Ireland data protection newsletter – Issue 24

In this issue, we explore a number of significant developments shaping the privacy and regulatory landscape across Europe and beyond.

Recent months have seen important developments that could shape how organisations transfer personal data internationally, manage marketing and advertising activities and prepare for evolving AI obligations. The EU-US Data Privacy Framework has come under renewed scrutiny following the US Supreme Court’s ruling in Trump v. Slaughter, while the European Data Protection Board has approved GDPR certification as a new transfer mechanism for international data transfers.

Regulators also continue to focus on transparency, lawful basis and accountability. A significant enforcement action by the Norwegian Data Protection Authority relating to social media-based marketing highlights the importance of obtaining valid consent and providing clear information about data-sharing practices. Recent fines issued by the Irish Data Protection Commission to the HSE and Permanent TSB further demonstrate the consequences of inadequate security controls, weaknesses in governance arrangements and failures to meet breach reporting obligations.

Alongside these data protection developments, the European Commission has proposed further amendments to the AI Act through the Digital Omnibus package. The proposals include revised implementation timelines for high-risk AI systems, changes to transparency obligations for generative AI providers and a reduction in certain compliance requirements. As negotiations continue, organisations should closely monitor developments and consider how upcoming changes may affect their AI governance and compliance programmes.

In this issue

  • International transfers – Trump v. Slaughter and the impact on the EU-US Data Privacy Framework.
  • GDPR certification approved as a transfer mechanism.
  • Social media-based marketing – Norwegian regulator issues €1.7 million fine.
  • Midlands Regional Hospital Tullamore – HSE fined €300,000.
  • Permanent TSB fined €277,500.
  • Digital Omnibus package and proposed changes to the AI Act.
  • Key actions for organisations managing data protection and AI compliance.

Contact