Dixon says GDPR misses tech power

A residential threshold in Dublin looms over the infrastructure of the digital age.
Cumadóireacht íomhá · tobriefIf you complain about Facebook, Instagram, WhatsApp or TikTok, the case does not usually land with your own national regulator. It comes to Dublin. Ireland’s Data Protection Commission has become the main enforcement authority for much of Europe’s technology sector, and its former commissioner has now said aloud what critics have argued for years: the GDPR is "not always useful for systemic issues" (Law Society of Ireland).
Helen Dixon’s remark matters because she led the Irish regulator through its most active period. It points to a tension built into Europe’s privacy regime: Ireland has the legal responsibility for some of the world’s largest platforms, but the problems those platforms create are continental in scale.
How Dublin became Europe’s privacy capital
The GDPR created the "one-stop-shop" system under Article 56 (EUR-Lex). The logic was tidy enough. A company operating across the EU would deal mainly with the regulator in the member state where it had its main European establishment, rather than facing 27 separate investigations.
That made Ireland central. Apple, Google, Meta, TikTok, LinkedIn and Microsoft all put their European headquarters here. The DPC therefore became, in practice, the privacy regulator for most of the global technology industry in Europe (anonym.community).
The machinery sits inside Article 60. The Irish regulator, as Lead Supervisory Authority, investigates a complaint and drafts a proposed decision. That draft is then sent to other national data protection authorities affected by the case, known as Concerned Supervisory Authorities. If they object, and they often do, the dispute can be sent to the European Data Protection Board for a binding ruling (EUR-Lex).
In plain English, Dublin writes the first version of the verdict, but other European regulators can challenge the result. The system was meant to stop companies shopping around for the friendliest regulator. What emerged was a different weakness: one mid-sized Irish agency became the main gate through which Europe’s biggest privacy cases had to pass.
Big fines, slow collection
The DPC has issued roughly 80% of all major EU technology fines under the GDPR (anonym.community). The figures are large enough to travel: €1.2 billion against Meta over unlawful transfers of European user data to the United States, €530 million against TikTok over access to European data by Chinese engineers, and €310 million against LinkedIn for illegal behavioural profiling (anonym.legal).
But announcing a fine is not the same as collecting it. The major companies appeal almost every big decision, and the Irish courts can freeze payment while litigation runs its course. That leaves a wide gap between the penalties announced and the money actually received.
Other European regulators have their own frustration. Under Article 60, smaller national authorities can object to Dublin’s draft decisions, but they cannot simply take over cross-border cases involving these companies. They can push, challenge and escalate. They cannot bypass Ireland.
A fix with a deadline
The next reform is procedural. A new GDPR Procedural Regulation, due to enter force in April 2027, will give lead authorities a 15-month deadline to issue draft decisions in cross-border cases (Netguardia).
That is aimed at the long delays that have marked the system so far. Meta’s €1.2 billion fine took five years from the first complaint to the final decision. The reform also sets clearer timelines for when Concerned Supervisory Authorities must submit objections and when disputes must move to the European Data Protection Board (Netguardia).
The change may make the pipeline faster. It does not change the pipeline itself. One national regulator, answerable to Irish courts and working under Irish administrative law, will still carry much of the burden for technology companies serving 450 million Europeans.
That is why Dixon’s comment lands with some weight (Law Society of Ireland). The 2027 reform deals with delay, but not with scale. Faster decisions still have to pass through the same narrow channel in Dublin. The larger question is whether Europe eventually decides that systemic platform problems need a different structure, not just a quicker timetable.
How was this article?
Help us get better
Help us get better
Details about this article
- Model:
- claude-opus-4-6
- Generated:
- 5/22/2026, 3:16:46 AM
- Pipeline run:
- eu_pipeline_20260522_015005
- Watermark:
- SynthID (Google's invisible watermark)
- Human review:
- None before publication