A report by Ireland's DPC: 17 large inquiries concluded in 2022, resulting in €1B+ fines; 10K+ cases concluded in 2022, including 246 cross-border complaints
Vish Gain / Silicon Republic :
Context & Ripple Effects
For years the story around Ireland's DPC was backlog, not enforcement: an FT analysis found 98% of significant complaints unresolved, and the EU ombudsman opened an inquiry into Irish GDPR application in response. That pressure followed years of accumulation — six new multinational probes in 2019 alone (bringing cross-border investigations to 21) on top of a complaint volume that had already climbed past 2,800 after GDPR took effect (per the 2018 report).
The 2022 annual report is the counter-argument to that record: 17 large inquiries concluded with over €1 billion in fines, more than 10,000 cases closed, and 246 cross-border complaints processed — anchored by the €405M Instagram children's privacy fine, the DPC's third penalty against Meta. The question the report answers is whether the DPC can convert its unique position as lead regulator for US Big Tech's EU operations into actual decisions.
First-order effects
- Meta and the other multinationals under DPC investigation now face a regulator that closes large inquiries rather than letting them sit — the €1B+ in 2022 fines makes continued non-decision costlier for the companies involved.
- Complainants and other EU data protection authorities get a functioning pipeline for the 246 cross-border complaints, replacing the stalled process the ombudsman had flagged.
Second-order effects
- Other EU regulators who had threatened to step in where Dublin stalled now have less grounds to bypass the Irish lead-authority mechanism, keeping decision-making power concentrated in Dublin — and the fines' scale (following the EU-wide €1.1B in 2021 GDPR penalties) pushes Big Tech's compliance budgets and EU legal teams toward Ireland's docket.
- With over 6% of Ireland's workforce in tech, the state now has to reconcile a revenue-relevant enforcement posture against its exposure to the same US companies it fines.
Third-order effects
- If the 2022 output holds, Ireland's DPC consolidates as the EU's de facto enforcement hub for US platforms — with the ombudsman's scrutiny setting the accountability mechanism for whether that hub stays credible.
- Sustained billion-euro penalty years would normalize large GDPR fines as a cost of operating in Europe, shifting platform behavior from contesting jurisdiction to budgeting for enforcement.
The trend: GDPR enforcement in Ireland is pivoting from complaint backlog to concluded cross-border decisions, under ombudsman pressure and with the DPC's role as lead regulator for US Big Tech on the line.