/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

Irish Council for Civil Liberties: 75% of the Irish DPC's GDPR decisions in EU-level cases since 2018 have been overruled by the European Data Protection Board

Meta, Google, Airbnb, Yahoo!, Twitter, Microsoft, Apple and Tinder account for 87^% of cross-border GDPR complaints to Ireland's DPC Source: Irish Council … .

The Irish Times Ciara O'Brien

Context & Ripple Effects

This ICCL tally is the sharpest number yet in a four-year arc of documented Irish DPC underperformance. Coverage began with critics questioning the regulator's willingness to crack down on firms that dominate Ireland's economy (critics question the DPC's willingness), then hardened into an FT finding that 98% of significant privacy complaints remained unresolved, which pushed the EU ombudsman to open its own inquiry (the ombudsman inquiry) and forced the Commission into six-times-yearly enforcement reporting after ICCL pressure (six-monthly reporting changes).

What the new figure adds is a verdict on output quality, not just speed: of the cross-border decisions the DPC did finally make since 2018, three-quarters were overturned by the European Data Protection Board — and the complaint pipeline it sits on is extraordinarily concentrated, with Meta, Google, Airbnb, Yahoo!, Twitter, Microsoft, Apple and Tinder accounting for 87% of cross-border cases.

First-order effects

  • The named eight companies face re-issued, harsher GDPR decisions as the EDPB rewrites the DPC's rulings — penalties and required processing changes land at EU level rather than at whatever leniency Dublin drafted.
  • The DPC's standing as lead enforcer for most US Big Tech takes a direct credibility hit: its own decisions are now statistically the exception, not the rule, in cross-border cases.

Second-order effects

  • Other national regulators and complainant groups gain a documented case for routing around Dublin — pushing more scrutiny through the ombudsman channel and the EDPB itself rather than waiting on Irish drafts.
  • The Commission's six-monthly reporting regime, created after ICCL campaigning earlier this year, now has a headline metric to justify tightening procedural rules on how lead-authority decisions get made.

Third-order effects

  • If the pattern holds, GDPR enforcement structurally migrates away from the country where the tech giants are domiciled toward Brussels-level bodies (EDPB, European Commission), weakening the one-stop-shop model that made Ireland the de facto privacy regulator for US platforms.
  • Persistent overruling also raises the prospect that the 'lead authority' role becomes contested or shared — a governance redesign question the ombudsman inquiry has already put on the EU agenda.

The trend: GDPR enforcement of US Big Tech is drifting from Ireland-based self-governance toward centralized EU oversight, with the DPC's overruled-decision rate accelerating that shift.

Discussion

  • @johnnyryan Johnny Ryan on x
    This morning: we publish analysis of #GDPR enforcement as we near 5 years. Insight 1 —> 75% of Irish GDPR decisions in EU-level cases have been overruled by the European Data Protection Board. @EU_EDPB https://www.iccl.ie/...
  • @m_mariastefania Maria Magierska on x
    this is telling: “EDPB register of EU-level decisions shows only 49 compliance orders over 4.5 years. By late 2022, most (64%) of the 159 EU-level enforcement measures were merely reprimands.” https://twitter.com/... [image]
  • @livingstone_s Sonia Livingstone on x
    “Almost five years after it was implemented, the GDPR is rarely enforced against Big Tech. Few major EU cases have resulted in serious enforcement measures. The European Commission must act.” @johnnyryan https://twitter.com/...
  • @iccltweet @iccltweet on x
    Today we've published a new report into the enforcement of #GDPR. Almost 5 years after it came into effect, the GDPR is rarely enforced against Big Tech. Few major EU cases have resulted in serious enforcement measures. 🧵 by ICCL Senior Fellow @johnnyryan https://twitter.com/...
  • @paultang Paul Tang on x
    Effectiveness of Europe's data protection rulebook is thwarted by weak national (read Irish) enforcement. Shows again: European values deserve European supervision! https://www.iccl.ie/...
  • @irishtimes @irishtimes on x
    The report said that the DPC tends to use its discretion under Irish law to choose “amicable resolution” to conclude 83 per cent of the cross-border complaints it receives, instead of using enforcement measures. Click here for more: https://www.irishtimes.com/... (5/5)
  • @maxschrems Max Schrems on x
    Next week the #GDPR hits #5yearsGDPR - @johnnyryan has (again) done a great job getting facts and numbers together! IMHO the national executive (aka DPAs) largely undermined the EU legislator's intention of serious privacy enforcement - which is not only a problem for privacy, ht…
  • @eoindrea Dr. Drea on x
    If you needed one fact to highlight the gap between how Ireland is perceived in Brussels, and how Ireland views itself - “75% of Irish GDPR decisions in EU-level cases have been overruled by the European Data Protection Board”😥https://www.iccl.ie/ ...