/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

With GDPR's two-year anniversary today, the Irish Data Protection Commission is under pressure to act, amid doubts about the agency's enforcement ability

Ireland's Data Protection Commission is under pressure to act, and act soon.  —  Facebook's European headquarters in Dublin.

Politico Mark Scott

Context & Ripple Effects

Two years into GDPR, the Irish Data Protection Commission remains the lead enforcer for most major tech firms by virtue of their European headquarters being in Dublin — yet it has issued almost nothing of substance against them. Critics were already questioning its willingness to crack down on companies that dominate Ireland's economy a year into the law (critics questioned the DPC's willingness), and the only substantial privacy penalty against a major firm since May 2018 came from the US, not Europe (Facebook's $5B US fine).

The anniversary lands as a test case is already on the record: when the DPC wanted documents from Facebook, it had to resort to an inspection that postponed Dating's European launch (the Dating postponement) — a signal of how hard routine supervision has been.

First-order effects

  • The DPC faces immediate pressure to open or conclude decisions on long-running complaints against Facebook and peers headquartered in Dublin, with its credibility as lead regulator staked on acting rather than another year of process.
  • Facebook and other US firms with European headquarters in Ireland now operate under an active threat that the one-stop-shop regime routes enforcement through an agency they have so far outlasted.

Second-order effects

  • If the DPC stays slow, complainants and other member-state regulators push cases up to the EU level — the pattern later confirmed when human rights group ICCL triggered changes obliging regulators in Ireland and elsewhere to report six times a year on GDPR enforcement (EU-mandated six-monthly reporting), tightening external scrutiny of Irish discretion.
  • Dublin's regulator becoming the bottleneck forces other national authorities to weigh taking on cross-border cases themselves, straining the one-stop-shop model GDPR was built on.

Third-order effects

  • If the pattern holds, GDPR enforcement structurally migrates away from the host-state regulator toward EU-level oversight and multi-regulator coalitions, because a small economy hosting most US tech headquarters cannot credibly police them — the conflict of interest flagged since the law's first year.
  • The staffing gap compounds it: even years later the DPC had still not advertised two senior posts ahead of key investigations (unfilled senior posts), suggesting capacity, not just will, limits national enforcement — an argument for resourcing or bypassing lead regulators entirely.

The trend: EU data protection enforcement is drifting from discretionary national control by Ireland's DPC toward externally supervised, EU-level accountability mechanisms.

Discussion

  • @maxschrems Max Schrems on x
    Today we published an Open Letter on cooperation two years after #GDPR, with a special focus on how the @DPCIreland is dealing with our first complaints and how they engaged with #Facebook about bypassing the law.. ⏩ For the #PrivacyBreaking details see https://noyb.eu/... https:…
  • @maxschrems Max Schrems on x
    @EU_Commission @VeraJourova @dreynders @EU_Justice ...but unfortunately we are still miles away from the #GDPR being properly enforced in the whole EU. Especially Ireland (where most IT companies have their HQ) lacks action. Our #OpenLetter to the DPAs, the #EDPB and the @EU_Comm…
  • @maxschrems Max Schrems on x
    Two years into #GDPR the main material question before the @DPCIreland is (seriously!), if #Facebook can simply “bypass” the consent requirements by dumping the consent in the civil law terms.. So far the DPC says: “Sure, great solution!” 😵 ⏩More: https://noyb.eu/... https://twit…
  • @rossjanderson Ross Anderson on x
    The Irish data protection commission has failed for two years to enforce the GDPR, as it's long been Dublin's policy to suck up to the tech firms who have their EU headquarters there https://twitter.com/...
  • @markets @markets on x
    Silicon Valley's main data-protection watchdog in Europe comes under attack from one of the region's leading privacy advocates for taking too long to wrap up probes into Facebook, Instagram and WhatsApp https://www.bloomberg.com/...
  • @kaminskimk Matthew Kaminski on x
    Ireland is the world's privacy regulator. It's enforcement record is coming under a microscope two years into GDPR. https://www.politico.com/...
  • @maxschrems @maxschrems on x
    The European Consumer Rights Organizations (@BEUC) equally highlighting the problems with #GDPR enforcement (also focusing on the @DPCIreland and their “own volition bypass” without naming them): https://www.beuc.eu/... https://twitter.com/...
  • @nicholasvinocur Nicholas Vinocur on x
    5/ In the days and hours before GDPR turned 2, the Irish watchdog issued its first monetary fine (against a local public body) and finalized a probe into Twitter, its first move of the kind. A step forward, but no fines or even results are known yet https://pro.politico.eu/...
  • @dataethicseu DataEthics on x
    For two years, Irish DPA has been sitting on its hands. UNACCEPTABLE. As opposed to French CNIL who single-handedly issued a €50 million fine against Google within 7 months. We need action now. https://noyb.eu/...
  • @malteengeler Malte Engeler on x
    Despite the danger of being mistaken for a heretic to the good cause of data protection I don't think I can completely support @maxschrehms open letter. At least not from a legal point of view👇 https://noyb.eu/...
  • @siliconbarry Barry O'Sullivan on x
    The only thing GDPR has done is to add an annoying extra step (click to accept) to visiting a website https://www.bloomberg.com/... via @technology
  • @jason_kint @jason_kint on x
    All 👀 on Ireland. If they follow law then it's likely Facebook will receive significant fines but more importantly will have to reduce its unbridled use of data without purposeful consent. And they'll give confidence to globe (and US) GDPR actually is what we hoped it would be. h…