Skip to content
Ceci est une traduction de commodite. La version anglaise est la version officielle et juridiquement contraignante. Voir la version anglaise
EUMEDIUM coverage1 enforcement action

Ireland — GDPR AI Enforcement (Data Protection Commission): AI Compliance Requirements

Ireland's DPC is the lead GDPR supervisor for most major US tech companies in the EU. DPC issued a €1.2B fine against Meta in 2023 for transatlantic data transfers — an Article 46(1)/Schrems-II data-transfer matter with NO AI dimension (Cycle 11 correction, see enforcementActions note; this is the same "AI-washing" fabrication this mission's eu_gdpr_art22 entry already caught and fixed for the identical fine, which had survived uncaught here). Separately, DPC guidance covers AI training data, generative AI models, and LLMs, and EU-US data transfers specifically for AI training require their own Transfer Impact Assessment.

Summary of publicly-available regulatory text as of 2026-08-22. Verify against current official sources before relying on this for compliance decisions. Not legal advice.

Key Facts

Effective Date

January 1, 2023

Maximum Penalty

€20,000,000 or 4% global turnover (DPC issued €1.2B fine in 2023)

What Your Business Must Do

2 compliance requirements identified. Critical requirements carry the highest risk of enforcement action.

Lawful Basis for AI Training Data (DPC Guidance)

High Priority

DPC requires documented GDPR lawful basis for AI model training on personal data. Legitimate interest requires a Legitimate Interest Assessment (LIA). Explicit consent recommended for user-generated content used in training.

GDPR Art. 6 (as applied by Irish DPC)

Transfer Impact Assessment for US AI Vendors

High Priority

EU organizations using US AI vendors must conduct a Transfer Impact Assessment (TIA). SCCs alone are insufficient without a TIA — DPC enforcement priority.

GDPR Art. 44-49 (Chapter V international transfers), Art. 46(1) (as applied by Irish DPC)

Who Does This Apply To?

Applies to any organisation processing the personal data of EU/Irish residents through AI under the supervision of Ireland's Data Protection Commission (DPC) — the lead GDPR supervisor for most major US tech companies operating in the EU. In scope: developers training AI models on personal data (a documented lawful basis is required; legitimate interest needs a Legitimate Interest Assessment and is not automatically available for training generative AI on user-generated content), and any EU organisation using US-based AI vendors or training compute (a Transfer Impact Assessment is mandatory — SCCs alone are insufficient, per the €1.2B Meta transatlantic-transfer decision). Maximum exposure: €20M or 4% of global turnover (the DPC has imposed a fine as high as €1.2B — CYCLE 5, 2026-08-22: verified this fine REMAINS UNDER APPEAL through the Irish courts as of April 2026, with no reduction or vacation ordered to date; treat as imposed-but-not-yet-final, not a fully settled precedent).

Recent Enforcement Actions

2024-08-06 (proceedings filed); 2024-09-04 (undertaking/conclusion announced)Source verified· as of 2026-08-22

Against:

Recent Regulatory Guidance

guidance2024-02

DPC AI and GDPR Guidance — Training Data Lawful Basis (2024)

DPC guidance on AI model training: legitimate interest is not automatically available for training generative AI on user-generated content; a documented Legitimate Interest Assessment (LIA) weighing user rights against training purposes is required. Explicit consent is the preferred basis for user content used in personalisation models. Transfer Impact Assessments mandatory for US-based AI training compute.

guidanceundated (ongoing as of this cycle)

DPC — open examination of Google's DPIA practice for PaLM2 (status unconfirmed)

Reporting this cycle indicates the DPC has been examining whether Google conducted an adequate Data Protection Impact Assessment before developing its PaLM2 large language model. No conclusion, formal decision, or dated outcome was found this cycle — treat as an open/unresolved regulatory examination, not a completed enforcement action.

Frequently Asked Questions

Does Ireland — GDPR AI Enforcement (Data Protection Commission) apply to my business?

Ireland's DPC is the lead GDPR supervisor for most major US tech companies in the EU. DPC issued a €1.2B fine against Meta in 2023 for transatlantic data transfers — an Article 46(1)/Schrems-II data-transfer matter with NO AI dimension (Cycle 11… Use Aegis Firma's free scanner to get a personalized assessment in under 5 minutes.

What is the penalty for non-compliance?

The maximum penalty under Ireland — GDPR AI Enforcement (Data Protection Commission) is: €20,000,000 or 4% global turnover (DPC issued €1.2B fine in 2023). Fines are typically scaled by company size, severity of violation, and whether violations were willful or accidental.

How do I comply with Ireland — GDPR AI Enforcement (Data Protection Commission)?

The 2 requirements above cover the core obligations. The fastest path to compliance is: (1) conduct an AI risk assessment, (2) document your AI systems, (3) implement transparency disclosures where required. Aegis Firma generates all required documents automatically.

Official Source

https://www.dataprotection.ie/en/news-media/blogs/ai-and-data-protection

Last updated: 2026-08-22 — verify at source before relying on this information.

Don't leave compliance to chance

Aegis Firma scans your AI tools, tells you exactly which regulations apply, and generates all required documents — in 30 minutes.

Start your free compliance scan