Law note · Ireland

Data Protection Act 2018

cite Data Protection Act 2018 (No. 7 of 2018) stage In effect since 2018-05-25 reviewed 2026-08-24

The General Data Protection Regulation (GDPR) applies directly in Ireland, and the Data Protection Act 2018 (DPA 2018), No. 7 of 2018, gives it domestic effect: Part 3 supplies Ireland's national derogations and exemptions, and Part 5 supplies the enforcement architecture and the Data Protection Commission (DPC) as supervisory authority.

Because most large United States technology companies base their EU headquarters in Ireland, the DPC is the lead supervisory authority under the GDPR one-stop-shop mechanism for most of their cross-border processing, which makes Irish enforcement practice a de facto reference point for the whole EU, including on how existing privacy law reaches AI training uses of personal data.

What it asks of an app

  • Establish and document a lawful basis under General Data Protection Regulation (GDPR) Article 6 before processing any personal data of a person in Ireland.
  • Expect the Data Protection Commission to act as lead supervisory authority under the one-stop-shop mechanism if your EU establishment is in Ireland, for any cross-border processing you carry out.

When LexLint raises it

Declared activities: crawls_web, trains_models, generates_content, deploys_chatbot, automated_outreach, high_risk_decisions, processes_voice, processes_biometrics

Primary source: Irish Statute Book, official consolidated text

← Back to the example  ·  Lint your app →