The European Data Protection Board convened its high-level meeting in Dublin on 16-17 July 2026, hosted by Ireland's Data Protection Commission as part of Ireland's six-month EU Council Presidency. The headline outcome was procedural rather than punitive: the EDPB called on the European Commission to propose a legal basis allowing data protection, competition and consumer-protection regulators to exchange information — including confidential material — relevant to enforcement within their respective mandates. EDPB Chair Anu Talus framed it plainly: "First-hand experience of cooperating with other EU digital regulators at both national and EU level has highlighted the need for stronger legislation to facilitate more effective cross-regulatory cooperation, including enhanced information sharing."
That request deserves more attention than it is getting, because it is arriving at the same moment as a louder, more personal argument about whether Ireland should be running these conversations at all.
The Recusal Campaign
On 9 July 2026, roughly fifty academics — including Shoshana Zuboff, Mariana Mazzucato and Trinity College Dublin's Abeba Birhane — published an open letter arguing, as the Irish Times reported, that Ireland's "questionable track record" on data protection and corporate tax enforcement created conflicts of interest too large to chair EU negotiations on digital and fiscal files. They asked the government to recuse itself and hand those files to Lithuania, the next presidency in the rotation. Taoiseach Micheál Martin rejected the premise, calling Ireland an "honest broker" and pointing to the DPC's fine record as evidence of independence; Fine Gael MEP Regina Doherty called the criticism "outrageous."
The steelman for the academics' position is real. Ireland hosts the European headquarters of Meta, Google, TikTok, X and Apple, drawn in large part by a corporate tax regime that itself has been a subject of EU scrutiny. A national government chairing Council working groups on the same files that determine how aggressively those companies get regulated is, on its face, an unusual arrangement — one no other member state faces at comparable scale, because no other member state hosts this concentration of the firms being regulated. If citizens are meant to trust that EU digital lawmaking isn't quietly shaped by host-state economic interest, that's a fair question to ask out loud, and Ireland's government should welcome rather than resent the scrutiny.
But the empirical record cuts against the letter's central claim. The DPC's own enforcement numbers, not the government's talking points, are what settle this. Since GDPR took effect in May 2018, Irish fines total roughly €3.5 billion — more than four times the tally of Luxembourg, the second-largest enforcer, and the largest share of the €5.88 billion imposed EU-wide. Meta alone has absorbed the DPC's record €1.2 billion fine in May 2023 for unlawful EU-US data transfers, plus separate nine-figure penalties for breach-notification and data-storage failures. A regulator captured by its host industry does not produce Europe's largest enforcement docket against that same industry. As Tech Policy Press has argued, the more accurate target for critics of Europe's digital direction is the European Commission's own pivot toward competitiveness and simplification under Ursula von der Leyen — a Brussels-driven shift, not a Dublin one.
The Real Structural Problem
Where the academics and the EDPB converge, productively, is on process rather than motive. Talus's call in Dublin is an admission that GDPR enforcement, the Digital Markets Act, the Digital Services Act and consumer-protection law now regulate overlapping conduct by the same handful of companies through entirely separate legal silos, with no statutory mechanism for the regulators enforcing each to share what they know. That is a genuine gap: a competition finding on self-preferencing and a data-protection finding on consent design can describe the same underlying practice without either regulator seeing the other's file. Fixing that requires EU legislation, not a recusal from a six-month Council rotation.
That is also the case for proportion in how this story gets covered. A one-country-hosts-everyone enforcement model was always going to generate friction as the EU's digital rulebook multiplied from one statute (GDPR) to four (adding DMA, DSA and the AI Act). The fix for regulatory fragmentation is the cross-regulator information-sharing law the EDPB is now formally requesting — plumbing work that closes real enforcement gaps — not a symbolic recusal that would strip the one member state with the deepest institutional experience regulating these firms out of the room while the rules are being written. Brussels should treat Talus's request as the priority item it is, rather than let it be drowned out by a presidency-legitimacy fight that the numbers don't support.