A record year for complaints, a record backlog for money
Ireland's Data Protection Commission (DPC) published its 2025 Annual Report on 30 June 2026, describing an "unprecedented" 45% jump in complaints — 16,160 new cases from individuals, up from roughly 11,150 the year before. The DPC closed 11,734 cases, a 12% improvement on 2024, and noted that October 2025 was its busiest month on record, partly because complainants are increasingly using AI tools to draft and file grievances. On paper, this looks like a regulator straining to keep up with genuine public demand for privacy enforcement.
The more consequential number sits elsewhere in the same reporting cycle. Since GDPR took effect in May 2018, the DPC has imposed €4.04 billion in administrative fines, overwhelmingly on multinational technology companies headquartered in Ireland for EU purposes. Of that sum, the DPC's own fines register confirms just €20 million — about half a percent — has actually been paid. In 2025 alone, the DPC issued roughly €530.77 million in fines, led by a €530 million penalty against TikTok for unlawfully transferring EEA user data to China, and collected only €125,000 of it.
Why the ledger doesn't move
This is not, primarily, a story about a toothless regulator. Irish and EU law require that a fine be confirmed by a court before it becomes collectable, and nearly every large GDPR penalty is appealed. The DPC has been explicit that it considers none of the €4.02 billion outstanding to be uncollectable — the money is contested, not written off. TikTok's €530 million fine is under appeal. Meta's earlier billion-euro-plus penalties are under appeal. And the case that best illustrates the mechanism is WhatsApp's.
In 2021 the DPC fined WhatsApp Ireland €225 million after the European Data Protection Board (EDPB) directed it to increase a smaller proposed penalty. WhatsApp challenged the EDPB's binding decision directly, and on 10 February 2026 the Court of Justice of the EU ruled (Case C-97/23 P) that the EDPB's intermediate decision was itself a challengeable act — overturning the General Court's finding that WhatsApp's suit was inadmissible, and sending the underlying merits back for a fresh ruling. Five years after the fine was issued, litigation over whether it was even properly reached has barely begun.
The steelman for slow money
There's a legitimate case for this architecture. GDPR fines can run into the hundreds of millions or billions of euros — sums large enough to materially affect a public company's balance sheet and shareholders who had no role in the underlying conduct. Requiring judicial confirmation before collection is a due-process safeguard against a regulator's initial finding being final and unreviewable. The EDPB's binding-decision mechanism exists precisely so that one national authority — Ireland, by dint of hosting nearly every major platform's EU headquarters — doesn't unilaterally set enforcement policy for 450 million Europeans without oversight. Multi-stage review is expensive in time, but it's not obviously wrong in principle.
Why it still doesn't work
The problem is that the system as practiced converts "appealable" into "effectively optional." A €4 billion headline fine total with a €20 million collection rate is not deterrence — it's a press release. Companies can treat GDPR penalties as a multi-year legal-fees line item rather than a cost of doing business, because the expected value of appealing is almost always positive: delay is free, and even a loss just resets the clock on the next appeal. Meanwhile the DPC's complaint volume — now approaching 20,000 projected cases a year — keeps rising precisely because individuals see that filing a complaint rarely produces a fast, enforceable outcome.
This is where the pro-innovation and pro-enforcement cases actually converge, rather than conflict. Predictable, proportionate, timely enforcement is better for platforms than the current ambiguity — a company facing a real prospect of paying within 18 months plans differently than one facing a fine it can litigate into 2031. Brussels and Dublin should be looking at procedural fixes — interim enforcement measures, expedited appellate tracks for finalized fines, or EU-level rules narrowing what's appealable at the EDPB stage post-WhatsApp — rather than either louder fines or louder complaints about non-collection. The DPC's 2025 numbers show a regulator that is, by volume, doing its job. Ireland's courts and the EU's appellate architecture are the actual chokepoint, and that's a legislative problem, not a DPC one.