Law note · Ireland

GDPR Chapter V, Cross-Border Transfer of Personal Data from Ireland

cite Regulation (EU) 2016/679, Arts. 44-49 stage In effect since 2018-05-25 reviewed 2026-08-24

Transferring personal data of a person in Ireland outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the highest Article 83(5) fine tier.

The DPC additionally operates the one-stop-shop coordination role given Ireland's concentration of EU-headquartered controllers, but this is an institutional and procedural role in cross-border enforcement coordination, not an added transfer restriction. No DPA 2018-specific derogation on outbound transfers was identified.

What it asks of an app

  • Rely on a European Commission adequacy decision, Standard Contractual Clauses with a transfer impact assessment, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Ireland outside the European Economic Area.

When LexLint raises it

Declared activities: crawls_web, trains_models, deploys_chatbot, automated_outreach, processes_voice, processes_biometrics

Primary source: Official Journal text, EUR-Lex, Regulation (EU) 2016/679
DPC one-stop-shop guidance

← Back to the example  ·  Lint your app →