DPC GDPR Enforcement Patterns: Six Technology Failures That Trigger Action

The DPC’s headline fines get the coverage. What’s more useful for a technology function is the pattern underneath them — the specific, repeated technology failures that turn a complaint into an enforcement decision.

As lead supervisory authority for many of the world’s largest technology platforms under the GDPR’s one-stop-shop mechanism, the Irish Data Protection Commission handles the largest cross-border GDPR inquiries in the EU, and its cumulative fines since 2018 exceed the totals of most other national authorities combined. But the DPC’s docket isn’t only Big Tech — it processed over 11,000 new cases in 2024 alone, a steady stream of which concern ordinary Irish-established controllers of every size. Reading the pattern across recent decisions is more useful to a technology function than the fine totals: it shows exactly which technical failures the DPC keeps finding.

Who this is for

  • The CTO or data protection lead at an Ireland-established controller trying to prioritise a limited remediation budget against real enforcement risk, not hypothetical risk.
  • The compliance officer building the case for investment in subject access request tooling or breach detection.
  • The board member who wants to know what actually triggers a DPC inquiry, rather than a general GDPR risk briefing.

What the complaint volumes actually show

The DPC’s own reporting on complaint categories is instructive before getting to the specific decisions: the right of access accounts for roughly a third of all complaints received, fair processing around a sixth, and the right to erasure close behind. These aren’t exotic, high-conceptual GDPR arguments — they’re operational failures in systems that are supposed to handle routine data subject requests correctly, at scale, under time pressure.

Free · 4 minutes

When two of your systems disagree, do you know which one to believe?

Fourteen questions on ownership, lineage, and quality — the difference between a number on a dashboard and a number you could defend. Banded finding on screen, full sheet by email.

Six patterns, read from recent decisions

1. Subject access requests that don’t actually complete. In a 2025 decision, the DPC found a systemic failure in a major operator’s handling of a rectification request and a series of follow-on subject access requests — the underlying technical process for locating, verifying, and returning all relevant personal data hadn’t held up under a real request. The lesson for a technology function: an SAR workflow that works in testing with clean, well-structured data often fails against the messy, distributed reality of production systems, and that gap is exactly where DPC findings land.

2. Third-party personal data tangled up in access requests. DPC guidance published in March 2025 specifically addresses how Article 15 applies where third-party personal data appears in documents that otherwise fall within an access request’s scope. A retrieval system that can’t technically separate the requester’s data from an unrelated third party’s data embedded in the same record or document creates a compliance failure on every request that touches shared records — a common architecture gap in CRM and case-management systems not originally designed with this separation in mind.

3. Cross-border transfer arrangements that don’t survive scrutiny. The DPC’s largest 2025 decision concerned unlawful transfers of personal data outside the EEA — a Chapter V failure. The decision reflects a regulator willing to scrutinise the actual technical and contractual transfer mechanism in detail, not accept a general assertion that “appropriate safeguards” exist. Transfer mapping needs to trace where data physically moves, not just where a data processing agreement says it should.

4. Breach notification and response processes that don’t hold up under repeat incidents. A decision concerning a series of linked data breach notifications from the same organisation over an extended period shows the DPC treating recurring incidents as a pattern worth deeper own-volition inquiry, not isolated events each assessed independently. A remediation plan that addresses the specific incident without addressing the systemic cause invites exactly this kind of follow-up scrutiny.

5. Facial recognition and biometric processing without adequate lawful-basis and transparency groundwork. A completed DPC inquiry into a public body’s processing of biometric facial templates reflects growing regulatory attention on biometric technology specifically — an area where the underlying technical processing (template generation, matching, retention) often runs ahead of the documented lawful basis and transparency notices that are supposed to govern it.

6. Article 12 response-timeline failures compounding into bigger findings. A pattern visible across several decisions: an initial, relatively minor failure to meet Article 12’s one-month response timeline for a rectification or access request escalates because the failure wasn’t isolated — the same organisation subsequently mishandled the follow-on erasure request the delay itself provoked. Timeline compliance failures rarely stay contained; a technology function’s SAR and rectification tooling needs response-time monitoring built in, not tracked manually against a deadline that’s easy to miss under operational pressure.

What this means for where remediation budget goes

None of the six patterns above are novel legal theories — they’re operational and architectural gaps in systems built for a different purpose than reliably serving GDPR data-subject rights at scale. That’s useful, because it means the fix is largely a technology investment, not a legal one: SAR tooling that can technically separate co-mingled third-party data, transfer mapping that tracks physical data location rather than paper agreements, and response-time monitoring built into the workflow rather than tracked in a spreadsheet.

A fine issued is not the same as a fine collected

Freedom-of-information data has shown organisations collectively owe the DPC billions of euros in imposed fines, with only a small fraction actually collected — a gap the DPC attributes to the court confirmation process large fines go through, and to ongoing appeals rather than any suggestion the fines are considered uncollectable. For a board weighing the real deterrent effect of DPC enforcement, this is worth understanding accurately: a headline fine figure doesn’t mean the money has changed hands, and a large decision under active appeal — as several recent ones are — can remain legally unresolved for years. None of this reduces the operational cost of an inquiry itself, which typically runs for years and consumes significant internal resource regardless of the eventual fine outcome or its collection status.

Also worth tracking forward: an EU regulation to speed up and harmonise cross-border GDPR enforcement procedures has been agreed and is expected to apply from around Q1 2027, specifically addressing the multi-year inquiry timelines that have characterised DPC cases to date. A technology function’s remediation planning should assume enforcement will get faster, not slower, over the next planning cycle.

How we engage with this

We read data architectures against the DPC’s actual enforcement patterns — not a generic GDPR checklist — as a Data Governance Review. The output is a written assessment identifying which of these six failure modes your systems are exposed to, and what closing each gap actually requires.

We don’t handle subject access requests on a client’s behalf. We don’t represent organisations to the DPC. We don’t sell privacy management software. We read what’s there, identify what’s missing, and write it down for the people who have to decide what to do about it.

Pricing is published at /pricing/. If your SAR and breach-response tooling hasn’t been tested against how the DPC actually finds against organisations, the place to start is a conversation.

Sixteen Pillars is a technology governance consultancy based in Cyprus. Engagements run remote across the EU, UK, and Middle East, with on-site time where the engagement requires it.

Free interactive tool

Website compliance checklist

What your site has to do, based on what it actually does

Answer as much or as little as you like — the list builds as you go. Nothing is stored against your name and no email is required.

Free interactive tool

Interactive deadline calculator

Check which regulations apply to you and when

Regulation across the EU, UK, US and Asia-Pacific has moved considerably in the past eighteen months, and several headline dates have shifted more than once. Twelve questions, about three minutes.

Results are shown on screen — no email required. A dated summary is available to download, and can be sent on if that's more useful. What we do with your answers.

Most technology problems are not technology problems. They are control problems.

The systems exist. The investment has been made. The question is whether leadership can understand, direct, evidence, and sustain what those systems produce. Find out where control exists — and where it only appears to.

Full Governance by Sixteen Pillars

Govern your business. Prove your compliance.

A board assurance cockpit for EU-regulated financial firms — tamper-evident, hash-chained proof of governance across DORA, GDPR, NIS2, ISO 27001, the EU AI Act and MiCA. In development.

See what's coming