Irish Data Protection Commission report: watchdog received 2,864 complaints in 2018 after May 25, when GDPR came into force, compared to 2,642 for all of 2017
Context & Ripple Effects
Ireland's Data Protection Commission logged 2,864 complaints in just over seven months of GDPR — more than its entire 2017 tally of 2,642 — making it one of several EU regulators reporting a step-change in volume: France counted 3,767 post-GDPR complaints while the UK ICO more than doubled its intake, and by January 2019 the European Commission tallied more than 95K complaints filed EU-wide.
For the DPC specifically, the surge matters because it hosts the EU lead-regulator role for most US tech giants. The complaint influx fed directly into what came next: by early 2020 the agency had opened six inquiries into multinational tech companies' GDPR compliance, part of 21 major cross-border probes still awaiting decisions.
First-order effects
- The DPC's caseload jumped immediately: seven months of GDPR produced more complaints than all of 2017, straining an agency sized for the pre-GDPR era.
- Multinationals regulated through Dublin — Meta among them — faced a rising volume of formal complaints that each require investigation under the new regime.
Second-order effects
- Complaint volume translated into investigative pipeline: the inquiries opened off this intake left the DPC carrying 21 major cross-border probes with no decisions delivered, drawing criticism of its enforcement pace.
- As cases matured, the cost of non-compliance became concrete for the complainants' targets — the DPC moved from intake to penalties, including a €17M fine on Meta over disclosed breaches.
Third-order effects
- If the pattern holds, GDPR converts data protection authorities from advisory offices into high-volume enforcement bodies, with Ireland's DPC structurally positioned as the bottleneck — and focal point — for policing US tech in Europe.
- Sustained complaint growth pressures the EU's one-stop-shop mechanism itself: when the lead regulator is seen as slow, other national authorities and complainants push for faster, more distributed enforcement.
The trend: GDPR is transforming Europe's data protection regulators from low-volume advisory bodies into mass-scale enforcement agencies, with Ireland's DPC at the center of the load.