Law / Ireland

GDPR Chapter V, Cross-Border Transfer of Personal Data from Ireland

Regulation (EU) 2016/679, Arts. 44-49

A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.

What follows is LexLint's own research summary of this law, not legal advice.

In force since 25 May 2018.

A cross border transfer rule binding public and private bodies.

As of 24 August 2026.

What it requires

  • Rely on a European Commission adequacy decision, Standard Contractual Clauses with a transfer impact assessment, Binding Corporate Rules, or a narrow Article 49 derogation before moving personal data of a person in Ireland outside the European Economic Area.

If you get it wrong

Criminal exposureNo

Private right of actionYes

Penalty structure

GDPR Article 83(5)(c): the higher fine tier, up to EUR 20,000,000 or 4% of total worldwide annual turnover of the preceding financial year, applies to infringement of the Chapter V transfer rules in Articles 44 to 49.

Rule
Higher of
As of
2 September 2026
Currency
EUR
Fixed cap
20,000,000
Turnover percentage cap
4

Who enforces it

Enforcement body

Data Protection Commission (An Coimisiún um Chosaint Sonraí), Ireland's supervisory authority under the GDPR and the Data Protection Act 2018.

Enforcement record

Counts the Data Protection Commission's finalised large scale statutory inquiries that resulted in an administrative fine in calendar year 2025 (4), per the Commission's own press release announcing its 2025 Annual Report, published 2026-06-30: two fines totalling EUR 530 million against TikTok Technology Limited over transfers of EEA user data to China, and a EUR 550,000 fine against the Department of Social Protection over biometric facial matching in the Public Services Card registration process; fines_per_year of just over EUR 530.77 million is the release's own stated total for the year. Public enforcement actions only, counted from the Commission's own announcement rather than a private tracker; the release does not restate a cumulative since-2018 total, so total_fines is not recorded here. This is the regime's own enforcement record, not specific to this instrument.

As of
2 September 2026
Currency
EUR
Source link
https://www.dataprotection.ie/en/data-protection-commission-publishes-2025-annual-report
Fines per year
530,770,000
Actions per year
4

What it reaches

Obligation class

Transfer

Who checks it

Audit expectation

continuous

Who audits it

Self

Where the report goes

Produced on request

What this law does

Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.

Transferring personal data of a person in Ireland outside the European Economic Area requires a European Commission adequacy decision, Standard Contractual Clauses, Binding Corporate Rules, or a narrow Article 49 derogation, backed by the highest Article 83(5) fine tier.

The DPC additionally operates the one-stop-shop coordination role given Ireland's concentration of EU-headquartered controllers, but this is an institutional and procedural role in cross-border enforcement coordination, not an added transfer restriction. No DPA 2018-specific derogation on outbound transfers was identified.

When LexLint raises it

  • crawls_web
  • trains_models
  • deploys_chatbot
  • automated_outreach
  • processes_voice
  • processes_biometrics

Read the law

Official Journal text, EUR-Lex, Regulation (EU) 2016/679
DPC one-stop-shop guidance

Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.

Back to the example  ·  Lint your app