Ireland

GDPR lead regulator for Big Tech, a Europol member and Council of Europe assistance-convention party whose hyperscale data centres fall under US CLOUD Act reach without Irish judicial oversight, an ECHELON participant and home to Intellexa’s Predator spyware

← Back to Privacy Law Directory

Overview

EU Member State: Ireland is subject to the GDPR, the Law Enforcement Directive, and the ePrivacy Directive. For the EU framework, see the EU Framework page.

The Irish DPC is the GDPR lead supervisor for Meta, Google, Apple, Microsoft, LinkedIn, TikTok, and X, making Ireland the regulatory chokepoint for EU personal data flows. Total fines: €4.04 billion (eight of the top 10 GDPR fines), but only €20 million collected due to legal appeals. This concentration results from Ireland’s 12.5% corporate tax rate and English-speaking workforce, creating what critics call a conflict of interest that earned the DPC the “bottleneck” of European data protection. The EDPB has overridden DPC draft decisions multiple times, including increasing the Meta fine to €1.2 billion for unlawful US data transfers.[1][2]

Intellexa Limited, the holding company for the Predator spyware consortium (functionally equivalent to NSO Group’s Pegasus), is registered in Dublin. Ireland has imposed no domestic export controls or sanctions despite the US Commerce Department’s Entity List designation (March 2024). Ireland participates in ECHELON despite nominal military neutrality. Hyperscale data centres (Meta, Google, Microsoft, AWS) are subject to US CLOUD Act access without Irish judicial authorisation.[3][4]

Ireland’s cross-border cooperation is shaped by its opt-outs. It is outside the Schengen Area (keeping the Common Travel Area with the UK) and does not use the European Investigation Order, relying on traditional mutual legal assistance instead, a bilateral MLAT with the United States and the 1959 Council of Europe Mutual Assistance Convention. It is the one Council of Europe state that signed but never ratified the Budapest Convention on Cybercrime, so it is not a party. It is, however, a member of Europol and, since March 2021, participates in the Schengen Information System for police cooperation, and it is a reported ECHELON participant. These are the channels through which the domestic protections described below are, in practice, bypassed.

International Data Sharing Agreements

Mutual Legal Assistance

Ireland has a bilateral MLAT with the United States (signed January 18, 2001, in force August 11, 2009), processed via the Criminal Justice (Mutual Assistance) Act 2008 (Minister for Justice as Central Authority). Because Big Tech has European HQs in Dublin, Ireland receives an exceptionally high volume of MLAT requests, creating processing delays. Ireland is also party to the Council of Europe Convention on MLA 1959 + Protocols and the EU-US MLAT framework covering all EU states. Ireland opted out of the EIO and is outside the Schengen Area, relying on traditional MLAT channels rather than mutual-recognition frameworks. Ireland’s bilateral treaties (mutual assistance and extradition) are published in the Department of Foreign Affairs’ Irish Treaty Series.[15]

European Convention on Mutual Assistance in Criminal Matters (1959, ETS 30): Ireland is a party to this Council of Europe instrument and its Additional Protocols, which as of July 2026 has 51 parties: all 46 Council of Europe member states (Albania, Andorra, Armenia, Austria, Azerbaijan, Belgium, Bosnia and Herzegovina, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Georgia, Germany, Greece, Hungary, Iceland, Ireland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Moldova, Monaco, Montenegro, the Netherlands, North Macedonia, Norway, Poland, Portugal, Romania, San Marino, Serbia, Slovakia, Slovenia, Spain, Sweden, Switzerland, Türkiye, Ukraine, and the United Kingdom) plus five non-members (Chile, Israel, Mongolia, the Republic of Korea, and the Russian Federation).[27]

Budapest Convention on Cybercrime (2001, ETS 185): Ireland signed the convention but has never ratified it, and so is not a party, the only Council of Europe member in that position (which is why it is the sole exception in the convention’s 82-party membership as of July 2026). This leaves Ireland outside the principal multilateral framework for expedited cross-border preservation and disclosure of stored computer and subscriber data, notable given that most major platforms hold their EU headquarters in Dublin.[28]

Europol

As an EU member state, Ireland is one of the 27 EU members that constitute Europol, the EU Agency for Law Enforcement Cooperation (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden). Europol also holds operational agreements permitting personal-data exchange with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, and the United States) and cooperates with US law enforcement including the FBI, so Irish person data flowing through Europol is reachable onward.[29]

ECHELON and Intelligence Sharing

ECHELON participation despite nominal neutrality. IMIS officers train at US military facilities. Defence Forces CIS Corps jointly responsible with IMIS for SIGINT and cyber operations.[9]

EU-US and Multilateral Frameworks

EU-US Umbrella Agreement: Irish citizens get judicial redress in US courts. SWIFT/TFTP: International wire transfers subject to US Treasury subpoena. PNR: Passenger data for Ireland-US flights. Interpol I-24/7. Egmont Group (Irish FIU). Common Travel Area with the UK (bilateral, not Schengen).

The Privacy Backdoor Effect

Despite €4.04B in DPC fines, alternative access pathways exist:

Ireland simultaneously hosts the corporate infrastructure enabling commercial spyware (Intellexa) and the corporate infrastructure subject to US extraterritorial data demands (Big Tech data centres), while imposing restrictions on neither.

Club de Berne and the Counter Terrorism Group

Ireland’s security and intelligence service within An Garda Síochána takes part in the Club de Berne (founded 1969), the forum of the heads of the domestic intelligence and security services of the 27 EU member states (Austria, Belgium, Bulgaria, Croatia, Cyprus, Czechia, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Ireland, Italy, Latvia, Lithuania, Luxembourg, Malta, the Netherlands, Poland, Portugal, Romania, Slovakia, Slovenia, Spain, and Sweden) together with Norway and Switzerland. The Club is a broad, all-source intelligence-sharing body, not a counterterrorism-specific one; its separate offshoot, the Counter Terrorism Group (CTG), created in September 2001, shares terrorism intelligence among the same services plus the United Kingdom and has run a joint operational platform in The Hague with a common database and real-time information system since 2016.[31]

Surveillance and Intelligence

Intelligence Apparatus

Garda Síochána Crime and Security Branch (CSB): National security, counterterrorism, serious crime. Operates the National Surveillance Unit (NSU) for clandestine intelligence gathering using technical and electronic espionage. Irish Military Intelligence Service (IMIS) (renamed from J2 in July 2025): Founded mid-1920s, responsible for Defence Forces security. Computer systems linked with Garda CSB. March 2025 reporting characterised Ireland’s intelligence as having “no strategy, ad hoc structures, mutual distrust.” ECHELON: Ireland has been reported as an ECHELON participant sharing/receiving intelligence with Five Eyes members. The 1993 Interception Act provides Defence Forces with surveillance and communications interception authority.[8][9]

Intellexa/Predator: Ireland as Surveillance Technology Hub

Intellexa Limited is registered in Dublin as the holding company for the Predator spyware consortium, operating vendors across Greece, Israel, and North Macedonia. Predator (a zero-click mobile exploitation tool comparable to Pegasus) has been deployed against journalists, politicians, and activists in Greece (“Greek Watergate”), Egypt, Spain, and other countries. The US Entity-Listed Intellexa in March 2024. Ireland imposes no equivalent export controls or sanctions, creating a jurisdictional gap: the company benefits from EU regulatory legitimacy while enabling human rights violations abroad. Ireland hosts both Big Tech headquarters and a major surveillance vendor: the DPC enforces GDPR against platforms while Ireland simultaneously hosts the corporate infrastructure for commercial spyware.[3][10]

Internet Infrastructure and CLOUD Act Exposure

INEX (Internet Neutral Exchange, est. 1997) connects 170+ networks across Equinix Dublin. DE-CIX Dublin extends the Frankfurt franchise. Hyperscale data centres: Meta (Clonee), Google (Grange Castle), Microsoft Azure (Blanchardstown), Amazon AWS (Dublin). Transatlantic submarine cables land at Ballylongford (AEConnect-1), Coonagh (Havfrue/AEC-2, Meta/Google), and Skibbereen (Celtic to France). Multiple Ireland-UK cable segments connect to the British network where GCHQ Tempora operates.[11]

CLOUD Act Exposure

The most significant surveillance exposure derives from the legal status of US companies operating Irish data centres. Under the US CLOUD Act (2018), US companies must comply with US data demands regardless of where data is stored. Data in Meta Clonee, Google Dublin, Microsoft Blanchardstown, or AWS Ireland is subject to National Security Letters, Section 702 FISA orders, and executive agreement requests, without Irish judicial authorisation. The Microsoft Ireland case (2018) directly led to the CLOUD Act’s passage.[12]

Recent Developments

Microsoft Azure Surveillance Complaint (December 2025): ICCL filed complaint alleging Azure facilitated mass surveillance of Palestinians, with intercepted mobile phone calls from Gaza/West Bank stored on Azure. Investigation pending.[16]

DPC Grok/X Deepfake Investigation (February 2026): Section 110 inquiry into X over Grok AI generating non-consensual sexualised deepfakes including of children. Gardaí separately investigating 200+ CSAM-related Grok images.[17]

TikTok €530M Appeal Stayed (November 2025): High Court stayed the DPC’s fine for China data transfers. EEA-China transfers continue pending appeal.[18] On April 30, 2026, the Irish Supreme Court unanimously dismissed the DPC’s appeal on a point of law, holding that the test for staying a DPC decision is governed by national law and balances irreparable harm against the public interest. The effect is that the High Court stay on the €530M fine and the data-transfer suspension order remains in place while TikTok’s substantive challenge proceeds through the courts.[23]

Biometric PSC Fine (February 2026): DPC fined Department of Social Protection €320,000 for unlawful biometric facial data collection during Public Services Card registration, affecting ~70% of the population.[19]

National Cyber Security Bill 2024: Proposes bulk communications metadata collection with 18-month retention beyond NIS2 requirements.[14]

AI Bill 2026 (Pre-Legislative Scrutiny): Ireland published the Regulation of Artificial Intelligence Bill 2026, establishing a distributed enforcement model across 13 sectoral regulators coordinated by a new statutory AI Office (statutory establishment deadline August 1, 2026 to satisfy AI Act requirements). Penalties reach 7% of global turnover for prohibited AI practices and 3% for high-risk system non-compliance; investigators have powers including source-code access. The Oireachtas Joint Committee on Enterprise opened a public consultation on March 6, 2026 and convened the first pre-legislative scrutiny hearing with IBEC on May 6, 2026; the Department of Enterprise, Tourism and Employment then published the formal Bill on June 17, 2026, keeping the AI Office (as market surveillance authority and single point of contact) on track for its August 1, 2026 statutory deadline.[20][32]

A separate Oireachtas Joint Committee on Artificial Intelligence has been running in parallel and is pushing the government toward a stricter settlement than the Bill currently contemplates. Its first interim report (December 16, 2025) carried 85 recommendations, including that recommender systems be switched off by default and that platforms be barred from running recommender algorithms on children’s accounts at all. Its second interim report, published June 9, 2026, added 39 recommendations on AI in public services: a mandatory public register of every AI system deployed by a public body, mandatory guidelines governing both the use and the procurement of public-sector AI, and the removal of the planned AI Office from the Department of Enterprise, Tourism and Employment so that it can be constituted as a genuinely independent agency. The committee also stated that “Ireland must not shy away from the EU AI Act or try to dilute it,” treating the Act as a floor rather than a ceiling, a position that sits awkwardly beside the Digital Omnibus amendments the Irish government supported at EU level. The recommendations are not binding, and neither report has yet changed the text of the Bill.[25]

EU Age Verification Blueprint Pilot: Ireland is one of seven Member States piloting the EU-wide Age Verification Solution (alongside France, Denmark, Greece, Italy, Spain, and Cyprus), with plans to integrate the app into the national EUDI Wallet. The Commission released the second-version blueprint on October 10, 2025; on April 15, 2026, von der Leyen announced the EU-level system was “technically ready.” Pilot architecture uses a zero-knowledge proof track to attest age brackets without disclosing identity to the relying party.[22] Ireland is also one of five EU countries (with Estonia, Spain, France, and Italy) where Google announced a summer-2026 Google Wallet rollout of passport-based digital IDs and age credentials via its Credential Manager API, deepening the dependence of a state-mandated identity function on a single US platform that already hosts its EU headquarters here. See the European Union page for the broader critique of Google’s positioning as the de facto age-assurance gatekeeper.[24]

Fine Collection Crisis: Despite issuing €4.04 billion in GDPR fines since 2018, the DPC has collected only €20 million, less than 0.5%. In 2024, only €582,500 was collected against €652 million in levied fines. Multiple Big Tech fines remain under appeal in the High Court, with the TikTok €530M and Meta fines stayed pending litigation.[2]

Under-15 Social Media Ban (Draft, February 2026): Ireland has circulated draft legislation that would make illegal “the provision by an online platform of an online social media service to a minor under 15.” The government’s preferred rollout would apply enforcement to new accounts from September 2026 (the start of the school year), with existing accounts phased in subsequently. Ireland is positioning this move in parallel with Australia’s under-16 ban, Denmark’s under-15 agreement, Spain’s under-16 announcement, and Greece’s under-15 announcement. Given that most major social media platforms have their EU headquarters in Ireland (Meta, TikTok, X, LinkedIn), any Irish statutory minimum-age regime would have outsized cross-border implications.[21]

Privacy Framework

The DPC (three commissioners since 2022) processes an exceptionally high volume of cross-border cases due to Big Tech headquarters. 2024: 7,781 breach notifications, 2,357 complaints concluded, 145 cross-border cases. Major fines: Meta €1.2B (US data transfers), TikTok €530M (China transfers, appeal stayed November 2025), Meta €390M (WhatsApp transparency), Meta €265M (data scraping). The Schrems litigation (I and II) originated through the Irish DPC, invalidating two successive EU-US data transfer frameworks.[5][6]

The Data Protection Acts 1988–2018 supplement the GDPR. Ireland is outside the Schengen Area, maintaining the Common Travel Area with the UK, and it opted out of the EIO (European Investigation Order), relying on traditional MLA channels rather than mutual-recognition frameworks. Since March 2021, however, it participates in the Schengen Information System (SIS) for police cooperation, having opted out of the border and immigration alert categories.[7][30]

Data Retention

The Graham Dwyer CJEU ruling (C-140/20, April 2022) found Ireland’s blanket retention (2 years telephony, 1 year internet under the 2011 Act) violated EU law. The 2022 Amendment Act restructured into three tiers: national security general retention (government determination, periodic review), targeted serious crime retention (judicial authorisation), and quick freeze (90-day preservation pending judicial order). A designated judge replaced the previous system where Garda officers authorised their own access. The National Cyber Security Bill 2024 proposes bulk metadata collection with 18-month retention beyond NIS2 requirements.[13][14]

Pending Legislation

Sources

[1] Law Society Gazette: DPC Leads GDPR Fines – Eight of top 10, €4.04B total
[3] Wikipedia: Intellexa – Dublin-registered, Predator spyware, Entity-Listed March 2024
[4] Wikipedia: ECHELON – Ireland reported as participant
[5] GDPRhub: DPC (Ireland) – Major fines: Meta €1.2B, TikTok €530M, Meta €390M
[6] Wikipedia: Schrems II – DPC-originated litigation invalidating Privacy Shield
[7] Wikipedia: EIO – Ireland opted out; not participating in Schengen
[8] Wikipedia: Garda Síochána – CSB, National Surveillance Unit
[9] Wikipedia: IMIS – Renamed July 2025, ECHELON participation, CIS Corps SIGINT
[11] Submarine Cable Map – AEConnect-1, Havfrue/AEC-2, Celtic, Ireland-UK segments
[12] Wikipedia: CLOUD Act – Microsoft Ireland case, extraterritorial data access
[13] CJEU: Graham Dwyer (C-140/20, April 2022) – Blanket retention struck down
[14] Oireachtas: National Cyber Security Bill 2024 – Bulk metadata collection, 18-month retention
[15] Criminal Justice (Mutual Assistance) Act 2008 – Minister for Justice as Central Authority
[19] DPC: PSC Biometric Fine (February 2026) – €320,000, ~70% of population affected
[20] William Fry: Ireland Publishes AI Enforcement Blueprint (2026) – 13 sectoral regulators, AI Office by August 1, 2026; 7% turnover penalties; source code access powers
[21] The Journal: Why Is Ireland Restricting Social Media for Under-16s? (February 2026) – Draft under-15 prohibition; September 2026 enforcement target for new accounts; parallel with AU/DK/ES/GR moves; Ireland hosts EU HQ of Meta, TikTok, X, LinkedIn giving cross-border impact
[22] European Commission: European Age-Verification App Pilots (April 15, 2026) – Seven pilot Member States (Ireland, France, Denmark, Greece, Italy, Spain, Cyprus); EU-wide Age Verification Solution integrated into national EUDI Wallets; second-version blueprint October 10, 2025; zero-knowledge-proof age-bracket attestation
[23] Irish Times: Supreme Court Finds for TikTok in Dispute with Data Protection Commission (April 30, 2026) – Supreme Court unanimously dismissed the DPC’s appeal on a point of law; test for staying a DPC decision is one of national law, balancing irreparable harm against public interest; High Court stay on the €530M fine and data-transfer suspension order remains in place pending TikTok’s substantive challenge
[24] Biometric Update: Google Expands Wallet with Digital IDs and Age Credentials in EU (June 2026) – Money 20/20 Europe announcement; summer-2026 Google Wallet rollout across Estonia, Ireland, Spain, France, and Italy; passport scan creates a digital pass; Credential Manager API age credentials integrated into Android and Chrome
[25] RTÉ: Oireachtas Committee Makes 39 Recommendations in AI Report (June 9, 2026) – Second interim report of the Joint Committee on Artificial Intelligence, on AI in public services; mandatory register of public-body AI deployments; mandatory guidelines on use and procurement; national AI office to be moved out of the Department of Enterprise, Tourism and Employment and made independent; “Ireland must not shy away from the EU AI Act or try to dilute it”; follows the first interim report of December 16, 2025 with 85 recommendations, including recommender systems off by default and a prohibition on recommender algorithms for children’s accounts
[26] The Record: EU Takes Member States to Court over Unimplemented Cybersecurity Law (July 9, 2026) – European Commission referred Ireland, Spain, France and the Netherlands to the Court of Justice of the European Union for failing to transpose NIS2 more than 20 months after the October 2024 deadline; Commission asked the Court to impose a lump sum and ongoing daily financial penalties until each state notifies full transposition; only 6 of 27 member states had transposed NIS2 by January 2025; Ireland’s National Cyber Security Bill described as close to finalisation with transposition expected by end of 2026
[27] Council of Europe Treaty Office: European Convention on Mutual Assistance in Criminal Matters (ETS No. 30) – Chart of signatures and ratifications; 51 parties as of July 2026 (all 46 Council of Europe member states plus Chile, Israel, Mongolia, the Republic of Korea and Russia), Ireland among them
[28] Council of Europe Treaty Office: Convention on Cybercrime (ETS No. 185) – Chart of signatures and ratifications; 82 parties as of July 2026; Ireland is the sole Council of Europe member that signed (2002) but has not ratified, and so is not a party
[29] Europol: Operational Agreements – Europol is constituted by the 27 EU member states (Ireland among them) and maintains operational cooperation agreements permitting exchange of personal data with 17 non-EU states (Albania, Australia, Bosnia and Herzegovina, Canada, Colombia, Georgia, Iceland, Liechtenstein, Moldova, Monaco, Montenegro, North Macedonia, Norway, Serbia, Switzerland, Ukraine, the United States) plus Denmark under a separate agreement, and with Eurojust, Frontex and Interpol
[30] An Garda Síochána: Schengen Information System (SIS) – SIS went live in Ireland on March 15, 2021 for police cooperation; Ireland participates in the law-enforcement alert categories while remaining outside the Schengen Area and opting out of the border/immigration provisions
[31] Wikipedia: Club de Berne – informal forum (founded 1969) of the heads of the domestic intelligence and security services of the 27 EU member states plus Norway and Switzerland; its separate post-9/11 offshoot the Counter Terrorism Group (September 2001) additionally includes the United Kingdom and has operated a joint platform in The Hague with a common database and real-time information system since 2016
[32] Department of Enterprise, Tourism and Employment: Publication of the Regulation of Artificial Intelligence Bill 2026 (June 17, 2026) – formal Bill published following pre-legislative scrutiny; establishes the AI Office of Ireland as a market surveillance authority and single point of contact coordinating 13 sectoral regulators, with regulatory sandboxes and liaison to the EU AI Office; AI Office operational deadline August 1, 2026
[33] Covington Global Policy Watch: Irish NCSC Issues Cyber Governance Guidance for Management Boards Ahead of NIS2 Implementation (July 2026) – NCSC guidance of July 7, 2026 for boards and senior executives of NIS2-scope organisations; published while the National Cyber Security Bill remains before the Oireachtas and days before the Commission’s CJEU referral; Ireland held the rotating EU Council presidency from July 1, 2026
← Back to Privacy Law Directory