DPC (Ireland)

From GDPRhub
Data Protection Commission
LogoIE.png
Name: Data Protection Commission

An Coimisún um Cosanta Sonraí

Abbreviation : DPC
Jurisdiction: Ireland
Head: Helen Dixon
Deputy: n/a
Adress: 21 Fitzwilliam Square South

Dublin 2, D02 RD28, Ireland

Webpage: dataprotection.ie
Email: n/a
Phone: +353 (0)761 104 800
Twitter: @dpcireland
Procedural Law: Irish Common Law

DPA 2018

Decision Database: Decisions not published
Translated Decisions: Category:DPC (Ireland)
Head Count: 138
Budget: 16,9 Mio EUR

The DPC is the federal Data Protection Authority for Ireland. It resides in Dublin and is in charge of enforcing GDPR in Ireland.

Structure[edit | edit source]

The DPC has switched from being the Commissioner to being a Commission under the Commissioner (Helen Dixon).

The organization is divided up in five sections: (1) Legal, (2) Breaches, Complaints, Investigations & Transfer, (3) Technology Multinational Supervision & Investigations; Technology Leadership; Prior Consultation, (4) Communications, Information & Assessment Unit and Corporate Affairs and (5) Strategy, Operations and International.[1]

Procedural Information[edit | edit source]

Applicable Procedural Law[edit | edit source]

Ireland does not have a codified administrative procedural law. Administrative law is predominantly case law.

There are some elements of the procedure before the DPC that are codified in the Irish Data Protection Act of 2018 (details see below). Compared to a continental law system, this also includes general elements of any procedure like the service of documents (Section 106 DPA 2018) or the appeals system (Section 150 DPA 2018) in data protection matters.

Complaints Procedure under Art 77 GDPR[edit | edit source]

Under Article 77 GDPR any data subject can file a complaints procedure with the DPC. The DPC will (1) assess the complaint to see if it falls within its mandate, (2) try to find and amicable resolution, then (3) handle the complaint.[2]

Currently a vast majority of all complaints does not lead to a decision by the DPC, but is "amicably resolved". Of the 1,046 complaints that were resolved from 1. 1. 2018 to 24. 5. 2018 the DPC has only made 12 formal decisions, which is equivalent to 1,1% of the complaints.[3]

Ex Officio Procedures under Art 57 GDPR[edit | edit source]

The DPC has previously directly engaged with controllers in an "audit" procedure.

The DPC now mentions the option to conduct an "inquiry" on their webpage, but highlights that "Generally speaking, the DPC will only consider commencing an inquiry where the matter raised indicates that the alleged data breach is of an extremely serious nature and/or indicative of a systemic failing within the organisation in question."[4]

Special Elements under the Irish DPA 2018[edit | edit source]

Investigations under Chapter 5 DPA[edit | edit source]

Under the DPA 2018 any ex officio investigation or complaint can lead to an "investigation" under Section 137 to 140.

Enforcement Notices[edit | edit source]

Under Section 133 DPA 2018 the DPC may issue an "enforcement notice" that orders a controller or processor to take certain steps specified in Section 109(5)(d) or 122(4)(d). Under Section 133(9) the consequence of failing to comply with an enforcement notice is an administrative fine. Under Section 133(10) failure to comply is publishable with a class A fine, up to 12 months imprisonment on summary conviction or a fine of € 250.000 and up to 5 years imprisonment on conviction on indictment.

Need for Court confirmation of any suspension, restriction and fines[edit | edit source]

Under Section 134 DPA 2018 the DPC has to apply to the Irish High Court to order a controller or processor to suspend or restrict the processing of personal data, when there is an urgent need to do so. Under Section 143 DPA 2018 any decision by the DPC to issue a fine has to be "confirmed" by a Circuit Court.

Appeals[edit | edit source]

Irish law knows different forms or recourse against actions of the DPC:

  • Under Section 142 of the DPA 2018 a controller or processor can appeal against a fine by the DPC within 28 days. If a fine is below € 75,000 the appel has to be brought in the Circuit Court, otherwise at the Irish High Court.
  • Under Section 150(1) DPA 2018 a controller or processor can appeal against an information notice or an enforcement notice within 28 days.
  • Under Section 150(5) DPA 2018 a data subject or any other person affected by a legally binding decision may appeal against the decision with in 28 days.
  • Further appeals on a point of law to the Hight Court or Appeals Court are possible (see Section 150(11) DPA)

In addition other instruments like a Judicial Review (not codified in the DPA 2018) can be brought against the DPC before the Irish High Court. This is for example the appropriate recourse in cases of inaction.

Practical Information[edit | edit source]

Known Problems[edit | edit source]

Duration of Procedures[edit | edit source]

The DPC is very slow to issue decisions. Since GDPR on 25. 5. 2018 was introduced no fines were issued so far. The handling of complaints can take a year and more.

Amicable Resolutions[edit | edit source]

Many data subjects report that their complaint was de facto rejected in an "amicable resolution" by the DPC that they did not agree with. The fact that more than 98% of all complaints in the first part of 2018 did not lead to a formal decision, indicates that the DPC does structurally not decide over complaints.

Statistics[edit | edit source]

You can help us filling this section!

  • Number of imposed fines : 0
  • Amount of these fines: 0

References[edit | edit source]

EU/EEA Data Protection Authorities
Austria · Belgium · Bulgaria · Croatia · Cyprus · Czech Republic · Denmark · Estonia · Finland · France · Germany (Baden-Württemberg · Bavaria, private sector · Bavaria, public sector · Berlin · Brandenburg · Bremen · Hamburg · Hesse · Lower Saxony · Mecklenburg-Vorpommern · North Rhine-Westphalia · Rhineland-Palatinate · Saarland · Saxony · Saxony-Anhalt · Schleswig-Holstein · Thuringia ) · Greece · Hungary · Ireland · Italy · Latvia · Lithuania · Luxembourg · Malta · Netherlands · Poland · Portugal · Romania · Slovakia · Slovenia · Spain · Sweden
Iceland · Liechtenstein · Norway EDPS · EDPB
Non-EU/EEA Data Protection Authorities
United Kingdom