Analysis: Irish DPC has failed to apply EU's privacy laws to US Big Tech companies, with 98% of 164 significant complaints about privacy abuses still unresolved
Irish regulator has not resolved 98% of 164 significant data protection complaints — Ireland is failing to apply … Source: Irish Council … .
Financial Times
Context & Ripple Effects
The Irish Data Protection Commission's record as the EU's lead GDPR enforcer has been in doubt since shortly after the law took effect: by late 2019, critics were already questioning whether a regulator overseeing firms so central to Ireland's economy would act against them. Its own reporting then confirmed the pattern — 21 cross-border probes opened by early 2020 with no decisions reached.
Complainants and civil-society groups like the ICCL are left without rulings years after filing, while US Big Tech companies continue operating in Europe under decisions made by a regulator whose own cases get overturned at the EU level.
The European Data Protection Board is forced into the role of de facto decision-maker, repeatedly correcting the lead regulator instead of receiving enforceable outcomes from it.
Second-order effects
The EU ombudsman's inquiry signals that Brussels institutions will police enforcement capacity itself, raising pressure on the DPC to staff up — the unfilled senior posts become a visible test of whether Ireland resources its regulator or protects its tech-sector employment base.
Big Tech faces a two-track compliance reality: nominal lead authority in Dublin but effective scrutiny from the EDPB and other national regulators, lengthening case timelines and increasing legal costs on all sides.
Third-order effects
If the overruling pattern holds, the one-stop-shop model that designated Ireland as lead enforcer for firms' EU headquarters risks structural revision — either through formal rebalancing of powers toward the EDPB or through other member states asserting parallel authority.
The episode sets a precedent for how the EU handles member states whose economic exposure conflicts with their regulatory duties, a tension that will recur wherever enforcement institutions and dominant industries share a jurisdiction.
The trend: EU data protection is shifting from nationally-led enforcement toward centralized correction, as Brussels bodies increasingly override the lead regulator they once relied on.
New report: Ireland is the bottleneck of GDPR enforcement against Google, Facebook, and Big Tech for all of Europe. European Justice Commissioner Didier Reynders must intervene @Dreynders @EU_Justice. #PeopleVsBigTech https://www.iccl.ie/...
Bad news for Ireland's privacy regulator, and speaks to inherent tensions of EU-wide regulations policed by devolved natl regulators & leveraged by transnational tech giants https://www.ft.com/...
Ireland owns the damage this failure to enforce has had on the publishing industry, consumer trust and the shaping of privacy law as the surveillance lobby has weaponized the current situation to support weak data regimes rather than strong privacy laws...because Facebook, Google…
Enforcement against Google, Facebook, and other Big Tech is paralysed by Ireland: in 3 years since GDPR (May 2018-May 2021) Ireland sent only 4 draft decisions for the EDPB. 98% (160) remain unresolved. #PeopleVsBigTech https://www.iccl.ie/... https://twitter.com/...
Germany alone accounts for almost a third (32%) of all spending on EU DPAs that oversee the private sector. More than half of all national DPAs have small (€5 million or less) annual budgets. (From page 9 of the report https://www.iccl.ie/...) https://twitter.com/...
Though Covid-19 has forced many Europeans to work online, GDPR enforcers remain ill equipped to supervise the tech sector. Only 9.7% of EU GDPR enforcers' 3,014 full time staff are tech specialists. (From page 10 of the report https://iccl.ie/...) https://twitter.com/...
We also examine final GDPR decisions (in “cross-border” cases of Europe-wide significance). Less than half (44%) of EDPB final EU-wide decisions include corrective measures, such has fines or orders to stop processing. (See pages 7-8 of full report —> https://www.iccl.ie/...) htt…
We accompany our report today with a letter to European Justice Commissioner Didier Reynders @Dreynders, urging him to launch an infringement procedure under Article 258 TEFU against Member States that jeopardise protection of personal data. https://www.iccl.ie/... https://twitte…
🇮🇪 Ireland is failing to apply the EU's privacy laws to US Big Tech companies, with 98 per cent of 164 significant complaints about privacy abuses still unresolved by its regulator. https://www.ft.com/...
Ireland is failing to apply the EU's privacy laws to US Big Tech companies, according to campaigners, with Spain producing 10 times more draft decisions despite having a smaller budget https://www.ft.com/... https://twitter.com/...