies follow from the rules.

Which is why the free checks on this site are scoped by activity rather than by regulation. Answering six questions about what you actually run gets you the list of duties, and the duties name their supervisors.

For the AI side specifically, the Irish designation has a gap in it worth knowing about: the Department publishes a list of fourteen competent authorities, and four of them do not appear in the statutory instrument we could find.

Sources

  1. 1.Digital Services Act 2024, No. 2 of 2024 · Irish Statute Book, Office of the Attorney General
  2. 2.Digital Services Act, and published investigations · Coimisiún na Meán
  3. 3.The Digital Services Act, enforcement and regulation · Competition and Consumer Protection Commission
  4. 4.S.I. No. 636 of 2023, and the designation of authorities in Regulation 4 · Irish Statute Book, Office of the Attorney General
  5. 5.Who we are · Data Protection Commission
  6. 6.DPC publishes 2025 Annual Report · Data Protection Commission
  7. 7.European Accessibility Act · National Disability Authority
  8. 8.AI Office of Ireland established, Paul Byrne appointed as CEO · Department of Enterprise, Tourism and Employment

One assessment, all of the regimes

The compliance audit works out which of these actually reach a business and which do not, and says so in writing with the instrument behind each answer. For most Irish SMEs the list of what does not apply is longer than the list of what does, and that is a useful document to hold.

GDPR and AI compliance audit

Who wrote this

Oscar Cobbe · Founder, FourWinds Digital

Writes and maintains the legal explainers on this site, and does the compliance work behind them. Every date and article number here is checked against the instrument itself before it is published, and corrected in place when the law moves.

More about how we work →

Read next

More on Selling online from Ireland

Written on 31 August 2026 and accurate as at that date. This is general information about how the rules work, not legal advice on your situation. We are not solicitors and we say so when you need one.