EU's top court says Facebook can't avoid potential EU-wide privacy orders from data protection authorities beyond its legal watchdog in Ireland
- EU top court rules on scope of so-called one-stop-shop system — Dispute stems from Belgian data order over Facebook cookies
Context & Ripple Effects
The ruling follows Belgium's earlier finding that Facebook's third-party-site cookies illegally collected user data, backed by threatened daily fines in the Belgian cookie-data case. It also turns the EU court's prior opinion permitting GDPR complaints in any member state into a more consequential constraint on Facebook's reliance on Ireland as its principal privacy regulator.
Facebook had separately challenged an Irish proposal affecting transfers of EU users' data, underscoring that its European privacy disputes already extended beyond the Belgian case and into the Irish regulator's proposed data-transfer order.
First-order effects
- Belgian and other EU data-protection authorities have a clearer path to seek orders affecting Facebook beyond Ireland's supervisory role, rather than treating the Irish watchdog as an absolute shield.
- Facebook faces enforcement exposure from the Belgian cookie dispute on an EU-wide basis, increasing the practical stakes of compliance decisions made outside Ireland.
Second-order effects
- Ireland's regulator loses some of the leverage conferred by being Facebook's primary EU watchdog, while national authorities gain greater incentive to bring cross-border cases.
- Facebook must manage privacy enforcement and litigation across more national authorities, not solely through its disputes with the Irish regulator.
Third-order effects
- If national authorities use the opening consistently, the GDPR's one-stop-shop model will operate less as a centralized gatekeeper and more as a coordinated system with meaningful local enforcement routes.
- The decision strengthens a European enforcement structure in which large platforms cannot rely on the jurisdiction hosting their main EU establishment to contain every cross-border privacy case.
The trend: EU privacy enforcement is moving toward a more distributed model, with national regulators retaining greater capacity to pursue cross-border cases against major platforms.