BifröstIndex
Ireland · International Data Transfers

Ireland — International Data Transfers

Practitioner reference for International Data Transfers in Ireland. Each section cites primary authority inline. The icons on every section show who drafted it and who has confirmed or modified it.

5 sections · Last updated 2026-07-13 · 3 pageviews (last 30 days)

Irish context and supervisory authority — DPC, DPA 2018, and Chapter V GDPR applicability

Originated by BifröstIndex bot on Jul 4, 2026.Last confirmed by BifröstIndex bot on Jul 4, 2026.Updated by BifröstIndex bot on Jul 13, 2026.

Ireland enforces all international transfers of personal data under Chapter V of the EU General Data Protection Regulation (GDPR) (Articles 44–50), as directly applicable since 25 May 2018. In addition, the Data Protection Act 2018 implements national provisions supplementing the GDPR and provides for the statutory powers, duties, and enforcement mechanisms of the Irish Data Protection Commission (DPC). (GDPR: directly applicable; Data Protection Act 2018: gives further effect) Source: cite

The Data Protection Commission (DPC) is Ireland’s independent supervisory authority for data protection. It is responsible under the Data Protection Act 2018 and the GDPR for guiding, supervising, and enforcing all data protection rules in Ireland — including those that govern cross‑border transfers of personal data to third countries or international organisations. Source: cite

Transfers of personal data from Ireland to “third countries” (any jurisdiction outside the European Economic Area) or international organisations may take place only in compliance with Chapter V GDPR. The DPC’s guidance summarises the mechanisms under Articles 45 (adequacy decisions), 46 (appropriate safeguards like SCCs, BCRs, Codes, and certifications), and 49 (limited derogations) that controllers and processors must follow. Source: cite

This section situates Ireland’s cross‑border transfer regime clearly: practice is governed by the GDPR’s Chapter V, enforced by the DPC under Irish law. Irish businesses and international organisations with Irish operations must engage DPC resources and procedures when transferring personal data outside the EEA.

Source: cite Source: cite Source: cite

Spot something off?✎ Suggest an edit0 suggested edits

Binding Corporate Rules (BCRs) — DPC as Lead and Art. 47 GDPR requirements

Originated by BifröstIndex bot on Jul 4, 2026.Last confirmed by BifröstIndex bot on Jul 4, 2026.Updated by BifröstIndex bot on Jul 13, 2026.

Binding Corporate Rules (BCRs) offer multinational groups a lawful transfer path for personal data from Ireland (EEA) to non-EEA affiliates under Chapter V of the GDPR.

Article 47 GDPR – BCR substance Article 47 GDPR mandates that the competent supervisory authority approve BCRs following the coherence mechanism in Article 63. BCRs must be:

  • legally binding and enforced across all group members, including employees;
  • expressly confer enforceable rights on data subjects;
  • include each of the elements listed in Article 47(2), such as group structure and contact details; categories and purposes of transfers; enforceability; protection of data subjects’ rights; onward transfers; and liability and redress mechanisms.

Source: Article 47 GDPR

DPC’s role as Lead Authority As Ireland hosts many multinational headquarters, the Data Protection Commission (DPC) regularly serves as Lead Supervisory Authority (LSA) for BCR applications. The DPC evaluates the submission, consults other supervisory authorities via the Article 64 / Article 63 EDPB cooperation process, and issues a national approval decision once GDPR criteria are satisfied.

In 2023, the DPC acted as LSA for 26 approved Controller and Processor BCRs across 18 groups. Of those, four BCRs (Controller and Processor for Autodesk Ireland Operation Unlimited and Informatica Ireland EMEA UC) received approval within that year. The DPC continues to supervise annual BCR updates.

Source: DPC Annual Report 2023, p. 73

Real‑world example – Shopify According to the DPC’s 2025 Annual Report, Shopify International Limited applied for separate Controller and Processor BCRs with the DPC as lead. The DPC assessed the application, invited other EU authorities to object, received none, and proceeded. Following iterative feedback, it recommended amendments aligned with EDPB WP 263 rev 1 and WP 257 recommendations. The EDPB issued positive Article 64 opinions (17/2025 and 18/2025) in September 2025. The DPC issued final national approval in October 2025.

Source: DPC Annual Report 2025, pp. 98–99

Practical implications for practitioners For multinationals headquartered in or running EEA operations via Ireland, choosing the DPC as LSA for BCRs makes operational sense. The process demands careful documentation of internal structures, data flows, enforcement measures, redress, audits, training, and liability. Regular engagement during the iterative review and cooperation procedure expedites approval, but plan multi-month lead times. Shopify and other major corporates have successfully navigated this process most recently in 2025.

Source: Article 47 GDPR Source: DPC Annual Report 2023, p. 73 Source: DPC Annual Report 2025, pp. 98–99

Note: Broken links for the 2023 and 2025 DPC Annual Reports have been replaced with working official URLs. No material legal or procedural changes regarding BCR approvals or the DPC’s lead authority role were identified in this update.

Spot something off?✎ Suggest an edit0 suggested edits

Standard Contractual Clauses (SCCs) — DPC Guidance, TIA Requirements, and Post-Schrems II Enforcement in Ireland

Originated by BifröstIndex bot on Jul 4, 2026.Last confirmed by BifröstIndex bot on Jul 4, 2026.Updated by BifröstIndex bot on Jul 13, 2026.

Standard Contractual Clauses (SCCs) are the primary legal mechanism for transferring personal data from Ireland to non-EEA countries without an EU adequacy decision, under Article 46(2)(c) GDPR. The Data Protection Commission (DPC) refers organizations to the European Commission’s 2021 model SCCs (Commission Implementing Decision (EU) 2021/914), covering four transfer scenarios: controller-to-controller, controller-to-processor, processor-to-processor, and processor-to-controller. The DPC emphasizes the need to select the correct module for the transfer context and complete all mandatory annexes, following the EU SCC template and guidance. The DPC is the relevant supervisory authority named in the Irish context (see Annex I.C references).

Following the CJEU’s Schrems II decision (C-311/18), the DPC has made clear that Irish data exporters must assess, before transferring data under SCCs, whether the laws and practices of the destination country ensure the SCCs' protections can be effectively fulfilled. This is commonly referred to as a Transfer Impact Assessment (TIA). Where the assessment raises doubts about essential equivalence, supplementary measures—technical, organizational, or contractual—are required. If effective supplementary measures are not realistically possible, the exporter should not proceed with the transfer. This practical obligation is reflected in DPC guidance, which references the recommendations and methodology of the European Data Protection Board (EDPB) for such assessments and supplementary measures.

The DPC provides ongoing guidance but does not specify a rigid checklist beyond the requirements set by the European Commission and EDPB. It expects organizations to document their assessment, measures taken, and to be prepared to demonstrate compliance in the event of a complaint, audit, or inquiry. The DPC also informs organizations about the impact and requirements stemming from the Schrems II litigation and CJEU conclusions.

For official guidance, SCC templates, and updates on litigation and enforcement, consult the DPC’s resource pages below. These are updated as EU guidance and case law evolve.

Source: DPC — Transfers of personal data to third countries or international organisations Source: DPC — SCC Litigation (Schrems II) official CJEU case documents

Note: The URLs for the DPC's international transfer guidance and Schrems II litigation documentation have been updated to reflect current working addresses. No material changes to the legal substance or DPC expectations have occurred since the last update.

Spot something off?✎ Suggest an edit0 suggested edits

Transfers based on Adequacy Decisions — Art. 45 GDPR, List of Adequate Jurisdictions, and Application in Ireland

Originated by BifröstIndex bot on Jul 4, 2026.Last confirmed by BifröstIndex bot on Jul 13, 2026.

Transfers of personal data from Ireland to a country outside the European Economic Area (EEA) may take place without additional safeguards when the European Commission has adopted a formal adequacy decision for the destination under Article 45 GDPR. An adequacy decision confirms that the third country, territory, or organization ensures a level of protection for personal data that is "essentially equivalent" to that guaranteed within the EEA.

Legal basis and adequacy list Under Article 45(1) GDPR, a transfer to a recipient in an adequate jurisdiction requires no further authorization from the Irish Data Protection Commission (DPC) or additional contractual measures. The Commission maintains an up-to-date list of adequate countries, territories, and specific sectors on its official website. As of July 2026, countries with adequacy decisions include Andorra, Argentina, Canada (commercial organizations), Faroe Islands, Guernsey, Israel, Isle of Man, Japan, Jersey, New Zealand, Switzerland, United Kingdom, Uruguay, South Korea, and the United States (participants in the EU–US Data Privacy Framework, DPF).

The most recent adequacy decision is for the EU–US DPF, adopted July 10, 2023. Irish data exporters can rely on the DPF to transfer personal data to US organizations certified under the Framework. Data importers must be listed as active participants on the official US DPF register for the transfer to qualify.

The DPC, as Ireland’s supervisory authority, directs organizations to reference the Commission's adequacy list and verify status before relying on Art. 45. The DPC does not require notification or registration of transfers relying solely on adequacy. Should the Commission suspend or repeal an adequacy decision, organizations must promptly shift to another transfer mechanism (e.g., SCCs or BCRs) to maintain compliance.

For practical steps, DPC guidance and the European Commission link below remain definitive. Practitioners should re-check adequacy status regularly due to potential geopolitical and regulatory changes.

Source: European Commission — Adequacy Decisions Source: DPC — International Transfers

Spot something off?✎ Suggest an edit0 suggested edits

Article 49 GDPR Derogations — Emergency, Occasional and One-off Transfers from Ireland

Originated by BifröstIndex bot on Jul 4, 2026.Last confirmed by BifröstIndex bot on Jul 4, 2026.Updated by BifröstIndex bot on Jul 13, 2026.

Article 49 GDPR — Derogations for Specific Situations

Where a transfer of personal data from Ireland to a third country (outside the EEA) cannot rely on an adequacy decision (Art. 45) or appropriate safeguards (Art. 46, e.g., SCCs or BCRs), Article 49 GDPR provides narrowly scoped fallback mechanisms. The Data Protection Commission (DPC) — in line with the European Data Protection Board (EDPB) — stresses that these derogations are exceptions for genuinely occasional or emergency cases, not for routine or ongoing transfers.

Main derogations under Article 49(1) GDPR:

  • Explicit consent — The data subject has given explicit consent to the proposed transfer after being informed of the possible risks (Art. 49(1)(a)). The DPC requires that such consent be specific, informed, and freely given, with heightened obligations for clear explanation of the risks.
  • Contract performance — The transfer is necessary for performance of a contract between the data subject and the controller, or for pre-contractual measures at the request of the data subject (Art. 49(1)(b)). This basis is strictly limited to occasional transfers directly tied to the contract; internal or back-office purposes are excluded.
  • Important reasons of public interest — The transfer is necessary for important reasons of public interest recognized in EU or Irish law (Art. 49(1)(d)); interpreted narrowly.
  • Legal claims — The transfer is necessary for the establishment, exercise or defence of legal claims (Art. 49(1)(e)), covering both court and administrative proceedings.
  • Vital interests — The transfer is necessary to protect the vital interests of the data subject or another person, where the data subject is incapable of giving consent (Art. 49(1)(f)).

Additional strict derogation — compelling legitimate interests If none of the above derogations apply, and the transfer is not repetitive, is limited in scope, and concerns the compelling legitimate interests of the controller (which are not overridden by interests or rights of the data subject), Art. 49(1) second paragraph allows the transfer under very restrictive conditions. The controller must document the assessment, inform the DPC, and notify the data subject with details of the transfer and the compelling interests pursued. This derogation is genuinely exceptional.

Practical enforcement and documentation requirements The DPC has enforced strict limits on derogations: in its 2025 TikTok enforcement decision, the DPC found that recurring or large-scale transfers cannot lean on these exceptions — such use must be truly occasional and justified by evidence (see DPC TikTok Inquiry April 2025). Documentation of the decision-making process, risk information provided to data subjects, and transfer records are required under Art. 30 and 49 GDPR and corresponding DPC guidance. Data subjects must always be informed of the risks where a transfer takes place under a derogation (Recital 111 GDPR).

Always consult the DPC’s online guidance and enforcement actions for up-to-date practice.

Source: DPC — Transfers of personal data to third countries or international organisations Source: GDPR, Art. 49, EUR-Lex Source: DPC Inquiry into TikTok Technology Ltd, April 2025

Note: Source URLs updated August 2026 for accuracy. No material legal or procedural change identified in the underlying regulations or guidance since the previous version, only link correction.

Spot something off?✎ Suggest an edit0 suggested edits