Consumer groups and privacy activists in the EU are increasingly turning to courts, rather than regulators, for speedier resolution of their GDPR complaints
With regulators faltering, privacy activists are turning to the courts to get the rules enforced. — Forget regulators. Tweets: @politicoeurope , @vmanancourt , and @alistair_sloan Tweets: @politicoeurope : Privacy campaigners are getting fed up with European regulators' sluggish approach to complaints. Now they're looking at lawsuits to break the logjam. Read the full story here: https://www.politico.eu/... https://twitter.com/... Vincent Manancourt / @vmanancourt : Forget regulators. Consumer groups and campaigners who want to see their GDPR complaints wrapped up in a timely manner are increasingly turning to Europe's court system for results: (story now free) https://www.politico.eu/... Alistair Sloan / @alistair_sloan : In Scotland, legal aid is available to data subjects for data protection cases in the Scottish courts (subject to financial eligibility and being able to satisfy the merits test) https://twitter.com/...
Context & Ripple Effects
The court turn is a response to a known bottleneck. The Irish Data Protection Commission became the EU's lead GDPR enforcer, but critics have long questioned its willingness to crack down on the firms dominating Ireland's economy critics question the Irish DPC's willingness. Nearly two years in, the only substantial privacy action against a major tech company was the US $5B Facebook fine, not an EU one.
The logjam has since worsened: regulators are publicly clashing over how much to fine Twitter for its 2018 breach the cross-border fight over Twitter's fine, a dispute that could delay the Facebook and Google investigations too. With the complaint pipeline stalling inside the one-stop-shop mechanism, campaigners are rerouting cases to national courts.
First-order effects
- Consumer groups and privacy activists get a faster enforcement track: court timelines replace multi-year regulator deliberations that have left major complaints unresolved since 2018.
- The Irish DPC's role as sole gatekeeper for big-tech cases is effectively being bypassed, weakening the one-stop-shop mechanism it anchors.
Second-order effects
- Tech giants shift from negotiating a single EU-level fine to defending parallel lawsuits across member states, multiplying their legal exposure and compliance costs.
- Regulators face pressure to show results or cede relevance; if courts start delivering penalties regulators couldn't, budget-strapped authorities risk becoming secondary venues — and companies may increasingly contest even regulator-issued fines in court, where appeals have already overturned or reduced many penalties.
Third-order effects
- If the pattern holds, GDPR enforcement migrates from administrative regulators to judiciaries, and the EU top court's opinion allowing complaints in any member state could channel a flood of litigation directly into national courts.
- Structurally, Big Tech's exposure becomes jurisdictional arbitrage in reverse: no single friendly regulator can contain liability once any member state's court can hear a complaint.
The trend: GDPR enforcement is shifting from slow-moving lead regulators toward national courts and plaintiffs, with judicial venue-shopping replacing the one-stop-shop as activists' preferred route.