University of Limerick – €98,000 Fine (Ireland, 2025)
General GDPR enforcement action
This case relates to broader data protection obligations, not specifically to cookie or consent banner compliance. It is not included in cookie statistics or the Risk Calculator.
The Irish Data Protection Commission fined the University of Limerick €98,000 for failing to protect staff email accounts from phishing attacks. The university did not notify the authorities quickly enough about data breaches. This case shows that educational institutions must take data security seriously.
What happened
The University of Limerick experienced unauthorized access to staff email accounts due to phishing.
Who was affected
Staff members whose email accounts were compromised and affected by the breaches.
What the authority found
The authority determined that the university did not have adequate security measures in place and failed to notify affected individuals and the DPA promptly.
Why this matters
This ruling serves as a reminder for all organizations, including universities, to prioritize data security and comply with notification requirements after breaches. Delays can lead to significant financial penalties.
GDPR Articles Cited
View original scraped data
Original data from scraper before AI verification against source document.
In 2020, the University of Limerick (the controller) notified the Irish DPA (DPC) of six personal data breaches that entailed unauthorised access to staff email accounts gained through ‘phishing’. Subsequently, the DPA launched an investigation into the controller. The DPA found infringements of the GDPR and issued a reprimand and a total fine of €98,000 to the controller. Firstly, the DPA found that the security and organisational measures in place at the time of the initial data breach did not meet the standards required by Article 5(1)(f) GDPR and Article 32(1) GDPR. Secondly, the DPA found that the controller infringed Article 30(1) GDPR by failing to maintain a record of processing activities that contained a description of its organisational and technical measures in place to protect the data it processed. Thirdly, the DPA found that the controller failed to notify two of the security incidents without undue delay, in violation of Article 33(1) GDPR. The DPA explained that an internal notification delay within the controller’s organisation did not excuse a delay in notifying the DPA. Fourthly, the DPA found that the controller breached Article 34(1) GDPR by failing to notify 24 data subjects affected by one of the data breaches and 76 data subjects affected by another data breach without undue delay.
Related Enforcement Actions (0)
No other enforcement actions found for University of Limerick in IE
This is the only recorded action for this entity in this jurisdiction.
Details
Fine Date
10 December 2025
Authority
Data Protection Commission
Fine Amount
€98,000
About this data
Cite as: Cookie Fines. University of Limerick - Ireland (2025). Retrieved from cookiefines.eu
Last updated: