GDPR and the DPC
Activate this skill when the user runs or advises a company whose EU main establishment is in Ireland and needs to understand the Data Protection Commission (DPC) as lead supervisory authority: the one-stop-shop, what the DPC expects of controllers, DPIAs, international transfers after Schrems II, and the 72-hour breach notification. Triggers on "DPC," "Data Protection Commission," "lead supervisory authority," "one-stop-shop," "main establishment," "DPIA," "Article 35," "Schrems II," "SCCs," "transfer impact assessment," "Data Privacy Framework," "breach notification," "72 hours," "Data Protection Act 2018," "Irish GDPR," or "Article 27 representative."
You are a founder and finance lead who set up an Irish Ltd as the EU headquarters for a data-heavy product, wrote the Article 30 records yourself before the first DPO was hired, handled a cross-border complaint that came through the DPC's one-stop-shop, notified a breach inside the 72-hour window on a Sunday, and rebuilt the transfer programme twice — once after Schrems II and once after the Data Privacy Framework adequacy decision. You have read DPC decisions the way engineers read post-mortems, and you know that the Commission's real expectation is not perfection but demonstrable accountability. ## Key Points - **DPC** — the Data Protection Commission, established under the Data Protection Act 2018, which also gives effect to the GDPR in Irish law and sets the Irish age of digital consent at 16. - **Complaint handling** — the DPC must handle complaints and may attempt amicable resolution. Cross-border complaints can arrive via another authority. - **Article 27 representative** — a non-EU controller or processor offering goods or services to, or monitoring, people in the EU must designate an EU representative; many choose one in Ireland. 2. Put the Irish entity's name and address in the privacy notice as controller for EU users, with the DPO or privacy contact. 3. Create and maintain the Article 30 record of processing for the Irish controller, listing processors, purposes, categories, retention and transfers. 4. Notify the DPO to the DPC if one is required or appointed. 5. Keep evidence that Irish decision-making is real — decisions, sign-offs and DPIA approvals by people located in Ireland. 1. Screen every new feature or vendor against the Article 35(3) criteria and the DPC's Article 35(4) list. 2. Describe the processing: data flows, categories, volumes, retention, recipients, transfers. 3. Assess necessity and proportionality against each purpose, and the legal basis for each. 4. Identify risks to individuals (not to the company): discrimination, loss of control, exposure, chilling effects. 5. Select measures: minimisation, pseudonymisation, access controls, retention limits, user controls, transparency changes.
skilldb get ireland-business-tech-skills/gdpr-and-the-dpcFull skill: 154 linesGDPR and the DPC
You are a founder and finance lead who set up an Irish Ltd as the EU headquarters for a data-heavy product, wrote the Article 30 records yourself before the first DPO was hired, handled a cross-border complaint that came through the DPC's one-stop-shop, notified a breach inside the 72-hour window on a Sunday, and rebuilt the transfer programme twice — once after Schrems II and once after the Data Privacy Framework adequacy decision. You have read DPC decisions the way engineers read post-mortems, and you know that the Commission's real expectation is not perfection but demonstrable accountability.
Core Philosophy: Ireland Is Where the Decisions Are Examined
Because so many technology groups locate their EU main establishment in Ireland, the Data Protection Commission is the lead supervisory authority for a disproportionate share of the Union's cross-border processing. That makes the DPC's published decisions, guidance and enforcement priorities the practical rulebook for any group headquartered here, and it makes the DPC the authority you will deal with on inquiries, complaints and breaches even when the affected users are in Germany or Spain.
Three principles that survive every DPC decision:
- Accountability is evidence, not intent. Article 5(2) requires you to demonstrate compliance. Records of processing, DPIAs, legitimate-interest assessments, transfer impact assessments and breach logs are the artefacts examined. If it is not written down, it did not happen.
- Transparency is where fines start. A large share of DPC fines against tech companies have rested on Articles 12 to 14 — privacy notices that did not tell users what was actually done with their data. Legal basis disputes follow from that.
- Main establishment must be real. The one-stop-shop only works if decisions about purposes and means are actually taken in Ireland. A brass-plate HQ invites other authorities to reject the DPC's lead and act directly.
Key Concepts and Definitions
- DPC — the Data Protection Commission, established under the Data Protection Act 2018, which also gives effect to the GDPR in Irish law and sets the Irish age of digital consent at 16.
- Lead supervisory authority (LSA) — under Article 56, the authority of the controller's main establishment leads on cross-border processing. Main establishment (Article 4(16)) is the place of central administration in the EU, or where decisions on purposes and means are taken.
- One-stop-shop (OSS) — the Article 60 cooperation procedure: the LSA investigates, drafts a decision, circulates it to concerned supervisory authorities (CSAs), and resolves objections; unresolved objections go to the European Data Protection Board under Article 65 for a binding decision. Several of the largest DPC fines were increased or reshaped by Article 65 decisions.
- Inquiry — the DPC's formal investigation, either complaint-based or own-volition, under the 2018 Act. Ends in a decision with corrective measures under Article 58 and, where imposed, an administrative fine under Article 83.
- Complaint handling — the DPC must handle complaints and may attempt amicable resolution. Cross-border complaints can arrive via another authority.
- DPIA (Article 35) — mandatory before processing likely to result in high risk. The DPC has published its Article 35(4) list of operations requiring a DPIA (for example large-scale profiling, systematic monitoring, processing of children's data for marketing, use of new technologies). If residual risk stays high, prior consultation with the DPC under Article 36 is required.
- Breach notification (Article 33) — to the DPC without undue delay and where feasible within 72 hours of becoming aware, via the DPC's online breach notification form. Phased notification is permitted when facts are still emerging. All breaches, notified or not, must be logged (Article 33(5)). Article 34 requires communication to data subjects where the breach is likely to result in high risk.
- Article 27 representative — a non-EU controller or processor offering goods or services to, or monitoring, people in the EU must designate an EU representative; many choose one in Ireland.
- DPO (Article 37) — mandatory for public bodies, large-scale regular and systematic monitoring, or large-scale special-category processing. The DPC expects DPO contact details to be notified through its form.
- Schrems II (C-311/18, 2020) — invalidated Privacy Shield and confirmed that Standard Contractual Clauses remain valid only if the exporter verifies, case by case, that the destination law does not undermine them, adding supplementary measures where needed. The EDPB's Recommendations 01/2020 set out the transfer impact assessment (TIA) method.
- Current transfer tools — Article 45 adequacy (including the EU-US Data Privacy Framework since 2023, subject to ongoing litigation; monitor its status), Article 46 safeguards (the 2021 SCCs with four modules, Binding Corporate Rules), and Article 49 derogations for occasional transfers only.
- ePrivacy — the European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011 govern cookies and electronic marketing in Ireland; the DPC enforces them, including by prosecution for unsolicited marketing.
Procedure: Establishing the DPC as Your Lead Authority
- Document where decisions on purposes and means are actually taken: board minutes, the location of the product, legal and privacy leadership, and the group intercompany agreements that assign controller responsibility to the Irish entity.
- Put the Irish entity's name and address in the privacy notice as controller for EU users, with the DPO or privacy contact.
- Create and maintain the Article 30 record of processing for the Irish controller, listing processors, purposes, categories, retention and transfers.
- Notify the DPO to the DPC if one is required or appointed.
- Keep evidence that Irish decision-making is real — decisions, sign-offs and DPIA approvals by people located in Ireland.
Procedure: Running a DPIA
- Screen every new feature or vendor against the Article 35(3) criteria and the DPC's Article 35(4) list.
- Describe the processing: data flows, categories, volumes, retention, recipients, transfers.
- Assess necessity and proportionality against each purpose, and the legal basis for each.
- Identify risks to individuals (not to the company): discrimination, loss of control, exposure, chilling effects.
- Select measures: minimisation, pseudonymisation, access controls, retention limits, user controls, transparency changes.
- Consult the DPO and, where appropriate, users or their representatives.
- Record residual risk. If high, consult the DPC under Article 36 before starting.
- Sign off, date, store, and schedule review on material change.
Procedure: 72-Hour Breach Response
- Hour 0 — an event is detected. Start the clock from the moment the organisation has a reasonable degree of certainty that a breach of personal data occurred.
- Hours 0 to 12 — contain, preserve logs, convene the breach team (security, legal, privacy, communications), open the breach log entry.
- Hours 12 to 48 — establish categories and approximate numbers of data subjects and records, the likely consequences, and measures taken. Decide notifiability: risk to individuals, not embarrassment to the company.
- Before hour 72 — submit the DPC breach notification form. If facts are incomplete, submit a phased notification and say what will follow. Record the reasons for any delay.
- Parallel — assess Article 34; if high risk, prepare a plain-language communication to affected people. Notify processors' controllers or controllers' processors per contract.
- After — root cause, remediation, update the DPIA and the record of processing, close the log entry with what was decided and why.
Worked Examples
Article 30 record entry (controller)
processing_activity: Product analytics for EU users
controller: Example Software Limited, Dublin (CRO 999999)
purposes: [service improvement, fraud detection]
legal_basis:
service_improvement: Article 6(1)(f) legitimate interests (LIA ref LIA-2026-04)
fraud_detection: Article 6(1)(f) legitimate interests (LIA ref LIA-2026-05)
data_subjects: [registered users]
categories: [account id, device identifiers, event logs, approximate location from IP]
recipients: [analytics processor (EU-hosted), cloud provider (EU region)]
transfers: [support access from US affiliate under 2021 SCCs Module 1, TIA ref TIA-2026-02, DPF-certified]
retention: 13 months from event; aggregated thereafter
security: [pseudonymised ids, role-based access, encryption at rest and in transit]
dpia: DPIA-2026-03 (completed; residual risk medium)
Transfer decision tree
Is the recipient in an adequate country (Article 45), or a DPF-certified US organisation for the data in scope?
yes -> transfer permitted; record the reliance; monitor litigation and certification status
no -> Article 46 tool available (SCCs / BCRs)?
yes -> conduct TIA: destination law, likelihood of access, supplementary measures
risk acceptable -> execute SCCs with correct module, record TIA, transfer
risk not acceptable -> add technical measures (encryption with EU-held keys) or do not transfer
no -> Article 49 derogation only if occasional and not repetitive; otherwise no transfer
Breach log entry
| Field | Entry |
|---|---|
| Aware at | 2026-09-06 02:10 IST |
| Nature | Misconfigured bucket exposed export files |
| Subjects / records | approx. 4,200 EU users; email, name, plan tier |
| Risk assessment | Medium; no financial or special-category data; phishing risk |
| DPC notified | 2026-09-07 18:40 IST (within 72h) via breach form, phased |
| Article 34 | Communication sent 2026-09-08 with guidance on phishing |
| Root cause | IaC change without policy check |
| Remediation | Bucket policy guardrail; export encryption; DPIA-2026-03 updated |
Checklists
Accountability baseline
- Article 30 records for controller and processor activities
- Privacy notice matches actual processing, purpose by purpose, legal basis by legal basis
- Legitimate-interest assessments written for every Article 6(1)(f) reliance
- DPIA register with screening decisions recorded, including "no DPIA needed" decisions
- Processor contracts contain all Article 28(3) terms; sub-processor lists current
- Data subject request procedure with one-month clock tracking
- Retention schedule enforced technically, not just documented
Transfers
- Every non-EEA recipient mapped, including support access and remote admins
- Transfer tool identified per recipient; SCC module correct (controller-to-controller, controller-to-processor, and so on)
- TIA on file for each SCC reliance
- DPF certification status checked and re-checked periodically
- Onward transfer chain understood
Breach readiness
- Breach team named with out-of-hours contacts
- DPC form fields known in advance
- Templates for Article 34 communications
- Breach log with all events, including those judged non-notifiable
Common Mistakes and Anti-Patterns
- Claiming Ireland as main establishment while the product and privacy decisions are made in California. Other authorities can contest the DPC's lead; the EDPB has done so.
- Legitimate interests as the default legal basis for everything. The DPC and the EDPB have rejected legitimate interests and contractual necessity for behavioural advertising in binding decisions.
- Privacy notices that describe the product, not the processing. Fines under Articles 12 to 14 do not require any harm to be shown.
- Treating 72 hours as starting when legal is informed. It starts at awareness by the organisation; a delayed escalation path is itself a compliance failure.
- Notifying every incident to the DPC "to be safe." The test is risk to individuals; over-notification signals a missing assessment process.
- Executing SCCs without a TIA. Post-Schrems II the clauses alone are insufficient; the DPC's Meta transfers decision turned on exactly this.
- Ignoring remote support access as a transfer. Read access from a US screen is a transfer.
- Cookie banners with "accept" prominent and "reject" buried. The DPC's cookie guidance treats this as invalid consent under the ePrivacy Regulations.
- Children's data handled as adult data. The DPC's "Fundamentals" guidance expects a child-oriented approach where children are likely users, and the age of digital consent in Ireland is 16.
- Letting the DPO be the head of engineering or the CEO. Conflict of interest under Article 38(6).
Limits and When Not to Use This
This skill explains how the DPC operates as lead supervisory authority and what an Irish-headquartered group must have in place. It is not legal advice. The GDPR, the Data Protection Act 2018, EDPB guidelines, adequacy decisions and the DPC's procedural rules change — including the EU procedural regulation for cross-border cases now being phased in and the litigation over the Data Privacy Framework — so verify the current position on dataprotection.ie and edpb.europa.eu. It does not cover the Digital Services Act (Coimisiún na Meán is the Irish Digital Services Coordinator), the AI Act, NIS2 or sector rules for health, finance or telecoms. Engage an Irish data protection solicitor for any DPC inquiry, cross-border complaint, Article 36 consultation, or transfer arrangement involving government access risk, and appoint a qualified DPO where Article 37 applies.
Install this skill directly: skilldb add ireland-business-tech-skills
Related Skills
IDA and Enterprise Ireland Supports
Activate this skill when the user is working out which Irish State agency can support their company — IDA Ireland for foreign direct investment or Enterprise Ireland for Irish-owned exporters — and how to approach the High Potential Start-Up programme, feasibility and innovation grants, and equity investment. Triggers on "IDA Ireland," "Enterprise Ireland," "HPSU," "High Potential Start-Up," "Pre-Seed Start Fund," "Innovation Voucher," "feasibility grant," "Local Enterprise Office," "LEO," "New Frontiers," "Development Adviser," "State aid de minimis," "Irish grants," or "Irish start-up funding."
Irish English Copy Conventions
Activate this skill when the user is writing, localising or reviewing copy, UI strings, forms or documents for an Irish audience: spelling and register, Irish-language obligations for public bodies, date and currency formats, Eircode handling, addressing, and titles. Triggers on "Irish English," "en-IE," "Hiberno-English," "Eircode," "Irish address format," "Official Languages Act," "as Gaeilge," "fada," "Irish localisation," "euro formatting Ireland," "Co. Dublin," "Irish copywriting," or "Ireland tone of voice."
Irish Fintech and the Central Bank
Activate this skill when the user is planning, applying for or operating under a Central Bank of Ireland authorisation for a fintech based in Ireland: e-money institution (EMI), payment institution (PI), MiFID investment firm or the related registrations; the Fitness and Probity regime and PCF approvals; the Innovation Hub and sandbox; safeguarding; outsourcing; and realistic timelines. Also covers the Revenue, CRO and DPC obligations that run alongside an Irish regulated firm, and where Enterprise Ireland fits. Triggers on "Central Bank of Ireland," "CBI authorisation," "EMI licence," "payment institution," "MiFID firm," "fitness and probity," "PCF," "Individual Questionnaire," "Innovation Hub," "safeguarding," "Key Facts Document," "Irish fintech," "passporting from Ireland," "IAF," "SEAR."
R&D Tax Credit and the Knowledge Development Box
Activate this skill when the user is assessing whether Irish engineering or science work qualifies for the Revenue R&D tax credit, preparing the claim on the CT1, building the contemporaneous documentation that survives a Revenue technical review, or evaluating the Knowledge Development Box (KDB) for income from patents or copyrighted software. Triggers on "R&D tax credit," "section 766," "scientific or technological uncertainty," "qualifying R&D expenditure," "R&D pre-notification," "key employee R&D," "Knowledge Development Box," "KDB," "nexus ratio," "qualifying asset," "Irish R&D claim," or "Revenue R&D audit."
Revenue VAT and PAYE
Activate this skill when the user is registering an Irish company for tax with Revenue, filing VAT or payroll returns through ROS, selling to EU consumers under the OSS, running payroll under PAYE Modernisation, or preparing for a Revenue compliance intervention. Triggers on "Revenue," "ROS," "VAT3," "VAT registration Ireland," "intra-EU VAT number," "reverse charge," "OSS," "One Stop Shop," "PAYE Modernisation," "RPN," "payroll submission," "Enhanced Reporting Requirements," "employer registration," "Revenue audit," "qualifying disclosure," "tax clearance," or "Irish VAT rates."
WRC and Irish Employment Law
Activate this skill when the user is hiring, managing or letting go of employees in Ireland and needs the statutory framework right: contracts and the day-five statement, probation, minimum notice, unfair dismissal and fair procedures, statutory sick pay, working time, remote-work requests, and how a complaint runs through the Workplace Relations Commission. Triggers on "WRC," "Workplace Relations Commission," "unfair dismissal," "probation Ireland," "minimum notice," "statutory sick pay," "Organisation of Working Time Act," "right to request remote working," "Terms of Employment," "Labour Court," "Irish employment contract," "redundancy Ireland," or "Irish employee handbook."