Instruments
Each one links to its
LexLint note, which carries what it requires and what it flags on.
Breach notification
cite Regulation (EU) 2016/679, Arts. 33-34
stage In effect
since 2018-05-25
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
A controller must notify the Data Protection Commission without undue delay, and within 72 hours where feasible, after becoming aware of a personal data breach, and must notify affected individuals without undue delay where the breach is likely to result in a high risk to their rights and freedoms. No DPA 2018 derogation from this timeline was identified.
What it asks of an app →
Comprehensive regime
cite Data Protection Act 2018 (No. 7 of 2018)
stage In effect
since 2018-05-25
source Irish Statute Book, official consolidated text
The General Data Protection Regulation (GDPR) applies directly in Ireland, and the Data Protection Act 2018 (DPA 2018), No. 7 of 2018, gives it domestic effect: Part 3 supplies Ireland's national derogations and exemptions, and Part 5 supplies the enforcement architecture and the Data Protection Commission (DPC) as supervisory authority.
Because most large United States technology companies base their EU headquarters in Ireland, the DPC is the lead supervisory authority under the GDPR one-stop-shop mechanism for most of their cross-border processing, which makes Irish enforcement practice a de facto reference point for the whole EU, including on how existing privacy law reaches AI training uses of personal data.
What it asks of an app →
cite Data Protection Commission, "AI, Large Language Models and Data Protection" guidance (18 July 2024)
stage In effect
since 2024-07-18
source Data Protection Commission guidance page, dataprotection.ie
The DPC's July 2024 guidance applies Ireland's existing General Data Protection Regulation (GDPR) and Data Protection Act 2018 duties, lawful basis before collecting personal data for AI training, data minimization, honoring access, rectification and erasure requests where feasible against a trained model, and data protection impact assessments for higher-risk processing, to the specific context of building and operating Large Language Models and other AI systems.
The guidance states directly that publicly accessible personal data still falls within the scope of the GDPR, and that a controller assessing necessity and proportionality for AI training must account for the purposes for which people made their personal data publicly accessible in the first place, not only for the fact of public accessibility.
This interprets Ireland's existing personal-data duties in an AI training context; it does not itself create a duty that attaches because a system is an AI system, and it is filed here rather than as `ai` topic content on that basis. The DPC has backed this guidance with active investigations into Twitter/X's use of EU personal data to train Grok and scrutiny of Meta's and LinkedIn's AI training practices.
What it asks of an app →
Cross border transfer
cite Regulation (EU) 2016/679, Arts. 44-49
stage In effect
since 2018-05-25
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
Transferring personal data of a person in Ireland outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the highest Article 83(5) fine tier.
The DPC additionally operates the one-stop-shop coordination role given Ireland's concentration of EU-headquartered controllers, but this is an institutional and procedural role in cross-border enforcement coordination, not an added transfer restriction. No DPA 2018-specific derogation on outbound transfers was identified.
What it asks of an app →
Data subject rights
cite Regulation (EU) 2016/679, Art. 22, as transposed by the Data Protection Act 2018
stage In effect
since 2018-05-25
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
General Data Protection Regulation (GDPR) Articles 12 to 23 apply, including Article 22 rights against a decision based solely on automated processing that produces legal or similarly significant effects, which the DPA 2018 gives domestic effect to with the DPC as enforcement authority. Where an automated decision is permitted, on contract necessity, legal authorization, or explicit consent, the controller must implement human-intervention, point-of-view, and contest safeguards.
Sections 41 to 43 of the DPA 2018 narrow specific data-subject rights, including the Article 22 adjacent rights of access, rectification, restriction and objection, for archiving in the public interest, scientific or historical research, or statistical purposes where exercising the right would render the purpose impossible or seriously impair it.
What it asks of an app →
Enforcement supervision
cite Regulation (EU) 2016/679, Arts. 82-83; Data Protection Act 2018 §117
stage In effect
since 2018-05-25
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
The DPC is Ireland's supervisory authority under Part 5 of the DPA 2018, with General Data Protection Regulation (GDPR) Article 83 administrative fines. Article 82 arms an individual with a direct private right of action, and Section 117 DPA 2018 specifies that the civil action for material or non-material damage, including distress, is brought in the Circuit Court or the High Court.
Ireland's own collective-redress channel is limited: a not-for-profit body can act on a data subject's authorised behalf under Article 80(1), and the Representative Actions for the Protection of the Collective Interests of Consumers Act 2023 lets a body designated a qualified entity by the Minister for Enterprise, Trade and Employment bring representative actions covering DPA 2018 claims, a designation reviewed at least every five years and revocable.
What it asks of an app →
Sensitive categories
cite Regulation (EU) 2016/679, Art. 9; Data Protection Act 2018 §46
stage In effect
since 2018-05-25
source Official Journal text, EUR-Lex, Regulation (EU) 2016/679
General Data Protection Regulation (GDPR) Article 9(1) governs biometric data as a special category, and the DPA 2018 explicitly lists biometric data among the special categories it elaborates on.
Section 46 addresses processing special category data, including biometric data, in the employment and social-welfare context: an employer must ground the processing in a legitimate argument tied to the employee's vital interests or another Article 9(2) condition with a public-interest character, with suitable and specific measures safeguarding the data subject.
No dedicated Irish provision on voiceprint capture, retention, or destruction specifically was found; the GDPR baseline, that a voiceprint captured through specific technical processing for identification is special category data on the same footing as a faceprint, governs by default.
What it asks of an app →