EU ombudsman opens an inquiry into how GDPR is applied in Ireland, after claims that 98% of privacy infringement complaints to the Irish DPC remain unsolved
Charlie Taylor / The Irish Times : Tweets: @chastaylor Tweets: Charlie Taylor / @chastaylor : Emily O'Reilly opens inquiry into European Commission policing of GDPR in Ireland. Move comes on foot of a complaint lodged by @johnnyryan and @ICCLtweet https://www.irishtimes.com/...
Context & Ripple Effects
Emily O'Reilly's inquiry is the escalation point of a campaign that has run for years: back in 2019 critics were already questioning whether the Irish Data Protection Commission, the EU's lead GDPR enforcer, was willing to crack down on the tech firms dominating Ireland's economy given its reliance on them. By GDPR's second anniversary in 2020 the DPC was under public pressure to act amid doubts about its enforcement capacity.
The trigger for the ombudsman's move was the September 2021 analysis showing the DPC had failed to apply EU privacy law to US Big Tech, with 98% of 164 significant complaints still unresolved despite years of filings. Johnny Ryan and the Irish Council for Civil Liberties converted that record into a formal complaint — but notably aimed not at the DPC itself rather at the European Commission's policing of it, testing whether Brussels supervises its own lead regulator.
First-order effects
- The European Commission must now formally account to the ombudsman for how it oversees Irish GDPR enforcement, putting the DPC's unresolved-complaint backlog under institutional scrutiny rather than just press criticism.
Second-order effects
- The ICCL's complaint strategy is compounding: the same group already forced the Commission into requiring regulators to report on GDPR enforcement six times a year via its earlier complaint, and an adverse ombudsman finding would hand it leverage for stricter Commission supervision of Dublin.
Third-order effects
- If the pattern holds — the EDPB has already overruled 75% of the DPC's decisions in EU-level cases since 2018 per the ICCL's own tally — GDPR enforcement migrates structurally upward from Ireland's lead regulator to EU-level bodies, eroding the one-stop-shop model that made Dublin the gatekeeper for Big Tech privacy cases.
The trend: GDPR enforcement is drifting upward from Ireland's lead regulator to EU-level institutions, as civil-society complaints force each successive layer of oversight to police the one below it.