Irish High Court Shifts Compliance Burden to Microsoft in GDPR Real-Time Bidding Case
The Irish High Court's ruling clarifies that once a data subject or representative body demonstrates that a controller is processing personal data in a way that engages GDPR obligations, the burden shifts to the controller to prove compliance — not the other way around. Microsoft's Xandr real-time bidding platform is alleged to have violated GDPR by sharing personal data with thousands of advertisers without adequate legal basis or transparency. This case highlights that ad-tech ecosystems, which rely on mass automated data sharing, carry significant regulatory exposure that organisations often underestimate. The ruling matters broadly because it makes it operationally harder for controllers to rely on procedural ambiguity as a defence, effectively raising the bar for demonstrable compliance across all data processing activities.
Tactical Insight
Immediate actions
- Conduct a GDPR Article 30 Records of Processing Activities (RoPA) audit specifically covering all third-party data-sharing integrations, including ad-tech and RTB platforms.
- Review and document the lawful basis for each category of personal data shared via real-time bidding or programmatic advertising systems.
Long-term improvements
- Implement a Data Protection by Design and by Default framework (GDPR Article 25) ensuring personal data minimisation is enforced at the platform architecture level.
- Establish a formal vendor due diligence programme that assesses GDPR compliance posture of all data processors and sub-processors before onboarding.
- Appoint or empower a Data Protection Officer (DPO) to continuously monitor regulatory developments and proactively audit high-risk processing activities.
Detection & response measures
- Deploy ongoing monitoring of data flows to third parties using data loss prevention (DLP) tools capable of flagging unauthorised or undocumented transmissions of personal data.
- Establish a regulatory response playbook that prepares legal, privacy, and security teams to rapidly produce compliance evidence when challenged by regulators or representative bodies.