Data Protection Commission (DPC) – Court Ruling (Ireland, 2026)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
An Irish court ruled on a case involving Meta, where a user requested access to their personal data. Meta denied the request for specific data formats, which led to a legal challenge. This case emphasizes users' rights to access their data and the obligations of companies to comply.
What happened
A user requested access to their personal data from Meta, but the company refused to provide it in the requested format.
Who was affected
Michael Veale, the user requesting his personal data from Meta, was affected.
What the authority found
The court examined whether Meta complied with the user's rights under data protection laws.
Why this matters
This ruling reinforces the importance of transparency and user rights in data access requests, urging companies to be more responsive to such inquiries.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
National Law Articles
On 25 May 2018, Michael Veale, the data subject, submitted an access and data portability request to Meta Platforms Ireland Limited (MPIL) (then Facebook Ireland Limited), the controller. He requested access to all personal data concerning him stored in the controller's internal "Hive" data warehouse under Article 15 GDPR, including the data in raw form and information on its processing. He also requested relevant personal data in a structured, commonly used and machine-readable format under Article 20 GDPR. On 19 July 2018, the controller refused to provide the raw Hive data. Among other grounds, it relied on Article 12(5) GDPR, Article 15(4) GDPR and Article 20(4) GDPR. The data subject subsequently lodged a complaint with the Data the DPA arguing that the controller had failed to comply with his rights under Articles 15 and 20 GDPR and had unjustifiably relied on restrictions to those rights. On 27 July 2018, the DPA opened a complaint-based inquiry under [https://www.legislation.gov.uk/ukpga/2018/12/contents Section 110(1) Data Protection Act 2018]. The inquiry examined the controller's compliance with its obligations concerning the data subject's request. During the investigation, the controller explained that its approach to Hive data was generally applicable to its users and argued, inter alia, that extracting user-specific log-level data from Hive was computationally unfeasible. In August 2023, the DPA issued its Final Inquiry Report. The investigator considered that the controller had failed to provide the data subject with information required under Article 15(1)(a), (d) and (g) GDPR. On 10 October 2025, the DPA issued a preliminary draft decision (PDD). It provisionally found that the controller had infringed Article 15(1) and (3) GDPR by refusing access to and a copy of relevant personal data; Article 15(1)(a), (d) and (g) GDPR by providing inadequate information; Article 20(1) GDPR by refusing to provide relevant portable data; and Article 12(3) and (4)
Outcome
Court Ruling
A ruling by a national court on a data-protection matter.
Related Cases (0)
No other cases found for Data Protection Commission (DPC) in IE
This is the only recorded case for this entity in this jurisdiction.
Details
About this data
Cite as: Cookie Fines. Data Protection Commission (DPC) - Ireland (2026). Retrieved from cookiefines.eu
Last updated: