Irish DPC report: 6 inquiries into multinational tech companies' GDPR compliance were opened in 2019, bringing major cross-border probes to 21, but no decisions
The lead European Union privacy regulator for most of big tech has put out its annual report which shows another major bump …
Context & Ripple Effects
By the time this annual report landed, the Irish DPC was already the de facto lead regulator for US big tech: it had opened a probe into Facebook's data breach in late 2018 and by May 2019 counted 19 cross-border investigations, eleven of them aimed at Facebook, WhatsApp, and Instagram alone. The new report extends that picture — six more inquiries opened in 2019, taking the total to 21 — but the striking detail is what is missing: not a single decision.
First-order effects
- Facebook, WhatsApp, and Instagram remain the dominant subjects of the DPC's inquiry pipeline, with no rulings yet forcing changes to their EU data practices despite probes running since 2018.
- Multinationals headquartered in Ireland now face a growing queue of open inquiries stacked on top of rising complaint volumes — the watchdog logged 2,864 complaints in its first full GDPR year, up from 2,642 across all of 2017.
Second-order effects
- The decision backlog invites scrutiny from other EU regulators and critics: an FT analysis found 98% of 164 significant privacy complaints about US Big Tech still unresolved, sharpening pressure on the one-stop-shop mechanism that routes everything through Dublin.
- Competing national regulators gain an argument for bypassing or challenging the Irish bottleneck, threatening the concentration of enforcement power the GDPR's cross-border design gave the DPC.
Third-order effects
- When the logjam finally broke, it broke large: 17 large inquiries concluded in 2022 produced over €1 billion in fines, suggesting the 2019-era backlog was deferred enforcement rather than abandoned enforcement — a pattern regulators elsewhere may replicate when capacity catches up with caseload.
- The same slow-build structure reappears in newer domains: the DPC's 2024 investigation into Google's use of EU user data for AI model training shows the inquiry-first, decide-later playbook extending from social data to foundation models.
The trend: GDPR enforcement against US big tech runs on a long fuse — years of accumulating inquiries funneled through Ireland's regulator before resolving into billion-euro decision waves.