[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"$fhyb039qzPZAllO9LrIeuR0FEliDfJPKS53kSYNoBzJM":3},{"article":4,"iocs":47},{"id":5,"title":6,"slug":7,"summary":8,"ai_summary":9,"brief":10,"full_text":11,"url":12,"image_url":13,"published_at":14,"ingested_at":15,"relevance_score":16,"entities":17,"category_id":24,"category":25,"article_tags":29},"dbd5fb76-ad8e-4852-8e3c-ef04ca21ca5e","High Court - 2016 IEHC 323","high-court-2016-iehc-323-7de967","Created page with \"{{COURTdecisionBOX |Jurisdiction=Ireland |Court-BG-Color= |Courtlogo=Courts_logo1.png |Court_Abbrevation=High Court |Court_Original_Name=High Court |Court_English_Name=High Court |Court_With_Country=High Court (Ireland) |Case_Number_Name=2016 IEHC 323 |ECLI= |Original_Source_Name_1=Bailii |Original_Source_Link_1=https:\u002F\u002Fwww.bailii.org\u002Fie\u002Fcases\u002FIEHC\u002F2026\u002F2026IEHC323.pdf |Original_Source_Language_1=English |Original_Source_Language__Code_1=EN |Original_Source_Name_2=...\" Show changes","The Irish High Court has ruled that a GDPR inquiry initiated by a complaint can address systemic issues and impose corrective measures, including fines, without needing to be formally converted into an 'own-volition' inquiry. This decision stems from a case where Meta Platforms Ireland Limited was challenged by the Data Protection Commission (DPC) over its handling of a data subject's access and portability requests. The DPC's investigation into the complaint revealed potential systemic issues affecting millions of users, leading to proposed fines and compliance orders.","High Court rules GDPR inquiry can address systemic issues and impose fines without conversion.","Help High Court - 2016 IEHC 323: Difference between revisions From GDPRhub Jump to:navigation, search Newer edit →VisualWikitext Revision as of 09:49, 26 August 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators277 edits Tag: Decisions [1.0]Newer edit → (No difference) Revision as of 09:49, 26 August 2026 High Court - 2016 IEHC 323 Court: High Court (Ireland) Jurisdiction: Ireland Relevant Law: Article 12 GDPR Article 15 GDPR Article 20 GDPR Article 57 GDPR Article 58 GDPR Article 77 GDPR Article 83 GDPR Section 110 Data Protection Act 2018Section 113 Data Protection Act 2018Section 115 Data Protection Act 2018 Decided: 21.08.2026 Published: Parties: Data Protection Commission (DPC) Meta Platforms Ireland Limited (MPIL) National Case Number\u002FName: 2016 IEHC 323 European Case Law Identifier: Appeal from: Appeal to: Unknown Original Language(s): English Original Source: Bailii (in English) Initial Contributor: bms The High Court held that a complaint-based GDPR inquiry may address systemic issues and result in system-wide corrective measures and fines without being converted into an own-volition inquiry. Contents 1 English Summary 1.1 Facts 1.2 Holding 2 Comment 3 Further Resources 4 English Machine Translation of the Decision English Summary Facts On 25 May 2018, Michael Veale, the data subject, submitted an access and data portability request to Meta Platforms Ireland Limited (then Facebook Ireland Limited), the controller. He requested access to all personal data concerning him stored in the controller's internal \"Hive\" data warehouse under Article 15 GDPR, including the data in raw form and information on its processing. He also requested relevant personal data in a structured, commonly used and machine-readable format under Article 20 GDPR. On 19 July 2018, the controller refused to provide the raw Hive data. Among other grounds, it relied on Article 12(5) GDPR, Article 15(4) GDPR and Article 20(4) GDPR. The data subject subsequently lodged a complaint with the Data Protection Commission (DPC), the DPA, arguing that the controller had failed to comply with his rights under Articles 15 and 20 GDPR and had unjustifiably relied on restrictions to those rights. On 27 July 2018, the DPA opened a complaint-based inquiry under Section 110(1) Data Protection Act 2018. The inquiry examined the controller's compliance with its obligations concerning the data subject's request. During the investigation, the controller explained that its approach to Hive data was generally applicable to its users and argued, inter alia, that extracting user-specific log-level data from Hive was computationally unfeasible. In August 2023, the DPA issued its Final Inquiry Report. The investigator considered that the controller had failed to provide the data subject with information required under Article 15(1)(a), (d) and (g) GDPR. On 10 October 2025, the DPA issued a preliminary draft decision (PDD). It provisionally found that the controller had infringed Article 15(1) and (3) GDPR by refusing access to and a copy of relevant personal data; Article 15(1)(a), (d) and (g) GDPR by providing inadequate information; Article 20(1) GDPR by refusing to provide relevant portable data; and Article 12(3) and (4) GDPR by failing to comply with the applicable time limits. The DPA also proposed a reprimand, a compliance order concerning the controller's general access and portability practices and administrative fines totalling between €360 million and €430 million. In determining the proposed corrective measures, the DPA took into account that the practices identified through the individual complaint potentially affected millions of users. The controller challenged the PDD before the High Court. It argued that the DPA had unlawfully transformed an inquiry concerning a single complaint into a systemic, EEA-wide own-volition inquiry. According to the controller, the DPA acted ultra vires by proposing systemic corrective measures and fines based on broader effects on other users. It also alleged breaches of fair procedures and legitimate expectations. Holding The High Court dismissed the controller's action. The Court held that neither the GDPR nor the Data Protection Act 2018 establishes the limitation alleged by the controller. Although a complaint under Article 77 GDPR must concern an alleged infringement of the complainant's personal data rights, this does not prevent the complaint from raising systemic issues where the complainant is personally affected. The Court distinguished the origin and scope of an inquiry from the corrective powers available to the DPA. A complaint-based inquiry is defined by the subject matter of the complaint, whereas an own-volition inquiry is defined by the DPA itself. However, this procedural distinction does not limit the corrective powers available once an infringement within the scope of the complaint has been identified. Consequently, the fact that an inquiry originated from an individual complaint did not require the DPA to disregard broader or systemic implications of the infringement. Addressing such implications did not convert the proceedings into an own-volition inquiry. Systemic corrective measures and administrative fines The Court noted that Articles 57 and 58 GDPR confer broad enforcement powers on supervisory authorities and do not distinguish between complaint-based and own-volition inquiries regarding the corrective measures available. Where an infringement is established, Article 58(2) GDPR requires the DPA to consider appropriate corrective measures. These may include orders bringing processing operations into compliance and administrative fines under Article 83 GDPR. Such measures are not necessarily confined to restoring the individual complainant's position and may address systemic deficiencies identified through the inquiry. In particular, the Court considered that Article 83 GDPR itself requires factors such as the nature, gravity and duration of the infringement and the number of affected data subjects to be considered when determining an administrative fine. Therefore, the broader impact of an infringement may legitimately influence a fine even when the underlying inquiry originated from one individual complaint. The Court consequently held that a complaint-based inquiry may result in system-wide corrective measures and administrative fines informed by systemic considerations, provided that these measures arise from infringements established within the subject matter of the complaint. The Court did not, however, determine whether the controller had actually infringed Articles 12, 15 or 20 GDPR or whether the proposed €360–€430 million fine was appropriate. Those findings and measures remained provisional within the DPA's ongoing decision-making procedure. Fair procedures The Court also rejected the controller's argument that the DPA had breached its right to fair procedures by expanding the inquiry after the investigative stage. The controller had been informed from the beginning that findings of infringement could result in the exercise of the DPA's corrective powers under Article 58 GDPR, including administrative fines. Moreover, throughout the inquiry, the controller had itself addressed the operation of Hive and its general approach to access requests across its user base. The systemic implications were therefore inherent in the issues under examination rather than introduced as a new subject matter at the decision-making stage. The Court further noted that the regulatory procedure had not yet concluded. The controller retained the opportunity to make submissions on the PDD before the Article 60 GDPR cooperation procedure and could subsequently challenge any legally binding final decision. Consequently, no procedural unfairness warranting judicial review had been established. Legitimate expectations The Court equally rejected the controller's claim that it had a leg","https:\u002F\u002Fgdprhub.eu\u002Findex.php?title=High_Court_-_2016_IEHC_323&diff=52800&oldid=0","https:\u002F\u002Fgdprhub.eu\u002Fimages\u002F4\u002F4c\u002FCourts_logo1.png","2026-08-26T09:49:57+00:00","2026-08-26T10:00:23.171286+00:00",7,[18,21],{"name":19,"type":20},"Meta Platforms Ireland Limited","vendor",{"name":22,"type":23},"Hive","product","c5c77cdb-f7d7-4990-9436-c81dcbff1163",{"id":24,"icon":26,"name":27,"slug":28},null,"Policy","policy",[30,35,40,45],{"category":31},{"id":32,"icon":26,"name":33,"slug":34},"2e06f76c-d5b9-4f54-9eef-4d3447b10730","Breaches","breaches",{"category":36},{"id":37,"icon":26,"name":38,"slug":39},"3f0f8451-91df-4b6c-9a73-ef3b2509b7f1","GDPR","gdpr",{"category":41},{"id":42,"icon":26,"name":43,"slug":44},"53f9c4b6-8bc6-4964-9169-d09e5cd41d72","Compliance","compliance",{"category":46},{"id":24,"icon":26,"name":27,"slug":28},[]]