GDPR Article 82, Data Protection Act 2018 Section 117, and DPC Enforcement in Ireland
Regulation (EU) 2016/679, Arts. 82-83; Data Protection Act 2018 §117
A citation is an address, not a summary. The first part names the law; what follows narrows it to the exact section, article or paragraph.
What follows is LexLint's own research summary of this law, not legal advice.
In force since 25 May 2018.
An enforcement supervision rule binding public and private bodies.
As of 24 August 2026.
What it requires
- Expect the Data Protection Commission to have jurisdiction and fining power, up to the higher of EUR 20,000,000 or 4 percent of global annual turnover, over your processing of personal data of a person in Ireland.
- Expect any person who suffered material or non-material damage from an infringement to have a direct right to claim compensation from you as controller or processor in the Circuit Court or the High Court, under General Data Protection Regulation (GDPR) Article 82 and Data Protection Act 2018 Section 117.
If you get it wrong
Criminal exposureNo
Private right of actionYes
Penalty structure
GDPR Article 83(5) sets the higher fine tier, up to EUR 20,000,000 or 4% of total worldwide annual turnover, for infringements including the Article 9 special category rules, the Article 12 to 22 data subject rights, and the Chapter V transfer rules. The lower Article 83(4) tier, up to EUR 10,000,000 or 2% of turnover, applies instead to the Article 25 to 39 controller and processor obligations, including the Article 33 and 34 breach notification duties. Data Protection Act 2018 section 141(4) caps the administrative fine the Commission may impose on a public authority or public body that does not act as an undertaking within the meaning of the Competition Act 2002 at EUR 1,000,000.
- Rule
- Higher of
- As of
- 2 September 2026
- Currency
- EUR
- Fixed cap
- 20,000,000
- Turnover percentage cap
- 4
Who enforces it
Enforcement body
Data Protection Commission (An Coimisiún um Chosaint Sonraí), Ireland's supervisory authority under the GDPR and the Data Protection Act 2018.
Enforcement record
Counts the Data Protection Commission's finalised large scale statutory inquiries that resulted in an administrative fine in calendar year 2025 (4), per the Commission's own press release announcing its 2025 Annual Report, published 2026-06-30: two fines totalling EUR 530 million against TikTok Technology Limited over transfers of EEA user data to China, and a EUR 550,000 fine against the Department of Social Protection over biometric facial matching in the Public Services Card registration process; fines_per_year of just over EUR 530.77 million is the release's own stated total for the year. Public enforcement actions only, counted from the Commission's own announcement rather than a private tracker; the release does not restate a cumulative since-2018 total, so total_fines is not recorded here. This is the regime's own enforcement record, not specific to this instrument.
- As of
- 2 September 2026
- Currency
- EUR
- Source link
- https://www.dataprotection.ie/en/data-protection-commission-publishes-2025-annual-report
- Fines per year
- 530,770,000
- Actions per year
- 4
What it reaches
Obligation class
Governance
What this law does
Drafted with AI from the cited sources under the direction of UnGovr staff. UnGovr holds editorial responsibility for this page.
The DPC is Ireland's supervisory authority, established under Part 2 of the DPA 2018 and enforcing under Part 6, with General Data Protection Regulation (GDPR) Article 83 administrative fines. Article 82 arms an individual with a direct private right of action, and Section 117 DPA 2018 specifies that the civil action for material or non-material damage, including distress, is brought in the Circuit Court or the High Court.
Ireland's own collective-redress channel is limited: a not-for-profit body can act on a data subject's authorised behalf under Article 80(1), and the Representative Actions for the Protection of the Collective Interests of Consumers Act 2023 lets a body designated a qualified entity by the Minister for Enterprise, Trade and Employment bring representative actions covering DPA 2018 claims, a designation reviewed at least every five years and revocable.
When LexLint raises it
crawls_webtrains_modelsgenerates_contentdeploys_chatbotautomated_outreachhigh_risk_decisionsprocesses_voiceprocesses_biometrics
Read the law
Official Journal text, EUR-Lex, Regulation (EU) 2016/679
Data Protection Act 2018 §117; Representative Actions for the Protection of the Collective Interests of Consumers Act 2023
Every line above is drawn from the primary source linked here, read on the date shown. This is a research summary, not legal advice.