Complaint-Based GDPR Inquiries Permit System-Wide Corrective Measures and Fines
1) Introduction
In Meta Platforms Ireland Ltd v Data Protection Commission (Approved) [2026] IEHC 323,
the High Court (Ms Justice Siobhán Phelan, 21 May 2026) addressed a recurring procedural and
constitutional-administrative law question in GDPR enforcement:
can the Data Protection Commission (DPC), in a complaint-based inquiry, adopt corrective measures and
propose administrative fines calibrated by reference to systemic effects on other users?
The proceedings arose from a single data subject complaint concerning access and portability rights under
Articles 12, 15 and 20 GDPR, in relation to Meta Platforms Ireland Limited’s (Meta Ireland’s)
“Hive” data warehouse. Although infringement findings in the DPC’s draft Preliminary Draft Decision (PDD)
were framed by reference to the complainant’s request, the draft PDD signalled the DPC’s intention to
consider corrective measures of general application and fines (in the range of €360–€430 million) based on
the scale of potentially affected users.
Meta Ireland challenged the draft of the PDD by judicial review, contending (i) lack of vires
(an unlawful “conversion” of a complaint-based inquiry into an “own-volition” inquiry), (ii) breach of fair
procedures, and (iii) breach of legitimate expectations.
2) Summary of the Judgment
-
Vires: The Court held that neither the GDPR nor the Data Protection Act 2018 limits a
complaint-based inquiry to complainant-only remedies. The DPC may, within a complaint-based inquiry,
lawfully consider and impose (or propose) system-wide corrective measures and fines where the infringement
found reflects a general practice and has wider impact.
-
No “conversion” required: Considering systemic implications at the corrective-measures
stage does not transform the inquiry into an own-volition inquiry. “Own-volition” and complaint-based
inquiries differ in origin/terms of reference, not in the availability of corrective powers once an
infringement is established.
-
Prematurity: Although the DPC initially pleaded prematurity, it urged the Court to
decide vires. The Court considered it appropriate to determine the legal issue mid-process, given its
fundamental nature and the impending Article 60 cooperation mechanism complexities.
-
Fair procedures and legitimate expectation: These claims failed. Meta Ireland was on
notice from the outset of the DPC’s Article 58 corrective powers (including fines), and the statutory
framework mandated consideration of Article 83 factors (including the number of data subjects affected).
-
Outcome: The judicial review was dismissed.
3) Analysis
3.1 Precedents Cited
(a) Irish judicial review “prematurity” and intervention mid-process
-
Facebook Ireland Ltd v. Data Protection Commission [2021] IEHC 336
Treated as authority that a “preliminary draft decision” can be amenable to judicial review in appropriate
circumstances, even before the administrative process concludes. The Court used this to support
justiciability and to explain why it could intervene to decide a fundamental legality issue before the
Article 60/65 mechanisms became engaged.
-
Rowland v. An Post [2017] 1 IR 355; [2017] IESC 20
Cited for the principle that courts generally avoid intervening mid-process unless it has “gone
irremediably wrong”. The Court considered the vires issue sufficiently fundamental (and likely to carry
through) to justify determination now, especially given cross-border escalation risks.
(b) Irish data protection inquiry jurisprudence
-
Meta Platforms Ireland Ltd v Data Protection Commission [2024] IEHC 75
Discussed chiefly as illustrating that the DPC may run complaint-based and own-volition inquiries in
parallel. The Court distinguished “procedural choice” (running separate tracks) from a legal requirement
to do so whenever systemic issues arise.
-
Facebook Ireland Limited v. The Data Protection Commissioner & Anor. [2021] IEHC 336
(as discussed in the judgment)
Relied on for the breadth of the DPC’s inquiry discretion under s.110 and its ability to “cause such
inquiry as it thinks fit”, subject to fair procedures.
-
Ryan v. Data Protection Commission [2024] IECA 152
Cited in the legitimate expectations discussion as part of the Irish appellate context on DPC processes
and the limits of process-based challenges.
(c) EU/CJEU authority on supervisory authority duties and corrective powers
-
SCHUFA Holding Case C-26/22 and Case C-64/22
Used for the proposition that supervisory authorities are responsible (Charter Article 8(3)) for
monitoring compliance with EU data protection rules, and that once an infringement is found, the authority
must react appropriately with measures that ensure GDPR compliance, considering recital 129
proportionality/necessity.
-
TR v. Land Hessen Case C-768/21
Quoted for the framing that Article 58 confers extensive investigative/corrective powers, and that where
infringements are found the authority must adopt appropriate measures to remedy shortcomings, with each
measure being appropriate, necessary, and proportionate (recital 129).
-
NVSC Case C-683/21 (Advocate General Emiliou’s Opinion, 4 May 2023)
Relied on for the structure of Article 83’s sanction system and the two-step analysis (whether to fine,
and amount), and for the role of recital 148 (reprimand for minor infringement/disproportionate burden),
reinforcing that the fining power is not purely compensatory and is calibrated to enforcement objectives.
(d) Legitimate expectation (Irish and EU)
-
Glencar Exploration plc v. Mayo County Council (No. 2) [2002] 1 IR 84; [2002] IESC 1
Provided the Irish test for legitimate expectation: clear representations, reliance, and unfairness in
resiling, subject to legality and the authority’s freedom to exercise statutory powers.
-
Murphy v. Revenue Commissioners & DPP [2023] IECA 110
Applied for the objective interpretation of administrative correspondence in assessing what, if any,
assurances were given.
-
Lett & Co Ltd v. Wexford Borough Council [2012] 2 IR 198; [2012] IESC 14 and
Cromane Seafoods Ltd. v. Minister for Agriculture [2017] 1 I.R. 119
Cited as part of the settled Irish framework that even established administrative practices may not bind
an authority where the statute requires otherwise, and departures may be permissible if fair procedures
are respected.
-
ZF v. European Commission Case T-605/18 and
Myland Ireland Ltd v. European Commission Case T-1181/23
Cited for the EU-law cumulative conditions: precise/consistent assurances; legitimate reliance; and
compatibility with applicable rules.
3.2 Legal Reasoning
(a) The core holding: complaint-based inquiries are not remedially “single-user only”
The Court rejected Meta Ireland’s central premise that a complaint-based inquiry under Article 77 GDPR and
s.110/s.113 of the Data Protection Act 2018 is limited to complainant-specific corrective outcomes.
Article 77 establishes standing (a data subject complains about processing “relating to him or her”),
but it does not constrain the DPC’s enforcement response once an infringement is found.
The Court’s interpretive method was strongly structural and purposive:
-
Structural: Articles 57 and 58 GDPR set the DPC’s “monitor and enforce” mandate. Those
provisions are not complaint-type dependent, and Article 58(2) does not distinguish between complaint-led
and own-volition origins.
-
Purposive: The GDPR is an enforcement-forward instrument. Limiting corrective measures in
complaint-based inquiries to the complainant alone would, on the Court’s reasoning, undermine effective
enforcement.
(b) The decisive role of Articles 58 and 83 GDPR
The Court treated Article 58(2) corrective powers and Article 83 administrative fines as central to the
answer. In particular:
-
Article 58(2)(d) empowers orders to “bring processing operations into compliance” (conceptually capable of
system-wide scope).
-
Article 58(2)(i) empowers fines “depending on the circumstances of each individual case”.
-
Article 83(2)(a) requires the authority, when deciding whether and how much to fine, to consider “the
number of data subjects affected” and “the nature, scope or purpose of the processing”.
Those mandatory criteria would be largely defeated if, merely because a case began as a single complaint,
the DPC were barred from considering evidence that the same practice affected many users. The Court thus
read “individual case” in Article 83 as the case under consideration, not as “the individual complainant
only”.
(c) The 2018 Act: procedural origin differs; corrective powers do not
The Court placed weight on the symmetry of the Data Protection Act 2018:
s.111 (own-volition inquiry) and s.113 (cross-border complaint) both require the DPC, after an infringement
decision, to decide whether to exercise corrective powers; and s.115 applies identically across those
routes. This statutory design contradicted the proposed dichotomy that systemic measures are only lawful in
own-volition inquiries.
(d) No procedural “ambush” on systemic impact
Meta Ireland’s fair procedures case was treated as parasitic on its vires theory.
Once the Court concluded that the DPC could lawfully consider systemic effects, the remaining question was
whether Meta Ireland had been on notice that such consequences could flow.
The Court pointed to multiple indicators of notice:
-
The initial Notice of Commencement expressly referenced Article 58(2) powers including fines.
-
Meta Ireland’s own inquiry responses defended general, at-scale refusal to provide raw Hive data, and
framed compliance burdens in terms of “each and every” user request—supporting the inference that the
contested practice was general, not bespoke to the complainant.
-
Later correspondence highlighted “undertaking” and the fining cap logic (Article 83 and recital 150),
signalling that fines were being evaluated in a manner characteristic of high-scale enforcement.
(e) Legitimate expectation: no clear lawful assurance of complainant-only remedies
The legitimate expectations claim failed for familiar reasons:
the Court found no “precise, unconditional and consistent” assurance that systemic corrective measures or
fines would not be contemplated in a complaint-based inquiry. Moreover, any expectation that the DPC would
decline to consider Article 83 factors because the case started with one complaint would conflict with the
statutory scheme, and cannot be legitimised by guidance documents or past administrative practice.
3.3 Impact
-
Enforcement leverage from individual complaints: The judgment confirms that a single data
subject complaint can be the procedural entry point for remedies that reshape a controller’s general
practices, where the infringement reflects a general policy or practice.
-
Reduced incentive for parallel own-volition inquiries: The DPC is not required to open a
separate own-volition inquiry merely to justify systemic corrective measures, provided the systemic issue
is within the subject matter of the complaint as investigated “to the extent appropriate”.
-
Fining analysis must reflect scale: Because Article 83 compels consideration of affected
data subjects and scope of processing, controllers should expect that even complainant-framed findings can
translate into high-range fining exposure where the underlying practice applies at scale.
-
Judicial review timing: Building on Facebook Ireland Ltd v. Data Protection Commission [2021] IEHC 336,
the case reinforces that draft-stage DPC steps can be justiciable where the point is fundamental and likely
to shape the remainder of the statutory process—though the Court emphasised that mid-process intervention
remains exceptional.
4) Complex Concepts Simplified
- Complaint-based inquiry vs “own-volition” inquiry
-
A complaint-based inquiry starts because a data subject alleges infringement of their own GDPR rights.
An “own-volition” inquiry starts because the DPC initiates it without needing an individual complainant.
This judgment holds that, once an infringement is found, the same toolbox of corrective powers applies
in either route.
- “Systemic” corrective measures
-
Measures that go beyond putting one complainant back in their proper position and instead require changes
to a controller’s general processing operations (e.g., changing default access practices for all users).
Article 58(2)(d) explicitly enables orders to bring “processing operations” into compliance.
- Article 83 “number of data subjects affected”
-
When deciding whether to fine and how much, the DPC must consider how many people are affected by the
infringement. This is an enforcement criterion, not a compensation criterion: it exists to ensure fines
are “effective, proportionate and dissuasive”.
- “Undertaking” and turnover cap
-
GDPR fines are capped by reference to an “undertaking” (competition-law concept), potentially capturing a
corporate group’s turnover. This increases the fining ceiling and supports deterrence for large corporate
groups.
- Article 60 / Article 65 GDPR
-
Article 60 is the cooperation process where the Lead Supervisory Authority circulates a draft decision to
other Concerned Supervisory Authorities. If there is a “relevant and reasoned objection” that cannot be
resolved, Article 65 allows the European Data Protection Board to adopt a binding decision.
5) Conclusion
[2026] IEHC 323 clarifies a high-stakes point of GDPR enforcement architecture in Ireland:
a complaint-based inquiry is not confined to complainant-only outcomes. Where the infringement found
reflects a general practice, the DPC may lawfully pursue system-wide corrective orders and calculate fines
by reference to the broader impact, as required by Articles 58 and 83 GDPR and mirrored by the 2018 Act.
The decision also narrows the practical force of “conversion” arguments: addressing systemic implications at
the corrective-measures stage is not a jurisdictional leap into own-volition territory, but an orthodox
application of the GDPR’s mandatory enforcement logic.