Ireland
Tier 2 Comprehensive law EuropePrincipal framework: GDPR + Data Protection Act 2018 (2018). Regulator: DPC. Broad journalism and academic exemption; DPC acts as lead authority for many multinationals.
At a glance
- Criminal offences
- Yes — indictable offences under the DPA 2018, up to €250,000 and/or 5 years
- Public-sector fines
- Yes
- Principal law
- GDPR + Data Protection Act 2018
- Regulator
- Data Protection Commission
- Breach notification
- 72 hours to the supervisory authority (Art 33); undue-delay notice to individuals at high risk
- Maximum penalty
- Up to €20m or 4% of global annual turnover
- DPO required
- Public authorities; large-scale regular monitoring or special-category processing (Art 37)
- Digital consent age
- 16
- Extraterritorial reach
- Yes — targeting or monitoring people in the EU (Art 3(2))
- National implementing act
- Data Protection Act 2018
Structure
- Structural pattern
- Not assessed
- Sub-jurisdictions
- None — no sub-national axis
- ISO code
- IE
A Pattern 4 jurisdiction has no sub-national layer to model. Devolution elsewhere in the legal system does not imply it here — check each Act rather than reasoning from the country.
Transfers and adequacy
- EU member
- Yes
- EEA member
- Yes
- Holds EU adequacy
- Yes
EU/EEA member — intra-EEA transfers need no adequacy decision.
Instruments
Also applies here
Directly applicable as EU law, without national transposition. The national act supplements it rather than replacing it.
Sources
- Regulator Data Protection Commission
- Primary GDPR — EUR-Lex
- Primary Data Protection Act 2018 — Irish Statute Book
- Regulator DPC — regulator
Never independently verified — seeded from the prototype.