GDPR Cannot Be Weaponised to Derail Conveyancing: Solicitors’ Routine Processing is Lawful Under Article 6 and Collateral Attacks Are Strike-Out Abuses

1. Introduction

Burns v John J. Quinn and Co. LLP. and Ors ([2026] IEHC 77) is a High Court strike-out decision (Nolan J., 13 February 2026) arising from the aftermath of a mortgage enforcement sale. The plaintiff, Mr Gerry Burns, alleged that his mortgage had been unlawfully transferred (PTSB to Start Mortgages DAC, and later to Mars Capital Finance Ireland DAC), contending that the transfer lacked his consent and therefore breached the GDPR. He then treated that alleged GDPR “taint” as infecting subsequent steps, including a receivers’ sale and the conveyancing work done by the purchasers’ solicitors.

The first and second defendants (a firm of solicitors and a solicitor within it) acted for third-party purchasers who acquired the property through an online auction process and proceeded with the normal conveyancing steps (contract, funds transfer, stamp duty, and first registration with Tailte Éireann). The third defendant was a tenant of the purchasers.

The core issue was whether the plaintiff’s pleadings disclosed any reasonable cause of action in GDPR against the purchasers’ solicitors (and associated parties), or whether the proceedings were bound to fail and/or an abuse of process—in substance a collateral attempt to obstruct or unwind the sale.

2. Summary of the Judgment

  • The Court dismissed the proceedings under Order 19 Rule 28(1) (and/or inherent jurisdiction), holding the claim disclosed no sustainable cause of action and was bound to fail.
  • The Court held that the solicitors’ processing of personal data (name of prior owners, address/description of the property, and title-related information) was plainly lawful under multiple bases in Article 6(1) GDPR—particularly Art. 6(1)(b), (c), (e), and (f).
  • The Court found the proceedings had an alternative/improper purpose: they were, in reality, a means to interfere with or frustrate the completed sale, not a genuine GDPR enforcement claim. On that ground alone, the case was dismissed as an abuse of process.
  • The Court criticised the plaintiff’s unsupported allegations of criminality (money laundering), referencing repeated judicial warnings against such pleading.
  • On costs, the Court indicated the default position under s.169 Legal Services Regulation Act 2015 would apply (costs follow the event), with a short window to seek a costs hearing.

3. Analysis

3.1 Precedents Cited (and How They Shaped the Outcome)

(A) Strike-out threshold and method

The Court grounded its approach to Order 19 Rule 28(1) in established Irish authority:

  • Aer Rianta v Ryanair [2004] IESC 23, [2004] 1 IR 506: cited for the principle that strike-out is a sparingly exercised jurisdiction, reserved for clear cases, aimed at preventing abuse of process, not merely relieving defendants of the burden of litigation. Nolan J. adopted this as the governing framework but found the case met the high threshold because the pleaded GDPR theory could not succeed as a matter of law on the undisputed facts.
  • Scotchstone Capital Fund Limited v. Ireland [2022] IECA 23 and Lopes v. Minister for Justice and Equality [2014] 2 IR 301: used to restate that, to resist strike-out, a plaintiff needs a statable case (not proof of a prima facie case). Even applying that plaintiff-friendly standard, the Court concluded the claim was fundamentally incapable of success and could not be rescued by amendment or discovery.

Importantly, Nolan J. added two practical propositions consistent with these authorities: (i) where there is no meaningful factual dispute, the Court can decide the legal futility question decisively; and (ii) minor tangential disputes cannot be used to immunise an otherwise doomed claim from strike-out.

(B) Abuse of process: proceedings brought for an alternative/improper purpose

  • Sean Quinn Group Ltd v an Bord Pleanála [2001] 1 IR 505: central to the “improper purpose” finding. Nolan J. applied Quirke J.’s reasoning that proceedings instituted not to vindicate rights but to achieve a collateral commercial (or strategic) objective are an improper use of the courts’ process. Here, the Court treated the GDPR framing as a vehicle to interfere with the conveyancing end-state (possession and title transition), reinforced by the joinder of the tenant (a person not meaningfully connected to “controller” conduct) and by the plaintiff’s admission that he paused other proceedings that more directly targeted the mortgagee/receivers’ authority.

(C) Pleading unfounded allegations of criminality

The Court relied on a cluster of High Court decisions condemning unsupported allegations of criminal conduct:

  • O'Hara v Ireland & Ors [2023] IEHC 268 (O’Moore J.): cited both for criticism of “peddled” claim types imposed on unrepresented litigants and for the broader concern that such litigation generates pointless costs. Nolan J. echoed this concern, suggesting the plaintiff had received “bad advice” and warning against unlawful “McKenzie friend” functions.
  • Carthy v Ireland & Ors [2024] IEHC 490, Ulster Bank DAC v McDonagh (No. 3) [2024] IEHC 609, and Mullins v Ireland [2022] IEHC 296: cited as examples of repeated judicial disapproval of baseless criminality allegations. This supported the Court’s firm rejection of “money laundering” insinuations against solicitors doing routine conveyancing work.

(D) GDPR lawful basis and “legitimate interests” analysis

  • Case C-252/21, Meta Platforms v Bundeskartellamt ("Meta Platforms"): relied on for the “legitimate interests” three-stage test (purpose, necessity, balancing). Although the judgment ultimately found multiple lawful bases (not only legitimate interests), “Meta Platforms” underpinned the Court’s approach that the balancing exercise is for courts to assess objectively—rather than for a data subject to veto ordinary legal/commercial processing by assertion.

3.2 Legal Reasoning

(A) The claim failed on the pleaded GDPR theory

The plaintiff’s core proposition was that a disputed (and allegedly unlawful) earlier mortgage transfer meant that any later use of his name/address/property description by later actors was necessarily unlawful “processing.” Nolan J. treated this as legally unstable because it conflated (i) a contested dispute about mortgage title/authority (being litigated elsewhere) with (ii) the separate GDPR question whether the purchasers’ solicitors had a lawful basis to process ordinary conveyancing data.

(B) Multiple independent lawful bases under Article 6(1)

The Court held the solicitors’ processing “falls squarely” within several Article 6 bases:

  • Art. 6(1)(b): processing necessary for performance of a contract to which the data subject is party—here, the contract for sale in the plaintiff’s and his wife’s names (completed through receivers).
  • Art. 6(1)(c): processing necessary for compliance with a legal obligation—here, the solicitors’ duties arising from retainer and the conveyancing framework.
  • Art. 6(1)(e): processing necessary for performance of a task in the public interest—here, steps relating to registration of title.
  • Art. 6(1)(f): processing necessary for legitimate interests—here, the legitimate interest of solicitors and their purchaser clients in completing a lawful conveyance and registration.

This multi-basis analysis is important: even if one basis were disputed, others could sustain the processing. The judgment thus resists the notion that “consent” is the default gateway for conveyancing-related processing.

(C) Conveyancing duties necessarily entail processing prior owner data

Nolan J. anchored the necessity analysis in the practical and legal content of conveyancing: solicitors must investigate title, deal with requisitions, draft and perfect instruments, transfer funds, address stamp duty, and complete registration steps. The judgment emphasised the statutory environment: s.58 Solicitors Act 1954, s.50 Legal Regulation Services Act 2015, s.25 Registration of Title Act 1964, and s.62 Land and Conveyancing Reform Act 2009. Against that background, the use of the plaintiff’s name and property details was described as “clearly incidental and necessary.”

(D) Abuse of process: GDPR pleaded as a collateral attack on the sale

The Court drew an inference from the structure and targets of the litigation: joining the tenant (who was not a meaningful data controller) and pursuing broad injunctive/disclosure relief indicated the aim was to disrupt occupation/title finality rather than vindicate a specific GDPR breach. The plaintiff’s admission that he paused other, more direct proceedings reinforced the conclusion that this case was strategically chosen as a procedural lever.

(E) Limits on “audit-style” litigation and role of evidence

While recognising Article 79 GDPR (right to an effective judicial remedy), the Court emphasised that such actions must be grounded in evidence of infringement and are not a licence to demand inspection of a controller’s files to see if a breach might be found. This reasoning aligned with the strike-out conclusion that discovery/inspection would not cure the fundamental legal defect.

(F) McKenzie friend and unlawful legal services warning

Nolan J. recorded that pleadings were not drafted by the plaintiff, that he relied on a “GDPR expert,” and that a McKenzie friend effectively dictated submissions. The Court reiterated that McKenzie friends cannot provide legal services such as drafting legal documents or acting as legal advisers, referring to criminal sanctions under the Solicitors Act 1954 (as amended) and the Legal Services Regulation Act 2015 (as amended). Though not determinative of the strike-out, this forms a notable judicial warning in the GDPR-and-property-litigation context.

3.3 Impact

(A) GDPR in property transactions: consent is not a universal prerequisite

The judgment underscores that conveyancing and registration inherently require processing of personal data and that such processing will commonly be lawful under Article 6(1)(b), (c), (e), and/or (f). This is likely to be relied upon to resist claims that attempt to characterise routine title/transaction steps as GDPR violations merely because an underlying mortgage dispute exists.

(B) Litigation strategy: GDPR claims used to stall sales are vulnerable to strike-out

By expressly characterising the proceedings as a collateral attack and an abuse of process, the Court provides defendants (particularly solicitors and transactional actors) with a template for early dispositive motions where the pleadings reveal an “alternative purpose” disconnected from a properly evidenced data protection complaint.

(C) Pleading discipline: criminality allegations will attract judicial censure

The decision continues a line of authority discouraging litigants from making reputationally damaging allegations (e.g., money laundering) without a pleaded factual foundation. That may influence how future GDPR/property claims are pleaded and case-managed, particularly where litigants in person rely on “sovereign citizen”-style or pseudo-legal templates.

(D) Professional practice reassurance

The Court’s articulation of the solicitor’s role (retainer duties, statutory context, and professional negligence risk if not pursued) provides reassurance that ordinary conveyancing steps are not merely permissible but required, and that GDPR arguments should not be allowed to paralyse land transfer systems and “commercial life.”

4. Complex Concepts Simplified

Order 19 Rule 28(1) (strike-out)
A procedure allowing the court to dismiss a claim at an early stage where it discloses no reasonable cause of action or is otherwise doomed. It is used sparingly and only where the case is plainly unsustainable.
Inherent jurisdiction
The court’s residual power to control its own process, including stopping proceedings that are abusive even if they do not fit neatly within a specific rule.
Article 5 GDPR
The “principles” of processing (lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, security).
Article 6 GDPR (lawful basis)
Processing is lawful only if it fits at least one basis (e.g., contract necessity, legal obligation, public task, legitimate interests). The judgment stresses that consent is only one possible basis—not the default for every situation.
Legitimate interests (Meta three-stage test)
A controller must identify a legitimate purpose, show the processing is necessary for it, and balance that interest against the data subject’s rights. The court—not the data subject by assertion—decides whether the test is met on the facts.
Abuse of process / collateral attack
Using a lawsuit for an ulterior aim (e.g., to derail a sale) rather than to vindicate the right supposedly relied on. Courts can dismiss such proceedings to protect the integrity of the legal process.
McKenzie friend
A lay assistant who may provide quiet support in court to a self-represented litigant, but cannot act as a lawyer, draft pleadings, or provide paid legal advice/services.

5. Conclusion

Burns v John J. Quinn and Co. LLP. and Ors [2026] IEHC 77 stands as a clear statement that the GDPR cannot be repurposed as a tactical weapon to obstruct completed conveyancing and registration steps. Where solicitors process limited, ordinary personal data as part of a property transaction, multiple lawful bases under Article 6(1) will typically apply, and courts will not permit “audit-style” claims untethered to evidence.

The judgment also reinforces two system-protective principles: (i) claims brought for an alternative or improper purpose are liable to be struck out as an abuse of process (drawing on Sean Quinn Group Ltd v an Bord Pleanála [2001] 1 IR 505), and (ii) unsupported allegations of criminality against professional defendants will be met with strong judicial disapproval.