Data Protection Commission Publishes Annual Report for 2025 and Results of “Sharenting” Survey
30th June 2026
The inquiry commenced following Permanent TSB’s (‘PTSB’) notification to the DPC of a series of three data breaches relating to PTSB’s ‘Open 24 Contact Centre’. Each of the data breach notifications concerned malicious actors, in possession of certain PTSB client information, contacting PTSB’s Open24 Contact Centre in order to gain access to client accounts.
The decision considered whether PTSB had complied with Articles 5(1)(f), 32(1) and 33(1) GDPR. In particular the DPC considered whether PTSB had implemented appropriate technical and organisational measures to ensure a level of security appropriate to the risks associated with its processing of personal data via the Open 24 Contact Centre, and also whether PTSB had reported the breaches to DPC within the required time periods under the GDPR.
The DPC’s decision found that PTSB:
You can download the full decision at this link: Permanent TSB (PTSB) - April 2026 (PDF, 898KB).
On 1 September 2025, following an inquiry concerning a complaint received against Microsoft Ireland Operations Limited (Microsoft), the Data Protection Commission (DPC) adopted a decision.
The DPC commenced this inquiry on 16 May 2023, on foot of a complaint that Microsoft failed to comply with an access request submitted by the complainant in August 2020.
The scope of the inquiry concerned an examination and assessment of the following:
Whether the Controller complied with Article 12(4) of the GDPR after the Complainant made an access request on 17 August 2020;
As the processing under examination constituted 'cross border' processing, the DPC’s decision was subject to the cooperation and consistency mechanism outlined in Article 60 of the GDPR and pursuant to Article 60(3) of the GDPR, the DPC submitted its draft decision to the supervisory authorities concerned for their opinion.
The DPC received one relevant and reasoned objection to the draft decision from the supervisory authorities concerned within the statutory period and therefore issued a revised draft decision. As the DPC did not receive any relevant and reasoned objections to the revised draft decision, the supervisory authorities concerned were deemed to be in agreement with the revised draft decision of the DPC and are bound by it in accordance with Article 60(6) of the GDPR.
The DPC adopted its decision in respect of this complaint in accordance with Article 60(7) of the GDPR. The decision, which was adopted on 1 September 2025, records findings of infringement as follows:
The DPC finds that Microsoft infringed Article 12(4) of the GDPR in respect of the access request when it failed to inform the complainant of the possibility to lodge a complaint with a supervisory authority and to seek a judicial remedy following the complainant’s access request.
The DPC finds that, the specific circumstances of the complaint, Microsoft infringed the lawfulness, fairness and transparency principle under Article 5(1)(a) of the GDPR in its handling of the access request and in its decision to delete the complainant’s data.
30th June 2026
30th June 2026
15th June 2026
08th May 2026
05th May 2026
This Decision arises from an own-volition inquiry into the University of Limerick (‘UL’) following a series of personal data breaches that occurred between November 2018 and January 2020. The temporal scope of the Inquiry is from May 2018 to January 2020.
Between 30 November 2018 and 20 January 2020, UL notified the Data Protection Commission (‘DPC’) of 12 personal data breaches, in six of which unauthorised persons gained access to the employee email accounts of UL staff members by means of phishing attacks. The unauthorised users were able some cases to set up forwarding rules which diverted emails containing specified keywords to a folder they had created in the user’s mailbox. The compromised email accounts contained personal data including identity information, contact details, PPS numbers, bank information, medical or legal documentation, staff disciplinary and HR records, and data belonging to students, staff, and external parties.
This DPC carried out this Inquiry under sections 110-111 of the Data Protection Act 2018. It assessed UL’s compliance with Articles 5(1)(f) and 32(1) GDPR (implementation of appropriate technical and organisational measures to ensure appropriate security of the personal data processed on its email service); Article 30(1) GDPR (maintenance of a record of processing activities); Article 33(1) GDPR (notification to the DPC of personal data breaches without undue delay, and in any event within 72 hours of becoming aware of them); Article 34(1) GDPR (notification to concerned data subjects without undue delay of personal data breaches assessed to pose a high risk).
The DPC found that UL did not implement appropriate technical and organisational measures to ensure the security of personal data as required by Articles 5(1)(f) and 32(1) GDPR. The DPC also found that UL’s initial record of processing activity did not fully comply with the requirements of Article 30(1) GDPR, though UL implemented a compliant record of processing activity in May 2020, after the period assessed by the DPC in this Inquiry. The DPC found that three breach notifications were filed more than 72 hours after UL became aware of them, and were not reported without undue delay in accordance with Article 33(1) GDPR. With respect to Article 34(1) GDPR, UL failed in three cases to inform persons affected by a high-risk breach without undue delay. The DPC therefore found infringements of Articles 5(1)(f), 32(1), 30(1), 33(1), and 34(1) of the GDPR.
The DPC’s decisions on corrective measures took account of UL’s significant steps to remediate the deficiencies in its processing of personal data identified in this inquiry. Based on the details of those improvements provided by UL in its submissions, the DPC has decided that it is not necessary or proportionate for it to issue an order for UL to bring that processing into compliance with the GDPR. The DPC’s acknowledgement of those improvements does not however relieve UL of its obligation to continually evaluate the effectiveness of its measures and the measures that are necessary to ensure a level of security that is appropriate to the dynamic risk presented by its processing.
Having carefully considered the infringements identified in this Decision, the DPC has decided to exercise certain corrective powers in accordance with section 115 of the 2018 Act and Article 58(2) GDPR. The corrective powers that the DPC has decided are appropriate to address the infringements in the particular circumstances are:
The administrative fines issued for the above infringements are as follows:
The DPC commends the tenor and tone of UL’s engagement with the DPC since being presented with the DPC’s proposed findings in a draft version of its Decision. These fines are substantially lower than the maximum fines proposed in the draft Decision. The final fines reflect the mitigation occasioned by UL accepting the majority of the findings in the draft Decision, acknowledging responsibility for significant infringements, and proactively taking steps to improve its systems, training, and policies, in order to reduce the likelihood of similar breaches occurring in the future.
The full decision can be downloaded at this link: Inquiry into University of Limerick December 2025 (16MB, PDF).
02nd March 2026
20th February 2026