← Enforcement
GDPR EU 2016/679 Ireland

DPC fines: Europe's most powerful — and most criticised — data regulator

A registry of fines from Ireland's DPC — the lead regulator for most of Big Tech, which imposed over €652 million in a single year, yet is accused of going easy on the platforms and being forced higher by the EU. The Big Tech mega-fines, the modest domestic Irish cases (Tusla, Bank of Ireland), and the bottleneck criticism — every fact sourced.

No regulator in Europe matters more for your data than Ireland’s Data Protection Commission (DPC) — and none is more criticised. Because Meta, Google, Apple, TikTok, X and LinkedIn run their EU operations from Dublin, the DPC is their lead supervisory authority under the GDPR’s one-stop-shop, which makes a five-million-person country’s regulator the front-line enforcer for hundreds of millions of EU residents’ data.

That produces a strange split personality, and this registry is about it. The DPC is, at once, the source of the largest fines in GDPR history — over €652 million in 2024 alone — and a regulator that privacy campaigners accuse of going easy on the very companies it polices. Every figure links to the regulator or the EU mirror of its decision.

A regulator of two halves

Half one: the Big Tech mega-fines

Almost every record GDPR fine runs through Dublin. In 2024 alone the DPC imposed over €652 million in administrative fines — on LinkedIn (€310 million), and Meta (€251 million and €91 million) (DPC Annual Report 2024). Across the years its decisions include Meta’s €1.2 billion transfer fine, TikTok’s €530 million, Meta’s €405 million and €390 million advertising and children’s-data fines, and WhatsApp’s €225 million.

These are detailed — amounts, articles, status — in the dedicated Big Tech GDPR fines registry, so this post does not repeat them case by case. The point here is the pattern: in several of the biggest cases, the DPC’s own draft proposed a smaller fine, or none, and the European Data Protection Board (EDPB) — through a binding decision under Article 65 GDPR — instructed it to raise the amount or add findings. The €1.2 billion, the €390 million and the €225 million were all pushed up this way. That is the central fact about DPC enforcement: it is the regulator that issues the biggest numbers, but often only after the rest of Europe makes it.

Half two: the modest domestic record

Away from Big Tech, the DPC is an ordinary national regulator with a modest fine book — and here the numbers are small:

  • Tusla — €75,000 — the DPC’s first-ever GDPR fine (May 2020). The Child and Family Agency wrongly disclosed information about children to unauthorised people across three cases.
  • Bank of Ireland — €463,000 — for data breaches affecting the Central Credit Register that could have hit thousands of customers’ credit ratings, under Articles 32(1), 33 and 34.
  • Sligo County Council — €29,500 (13 November 2024) — unlawful CCTV use, with a temporary ban on cameras at several locations (DPC Annual Report 2024).
  • Maynooth University — €40,000 (22 November 2024) — security and breach-notification failings under Articles 5(1)(f), 32(1) and 33(1) (DPC Annual Report 2024).

Many DPC conclusions are not fines at all but reprimands — Airbnb Ireland, Groupon and Apple Distribution all received reprimands in early 2024 with no monetary penalty (DPC Annual Report 2024). The contrast is stark: hundreds of millions for the platforms, tens of thousands for an Irish university or council.

The criticism: bottleneck, “handling”, and fines that don’t get paid

The DPC is the most contested regulator in the EU, and the criticism is specific and on the record:

  • The bottleneck argument. Civil-society groups including the Irish Council for Civil Liberties (ICCL) argue that because most Big Tech cases must run through Dublin, a slow or lenient DPC becomes a chokepoint for the whole EU — every other regulator depends on Ireland to move (ICCL / noyb coverage).
  • “Handling” without deciding. The campaign group noyb (Max Schrems) accuses the DPC of resolving the overwhelming majority of complaints through amicable resolution rather than formal decisions — in noyb’s framing, “handling” complaints by not deciding them (noyb).
  • Big numbers, little collected. Because every DPC fine must be confirmed by an Irish court and the companies appeal, billions in headline fines have been imposed while very little has actually been paid — a gap critics highlight repeatedly (Cybernews).

The DPC rejects this. It points to the €652 million imposed in 2024 and argues that some criticism of the one-stop-shop is politically motivated. Both things can be true at once: the DPC genuinely issues the largest fines in Europe, and it is repeatedly pushed to do so by the EDPB and dogged by a backlog its critics consider deliberate restraint. Readers can weigh the record themselves — that is why this registry links every claim.

What this means for you

  • If you are Big Tech with an EU base in Ireland: the DPC is your lead regulator — but the EDPB sits behind it, and the Article 65 mechanism means a DPC draft you are comfortable with can still be revised upward by the other 26 authorities. The fine is not settled when Dublin proposes it.
  • If you are an ordinary Irish controller: the DPC’s domestic enforcement is real but proportionate — Tusla, a council, a university. The avoidable failings are the universal ones: don’t disclose data to the wrong people (Tusla), secure it properly (Bank of Ireland, Maynooth), and have a lawful basis and limits for surveillance (Sligo’s CCTV).
  • If you are a complainant: be realistic about timelines. The DPC’s critics’ central charge is slowness; cross-border complaints in particular can take years.

Sources for independent verification

Short conclusion

The DPC is the most powerful data regulator in Europe by reach and the most criticised by reputation. It issues the continent’s biggest fines — €652 million in 2024 — yet is repeatedly pushed higher by the EDPB and accused by civil society of being a bottleneck that “handles” complaints without deciding them. Its domestic record, by contrast, is small and ordinary. To understand EU data enforcement you have to understand Dublin — both halves of it.