High Court - 2016 IEHC 323
High Court rules complaint-based inquiries can lead to system-wide measures and fines.
Summary
The Irish High Court has dismissed Meta's challenge against the Data Protection Commission's (DPC) inquiry into a data access request. The court affirmed that a complaint-initiated investigation can lead to system-wide corrective measures and significant administrative fines, even if it started with an individual's request. This ruling clarifies that supervisory authorities can address broader systemic issues and impose penalties based on the overall impact of infringements, not just the individual case.
Full text
Help High Court - 2016 IEHC 323: Difference between revisions From GDPRhub Jump to:navigation, search VisualWikitext Revision as of 09:49, 26 August 2026 view sourceBms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators277 edits Tag: Decisions [1.0] Latest revision as of 09:57, 26 August 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators277 editsTag: Visual edit Line 133: Line 133: === Facts ====== Facts === On 25 May 2018, Michael Veale, the data subject, submitted an access and data portability request to Meta Platforms Ireland Limited (then Facebook Ireland Limited), the controller. He requested access to all personal data concerning him stored in the controller's internal "Hive" data warehouse under [[Article 15 GDPR|Article 15 GDPR]], including the data in raw form and information on its processing. He also requested relevant personal data in a structured, commonly used and machine-readable format under [[Article 20 GDPR|Article 20 GDPR]].On 25 May 2018, Michael Veale, the data subject, submitted an access and data portability request to Meta Platforms Ireland Limited (then Facebook Ireland Limited), the controller. He requested access to all personal data concerning him stored in the controller's internal "Hive" data warehouse under [[Article 15 GDPR]], including the data in raw form and information on its processing. He also requested relevant personal data in a structured, commonly used and machine-readable format under [[Article 20 GDPR]]. On 19 July 2018, the controller refused to provide the raw Hive data. Among other grounds, it relied on [[Article 12 GDPR|Article 12(5) GDPR]], [[Article 15 GDPR|Article 15(4) GDPR]] and [[Article 20 GDPR|Article 20(4) GDPR]]. The data subject subsequently lodged a complaint with the Data Protection Commission (DPC), the DPA, arguing that the controller had failed to comply with his rights under Articles 15 and 20 GDPR and had unjustifiably relied on restrictions to those rights.On 19 July 2018, the controller refused to provide the raw Hive data. Among other grounds, it relied on [[Article 12 GDPR|Article 12(5) GDPR]], [[Article 15 GDPR|Article 15(4) GDPR]] and [[Article 20 GDPR|Article 20(4) GDPR]]. The data subject subsequently lodged a complaint with the Data Protection Commission (DPC), the DPA, arguing that the controller had failed to comply with his rights under [[Article 15 GDPR|Articles 15]] and [[Article 20 GDPR|20 GDPR]] and had unjustifiably relied on restrictions to those rights. On 27 July 2018, the DPA opened a complaint-based inquiry under Section 110(1) Data Protection Act 2018. The inquiry examined the controller's compliance with its obligations concerning the data subject's request. During the investigation, the controller explained that its approach to Hive data was generally applicable to its users and argued, inter alia, that extracting user-specific log-level data from Hive was computationally unfeasible.On 27 July 2018, the DPA opened a complaint-based inquiry under [https://www.legislation.gov.uk/ukpga/2018/12/contents Section 110(1) Data Protection Act 2018]. The inquiry examined the controller's compliance with its obligations concerning the data subject's request. During the investigation, the controller explained that its approach to Hive data was generally applicable to its users and argued, inter alia, that extracting user-specific log-level data from Hive was computationally unfeasible. In August 2023, the DPA issued its Final Inquiry Report. The investigator considered that the controller had failed to provide the data subject with information required under [[Article 15 GDPR|Article 15(1)(a)]], [[Article 15 GDPR|(d)]] and [[Article 15 GDPR|(g) GDPR]]. In August 2023, the DPA issued its Final Inquiry Report. The investigator considered that the controller had failed to provide the data subject with information required under Article 15(1)(a), (d) and (g) GDPR. On 10 October 2025, the DPA issued a preliminary draft decision (PDD). It provisionally found that the controller had infringed Article 15(1) and (3) GDPR by refusing access to and a copy of relevant personal data; Article 15(1)(a), (d) and (g) GDPR by providing inadequate information; [[Article 20 GDPR|Article 20(1) GDPR]] by refusing to provide relevant portable data; and Article 12(3) and (4) GDPR by failing to comply with the applicable time limits.On 10 October 2025, the DPA issued a preliminary draft decision (PDD). It provisionally found that the controller had infringed [[Article 15 GDPR|Article 15(1)]] and [[Article 15 GDPR|(3) GDPR]] by refusing access to and a copy of relevant personal data; [[Article 15 GDPR|Article 15(1)(a)]], [[Article 15 GDPR|(d)]] and [[Article 15 GDPR|(g) GDPR]] by providing inadequate information; [[Article 20 GDPR|Article 20(1) GDPR]] by refusing to provide relevant portable data; and [[Article 12 GDPR|Article 12(3)]] and [[Article 12 GDPR|(4) GDPR]] by failing to comply with the applicable time limits. The DPA also proposed a reprimand, a compliance order concerning the controller's general access and portability practices and administrative fines totalling between €360 million and €430 million. In determining the proposed corrective measures, the DPA took into account that the practices identified through the individual complaint potentially affected millions of users.The DPA also proposed a reprimand, a compliance order concerning the controller's general access and portability practices and administrative fines totalling between €360 million and €430 million. In determining the proposed corrective measures, the DPA took into account that the practices identified through the individual complaint potentially affected millions of users. The controller challenged the PDD before the High Court. It argued that the DPA had unlawfully transformed an inquiry concerning a single complaint into a systemic, EEA-wide own-volition inquiry. According to the controller, the DPA acted ultra vires by proposing systemic corrective measures and fines based on broader effects on other users. It also alleged breaches of fair procedures and legitimate expectations.The controller challenged the PDD before the High Court. It argued that the DPA had unlawfully transformed an inquiry concerning a single complaint into a systemic, EEA-wide own-volition inquiry. According to the controller, the DPA acted ultra vires by proposing systemic corrective measures and fines based on broader effects on other users. It also alleged breaches of fair procedures and legitimate expectations. === Holding ====== Holding === The High Court dismissed the controller's action.The High Court dismissed the controller's action. The Court held that neither the GDPR nor the Data Protection Act 2018 establishes the limitation alleged by the controller. Although a complaint under [[Article 77 GDPR|Article 77 GDPR]] must concern an alleged infringement of the complainant's personal data rights, this does not prevent the complaint from raising systemic issues where the complainant is personally affected.The Court held that neither the GDPR nor the Data Protection Act 2018 establishes the limitation alleged by the controller. Although a complaint under [[Article 77 GDPR]] must concern an alleged infringement of the complainant's personal data rights, this does not prevent the complaint from raising systemic issues where the complainant is personally affected. The Court distinguished the origin and scope of an inquiry from the corrective powers available to the DPA. A complaint-based inquiry is defined by the subject matter of the complaint, whereas an own-volition inquiry is defined by the DPA itself. However, this procedural distinction does not limit the corrective powers available once an infringement within the scope of the complaint has been identified.The Court distinguished the origin and scope of an inquiry from the corr