Law note · Ireland
Data Protection Act 2018
The General Data Protection Regulation (GDPR) applies directly in Ireland, and the Data Protection Act 2018 (DPA 2018), No. 7 of 2018, gives it domestic effect: Part 3 supplies Ireland's national derogations and exemptions, and Part 5 supplies the enforcement architecture and the Data Protection Commission (DPC) as supervisory authority.
Because most large United States technology companies base their EU headquarters in Ireland, the DPC is the lead supervisory authority under the GDPR one-stop-shop mechanism for most of their cross-border processing, which makes Irish enforcement practice a de facto reference point for the whole EU, including on how existing privacy law reaches AI training uses of personal data.
What it asks of an app
- Establish and document a lawful basis under General Data Protection Regulation (GDPR) Article 6 before processing any personal data of a person in Ireland.
- Expect the Data Protection Commission to act as lead supervisory authority under the one-stop-shop mechanism if your EU establishment is in Ireland, for any cross-border processing you carry out.
When LexLint raises it
Declared activities: crawls_web, trains_models, generates_content, deploys_chatbot, automated_outreach, high_risk_decisions, processes_voice, processes_biometrics
Primary source: Irish Statute Book, official consolidated text