Complaint-Based GDPR Inquiries Permit System-Wide Corrective Measures and Fines

1) Introduction

In Meta Platforms Ireland Ltd v Data Protection Commission (Approved) [2026] IEHC 323, the High Court (Ms Justice Siobhán Phelan, 21 May 2026) addressed a recurring procedural and constitutional-administrative law question in GDPR enforcement: can the Data Protection Commission (DPC), in a complaint-based inquiry, adopt corrective measures and propose administrative fines calibrated by reference to systemic effects on other users?

The proceedings arose from a single data subject complaint concerning access and portability rights under Articles 12, 15 and 20 GDPR, in relation to Meta Platforms Ireland Limited’s (Meta Ireland’s) “Hive” data warehouse. Although infringement findings in the DPC’s draft Preliminary Draft Decision (PDD) were framed by reference to the complainant’s request, the draft PDD signalled the DPC’s intention to consider corrective measures of general application and fines (in the range of €360–€430 million) based on the scale of potentially affected users.

Meta Ireland challenged the draft of the PDD by judicial review, contending (i) lack of vires (an unlawful “conversion” of a complaint-based inquiry into an “own-volition” inquiry), (ii) breach of fair procedures, and (iii) breach of legitimate expectations.

2) Summary of the Judgment

  • Vires: The Court held that neither the GDPR nor the Data Protection Act 2018 limits a complaint-based inquiry to complainant-only remedies. The DPC may, within a complaint-based inquiry, lawfully consider and impose (or propose) system-wide corrective measures and fines where the infringement found reflects a general practice and has wider impact.
  • No “conversion” required: Considering systemic implications at the corrective-measures stage does not transform the inquiry into an own-volition inquiry. “Own-volition” and complaint-based inquiries differ in origin/terms of reference, not in the availability of corrective powers once an infringement is established.
  • Prematurity: Although the DPC initially pleaded prematurity, it urged the Court to decide vires. The Court considered it appropriate to determine the legal issue mid-process, given its fundamental nature and the impending Article 60 cooperation mechanism complexities.
  • Fair procedures and legitimate expectation: These claims failed. Meta Ireland was on notice from the outset of the DPC’s Article 58 corrective powers (including fines), and the statutory framework mandated consideration of Article 83 factors (including the number of data subjects affected).
  • Outcome: The judicial review was dismissed.

3) Analysis

3.1 Precedents Cited

(a) Irish judicial review “prematurity” and intervention mid-process

  • Facebook Ireland Ltd v. Data Protection Commission [2021] IEHC 336
    Treated as authority that a “preliminary draft decision” can be amenable to judicial review in appropriate circumstances, even before the administrative process concludes. The Court used this to support justiciability and to explain why it could intervene to decide a fundamental legality issue before the Article 60/65 mechanisms became engaged.
  • Rowland v. An Post [2017] 1 IR 355; [2017] IESC 20
    Cited for the principle that courts generally avoid intervening mid-process unless it has “gone irremediably wrong”. The Court considered the vires issue sufficiently fundamental (and likely to carry through) to justify determination now, especially given cross-border escalation risks.

(b) Irish data protection inquiry jurisprudence

  • Meta Platforms Ireland Ltd v Data Protection Commission [2024] IEHC 75
    Discussed chiefly as illustrating that the DPC may run complaint-based and own-volition inquiries in parallel. The Court distinguished “procedural choice” (running separate tracks) from a legal requirement to do so whenever systemic issues arise.
  • Facebook Ireland Limited v. The Data Protection Commissioner & Anor. [2021] IEHC 336 (as discussed in the judgment)
    Relied on for the breadth of the DPC’s inquiry discretion under s.110 and its ability to “cause such inquiry as it thinks fit”, subject to fair procedures.
  • Ryan v. Data Protection Commission [2024] IECA 152
    Cited in the legitimate expectations discussion as part of the Irish appellate context on DPC processes and the limits of process-based challenges.

(c) EU/CJEU authority on supervisory authority duties and corrective powers

  • SCHUFA Holding Case C-26/22 and Case C-64/22
    Used for the proposition that supervisory authorities are responsible (Charter Article 8(3)) for monitoring compliance with EU data protection rules, and that once an infringement is found, the authority must react appropriately with measures that ensure GDPR compliance, considering recital 129 proportionality/necessity.
  • TR v. Land Hessen Case C-768/21
    Quoted for the framing that Article 58 confers extensive investigative/corrective powers, and that where infringements are found the authority must adopt appropriate measures to remedy shortcomings, with each measure being appropriate, necessary, and proportionate (recital 129).
  • NVSC Case C-683/21 (Advocate General Emiliou’s Opinion, 4 May 2023)
    Relied on for the structure of Article 83’s sanction system and the two-step analysis (whether to fine, and amount), and for the role of recital 148 (reprimand for minor infringement/disproportionate burden), reinforcing that the fining power is not purely compensatory and is calibrated to enforcement objectives.

(d) Legitimate expectation (Irish and EU)

  • Glencar Exploration plc v. Mayo County Council (No. 2) [2002] 1 IR 84; [2002] IESC 1
    Provided the Irish test for legitimate expectation: clear representations, reliance, and unfairness in resiling, subject to legality and the authority’s freedom to exercise statutory powers.
  • Murphy v. Revenue Commissioners & DPP [2023] IECA 110
    Applied for the objective interpretation of administrative correspondence in assessing what, if any, assurances were given.
  • Lett & Co Ltd v. Wexford Borough Council [2012] 2 IR 198; [2012] IESC 14 and Cromane Seafoods Ltd. v. Minister for Agriculture [2017] 1 I.R. 119
    Cited as part of the settled Irish framework that even established administrative practices may not bind an authority where the statute requires otherwise, and departures may be permissible if fair procedures are respected.
  • ZF v. European Commission Case T-605/18 and Myland Ireland Ltd v. European Commission Case T-1181/23
    Cited for the EU-law cumulative conditions: precise/consistent assurances; legitimate reliance; and compatibility with applicable rules.

3.2 Legal Reasoning

(a) The core holding: complaint-based inquiries are not remedially “single-user only”

The Court rejected Meta Ireland’s central premise that a complaint-based inquiry under Article 77 GDPR and s.110/s.113 of the Data Protection Act 2018 is limited to complainant-specific corrective outcomes. Article 77 establishes standing (a data subject complains about processing “relating to him or her”), but it does not constrain the DPC’s enforcement response once an infringement is found.

The Court’s interpretive method was strongly structural and purposive:

  • Structural: Articles 57 and 58 GDPR set the DPC’s “monitor and enforce” mandate. Those provisions are not complaint-type dependent, and Article 58(2) does not distinguish between complaint-led and own-volition origins.
  • Purposive: The GDPR is an enforcement-forward instrument. Limiting corrective measures in complaint-based inquiries to the complainant alone would, on the Court’s reasoning, undermine effective enforcement.

(b) The decisive role of Articles 58 and 83 GDPR

The Court treated Article 58(2) corrective powers and Article 83 administrative fines as central to the answer. In particular:

  • Article 58(2)(d) empowers orders to “bring processing operations into compliance” (conceptually capable of system-wide scope).
  • Article 58(2)(i) empowers fines “depending on the circumstances of each individual case”.
  • Article 83(2)(a) requires the authority, when deciding whether and how much to fine, to consider “the number of data subjects affected” and “the nature, scope or purpose of the processing”.

Those mandatory criteria would be largely defeated if, merely because a case began as a single complaint, the DPC were barred from considering evidence that the same practice affected many users. The Court thus read “individual case” in Article 83 as the case under consideration, not as “the individual complainant only”.

(c) The 2018 Act: procedural origin differs; corrective powers do not

The Court placed weight on the symmetry of the Data Protection Act 2018: s.111 (own-volition inquiry) and s.113 (cross-border complaint) both require the DPC, after an infringement decision, to decide whether to exercise corrective powers; and s.115 applies identically across those routes. This statutory design contradicted the proposed dichotomy that systemic measures are only lawful in own-volition inquiries.

(d) No procedural “ambush” on systemic impact

Meta Ireland’s fair procedures case was treated as parasitic on its vires theory. Once the Court concluded that the DPC could lawfully consider systemic effects, the remaining question was whether Meta Ireland had been on notice that such consequences could flow.

The Court pointed to multiple indicators of notice:

  • The initial Notice of Commencement expressly referenced Article 58(2) powers including fines.
  • Meta Ireland’s own inquiry responses defended general, at-scale refusal to provide raw Hive data, and framed compliance burdens in terms of “each and every” user request—supporting the inference that the contested practice was general, not bespoke to the complainant.
  • Later correspondence highlighted “undertaking” and the fining cap logic (Article 83 and recital 150), signalling that fines were being evaluated in a manner characteristic of high-scale enforcement.

(e) Legitimate expectation: no clear lawful assurance of complainant-only remedies

The legitimate expectations claim failed for familiar reasons: the Court found no “precise, unconditional and consistent” assurance that systemic corrective measures or fines would not be contemplated in a complaint-based inquiry. Moreover, any expectation that the DPC would decline to consider Article 83 factors because the case started with one complaint would conflict with the statutory scheme, and cannot be legitimised by guidance documents or past administrative practice.

3.3 Impact

  • Enforcement leverage from individual complaints: The judgment confirms that a single data subject complaint can be the procedural entry point for remedies that reshape a controller’s general practices, where the infringement reflects a general policy or practice.
  • Reduced incentive for parallel own-volition inquiries: The DPC is not required to open a separate own-volition inquiry merely to justify systemic corrective measures, provided the systemic issue is within the subject matter of the complaint as investigated “to the extent appropriate”.
  • Fining analysis must reflect scale: Because Article 83 compels consideration of affected data subjects and scope of processing, controllers should expect that even complainant-framed findings can translate into high-range fining exposure where the underlying practice applies at scale.
  • Judicial review timing: Building on Facebook Ireland Ltd v. Data Protection Commission [2021] IEHC 336, the case reinforces that draft-stage DPC steps can be justiciable where the point is fundamental and likely to shape the remainder of the statutory process—though the Court emphasised that mid-process intervention remains exceptional.

4) Complex Concepts Simplified

Complaint-based inquiry vs “own-volition” inquiry
A complaint-based inquiry starts because a data subject alleges infringement of their own GDPR rights. An “own-volition” inquiry starts because the DPC initiates it without needing an individual complainant. This judgment holds that, once an infringement is found, the same toolbox of corrective powers applies in either route.
“Systemic” corrective measures
Measures that go beyond putting one complainant back in their proper position and instead require changes to a controller’s general processing operations (e.g., changing default access practices for all users). Article 58(2)(d) explicitly enables orders to bring “processing operations” into compliance.
Article 83 “number of data subjects affected”
When deciding whether to fine and how much, the DPC must consider how many people are affected by the infringement. This is an enforcement criterion, not a compensation criterion: it exists to ensure fines are “effective, proportionate and dissuasive”.
“Undertaking” and turnover cap
GDPR fines are capped by reference to an “undertaking” (competition-law concept), potentially capturing a corporate group’s turnover. This increases the fining ceiling and supports deterrence for large corporate groups.
Article 60 / Article 65 GDPR
Article 60 is the cooperation process where the Lead Supervisory Authority circulates a draft decision to other Concerned Supervisory Authorities. If there is a “relevant and reasoned objection” that cannot be resolved, Article 65 allows the European Data Protection Board to adopt a binding decision.

5) Conclusion

[2026] IEHC 323 clarifies a high-stakes point of GDPR enforcement architecture in Ireland: a complaint-based inquiry is not confined to complainant-only outcomes. Where the infringement found reflects a general practice, the DPC may lawfully pursue system-wide corrective orders and calculate fines by reference to the broader impact, as required by Articles 58 and 83 GDPR and mirrored by the 2018 Act.

The decision also narrows the practical force of “conversion” arguments: addressing systemic implications at the corrective-measures stage is not a jurisdictional leap into own-volition territory, but an orthodox application of the GDPR’s mandatory enforcement logic.