Knocking on your door

21 Sept 2026 data law Print

Knocking on your door

Three themes dominate the DPC’s 2025 annual report: policies, transparency, and training. Where these were lacking, incidents occurred, complaints followed, and the DPC engaged – sometimes by knocking on the office door. Elaine Morrissey answers it

The DPC’s 2025 Annual Report and Case Studies confirms what most practitioners already suspect: the same failures keep recurring.

The numbers show a regulator doing more – with less patience for excuses – including:

  • Fines imposed: €652 million (2024) versus €530.77 million (2025); cumulative since May 2018, €4.04 billion,
  • Cases concluded: 10,510 (2024) versus 11,734 (2025) – up 12%,
  • Data-breach notifications: 7,781 (2024) versus 6,521 (2025) – down 16%, 
  • Electronic marketing investigations: 146 (2024) versus 275 (2025) – up 88%, 
  • New cases: 16,160 – up 45%.

Electronic direct-marketing complaints are up 24% (245 new complaints in 2025), cases progressing to the formal complaint-handling process are up 27%, and the DPC’s first Public Attitudes Survey found strong public awareness of data protection rights – 70% of respondents trust the DPC to uphold them.

Biggest headache

Data-subject access requests (DSARs) continue to rule the roost. DSARs remain the DPC’s biggest headache – and everyone else’s.

Of GDPR complaints received, access requests accounted for 42%, erasure 17%, and fair processing 16%, with 1,280 complaints on the right of access alone.

The report states that organisations “must do more to enhance transparency… when responding to subject-access requests”. Where exemptions are relied on, organisations “frequently fail to clearly explain to the individual the rationale for applying those restrictions”.

It is the most repeated message across this year’s case studies: document the reason for any restriction or exemption relied on.

Case Study 2 warns that personal data cannot be withheld “without careful consideration of the concept of necessity and proportionality”, while Case Study 4 requires an organisation to “demonstrate the reasoning for any restrictions and/or exemptions made over the right of access”.

Privilege exemption

In Case Study 1, a national school withheld records, citing legal advice and litigation privilege under section 162 of the 2018 act.

The DPC undertook a detailed review of the records and information provided by the school and found that the school had correctly applied the privilege exemption. The lesson: keep a schedule of what is withheld or redacted and why, tied to the provision relied upon.

The DPC also published Subject Access Requests: A Data Controller’s Guide in 2025.

Its principles were tested in Patreon Ireland Ltd, where the DPC confirmed that an access request can be made through any channel, and that the clock starts when the request lands – not when it reaches the right department.

Patreon sat on the request for months and was reprimanded.

Of the queries received by the Law Society’s IP and Data Protection Law Committee, the majority relate to DSARs received by firms from clients, former clients, or third parties.

These are challenging requests for solicitors, but it is important to deal with them within the timeline (one month) and to document all decision-making. The most important thing is not to ignore the request – ultimately, that may result in engagement with the DPC.

The use of GenAI

The report flags an issue that solicitors are already dealing with: individuals are increasingly using GenAI to draft their own DSARs and complaints.

The DPC notes that AI-drafted requests are often inaccurate or invalid, which frustrates the process for all involved. 

Case Study 28 highlights inappropriate use of AI that caused a data breach. An employee at a financial services firm uploaded 32 CVs – including passport and visa details – to a free external AI tool to get through the work faster.

There was no data-processing agreement with the provider, the data left the organisation’s control, and the organisation’s data loss prevention tool flagged the upload, which it then notified to the DPC as a breach.

The organisation had no policy on AI tools at all – precisely the gap the DPC’s key takeaway zeroes in on.

The Law Society’s guidance on generative AI warns against exactly this: free and paid consumer versions of GenAI tools are not suitable for personal or client confidential data.

Case Study 28 highlights that every organisation should have an AI policy setting out which AI tools staff may use, for what purposes, and what data may be inputted. Staff then need to be made aware of it and trained on it.

Training never gets old

The Cubic Telecom decision shows why training is not a box-ticking exercise. A support contractor misread a customer’s subject access request as an erasure request and deleted the individual’s personal data.

The lesson: staff need to recognise a rights request and know what to do with it.

In 2025, the DPC also carried out 13 site visits to organisations that had ignored its complaints process or a rights request.

The premises included restaurants, a GP’s surgery, a solicitor’s office, and several sole traders’ addresses. Firms are data controllers too – ignoring the DPC can escalate from a letter to a knock on the door.

Sharp focus

Transparency runs through the report and case studies, and ties in with the European Data Protection Board’s October 2025 announcement that transparency obligations under articles 12-14 of the GDPR will be the focus of its 2026 coordinated enforcement action: participating authorities, including the DPC, will assess whether controllers give individuals clear, accessible information about their processing.

Expect the 2026 annual report to reflect that focus. Now is the time to review firm and client policies against the transparency requirements, particularly as AI use increases.

Not just a footnote

Children’s data was arguably the DPC’s headline act in 2025. The ‘Pause Before You Post’ campaign, tackling parents’ sharing of children’s images online, generated over 150 million views worldwide.

For any firm or client working with children, this is a sharp reminder to check compliance.

Keep the paper trail

The DPC’s ‘Kick-Start Compliance’ sports data conference (applicable to all organisations) produced a ten-point checklist, running from knowing what data you hold, to having a breach plan, and finishing on the point that matters most – keep records of decision, processes, policies, and training.

The City of Dublin Education and Training Board (CDETB) decision shows the cost of failing that – poor security and a two-year delay in notifying data subjects led to a €125,000 fine, reduced meaningfully by CDETB’s cooperation once the DPC came calling.

Worth remembering the next time a client asks whether owning up is worth it.

Looking ahead

This year brings the European Data Protection Board’s transparency sweep and, if 2025 is any guide, more data-subject requests and complaints. Solicitors (for their own firms and when advising) should focus on procedures, transparency, and training – and document it, to show the DPC what was done, when, and why.

Elaine Morrissey is chair of the Law Society’s IP and Data Protection Law Committee.

Further Reading

Gazette Desk
Gazette.ie is the daily legal news site of the Law Society of Ireland

Copyright © 2026 Law Society Gazette. The Law Society is not responsible for the content of external sites – see our Privacy Policy.