← Regulators
GDPR EU 2016/679 Ireland

Who is the DPC: Ireland's data regulator that polices most of Big Tech

The Data Protection Commission is Ireland's GDPR supervisory authority — and, because Meta, Google, Apple, TikTok, X and LinkedIn run their EU operations from Ireland, the lead regulator for most of Big Tech across the whole EU under the one-stop-shop. What it does, why one national authority carries EU-wide weight, and who runs it after the move from one Commissioner to a three-person Commission — every fact sourced.

If a GDPR case involves Meta, Google, Apple, TikTok, X or LinkedIn, it very likely runs through Dublin — because their EU establishment is in Ireland, and under the GDPR a company’s main regulator is where its EU base sits. That makes Ireland’s DPC the single most consequential data regulator in Europe, far beyond its own borders. This is a profile of what the DPC is, why it carries that weight, and who runs it after a structural change at the top. Every fact is sourced.

Quick facts

  • Full name: Data Protection Commission (DPC); in Irish, An Coimisiún um Chosaint Sonraí (DPC)
  • Role: Ireland’s GDPR supervisory authority — the “national independent authority in Ireland responsible for upholding the fundamental right … to have their personal data protected” and monitoring application of the GDPR (DPC); a member of the EDPB
  • Founding law: established under the Data Protection Act 2018, which gives further effect to the GDPR in Ireland (DPC Annual Report 2024)
  • Legal status: a national independent authority (DPC)
  • Structure: a three-person Commission — a Chairperson plus two Commissioners — supported by Deputy Commissioners
  • Commissioners: Dr Des Hogan (Chairperson, Commissioner for Data Protection, from February 2024), Dale Sunderland (Commissioner, from February 2024), and Niamh Sweeney (Commissioner, appointed 17 September 2025, completing the three-person Commission) (DPC)
  • Headquarters: 6 Pembroke Row, Dublin 2, D02 X963, Ireland (DPC)
  • Website: dataprotection.ie

What the DPC is — and what it is not

The DPC is Ireland’s data protection authority (DPA — the independent national regulator that supervises and enforces data-protection law) and Ireland’s GDPR supervisory authority (DPC). It was established under the Data Protection Act 2018 (DPC Annual Report 2024) and is one of the 27 national authorities on the EDPB.

What makes it different from every other DPA is not a special legal power — it is geography. Most of the world’s largest technology companies locate their EU headquarters in Ireland, and under the GDPR that makes the DPC their lead supervisory authority for cross-border processing. So the DPC is not “just Ireland’s regulator”: in practice it is the front-line regulator for a large share of all EU residents’ data held by Big Tech.

It is not an AI Act authority and not a court. Its AI-relevant work, like every DPA’s, is GDPR enforcement.

What the DPC actually does

Its core job is the same as any GDPR supervisory authority — complaints, investigations, inquiries, corrective measures and fines. Two features make it stand out:

  1. It is the lead authority for Big Tech. Through the one-stop-shop (below), the DPC runs the major cross-border inquiries into the largest platforms.
  2. Its decisions set EU-wide outcomes. Because a lead-authority decision applies to processing affecting people across the EU, a single DPC inquiry can reshape how a global product handles data for hundreds of millions of users.

The one-stop-shop — why one national authority carries EU-wide weight

The GDPR’s one-stop-shop (OSS — the rule that a company doing cross-border processing deals primarily with one lead supervisory authority, the one where its EU “main establishment” sits) is why the DPC matters far beyond Ireland. With Meta, Google, Apple, TikTok, X, LinkedIn and others establishing in Ireland, the DPC is lead supervisory authority for their cross-border cases.

That lead role is powerful but not absolute. Other affected authorities can raise objections, and where the lead authority and the others cannot agree, the matter goes to the EDPB for a binding decision under Article 65 of the GDPR (Regulation (EU) 2016/679). Several high-profile Big Tech outcomes were shaped, or escalated in size, through that EDPB mechanism rather than the DPC acting alone — a built-in check on any single lead authority. For the EU-wide enforcement and dispute-resolution picture, see the GDPR pillar and the EDPB profile.

The Commission — how the DPC is run

The DPC used to be led by a single Commissioner. It is now a collegiate three-person Commission — a structural change, not just a personnel one.

  • Dr Des Hogan — Chairperson and Commissioner for Data Protection, from February 2024 (DPC Annual Report 2024).
  • Dale Sunderland — Commissioner for Data Protection, from February 2024; previously a Deputy Commissioner at the DPC (DPC).
  • Niamh Sweeney — Commissioner for Data Protection, appointed 17 September 2025, “completing the DPC’s three-person Commission” (DPC).
  • Predecessor: Hogan and Sunderland took over from Helen Dixon, the previous (single) Commissioner, whose terms had ended (DPC Annual Report 2024).

If you have a memory of “the Irish DPC = Helen Dixon”, update it: since February 2024 it is a three-person Commission chaired by Des Hogan.

What this means for you

  • If you are a multinational with an EU base in Ireland: the DPC is most likely your lead supervisory authority for cross-border processing — your primary GDPR interlocutor for the whole EU, not just Ireland.
  • If you are a business or individual elsewhere in the EU dealing with Big Tech: the regulator effectively deciding how your data is handled is often the DPC, via the one-stop-shop — but the EDPB’s Article 65 power means the final outcome is not always the DPC’s alone.
  • If you are tracking a Big Tech GDPR case: check whether the DPC is lead authority and whether an Article 65 EDPB binding decision is in play — that combination explains most large cross-border outcomes.
  • If you are a journalist or researcher: “Ireland’s data regulator” = the Data Protection Commission (An Coimisiún um Chosaint Sonraí), established under the Data Protection Act 2018, now a three-person Commission — Chairperson Des Hogan and Commissioner Dale Sunderland (both from February 2024) and Commissioner Niamh Sweeney (from 17 September 2025) — seated at 6 Pembroke Row, Dublin 2. The single-Commissioner Helen Dixon era ended in February 2024.

TL;DR

The DPC (An Coimisiún um Chosaint Sonraí) is Ireland’s GDPR supervisory authority, established under the Data Protection Act 2018. Because Meta, Google, Apple, TikTok, X and LinkedIn base their EU operations in Ireland, the DPC is the lead supervisory authority for most of Big Tech’s cross-border processing under the GDPR one-stop-shop — making one national regulator decisive for data held on hundreds of millions of EU residents. That lead role is checked by the EDPB’s Article 65 binding-decision power. Governance changed structurally: from a single Commissioner (Helen Dixon, until February 2024) to a three-person Commission — Chairperson Dr Des Hogan and Commissioner Dale Sunderland (February 2024), plus Commissioner Niamh Sweeney (17 September 2025). Seat: 6 Pembroke Row, Dublin 2.

Sources