Groupon Ireland Operations Limited
On 8 March 2024, the Data Protection Commission (DPC) adopted a decision following its examination of a complaint received against Groupon Ireland Operations Limited (Groupon).
The complaint concerned an access request and an erasure request made to Groupon. In response to the requests, Groupon initially required the complainant to provide a copy of an ID document in order to verify their identity, which the complainant objected to. Groupon later facilitated the complainant’s requests without imposing such a requirement. However, having been provided with their personal data, the complainant was not satisfied that all of their personal data had subsequently been fully deleted in accordance with their erasure request.
The issues under examination in the DPC’s decision were the following:
- Whether Groupon’s request for ID in order to verify the identity of the complainant for the purposes of their original access and erasure requests was compliant with Groupon’s relevant obligations under the GDPR.
- Whether Groupon had appropriately demonstrated that the complainant’s personal data had been fully deleted in response to the erasure request
As the processing under examination constituted “cross border” processing, the DPC’s decision was subject to the cooperation and consistency mechanism outlined in Article 60 of the GDPR and pursuant to Article 60(3) of the GDPR, the DPC submitted its draft decision to the supervisory authorities concerned for their opinion.
As the DPC received no relevant and reasoned objections to the draft decision from the supervisory authorities concerned within the statutory period, the supervisory authorities concerned were deemed to be in agreement with the draft decision of the DPC and are bound by it in accordance with Article 60(6) of the GDPR.
The DPC adopted its decision in respect of this complaint in accordance with Article 60(7) of the GDPR. In relation to whether Groupon had appropriately demonstrated that the complainant’s personal data had been fully deleted in response to the erasure request, the DPC’s decision finds no infringement. In relation to whether Groupon’s request for ID in order to verify the identity of the complainant for the purposes of their original access and erasure requests was compliant with Groupon’s relevant obligations under the GDPR, the DPC’s decision records findings of infringement as follows:
- Article 5(1)(c) of the GDPR
The DPC finds that Groupon infringed Article 5(1)(c) GDPR by having initially required the complainant to provide a copy of their ID in order to verify their identity for the purposes of their access and erasure requests, in circumstances where no such verification appeared to have been obtained or required in order to initially open an account and a less data-driven means of verification (namely, by way of the email address associated with the account) was available to Groupon.
- Article 12(2) of the GDPR
The DPC finds that Groupon infringed Article 12(2) GDPR by initially requesting additional information as to the complainant’s identity at the time they made their access and erasure requests, in circumstances where it has not demonstrated that reasonable doubts existed concerning the complainant’s identity that would have necessitated that application of Article 12(6) of the GDPR.
- Articles 15(1), 15(3) and 17(1) of the GDPR
The DPC finds that Groupon infringed Articles 15(1), 15(3) and 17(1) GDPR by having failed to comply with the complainant’s initial access and erasure requests at the time they were made without a lawful basis for not complying, in circumstances where Groupon’s request (as a prerequisite to responding to the initial access and erasure requests) for photographic ID has been found to be an infringement of Article 5(1)(c) GDPR.
- Article 6(1) of the GDPR
The DPC finds that Groupon infringed Article 6(1) GDPR by continuing to process the complainant’s personal data following receipt of their initial request for erasure.
Corrective Powers Exercised:
In light of the infringements found, the DPC issued a reprimand to Groupon pursuant to Article 58(2)(b) of the GDPR.
For more information, you can download a copy of the full decision at this link: Groupon Ireland Operations Limited – March 2024 (PDF, 599 KB).
Inquiry into Apple Distribution International Limited
On 7 March 2024, following an inquiry in relation to a complaint received against Apple Distribution International Limited (Apple), the Data Protection Commission (DPC) adopted a decision.
The DPC commenced this inquiry on 2 November 2022 on foot of a complaint that Apple did not give effect to the Complainant’s rights and did not properly comply with its obligations under the GDPR. The Complainant contended that Apple failed to properly comply with an erasure request he submitted and had unlawfully retained certain personal data, in particular his email address.
The Complainant had made an erasure request to Apple in respect of his Apple ID on 3 March 2019. Apple confirmed to the Complainant on the same date that it was handling the erasure request to delete his Apple ID. This confirmation set out that, when the account was deleted, the data stored with Apple would also be permanently deleted. The Complainant was not informed by Apple at the time the erasure request was processed that it had retained a hashed value of his email address.
Apple submitted that it had retained a hashed value of the Complainant’s email address on the basis that the processing was necessary for the purposes of its legitimate interests, including in order to be able to demonstrate compliance with its security obligations under Article 32 of the GDPR; to prevent the recycling of namespaces by users; to protect its users against fraud and security breaches by third parties; and, to demonstrate compliance with a user’s request to delete their Apple ID. Apple stated that longer period of retention are subject to periodic reviews, and that periodic reviews are carried out of its retention practices. Apple informed the DPC it had convened with its security and engineering teams to review the period for deletion of the hashed email addresses at some fixed period of time and informed the DPC about a project which it had commenced.
The scope of the inquiry concerned an examination and assessment of the following:
- Whether Apple had a lawful basis for retaining a hashed value of the Complainant’s email address on foot of processing an erasure request pursuant to Article 17 of the GDPR;
- The period for which Apple intends to retain the hashed value of the Complainant’s email address;
- Whether Apple met the requirements of Articles 12(1) and 17(1) of the GDPR with regard to the processing of the Complainant’s erasure request;
- Whether Apple complied with the principles of transparency and the provision of information in terms of notifying the Complainant that a hashed value of his email address was retained following the processing of his erasure request.
As the processing under examination constituted “cross border” processing, the DPC’s decision was subject to the cooperation and consistency mechanism outlined in Article 60 of the GDPR and pursuant to Article 60(3) of the GDPR. The DPC submitted its draft decision to the supervisory authorities concerned.
Following consultation and agreement from the supervisory authorities concerned, the DPC adopted its decision in accordance with Article 60(7) of the GDPR.
In its decision, following the investigation of the complaint against Apple, the DPC made the following findings:
- The DPC is satisfied that Apple validly relied on Article 6(1)(f) of the GDPR as the lawful basis for retaining a hashed value of the Complainant’s email address in this particular case;
- The DPC is satisfied that Apple has given due consideration to the principle of data minimisation in relation to the retention of the hashed value of the Complainant’s email address;
- The DPC is satisfied that Apple met the requirements of Articles 12 and 17 of the GDPR with regard to the processing of the Complainant’s erasure request in March 2019;
- In the absence of specifically informing the Complainant when he made his erasure request in March 2019 of its intention to retain a hashed value of his email address, and the legal basis and legitimate interests for so doing, Apple failed to meet the transparency requirements of Article 13(1)(c) and Article 13(1)(d) at that time.
Corrective Powers Exercised:
In light of the infringements of Articles 13(1)(c) and 13(1)(d) of the GDPR, the DPC issued a reprimand to Apple pursuant to Article 58(2)(b) of the GDPR, and the DPC ordered Apple, pursuant to Article 58(2)(d) of the GDPR to review and revise its document entitled “Apple ID Deletion Terms and Conditions” to address the transparency deficiencies identified in the DPC’s decision. In addition, with regard to Apple’s project, the DPC ordered Apple to provide details of completion of this project to the DPC by 31 December 2024.
For more information, you can download a copy of the full decision at this link: Apple Distribution International Limited Final Decision - March 2024 (PDF, 9.7 MB).
Inquiry into Airbnb Ireland UC
On 31 January 2024, following an inquiry concerning a complaint received against Airbnb Ireland UC (Airbnb), the Data Protection Commission (the DPC) adopted a decision.
The DPC had commenced this inquiry on 8 December 2022, on foot of a complaint that Airbnb had unlawfully requested a copy of the complainant’s ID (ID) in order to verify their identity in order to carry out an erasure request when he decided to discontinue with the registration process. The complainant alleged that during the course of his registration with the platform, Airbnb sought a copy of his identity to complete the registration process. The complainant had entered his email address and phone number. He had also ticked a box to be excluded from advertising emails. The complainant stated that once he was asked to submit his ID documentation, he decided to abort his registration process. He provided his email address and created a password to access an internal area within the platform and within this area he asked Airbnb to delete all of his personal data and ensure that none of his data was transferred to third parties. The complainant stated that he was told that it was not possible to delete his data without his ID. He stated that he did not consider Airbnb’s request to have any legal basis and that it was an infringement of his right to erasure of his personal data.
The scope of the inquiry concerned an examination and assessment of the following:
- Whether Airbnb had a lawful basis for requesting the complainant’s ID at the point of registration of an account.
- Whether Airbnb had a lawful basis for requesting a copy of the complainant’s ID in order to verify his identity so that he could delete his account.
- Whether Airbnb complied with the principle of data minimisation when requesting a copy of the complainant’s ID in order to verify his account and when processing personal data relating to same processing.
- Whether Airbnb complied with the principles of transparency and provision of information at the point when the complainant’s personal data was collected from him.
As the processing under examination constituted cross-border processing, the DPC’s decision was subject to the cooperation and consistency mechanism outlined in Article 60 of the GDPR and pursuant to Article 60(3) of the GDPR. The DPC submitted its draft decision to the supervisory authorities concerned for their opinion. As the DPC received no relevant and reasoned objections to the draft decision from the supervisory authorities concerned within the statutory period, the supervisory authorities concerned were deemed to be in agreement with the draft decision of the DPC and are bound by it in accordance with Article 60(6) of the GDPR. The DPC adopted its decision in respect of this complaint in accordance with Article 60(7) of the GDPR.
The decision, which was adopted on 31 January 2024, records findings of infringement as follows:
- Article 5(1)(c) of the GDPR
- Article 6 of the GDPR
The DPC found that Airbnb did not validly rely on Article 6 of the GDPR as the legal basis for processing the complainant’s ID. Furthermore the DPC found that in the particular situation that arose in this complainant’s case, Airbnb’s requirement that the complainant verify his identity by submitting a copy of his ID in order to make an erasure request constituted an infringement of the principle of data minimisation, pursuant to Article 5(1)(c) of the GDPR.
In light of the infringements of Article 5(1)(c) and Article 6, the DPC issued a reprimand to Airbnb pursuant to Article 58(2)(b) of the GDPR.
The DPC notes that Airbnb has discontinued the practice of requesting a copy of ID in order to verify identity in order to verify erasure requests.
The DPC also notes that following an order made in a previous DPC decision, Airbnb has revised its internal policies and procedures in order to prevent further infringements of Article 5(1)(c), similar to those that occurred in this case, occurring to data subjects in the future.
For more information, you can download a copy of the full decision at this link: Inquiry into Airbnb Ireland UC - January 2024 (PDF, 4.9 MB).
Inquiry into Microsoft Ireland Operations Limited
On 15 November 2023, following an inquiry concerning a complaint received against Microsoft Ireland Operations Limited (Microsoft), the Data Protection Commission (DPC) adopted a decision.
The DPC commenced this inquiry on 29 June 2023, on foot of a complaint that Microsoft failed to comply with two erasure requests submitted by the complainant in March and October 2021.
The scope of the inquiry concerned an examination and assessment of the following:
- Whether Microsoft’s handling of the complainant’s erasure requests was compliant with Articles 12 and 17 of the GDPR.
As the processing under examination constituted 'cross border' processing, the DPC’s decision was subject to the cooperation and consistency mechanism outlined in Article 60 of the GDPR and pursuant to Article 60(3) of the GDPR, the DPC submitted its draft decision to the supervisory authorities concerned for their opinion.
As the DPC received no relevant and reasoned objections to the draft decision from the supervisory authorities concerned within the statutory period, the supervisory authorities concerned were deemed to be in agreement with the draft decision of the DPC and are bound by it in accordance with Article 60(6) of the GDPR.
The DPC adopted its decision in respect of this complaint in accordance with Article 60(7) of the GDPR.
The decision, which was adopted on 15 November 2023, records findings of infringement as follows:
- Article 12(4) of the GDPR
The DPC finds that Microsoft infringed Article 12(4) of the GDPR in respect of the March erasure request when it failed to inform the complainant of the possibility of seeking a judicial remedy when it responded to them outlining the reasons for not taking action, in part, on the complainant’s erasure request.
- Article 12(4) of the GDPR
The DPC finds that Microsoft infringed Article 12(4) of the GDPR in respect of the October erasure request when it failed to inform the complainant of the possibility of seeking a judicial remedy when it responded to them outlining the reasons for not taking action on the complainant’s erasure request.
- Article 17 of the GDPR
The DPC finds that Microsoft infringed Article 17 of the GDPR by failing to erase personal data that were the subject of the complainant’s erasure request of October 2021 without undue delay.
Corrective Powers Exercised:
-
An order, in accordance with Article 58(2)(d) of the GDPR for Microsoft to revise its internal policies and procedures as regards the information to be provided to data subjects pursuant to Article 12, to ensure that, where it informs data subjects on foot of requests made under Articles 15 to 22 of the GDPR that it has decided not to take action on the request, that data subjects are informed in all cases of their right to seek a judicial remedy. Details of compliance to be provided to the DPC by 7 February 2024.
-
A reprimand to Microsoft Ireland Operations Limited pursuant to Article 58(2)(b) of the GDPR in light of the infringements found.
For more information, you can download the full decision at this link: Inquiry into Microsoft Ireland Operations Limited - November 2023 (PDF, 5.6mb)
Inquiry into Airbnb Ireland UC - 28 September 2023 (2)
On 28 September 2023, following an inquiry concerning a complaint received against Airbnb Ireland UC (“Airbnb”), the Data Protection Commission (“the DPC”) adopted a decision.
The DPC had commenced this inquiry on 22 September 2022, on foot of a complaint that Airbnb had unlawfully requested a copy of the Complainant’s ID (“ID”) in order to verify their identity in order to complete a booking on the platform. In this particular instance the complainant had previously booked the same listing earlier that year on the Airbnb platform without the need for ID verification. Airbnb rejected the IDs submitted by the Complainant as the images of his ID were unclear. Ultimately however the complainant was successfully able to complete the booking by using another Airbnb account which Airbnb believe he shares with another person.
The scope of the inquiry concerned an examination and assessment of the following:
-
Whether Airbnb had a lawful basis for requesting copies of the Complainant’s ID and photograph in order to verify his identity.
-
Whether Airbnb complied with the principle of data minimisation when processing a copy of the Complainant’s ID and photograph in order to verify his account.
-
Whether Airbnb complied with the Conditions for Consent by making the Complainant’s ability to complete his booking conditional on the Complainant submitting his ID and photograph in order to verify his identity.
-
Whether Airbnb complied with principles of transparency and provision of information where the Complainant’s personal data was collected.
As the processing under examination constituted “cross border “ processing, the DPC’s decision was subject to the cooperation and consistency mechanism outlined in Article 60 of the GDPR and pursuant to Article 60(3) of the GDPR, the DPC submitted its draft decision to the supervisory authorities concerned for their opinion. As the DPC received no relevant and reasoned objections to the draft decision from the supervisory authorities concerned within the statutory period, the supervisory authorities concerned were deemed to be in agreement with the draft decision of the DPC and are bound by it in accordance with Article 60(6) of the GDPR. The DPC adopted its decision in respect of this complaint in accordance with Article 60(7) of the GDPR.
The decision, which was adopted on Thursday 28 September 2023, records findings of infringement as follows:
-
Article 5(1)(c) and Article 6(1)(f) of the GDPR
The DPC found Airbnb did not validly rely of Article 6(1)(f) of the GDPR as the legal basis for processing the Complainant’s photographic IDs and supplemental image. Furthermore the DPC found that in the particular situation that arose in this Complainant’s case, Airbnb’s requirement that the Complainant verify his identity by submitting an unredacted copy of his photographic ID constituted an infringement of the principle of data minimisation, pursuant to Article 5(1)(c) of the GDPR.
In light of the infringements of Article 5(1)(c) and Article 6(1)(f) the DPC issued a reprimand to Airbnb pursuant to Article 58(2)(b) of the GDPR. In addition, the DPC made the following order against Airbnb pursuant to Article 58(2)(d) to remedy the infringements identified in this case and to prevent similar infringements occurring with regard to data subjects in the future in similar circumstances:
-
revise its internal policies and procedures to ensure that the seeking of photographic ID and supplemental photographs in the verification process for users is used only where necessary, proportionate and in accordance with the GDPR for the purpose for which the personal data is collected and processed, having regard, in particular, to Airbnb’s legal obligations and the issue of whether less privacy intrusive verification methods are available and effective. Details of compliance with this order should be provided to the DPC by Airbnb by Thursday, 21 December 2023.
For more information, you can download a copy of the full decision at this link: Airbnb Ireland UC Final Decision - 28 September 2023 (2) (PDF, 2 MB).
Inquiry into Airbnb Ireland UC - 28 September 2023
On 28 September 2023, following an inquiry concerning a complaint received against Airbnb Ireland UC (“Airbnb”), the Data Protection Commission (“the DPC”) adopted a decision.
The DPC had commenced this inquiry on 7 September 2022, on foot of a complaint that Airbnb had unlawfully requested a copy of the Complainant’s ID (“ID”) in order to verify their identity in order to complete a booking on the platform. The complainant stated that he had concerns in relation to identity theft given the volume of personal data that he was required to submit in order to complete his accommodation booking. In this particular instance the complainant stated that Airbnb would not accept his booking until he verified his identity by providing a copy of his ID in addition to a newly taken photograph to ensure that the ID related only to the person making the booking. ID submitted by the Complainant was rejected as he had redacted certain information. Ultimately however the Complainant was successfully able to verify his identity by submitting a copy of his ID with only the online access code redacted.
In a further submission the Complainant stated that Airbnb initially misunderstood what he wanted to do and thought he wanted to erase his Airbnb account. He stated that Airbnb requested another copy of ID. In addition to the complaint regarding ID verification the Complainant also wanted Airbnb to delete his ID card, both redacted and unredacted versions.
The scope of the inquiry concerned an examination and assessment of the following:
-
Whether Airbnb had a lawful basis for requesting a copy/copies of the Complainant’s ID and/or photograph/s in order to verify his identity, so that he could complete his booking on the platform.
-
Whether Airbnb complied with the principle of data minimisation when requesting an unredacted copy of the Complainant’s ID and/or photograph/s in order to verify his identity and when processing personal data relating to same processing.
-
Whether Airbnb had a lawful basis for retaining a copy of the Complainant’s ID after it had verified his identity.
-
Whether Airbnb complied with the principles of transparency and provision of information where the Complainant’s personal data was collected.
-
Whether Airbnb received an Article 17 erasure request from the data subject and if so, whether Airbnb’s handling of the Complainant’s erasure request complied with the GDPR and the Act.
As the processing under examination constituted “cross border “ processing, the DPC’s decision was subject to the cooperation and consistency mechanism outlined in Article 60 of GDPR and pursuant to Article 60(3) of the GDPR, the DPC submitted its draft decision to the supervisory authorities concerned for their opinion. As the DPC received no relevant and reasoned objections to the draft decision from the supervisory authorities concerned within the statutory period, the supervisory authorities concerned were deemed to be in agreement with the draft decision of the DPC and are bound by it in accordance with Article 60(6) of the GDPR. The DPC adopted its decision in respect of this complaint in accordance with Article 60(7) of the GDPR.
The decision, which was adopted on Thursday 28 September 2023, records findings of infringement as follows:
-
Article 5(1)(c) , Article 5(1)(e) and Article 6(1)(f) of the GDPR
The DPC found that Airbnb did not validly rely on Article 6(1)(f) of the GDPR as the legal basis for processing the Complainant’s photographic ID and supplemental photographs; that Airbnb’s requirement that the Complainant verify his identity by submitting a complete and unredacted copy of his photographic ID constituted an infringement of the principle of data minimisation, pursuant to Article 5(1)(c); that by retaining, after the identity verification process was successfully completed and until 2 February 2021 a copy of the Complainant’s un-redacted ID documents, Airbnb infringed the principle of data minimisation in Article 5(1)(c) and the principle of storage limitation in Article 5(1)(e); by retaining, after the identity verification process was successfully completed and for the duration of the user’s account, a copy of the Complainant’s supplemental images, Airbnb infringed the principle of data minimisation and the principle of storage limitation; and that Airbnb’s processing and retention until 2 February, 2021 of identity documents that it deemed inadequate or insufficient to verify the identity of the Complainant infringed the principle of data minimisation and the principle of storage limitation.
In light of the infringements of Article 5(1)(c), Article 5(1)(e) and Article 6(1)(f) the DPC issued a reprimand to Airbnb pursuant to Article 58(2)(b) of the GDPR. In addition, the DPC made the following orders against Airbnb pursuant to Article 58(2)(d) to remedy the infringements identified in this case and to prevent similar infringements occurring with regard to data subjects in the future in similar circumstances.
-
delete from all of its systems and records the supplemental photographs that the Complainant uploaded (keeping only a record that such documentation was submitted and the date of submission). Details of compliance with this order should be provided to the DPC by Airbnb by Thursday, 21 December 2023.
-
revise its internal policies and procedures to ensure that the seeking of photographic ID and supplemental photographs in the verification process for users is used only where necessary, proportionate and in accordance with the GDPR for the purpose for which the personal data is collected and processed, having regard, in particular, to Airbnb’s legal obligations and the issue of whether less privacy intrusive verification methods are available and effective. Details of compliance with this order should be provided to the DPC by Airbnb by Thursday, 21 December 2023.
For more information, you can download the full decision at this link: Inquiry into Airbnb Ireland UC - 28 September 2023 (PDF, 3mb)
Inquiry into Airbnb Ireland UC
On 14 September 2023, the Data Protection Commission (DPC) adopted a decision in relation to a complaint against Airbnb Ireland UC (Airbnb), which was submitted to the Cypriot DPA, in its capacity as the concerned supervisory authority and thereafter referred to the DPC in its capacity as lead supervisory authority.
The DPC commenced this inquiry on 7 October 2022, on foot of a complaint that Airbnb did not properly comply with its obligations and the complainant’s rights under the GDPR. In particular:
- That Airbnb did not properly comply with his erasure request,
- That Airbnb unlawfully retained his personal data,
- That it did not comply with the data minimisation principle, and
- That Airbnb failed to comply with the principles of transparency and provision of information.
In this case, the data subject had submitted an erasure request to Airbnb. Airbnb responded to the data subject requesting that he verify his identity for the purpose of authenticating his erasure request, and once authenticated it informed the data subject that his personal data would be deleted unless it was permitted or required to retain data.
Airbnb did not further update the data subject in respect of his erasure request and as far as he was concerned his accounts and personal data had been deleted on foot of his erasure request. Airbnb ultimately retained the complainant’s accounts and did not delete any personal data in relation to the accounts on the advice of legal counsel following an alleged serious incident at an Airbnb listing that was the subject of a police investigation and legal proceedings.
The DPC first attempted through complaint handling to facilitate the amicable resolution of the complaint between the parties. However ultimately an inquiry and an Article 60 decision was required to bring the case to a conclusion.
Airbnb stated that it retained the complainant’s data on the basis of the legitimate interests of those involved in or otherwise connected with the underlying police investigation and legal proceedings, including the wider public interest in preserving the integrity of police investigations and judicial processes, and the legitimate interests of Airbnb, its users, partners and those otherwise associated with the platform in keeping the Airbnb platform safe.
In its decision, the DPC:
- Was satisfied that Airbnb validly relied on Article 6(1)(f) as the lawful basis for the retention of the complainant’s personal data;
- Found that Airbnb validly relied on Article 17()(e) and that it did not infringe Article 17(1) when it restricted the complainant’s right of erasure of his personal data;
- Found that Airbnb’s retention of the complainant’s personal data in its entirety across a number of his accounts did not infringe the principle of data minimisation in Article 5(1)(c).
Following the investigation of the complaint against Airbnb Ireland UC, the DPC was of the opinion that, in the circumstances of the complainant’s case, Airbnb Ireland UC:
- Infringed Article 12(4) of the GDPR with respect to its handling of the complainant’s erasure request by failing to inform him without delay and at the latest within one month of receipt of the request of the reasons for not taking action on it and on the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy.
Following consultation and agreement from the supervisory authorities concerned, the DPC has now adopted its decision in respect of this complaint in accordance with Article 60(7) of the GDPR. The decision of the DPC also applied the following corrective power:
- The DPC issued a reprimand to Airbnb Ireland UC, pursuant to Article 58(2)(b) of the GDPR.
For more information, you can download the full decision at this link: Inquiry into Airbnb Ireland UC - September 2023 (PDF, 8mb)
Inquiry into TikTok Technology Limited
The Data Protection Commission (DPC) adopted its final decision regarding its inquiry into TikTok Technology Limited (TTL) on 1 September 2023.
This own-volition inquiry sought to examine the extent to which, during the period between 31 July 2020 and 31 December 2020 (the Relevant Period), TTL complied with its obligations under the GDPR in relation to its processing of personal data relating to child users of the TikTok platform in the context of:
- Certain TikTok platform settings, including public-by-default settings as well as the settings associated with the ‘Family Pairing’ feature; and
- Age verification as part of the registration process.
As part of the inquiry, the DPC also examined certain of TTL’s transparency obligations, including the extent of information provided to child users in relation to default settings.
At the conclusion of its investigation, the DPC submitted a draft decision to all Supervisory Authorities Concerned (CSAs), for the purpose of Article 60(3) GDPR, on 13 September 2022. The DPC’s draft decision proposed findings of infringement of Articles 5(1)(c), 5(1)(f), 24(1), 25(1), 25(2), 12(1) and 13(1)(e) GDPR, in relation to the above processing. While there was broad consensus on the DPC’s proposed findings, objections to the draft decision were raised by the Supervisory Authorities (each an SA, collectively SAs) of Italy and Berlin (acting on behalf of itself and the Baden-Württemberg SA).
The objection raised by the Berlin SA sought the inclusion of an additional finding of infringement of the Article 5(1)(a) GDPR principle of fairness as regards ‘dark patterns’ while the objection raised by the Italian SA sought to reverse the DPC’s proposed finding of compliance with Article 25 GDPR, as regards TTL’s approach to age verification during the Relevant Period. The DPC was unable to reach consensus with the CSAs on the subject-matter of the objections and, in the circumstances, decided to refer the objections to the EDPB for determination pursuant to the Article 65 GDPR dispute resolution mechanism.
The European Data Protection Board adopted its binding decision on the subject matter of the objections on 2 August 2023 with a direction that the DPC must amend its draft decision to include a new finding of infringement of the Article 5(1)(a) GDPR principle of fairness, further to the objection raised by the Berlin SA, and to extend the scope of the existing order to bring processing into compliance, to include reference to the remedial work required to address this new finding of infringement.
The DPC’s decision, which was adopted on 1 September 2023, records findings of infringement of Articles 5(1)(c), 5(1)(f), 24(1), 25(1), 25(2), 12(1), 13(1)(e) and 5(1)(a) GDPR.
The decision further exercises the following corrective powers:
- A reprimand;
- An order requiring TTL to bring its processing into compliance by taking the action specified within a period of three months from the date on which the DPC’s decision is notified to TTL; and
- Administrative fines totalling €345 million.
For more information, you can download the full decision at this link: Inquiry into TikTok Technology Limited - September 2023 (PDF, 5.9mb).

Inquiry into Galway County Council
This inquiry sought to assess whether Galway County Council was processing personal data in compliance with the GDPR and the Data Protection Act 2018. The inquiry examined a number of the Council’s processing operations including its use of CCTV cameras in public places used for the purposes of prosecuting crime or other purposes.
The findings made in the decision include:
- Findings that Galway County Council lacked a valid legal basis for processing of personal data from CCTV, ANPR and body-worn cameras.
- Findings that Galway County Council failed to erect appropriately worded and located signage in respect of the processing of personal data collected via these CCTV cameras for purposes related to law enforcement.
The other findings in the decision include infringements relating to Galway County Council’s obligations to carry out data protection impact assessments, to maintain data logs for specific accesses to CCTV recordings, and to implement appropriate technical and organisational measures.
Corrective Powers Exercised:
- A temporary ban on the processing of personal data through CCTV cameras and ANPR cameras at a number of locations until a valid legal basis can be identified.
- A temporary ban on the processing of personal data through body-worn cameras until a valid legal basis can be identified.
- An order to Galway County Council to bring its processing of personal data into compliance taking certain actions specified in the decision.
- A reprimand in respect of Galway County Council’s infringement of Article 24 GDPR.
For more information, you can download the full decision at this link: Inquiry into Galway County Council - August 2023 (PDF, 2.6mb).
Inquiry into Airbnb Ireland UC
On 20 July 2023, following an inquiry the Data Protection Commission (DPC) adopted a decision to exercise corrective powers on Airbnb Ireland UC (Airbnb).
The DPC commenced this inquiry on 22 December 2022, on foot of a complaint that Airbnb failed to comply with an access request and subsequent erasure request within the statutory timeframe and, further, that when the Complainant submitted their access and erasure requests, Airbnb requested that they verify their identity by providing a photocopy of their identity document (ID), which they had not previously provided to Airbnb.
The scope of the inquiry concerned an examination and assessment of the following:
1) Whether Airbnb’s provision of the personal data and information concerning the processing of that personal data in response to the Complainant’s access request was compliant with the GDPR and the Data Protection Act 2018.
2) Whether Airbnb’s handling of the Complainant’s access request was compliant with the GDPR and the Act insofar as the information provided to the Complainant was in a concise, transparent, intelligible and easily accessible form using clear and plain language as specified by Article 12(1) of the GDPR.
3) Whether Airbnb’s handling of the Complainant’s erasure request was compliant with the GDPR and the Act.
4(a) Whether Airbnb had a lawful basis for requesting a copy of the Complainant’s ID, and upon their refusal to provide same, whether Airbnb had a lawful basis to thereafter request a telephone call in order to verify the Complainant’s identity in circumstances where he had submitted a request for access and erasure pursuant to Articles 15 and 17 GDPR; and
4(b) Whether Airbnb’s obligation to provide information on action taken in response to the access and erasure requests without undue delay pursuant to Article 12(3) GDPR was suspended until after the verification of the Complainant’s identity by phone call.
As the processing under examination constituted “cross border” processing, the DPC’s decision was subject to the cooperation and consistency mechanism outlined in Article 60 of the GDPR and pursuant to Article 60(3) of the GDPR, the DPC submitted its draft decision to the supervisory authorities concerned for their opinion.
As the DPC received no relevant and reasoned objections to the draft decision from the supervisory authorities concerned within the statutory period, the supervisory authorities concerned were deemed to be in agreement with the draft decision of the DPC and are bound by it in accordance with Article 60(6) of the GDPR.
The DPC adopted its decision in respect of this Complaint in accordance with Article 60(7) of the GDPR.
The decision, which was adopted on 20 July 2023, records findings of infringement as follows:
- Article 5(1)(c) of the GDPR
The DPC finds that Airbnb’s request that the Complainant verify their identity by way of submission of a copy of their ID constituted an infringement of the principle of data minimisation, pursuant to Article 5(1)(c) of the GDPR. This infringement occurred in circumstances where less data-driven solutions to the question of identity verification were available to Airbnb.
- Article 6(1)(f) of the GDPR
The DPC finds that, in the specific circumstances of this Complaint, the legitimate interest pursued by Airbnb did not constitute a valid lawful basis under Article 6(1)(f) of the GDPR for seeking a copy of the Complainant’s ID in order to process the Complainant’s access and erasure requests.
- Article 15(1) of the GDPR
The DPC finds that Airbnb infringed Article 15(1) of the GDPR at the time of first processing the Complainant’s access request by not providing the Complainant with access to all of their personal data that was being processed by Airbnb on the date of receipt of their access request.
- Article 12(1) of the GDPR
The DPC finds that Airbnb infringed Article 12(1) of the GDPR at the time of first processing the Complainant’s access request by failing to provide the Complainant with an access file that was of a concise, transparent, intelligent and easily accessible form.
- Article 12(3) of the GDPR
The DPC finds that Airbnb failed to provide information to the Complainant on the actions taken on their access and erasure requests within one month of receipt of the requests and therefore failed in its obligations under Article 12(3) of the GDPR.
Corrective Powers Exercised:
- An order for Airbnb to revise its internal policies and procedures as regards the default position to provide a cover email in English when a data protection rights request is received outside the privacy portal.
- A reprimand to Airbnb Ireland UC pursuant to Article 58(2)(b) of the GDPR.
For more information, you can download the full decision at this link: Inquiry into Airbnb Ireland UC - July 2023 (PDF, 4.5mb).