Privacy chief admits GDPR fails systemic issues

A residential threshold in Dublin looms over the infrastructure of the digital age.
Image composition · tobriefWhen you file a privacy complaint about Facebook, Instagram, WhatsApp, or TikTok, it doesn't go to your national regulator. It goes to Dublin. The Irish Data Protection Commission handles nearly all major GDPR enforcement against global technology companies, and its former head just admitted the system isn't working for the problems that matter most. Helen Dixon told a Law Society event this month that the GDPR is "not always useful for systemic issues" (Law Society of Ireland).
That admission, from the person who led Irish enforcement through its most active years, captures a structural tension eight years in the making.
How one city became Europe's privacy capital
The GDPR created a mechanism called "one-stop-shop" under Article 56 (EUR-Lex). The idea was practical: instead of forcing a company to deal with 27 separate national regulators, the authority in the country where the company has its main EU office handles all cross-border cases. Apple, Google, Meta, TikTok, LinkedIn, and Microsoft all established their European headquarters in Ireland. The DPC became, in effect, Europe's privacy regulator for most of the technology industry (anonym.community).
The enforcement pipeline works through Article 60 cooperation. The DPC, as Lead Supervisory Authority, investigates a complaint and drafts a proposed decision. It shares that draft with every other national data protection authority affected by the case, known as Concerned Supervisory Authorities. If they object, and they frequently do, the dispute escalates to the European Data Protection Board for a binding resolution (EUR-Lex). Think of it like a court where Dublin writes the verdict but 26 other judges get veto power on the sentence.
This system was designed to prevent forum-shopping between lenient regulators. In practice, it created a different problem: one mid-sized agency became the enforcement bottleneck for an entire continent.
Big fines, slow collection
The DPC has issued roughly 80% of all major EU technology fines under the GDPR (anonym.community). The headline penalties: €1.2 billion against Meta for unlawful transfers of European user data to the United States, €530 million against TikTok for allowing Chinese engineers to access European data, and €310 million against LinkedIn for illegal behavioural profiling (anonym.legal).
Imposing fines and collecting them are different activities. Companies appeal nearly every major decision, and Irish courts can freeze payment while litigation proceeds. The gap between penalties announced and money actually received remains wide. Other national regulators face their own constraints: the Article 60 cooperation system means smaller authorities can raise objections but cannot act independently on cross-border cases involving these companies. They observe while Dublin decides.
A fix with a deadline
A new GDPR Procedural Regulation, entering force in April 2027, introduces a 15-month deadline for lead authorities to issue draft decisions in cross-border cases (Netguardia). Under the current system, investigations have stretched for years. Meta's €1.2 billion fine took five years from initial complaint to final decision. The reform also sets clearer timelines for when Concerned Supervisory Authorities must submit objections and when disputes must move to the EDPB (Netguardia).
The procedural fix addresses speed. It does not address the underlying asymmetry: one national agency, accountable to Irish courts and subject to Irish administrative law, carrying regulatory responsibility for technology companies serving 450 million Europeans. Dixon's acknowledgement that the framework struggles with systemic issues (Law Society of Ireland) points to something the 2027 reform leaves untouched. Faster decisions still flow through the same narrow channel. Whether Europe eventually rethinks the channel itself, rather than just the speed of traffic through it, is the longer question worth watching.
How was this article?
Help us get better
Help us get better
Details about this article
- Model:
- claude-opus-4-6
- Generated:
- 5/22/2026, 3:16:46 AM
- Pipeline run:
- eu_pipeline_20260522_015005
- Watermark:
- SynthID (Google's invisible watermark)
- Human review:
- None before publication