High Court - 2026 IEHC 640
High Court rules controller must prove GDPR compliance once engaged.
Summary
The Irish High Court has ruled on the burden of proof in GDPR infringement cases. While not creating a general reversal, the court determined that once a claimant establishes the defendant is a controller and GDPR obligations are engaged, the controller must then prove its compliance. This ruling clarifies pleading requirements and access to information in representative actions.
Full text
Help High Court - 2026 IEHC 640: Difference between revisions From GDPRhub Jump to:navigation, search ← Older editVisualWikitext Revision as of 08:06, 5 October 2026 view sourceBms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators355 editsTag: Visual edit← Older edit Latest revision as of 13:49, 6 October 2026 view source Bms (talk | contribs)Bureaucrats, Interface administrators, noContributionReport, Administrators355 editsTag: Visual edit Line 108: Line 108: }}}} A high court held that [[Article 5 GDPR|Articles 5(2)]] and [[Article 24 GDPR|24(1) GDPR]] do not generally reverse the burden of proof, but the controller must prove compliance once the relevant GDPR obligations are engaged.A court held that there is no general reversal of the burden of proof in civil procedures alleging GDPR infringements. However, according to the court, the controller has to prove GDPR compliance once the plaintiff proved controllership and the application of the GDPR. == English Summary ==== English Summary == Line 117: Line 117: A dispute subsequently arose concerning the burden of proof and the parties' pleading obligations. ICCL argued that [[Article 5 GDPR|Articles 5(2)]] and [[Article 24 GDPR|24(1) GDPR]] required the controller to demonstrate its compliance with the GDPR. Microsoft disputed that it was the relevant controller and argued that the ordinary rules of civil procedure placed the burden of establishing the alleged infringements on ICCL.A dispute subsequently arose concerning the burden of proof and the parties' pleading obligations. ICCL argued that [[Article 5 GDPR|Articles 5(2)]] and [[Article 24 GDPR|24(1) GDPR]] required the controller to demonstrate its compliance with the GDPR. Microsoft disputed that it was the relevant controller and argued that the ordinary rules of civil procedure placed the burden of establishing the alleged infringements on ICCL. The parties also disagreed about the information that had to be provided in the representative action. Microsoft sought further information concerning, among other things, the alleged infringements, the consumers affected and the funding of the proceedings. The High Court therefore determined several preliminary questions relating to the burden of proof, pleading requirements and access to information before the underlying GDPR allegations were decided.The parties also disagreed about the information that had to be provided in the representative action. Microsoft sought further information concerning, among other things, the alleged infringements, the consumers affected and the funding of the proceedings. The court therefore determined several preliminary questions relating to the burden of proof, pleading requirements and access to information before the underlying GDPR allegations were decided. === Holding ====== Holding === The High Court held that [[Article 5 GDPR|Articles 5(2)]] and [[Article 24 GDPR|24(1) GDPR]] do not create a general reversal of the legal or evidential burden of proof. The claimant must first establish the matters for which it bears the burden, including that the defendant is a controller and that processing takes place which engages the relevant GDPR obligations.The court held that [[Article 5 GDPR|Articles 5(2)]] and [[Article 24 GDPR|24(1) GDPR]] do not create a general reversal of the legal or evidential burden of proof. The claimant must first establish the matters for which it bears the burden, including that the defendant is a controller and that processing takes place which engages the relevant GDPR obligations. However, once those matters are established and compliance with a relevant GDPR obligation is at issue, the controller bears the legal and evidential burden of demonstrating compliance. In particular, where compliance with the principles in [[Article 5 GDPR|Article 5(1) GDPR]] or with the requirements covered by [[Article 24 GDPR|Article 24(1) GDPR]] must be determined, it is for the controller to prove that the relevant processing complies with those obligations. The Court considered this to follow from the accountability obligations.However, once those matters are established and compliance with a relevant GDPR obligation is at issue, the controller bears the legal and evidential burden of demonstrating compliance. In particular, where compliance with the principles in [[Article 5 GDPR|Article 5(1) GDPR]] or with the requirements covered by [[Article 24 GDPR|Article 24(1) GDPR]] must be determined, it is for the controller to prove that the relevant processing complies with those obligations. The Court considered this to follow from the accountability obligations. The High Court further held that the ordinary national rules on pleadings continue to apply to both parties. Each party must plead the material facts supporting the matters it is required to prove. Consequently, where the controller wishes to advance a positive case that it complied with the GDPR, it must plead the material facts on which that claim of compliance is based.The court further held that the ordinary national rules on pleadings continue to apply to both parties. Each party must plead the material facts supporting the matters it is required to prove. Consequently, where the controller wishes to advance a positive case that it complied with the GDPR, it must plead the material facts on which that claim of compliance is based. Regarding the representative action, the High Court held that [https://www.irishstatutebook.ie/eli/2023/act/22/enacted/en/print Sections 19(10)] and [https://www.irishstatutebook.ie/eli/2023/act/22/enacted/en/print 19(11) of the Representative Actions for the Protection of the Collective Interests of Consumers Act 2023] do not give the controller a standalone right to require the claimant to provide further information. However, the controller may rely on ordinary procedural mechanisms, including requests for particulars, discovery or disclosure under [https://www.irishstatutebook.ie/eli/2023/act/22/enacted/en/print Section 34(2)], where the applicable requirements are met, and may challenge the admissibility of the representative action.Regarding the representative action, the court held that [https://www.irishstatutebook.ie/eli/2023/act/22/enacted/en/print Sections 19(10)] and [https://www.irishstatutebook.ie/eli/2023/act/22/enacted/en/print 19(11) of the Representative Actions for the Protection of the Collective Interests of Consumers Act 2023] do not give the controller a standalone right to require the claimant to provide further information. However, the controller may rely on ordinary procedural mechanisms, including requests for particulars, discovery or disclosure under [https://www.irishstatutebook.ie/eli/2023/act/22/enacted/en/print Section 34(2)], where the applicable requirements are met, and may challenge the admissibility of the representative action. The High Court did not determine whether the processing through the Xandr platform actually infringed the GDPR. It also declined to determine certain additional questions, including the application of the "peculiar knowledge principle", because the necessary facts had not been agreed. No fine or corrective measure was imposed.The court did not determine whether the processing through the Xandr platform actually infringed the GDPR. It also declined to determine certain additional questions, including the application of the "peculiar knowledge principle", because the necessary facts had not been agreed. No fine or corrective measure was imposed. == Comment ==== Comment == Latest revision as of 13:49, 6 October 2026 High Court - 2026 IEHC 640 Court: High Court (Ireland) Jurisdiction: Ireland Relevant Law: Article 5(1)(f) GDPR Article 24 GDPR Section 19 Irish Representative Actions ActSection 23 Irish Representative Actions ActSection 34 Representative Actions Act Decided: 25.09.2026 Published: Parties: Microsoft Ireland Operations Limited Irish Council for Civ