Ireland’s DPC responsible for over half of the €1.2bn in GDPR fines issued last year
The Irish Data Protection Commission (DPC) issued fines of €310m against LinkedIn and €251m against Meta last year.
The DPC was responsible for more than half of the total €1.2bn in European GDPR fines that were levied last year, according to the law firm DLA Piper’s GDPR Fines and Data Breach Survey.
In 2023, Ireland imposed the largest GDPR fine ever – a penalty of €1.2bn on Meta, the firm headed by Mark Zuckerberg which is the parent group of Facebook and Instagram.
The total fines reported since the application of GDPR in 2018 now stand at €5.88bn.
Since May 2018, Ireland has issued €3.5bn in fines – the largest tally in Europe and largely because authorities here are responsible for overseeing US multinationals that have their EU base here.
The Irish fines are more than four times the value of fines issued by the next busiest regulator in Luxembourg – its data protection authority issued €746.38m in fines over the same period.
“GDPR enforcement remains a dynamic and evolving arena with Ireland’s DPC remaining at the forefront as Europe’s leading data regulator,” said John Magee, partner and global co-chair of DLA Piper’s privacy and cybersecurity group.
“It ranges from growing enforcement in sectors away from big tech and social media, to the use of the GDPR as an incumbent guardrail for AI enforcement as AI-specific regulation falls into place, and supervisory authorities looking to impose personal liability on company directors.”
Despite growing numbers, last year saw a 33pc decrease in aggregate fines imposed compared to the previous seven years of increasing enforcement. Big tech and social media companies continued to be the primary targets for large fines, with the top 10 largest fines being imposed in this sector since 2018.
Last August, the Dutch data protection authority issued a fine of €290m against a popular ride-hailing app citing transfers of personal data to a third country.
A significant trend from last year was a new focus by authorities on governance and oversight.
The Dutch Data Protection Commission investigated the personal liability of the directors of Clearview AI for numerous breaches of the GDPR following a €30.5m fine against the company.
Other major sectors impacted include financial services and energy. The UK was an outlier, having issued very few fines.
Free Claim Assessment
Find out if you have a valid claim — free, no obligation.
Start Free Assessment