Irish High Court Clarifies GDPR Compliance Burden of Proof for Data Controllers
The Irish High Court ruled that once a claimant establishes a defendant is a data controller with engaged GDPR obligations, the burden shifts to the controller to prove its own compliance. This case, involving Microsoft's Xandr real-time bidding platform, highlights that data controllers cannot passively assume compliance — they must be able to affirmatively demonstrate it. Real-time bidding ecosystems process vast amounts of personal data at scale, making documented accountability mechanisms essential. The ruling reinforces that GDPR's accountability principle (Article 5(2)) carries real legal weight in litigation and that controllers must proactively maintain and produce evidence of compliance.
Tactical Insight
Immediate actions
- Conduct a comprehensive audit of all data processing activities involving personal data to ensure documented lawful bases exist.
- Review and update Records of Processing Activities (RoPA) to accurately reflect current data flows, especially within ad-tech or real-time bidding platforms.
Long-term improvements
- Embed a data protection by design and by default framework into all product development and third-party platform integrations.
- Appoint or empower a Data Protection Officer (DPO) to continuously monitor and document GDPR compliance posture across all controller activities.
- Establish contractual accountability mechanisms with all data processors and sub-processors to ensure compliance obligations flow down the supply chain.
Detection & evidence measures
- Implement ongoing compliance monitoring and logging of consent records, data subject requests, and processing activities to build an auditable evidence trail.
- Schedule periodic Data Protection Impact Assessments (DPIAs) for high-risk processing activities such as behavioural advertising and profiling.