EU's top court issues an opinion allowing GDPR complaints in any member state, which could lead to a flood of complaints against tech giants
The Advocate General of the European Court of Justice has issued an opinion that a privacy complaint against the US tech giant Facebook does …
Context & Ripple Effects
This opinion extends a run of Advocate General interventions at the European Court of Justice that have reshaped how Big Tech's EU legal exposure works. In 2019 an adviser opinion added uncertainty around the EU-US Privacy Shield transfer mechanism, which the court then struck down outright in July 2020, leaving thousands of companies including Facebook without their flagship transfer framework.
The new opinion attacks the enforcement side of the same edifice: if GDPR complaints can be lodged in any member state rather than only where a company has its EU establishment, Facebook's long-standing arrangement of being policed primarily by Ireland's regulator stops being a chokepoint. A subsequent court position that Facebook can't avoid EU-wide privacy orders from authorities beyond its Irish watchdog shows where this line of reasoning lands.
First-order effects
- Facebook and other US tech giants become exposed to GDPR complaints filed in any of the EU's national data protection authorities, ending the practical funnel through Ireland's watchdog.
- Complainants gain forum choice, letting them route cases to regulators perceived as faster or more aggressive than the Irish DPC.
Second-order effects
- National data protection authorities outside Ireland see complaint volumes rise, forcing them to staff up cross-border enforcement and eroding the one-stop-shop division of labor the GDPR was built on.
- Tech companies must defend parallel proceedings in multiple jurisdictions at once, raising compliance costs and making settlement with individual regulators more attractive than waiting out a single lead authority.
Third-order effects
- If the court adopts the opinion, GDPR enforcement structurally shifts from a single-gatekeeper model to distributed multi-country enforcement, with the Irish DPC reduced from de facto chief regulator to one voice among many.
The trend: EU privacy enforcement is moving from centralized oversight through Ireland's regulator toward multi-jurisdictional action against large platforms, compounding the loss of the Privacy Shield transfer framework.