University of Limerick – €98,000 Fine (Ireland, 2025)

€98,000Data Protection Commission10 December 2025Ireland
final
Fine

General GDPR enforcement action

This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.

The Irish Data Protection Commission fined the University of Limerick €98,000 for failing to protect staff email accounts from phishing attacks. The university did not notify the authorities quickly enough about data breaches. This case shows that educational institutions must take data security seriously.

What happened

The University of Limerick experienced unauthorized access to staff email accounts due to phishing.

Who was affected

Staff members whose email accounts were compromised and affected by the breaches.

What the authority found

The authority determined that the university did not have adequate security measures in place and failed to notify affected individuals and the DPA promptly.

Why this matters

This ruling serves as a reminder for all organizations, including universities, to prioritize data security and comply with notification requirements after breaches. Delays can lead to significant financial penalties.

GDPR Articles Cited

AI-verified

Art. 5(1)(f) GDPR
Art. 30(1) GDPR
Art. 32(1) GDPR
Art. 33(1) GDPR
Art. 34(1) GDPR
View original scraped data
Art. 5(1)(f) GDPR
Art. 30(1) GDPR
Art. 32(1) GDPR
Art. 33(1) GDPR
Art. 34(1) GDPR

Original data from scraper before AI verification against source document.

Source verified 10 March 2026
national law identified
verified correct
Full Legal Summary
Detailed

In 2020, the University of Limerick (the controller) notified the Irish DPA (DPC) of six personal data breaches that entailed unauthorised access to staff email accounts gained through ‘phishing’. Subsequently, the DPA launched an investigation into the controller. The DPA found infringements of the GDPR and issued a reprimand and a total fine of €98,000 to the controller. Firstly, the DPA found that the security and organisational measures in place at the time of the initial data breach did not meet the standards required by Article 5(1)(f) GDPR and Article 32(1) GDPR. Secondly, the DPA found that the controller infringed Article 30(1) GDPR by failing to maintain a record of processing activities that contained a description of its organisational and technical measures in place to protect the data it processed. Thirdly, the DPA found that the controller failed to notify two of the security incidents without undue delay, in violation of Article 33(1) GDPR. The DPA explained that an internal notification delay within the controller’s organisation did not excuse a delay in notifying the DPA. Fourthly, the DPA found that the controller breached Article 34(1) GDPR by failing to notify 24 data subjects affected by one of the data breaches and 76 data subjects affected by another data breach without undue delay.

Related Enforcement Actions (0)

No other enforcement actions found for University of Limerick in IE

This is the only recorded action for this entity in this jurisdiction.

Details

Fine Date

10 December 2025

Authority

Data Protection Commission

Fine Amount

€98,000

About this data

Data: GDPRhub (noyb.eu)
Licensed under CC BY-NC-SA 4.0
AI-verified and classified

Cite as: Cookie Fines. University of Limerick - Ireland (2025). Retrieved from cookiefines.eu

Report Inaccuracy

Last updated: