Irish Council for Civil Liberties: 75% of the Irish DPC's GDPR decisions in EU-level cases since 2018 have been overruled by the European Data Protection Board
Meta, Google, Airbnb, Yahoo!, Twitter, Microsoft, Apple and Tinder account for 87^% of cross-border GDPR complaints to Ireland's DPC Source: Irish Council … .
Context & Ripple Effects
This ICCL tally is the sharpest number yet in a four-year arc of documented Irish DPC underperformance. Coverage began with critics questioning the regulator's willingness to crack down on firms that dominate Ireland's economy (critics question the DPC's willingness), then hardened into an FT finding that 98% of significant privacy complaints remained unresolved, which pushed the EU ombudsman to open its own inquiry (the ombudsman inquiry) and forced the Commission into six-times-yearly enforcement reporting after ICCL pressure (six-monthly reporting changes).
What the new figure adds is a verdict on output quality, not just speed: of the cross-border decisions the DPC did finally make since 2018, three-quarters were overturned by the European Data Protection Board — and the complaint pipeline it sits on is extraordinarily concentrated, with Meta, Google, Airbnb, Yahoo!, Twitter, Microsoft, Apple and Tinder accounting for 87% of cross-border cases.
First-order effects
- The named eight companies face re-issued, harsher GDPR decisions as the EDPB rewrites the DPC's rulings — penalties and required processing changes land at EU level rather than at whatever leniency Dublin drafted.
- The DPC's standing as lead enforcer for most US Big Tech takes a direct credibility hit: its own decisions are now statistically the exception, not the rule, in cross-border cases.
Second-order effects
- Other national regulators and complainant groups gain a documented case for routing around Dublin — pushing more scrutiny through the ombudsman channel and the EDPB itself rather than waiting on Irish drafts.
- The Commission's six-monthly reporting regime, created after ICCL campaigning earlier this year, now has a headline metric to justify tightening procedural rules on how lead-authority decisions get made.
Third-order effects
- If the pattern holds, GDPR enforcement structurally migrates away from the country where the tech giants are domiciled toward Brussels-level bodies (EDPB, European Commission), weakening the one-stop-shop model that made Ireland the de facto privacy regulator for US platforms.
- Persistent overruling also raises the prospect that the 'lead authority' role becomes contested or shared — a governance redesign question the ombudsman inquiry has already put on the EU agenda.
The trend: GDPR enforcement of US Big Tech is drifting from Ireland-based self-governance toward centralized EU oversight, with the DPC's overruled-decision rate accelerating that shift.