Section 60(3)(a)(iv) DPA 2018 upheld as an Article 23 GDPR-compliant litigation restriction, and confidentiality recognised under Article 15(4)
Case: O'Brien v The Data Protection Commission and Ors (Approved) [2026] IEHC 250 (High Court, Lankford J, 20 February 2026)
Statutory route: Appeal under s.150 Data Protection Act 2018 (decision under s.109(5)(b))
Parties (by role): the appellant (data subject), the Data Protection Commission (respondent), Red Flag Consulting Limited (notice party/controller), the Attorney General (notice party)
Key takeaways
- Article 23(2) GDPR “where relevant” is meaningful: a national restriction does not need to reproduce an exhaustive “checklist” of Article 23(2)(a)-(h) elements if, properly construed, the legislative measure contains the relevant safeguards for the specific derogation.
- Section 60(3)(a)(iv) DPA 2018 is compatible with Article 23 GDPR: its built-in necessity and proportionality threshold, defined scope, and litigation-related purpose were held sufficient in this context.
- Section 60 and Section 162 are distinct: s.162 covers legal professional privilege; s.60(3)(a)(iv) is broader and can protect litigation interests (including confidentiality interests) even where privilege may not apply.
- Confidentiality can qualify the “copy” right: a third party’s confidentiality interests can fall within “the rights and freedoms of others” under Article 15(4) GDPR.
- DSARs are not barred by litigation, but context matters: the request remains a data protection exercise (cf. Dublin Bus v Data Protection Commissioner [2012] IEHC 339), yet litigation context is central to applying Article 23 / s.60 restrictions.
1. Introduction
The appellant made a data subject access request (DSAR) seeking (i) all personal data relating to him and (ii) information about recipients or categories of recipients under Article 15(1)(c) GDPR.
The DSAR arose against a background of long-running civil proceedings concerning a “dossier” prepared by the controller, Red Flag Consulting Limited, for an unidentified client.
Red Flag provided limited material and withheld the remainder on three bases:
(a) the litigation-claim restriction in s.60(3)(a)(iv) Data Protection Act 2018;
(b) legal professional privilege under s.162; and
(c) protection of third-party rights under Article 15(4) GDPR (copy right not to adversely affect rights and freedoms of others).
The DPC rejected the complaint. The appellant appealed under s.150 DPA 2018, crystallising three issues:
(1) whether s.60(3)(a)(iv) is compatible with Article 23 GDPR (and if doubt arose, whether a CJEU reference was required);
(2) whether the DPC should have engaged the s.151 procedure to test asserted privilege; and
(3) whether Article 15(4) could justify withholding personal data that might identify Red Flag’s client on confidentiality grounds.
2. Summary of the judgment
The High Court dismissed the appeal and upheld the DPC’s decision:
- Compatibility: s.60(3)(a)(iv) was held compatible with Article 23 GDPR, interpreted in line with EU-law-consistent principles and the text “at least where relevant” in Article 23(2).
- Privilege: the DPC acted reasonably in not invoking s.151; the point was not ultimately pursued at hearing and, on the facts, the DPC lacked the statutory triggers (“reasonable grounds”) for s.151 engagement.
- Article 15(4): confidentiality/privacy interests of the controller’s client could fall within “rights and freedoms of others”; no error of law was shown in the DPC’s balancing conclusion.
- Costs: the appellant was ordered to pay the costs of the DPC and Red Flag; the Attorney General (joined due to the constitutional/EU-law compatibility issue) was to bear his own costs.
3. Analysis
3.1 The appellate standard: deference on mixed fact/law, not on pure law
Lankford J framed the s.150 appeal using the established Irish “statutory appeal” approach:
-
Orange Limited v Director of Telecommunications (No.2) [2000] 4 IR 159:
the High Court does not conduct a full rehearing on the merits; the appellant must show a serious and significant error (or series of errors) vitiating the decision, with regard to the decision-maker’s expertise.
-
Nowak v Data Protection Commissioner [2016] 2 IR 585:
confirms the Orange test applies in data protection statutory appeals.
-
Miller v Financial Services Ombudsman [2015] IECA 126:
no deference on questions of law.
-
EMI Records (Ireland) Ltd and Ors v Data Protection Commissioner [2012] IEHC 264:
“curial deference” does not excuse jurisdictional error or fair-procedures failures.
This framing mattered: the appellant’s central challenge (compatibility of s.60 with Article 23) was treated as a legal question, while the application of necessity/proportionality and Article 15(4) balancing operated as mixed fact-and-law assessments to which the Court would be slow to intervene absent significant error.
3.2 Section 60(3)(a)(iv) and Article 23 GDPR: how the Court found compatibility
(a) EU-conforming interpretation and interpretive method
The Court emphasised EU-conforming interpretation (indirect effect) and ordinary statutory interpretation tools:
-
Marleasing SA v La Commercial Internacional de Alimentacion SA Case C-106/89 (as discussed via DPP v Quirke [2023] IESC 5):
national courts must interpret domestic law, so far as possible, in light of EU law’s wording and purpose (but not contra legem).
-
A, B & C v Minister for Foreign Affairs and Trade [2023] IESC 10:
“language, context and purpose” are all in play.
-
Friends of the Irish Environment Clg v The Minister for Agriculture Food and the Marine, Ireland and the Attorney General [2022] IEHC 64:
identifies textual, schematic, and teleological approaches common in EU interpretation.
Against that backdrop, s.60 benefited from presumptions of constitutionality and EU-law compatibility, reinforcing a “save if possible” interpretive stance.
(b) The “not absolute” nature of access rights and the proportionality baseline
The Court located Article 15 within the GDPR’s broader balancing structure and reiterated that data protection rights are not absolute:
-
Volker und Markus Schecke GbR and Hartmut Eifert v Land Hessen Joined Cases C-92/09 and C-93/09:
data protection must be considered relative to its function in society.
-
UI v Österreichische Post AG Case C-154/21 and
Facebook Ireland and Schrems Case C-311/18:
Recital 4 proportionality balancing; access rights can be qualified.
This was doctrinally important: it framed Article 23 not as an exceptional “hostile” carve-out, but as an express GDPR mechanism for reconciling competing interests, provided the essence of rights is respected and the measure is necessary and proportionate.
(c) Article 23(2) “at least where relevant”: the Court’s central move
The appellant argued s.60(3)(a)(iv) failed Article 23(2) because it did not set out the detailed “specific provisions” (purposes, categories of data, safeguards, storage periods, risks, etc.).
The Court’s answer turned on the qualifier “at least where relevant”.
Holding in substance: Article 23(2) requires Member States to include relevant specific provisions for the particular restriction, not to populate every item (a)-(h) regardless of fit; the phrase “where relevant” limits the obligation.
On the Court’s reading, s.60(3)(a)(iv) satisfied the “relevant” requirements in three key ways:
-
Necessity and proportionality are explicit (“necessary and proportionate”), matching Article 23(1)’s threshold and requiring case-by-case balancing.
-
The scope of rights restricted is specified (Articles 12–22, 34, and parts of Article 5).
-
The purpose/category of processing is defined (processing “in contemplation of or for the establishment, exercise or defence of” legal claims/proceedings, broadly framed).
The Court also stressed practical-legislative feasibility: the s.60(3)(a)(iv) category spans an “extraordinarily varied” range of controllers and contexts, making it difficult to legislate ex ante for all Article 23(2) checklist items at an abstract level, unlike sectoral restrictions implemented via regulations for specific public bodies (which can include detailed safeguards).
(d) Treatment of the UK authority: Open Rights distinguished, not followed
The appellant relied heavily on:
R v (The Open Rights Group and Another) v The Secretary of State for the Home Department and Another [2021] EWCA Civ 800,
the leading common-law authority on Article 23(2).
Lankford J treated Open Rights as persuasive but distinguishable:
-
The UK “Immigration Exemption” was extremely broad, effectively applying to “maintenance of effective immigration control” with a prejudice test and lacking “specific provisions” aligned with Article 23(2).
-
By contrast, s.60(3)(a)(iv) contains a necessity/proportionality threshold, delimits the affected rights, and defines the relevant litigation-related purpose.
-
Open Rights itself recognised legislatures may conclude some Article 23(2) matters are “not relevant” to a particular exemption; the defect in the UK case was the State’s stance that no tailored legislative process was required.
In short: Open Rights supported the seriousness of Article 23(2), but did not compel invalidation of a litigation-claims restriction that is narrower in structure and contains internal proportionality controls.
(e) Limited CJEU guidance and proportionality strictness
The Court noted the absence of detailed CJEU authority on the meaning of “where relevant”.
It referred to:
La Quadrature du Net and Others v Premier Ministre and Ministère de la Culture Case C-470-21,
where the CJEU reiterated that Article 23 restrictions must comply with Article 23(2) and meet strict proportionality (“only in so far as is strictly necessary”).
However, that case did not resolve the interpretive question posed here.
(f) Outcome on Ground 1
Applying these principles, the Court found no serious legal error in the DPC’s conclusion that Red Flag could rely on s.60(3)(a)(iv) to withhold information (in substance, relating to client identity/recipients) in the litigation context.
The Court also treated it as “unrealistic” to view the DSAR in isolation from the surrounding proceedings when assessing necessity and proportionality.
3.3 Section 162 privilege and Section 151 procedure: why the DPC was not required to escalate
The appellant criticised the DPC for not invoking s.151 (High Court assistance to test privilege).
The High Court accepted the DPC’s position:
-
s.151 is triggered only if the DPC has reasonable grounds to believe the material is not privileged, or suspicion that it contains evidence of infringement where extraction is impractical.
-
On the facts, the appellant had indicated he was not seeking privileged material; the DPC confirmed Red Flag asserted privilege; and no concrete dispute requiring s.151 adjudication was identified.
The Court also recorded that the point was not ultimately pursued in oral argument, further undermining any basis for appellate interference.
3.4 Article 15(4) GDPR: confidentiality as a “right or freedom of others”
The third challenge targeted the DPC’s reliance on Article 15(4) to refuse a copy of personal data where that copy might reveal the identity of Red Flag’s client.
The Court upheld the DPC’s approach.
(a) The structural point: Article 15(4) is part of GDPR’s balancing design
Article 15(3) grants a right to a copy of personal data undergoing processing.
Article 15(4) expressly limits that right where it would “adversely affect the rights and freedoms of others”.
The Court accepted that this calls for a balancing assessment rather than a categorical rule.
(b) Confidentiality/privacy is capable of qualifying disclosure
The DPC treated the client’s confidentiality interest as falling within “rights and freedoms of others”, and referenced ECHR privacy rights (Articles 7 and 8 as characterised in the judgment).
It cited ECHR authority including:
Fernandez Martinez v Spain application no. 56030/07.
The High Court noted the appellant offered no authority for the proposition that confidentiality could never be an operative factor under Article 15(4), and found no legal error in the DPC’s position that confidentiality can, in principle, be protected within the “rights and freedoms of others”.
(c) No “blanket refusal” on the facts
The Court regarded the “blanket refusal” assertion as not made out: the withheld data related solely to information that would identify or tend to identify the client—an issue already litigated in earlier discovery disputes, where the courts had refused to compel disclosure of client identity-related material as irrelevant and potentially damaging.
3.5 Relationship with litigation and discovery: DSARs are separate, but restrictions can prevent procedural end-runs
The Court accepted the proposition (from Dublin Bus v Data Protection Commissioner [2012] IEHC 339) that data protection rights are not simply a proxy for discovery rules.
Nonetheless, it endorsed the DPC’s view that litigation context is part of the factual matrix relevant to applying statutory and GDPR restrictions—particularly the s.60(3)(a)(iv) “legal claim” restriction and Article 15(4)’s third-party rights limitation.
Practically, the decision signals that Irish law will not treat DSARs as an automatic route to compel disclosure of material (especially identity-related material) that courts have declined to order in civil procedure, where the controller can justify restriction by necessity/proportionality and third-party rights.
4. Impact
-
Clarifies Irish position on Article 23(2): the “where relevant” qualifier can limit the specificity demanded of national measures, especially in a broadly-scoped litigation-claims restriction, provided necessity/proportionality and definitional constraints are built in.
-
Strengthens s.60(3)(a)(iv) as an anti-circumvention tool: controllers defending/advancing civil proceedings have a clearer statutory basis to resist DSARs that would undermine the conduct of claims, subject to case-by-case proportionality.
-
Confidentiality explicitly within Article 15(4) balancing: third-party confidentiality (linked to privacy interests) can justify limiting the “copy” right, reinforcing the GDPR’s internal balancing logic.
-
Guidance for the DPC’s investigative choices: s.151 privilege referrals are not routine; they require statutory preconditions (reasonable grounds/suspicion) and a concrete dispute.
-
Litigation-sensitive compliance expectations: organisations in contentious contexts should document their necessity/proportionality assessment when invoking s.60(3)(a)(iv) and identify precisely what is withheld and why (to withstand DPC scrutiny and potential s.150 appeals).
5. Complex concepts simplified
5.1 “Statutory appeal” vs “judicial review”
A statutory appeal (here, s.150 DPA 2018) allows broader scrutiny than judicial review, but it is not a full rehearing. The court looks for serious/significant error in the decision-making process as a whole (Orange Limited v Director of Telecommunications (No.2) [2000] 4 IR 159), deferring on expert fact/mixed assessments but not on pure law (Miller v Financial Services Ombudsman [2015] IECA 126).
5.2 Article 23 GDPR “restrictions”
Article 23 permits Member States to restrict GDPR rights (including Article 15 access) by legislation, but only if the restriction preserves the “essence” of rights and is necessary and proportionate to protect listed interests (including enforcement of civil law claims). Article 23(2) then requires “specific provisions” in the legislative measure—“at least where relevant”.
5.3 Necessity and proportionality (in practice)
“Necessary” asks whether the restriction is genuinely required to protect the identified interest; “proportionate” asks whether it goes no further than needed, balancing the data subject’s access rights against competing rights (e.g., fair trial, privacy/confidentiality). The Court treated these as familiar, operational legal standards capable of case-by-case application.
5.4 Article 15(4) GDPR
Even where a data subject is entitled to a copy of personal data, the controller may limit what it provides if giving that copy would adversely affect others’ rights and freedoms. This is the GDPR’s built-in balancing mechanism for third-party impacts.
6. Conclusion
O'Brien v The Data Protection Commission and Ors (Approved) [2026] IEHC 250 is a significant Irish High Court endorsement of the litigation-claims restriction in s.60(3)(a)(iv) DPA 2018 as compatible with Article 23 GDPR, anchored in a text-driven reading of Article 23(2)’s qualifier “where relevant” and in the centrality of necessity and proportionality.
It also affirms that confidentiality interests can, in principle, fall within “the rights and freedoms of others” under Article 15(4), legitimising targeted limits on DSAR outputs where disclosure would intrude on third-party privacy/confidentiality.