Ireland Ireland DPC GDPR enforcement Big Tech HQ

The EDPB Wants a Legal Bypass Around Regulatory Silos — Ireland's DPC Shows Why That's Overdue

Meeting in Dublin, EU privacy regulators asked Brussels for a law letting them share confidential data with competition and consumer agencies as AI complaints pile up.

Ireland's GDPR Enforcement Bottleneck People of Internet Research · Ireland €4B+ Cumulative DPC fines since 2018 Highest total of any EU data prote… <€20M Of those fines actually collected Most of the total remains tied up … 13 of 15 Major DPC decisions under appeal Companies challenge nearly every l… 16-17 Jul EDPB Dublin meeting dates High-level event hosted by Ireland… peopleofinternet.com
Ireland's GDPR Enforcement Bottleneck People of Internet Research · Ireland €4B+ Cumulative DPC fines since 2018 <€20M Of those fines actually collect… 13 of 15 Major DPC decisions under … 16-17 Jul EDPB Dublin meeting dates peopleofinternet.com

Key Takeaways

A quiet request with large implications

On 17 July 2026, the European Data Protection Board wrapped a high-level meeting in Dublin — hosted by Ireland's Data Protection Commission (DPC) and timed to Ireland's stint chairing the EU Council — with a request to the European Commission that sounds procedural but is not: give data protection authorities (DPAs) a legal basis to share information, including confidential case material, with competition and consumer protection regulators investigating the same conduct.

Right now, EU law mostly doesn't let them. A national DPA that uncovers evidence of anti-competitive data practices while investigating a GDPR complaint generally cannot hand that evidence to a competition authority; a consumer protection regulator building a case on dark patterns cannot draw on a DPA's file. EDPB Chair Anu Talus said the board's own experience cooperating with other EU digital regulators — inevitable now that the GDPR, the Digital Markets Act, the Digital Services Act and national consumer law all touch the same platform conduct — "has highlighted the need for stronger legislation to facilitate more effective cross-regulatory cooperation."

The caseload problem is real

The steelman case for this fix is straightforward. Behavioural advertising, dark-pattern consent flows and now AI training and deployment sit simultaneously inside data protection, competition and consumer-protection jurisdiction. Forcing three regulators to reconstruct the same facts from scratch, under three different confidentiality regimes, is a waste of scarce enforcement capacity — and DPAs say that capacity is genuinely scarce. The EDPB's own framing points to a "considerable rise in the number and complexity of complaints" driven by wider AI deployment, and secondary reporting on the Dublin meeting describes authorities that are visibly struggling to convert caseload into outcomes: Portugal's DPA reportedly opened 3,201 cases in 2025 but closed the year with just two fines totalling €47,000, a gap reported by ppc.land that illustrates throughput strain more than any single Irish case does. A genuine one-stop-shop information gateway — narrowly scoped, with confidentiality protections carried across the handoff — could let one investigation feed three enforcement tracks instead of triplicating the fact-finding. That is a legitimate efficiency argument, and this publication has generally favoured proportionate consolidation of overlapping digital-regulation mandates over each authority building its own silo.

Why Dublin is the wrong messenger, structurally

But the venue undercuts the pitch. Ireland's DPC is the lead supervisory authority for Meta, Google, TikTok, LinkedIn and X specifically because those companies' EU headquarters sit in Dublin — a jurisdictional accident of GDPR's one-stop-shop mechanism, not a competence Ireland sought out. The DPC has since become the bottleneck the mechanism was supposed to prevent. Ireland has issued more than €4 billion in GDPR fines since 2018 — the largest cumulative total of any EU DPA — but less than €20 million of that has actually been collected, because 13 of the DPC's last 15 major decisions have been appealed through Irish and EU courts, some for years. Meta's €1.2 billion transfer-violation fine from May 2023 is still working through appeals. TikTok challenged its €530 million transfer fine as "penal." A regulator that cannot close out the enforcement actions it already has is now, through Ireland's rotating EU Council Presidency, chairing the conversation about giving DPAs more cross-agency reach.

That is not a reason to reject the underlying proposal, but it is a reason to be precise about scope. Tech Policy Press has documented the structural tension in Ireland regulating the companies its economy depends on for corporate tax revenue and jobs — more than fifty academics wrote to the government this year urging it to recuse itself from chairing digital and tax files during the Presidency, citing exactly this conflict. A cross-regulatory information gateway routed through an already-overloaded, appeal-bound lead authority risks amplifying the bottleneck rather than relieving it: more agencies waiting on the same slow Irish case file, not fewer redundant investigations.

What the Commission should actually build

The fix is not to deny DPAs the tool. It is to attach hard guardrails when Brussels drafts it. Any legal basis for cross-regulatory sharing should (1) cap the shared material to what is strictly necessary for the receiving regulator's own statutory test, not full case files; (2) preserve the appeal and due-process rights a company has in the originating proceeding, so information moving to a competition regulator doesn't let a still-contested DPA finding function as settled fact; and (3) come paired with the case-management funding DPAs actually need — Ireland's DPC has grown its budget and headcount substantially since 2018 and still cannot close cases faster than they arrive. Information-sharing without capacity-building just moves the queue sideways.

The EDPB is right that the current silos are an artifact of an EU regulatory architecture built pre-DMA, pre-DSA and pre-generative-AI, when data protection, competition and consumer law rarely touched the same conduct. Fixing that is worth doing. But the Commission should design the mechanism around the caseload problem the EDPB actually named — AI-driven complaint growth outstripping authority capacity — not treat it as a lever to route more work through the one authority whose backlog is already Exhibit A for why EU digital enforcement moves too slowly.

Sources & Citations

  1. EDPB: Calls for legal basis for cross-regulatory information sharing
  2. EDPB High-Level Event 2026 (Dublin, 16-17 July)
  3. Irish Times: How Ireland's regulators are taking action against Big Tech
  4. Tech Policy Press: Ireland's Big Tech dependence in spotlight
  5. ppc.land: EDPB presses EU for data-sharing law as AI complaints strain regulators
  6. RTE: European data protection commissioners meeting in Dublin