Enforcement

What the Irish DPC's Cookie Enforcement Means for Your Website

Fabio Cerullo  ·  5 August 2026


For most European regulators, cookie enforcement means investigating websites that operate within their borders. For the Irish Data Protection Commission (DPC), it means something far more consequential — it means being the lead supervisory authority for a significant portion of the global internet.

The DPC's unique position

Under GDPR's "one-stop-shop" mechanism, a company established in one EU member state is supervised primarily by the data protection authority of that state — even if it operates across the entire EU. Ireland, with its favourable corporate tax regime, is the European headquarters for an extraordinary concentration of technology companies. Google, Meta, Apple, LinkedIn, Twitter/X, TikTok, Airbnb, Dropbox and hundreds of others have their EU establishments in Ireland, which makes the DPC their lead supervisory authority.

This means that when the DPC investigates a cookie compliance issue with Meta's advertising system, the consequences apply not just to Irish users but to all EU and EEA users. The DPC's enforcement decisions carry EU-wide effect. For companies establishing themselves in Dublin, this creates both an opportunity and a responsibility — and regulators across Europe have at times been critical of the pace of DPC enforcement.

Cookie enforcement history

The DPC's cookie enforcement has escalated significantly over the past four years. In 2022, the DPC conducted a sweep of 40 Irish websites across multiple sectors — retail, media, financial services, and public sector — and found the majority non-compliant in at least one material respect. The most common issues were cookies firing before consent, and consent banners that made rejection difficult relative to acceptance.

The DPC's 2023 and 2024 focus sharpened on dark patterns in consent interfaces — designs that manipulate users into consenting when they would otherwise not. This aligned with a broader European Data Protection Board (EDPB) initiative: a coordinated enforcement action on cookie consent across EU member states. National authorities swept their local markets simultaneously, creating a consistent EU-wide enforcement signal. The EDPB's guidelines on dark patterns (published in 2022 and updated since) remain the definitive reference for what constitutes manipulative consent design.

What the DPC specifically looks for

DPC audit activity and published guidance reveal a consistent set of red flags that attract scrutiny:

  • Cookies firing before consent. The DPC is explicit: if any non-essential cookie is set before the user has had the opportunity to make an informed choice, the consent is invalid regardless of what the banner looks like.
  • Reject buttons harder to find than Accept. Asymmetric button sizing, colour contrast, or placement — where "Accept all" is a prominent primary button and "Reject" requires navigating to a settings panel — is treated as a dark pattern that undermines freely given consent.
  • Cookie walls. Blocking access to content unless cookies are accepted (without a genuine paid alternative) is not considered freely given consent under the DPC's approach.
  • Vague or misleading descriptions. Cookie category descriptions that use marketing language rather than plain explanations of what is collected and by whom are treated as failures of the "informed" requirement.

The fines and sanctions landscape

GDPR fines can reach 4% of global annual turnover or €20 million, whichever is higher. At the scale of a company like Meta or Google, this translates to multi-billion euro exposure. The DPC has issued some of the largest GDPR fines in history — including a €1.2 billion fine against Meta in 2023 for data transfers to the US — though that specific case was about international transfers rather than cookies.

For cookie-specific violations, fines are typically based on the ePrivacy Directive, which in Ireland is implemented through the European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011. The maximum fines under ePrivacy are lower than GDPR, but the DPC's enforcement toolkit goes beyond fines. The DPC can issue formal reprimands (which are published and carry significant reputational consequences), binding enforcement notices requiring immediate remediation, and in cases of persistent or wilful non-compliance, referral to the Director of Public Prosecutions. For companies that depend on data-driven advertising revenue, a formal DPC reprimand can itself be more damaging than a fine.

Who is at risk

The obvious targets are multinationals with EU establishments in Ireland. But the DPC's reach is broader than that. Any website that targets Irish or EU consumers — regardless of where the company is incorporated — can be subject to complaint and investigation. A German user complaining about an American retailer's cookie practices can be directed to the Irish DPC if the retailer's EU establishment is in Dublin.

Smaller Irish businesses are also not immune. The DPC's 2022 sweep specifically included domestic Irish organisations. Complaints can be filed by anyone, and the DPC accepts complaints from EU residents about any website they encounter, regardless of the site's origin.

What the DPC does not accept

One of the most persistent misconceptions in cookie compliance is that analytics and advertising cookies can be justified on "legitimate interests" grounds under GDPR Article 6(1)(f). This is incorrect. Under the ePrivacy Directive, the legal basis for setting any non-essential cookie is consent — full stop. Legitimate interests is not an available basis for cookie deployment. The DPC has been unambiguous on this point, as has the EDPB. Any CMP or legal team suggesting that analytics cookies can be placed on legitimate interests is wrong, and acting on that advice creates direct regulatory exposure.

Practical steps to reduce your risk

  1. Audit what cookies your site sets and when. Use a tool that tests in a fresh browser session with no prior consent — this mirrors exactly what the DPC looks at when investigating a complaint.
  2. Verify that your CMP is actually blocking tags, not just displaying a banner. These are different things and the distinction is what regulators test.
  3. Review your banner design against the EDPB's dark patterns guidelines. Accept and Reject buttons should be visually equivalent. There should be no additional clicks required to reject compared to accepting.
  4. Check that your cookie descriptions are written in plain English, naming the specific tools used and what data they collect.
  5. Ensure your CMP logs consent with timestamps. If the DPC requests evidence of consent, you need to be able to produce it.
  6. Remove any "legitimate interest" reliance for analytics or advertising purposes from your privacy notice. It is not a valid basis under ePrivacy and will not withstand regulatory scrutiny.

The DPC's enforcement trajectory is clearly upward. The combination of coordinated EU-wide sweeps, published guidance on dark patterns, and an increasing volume of user complaints means the probability of a site being investigated for cookie violations — not just the penalty if it is — is rising year on year. The time to audit your implementation is before a complaint arrives, not after.

Would your site pass a DPC audit?

ConsentScan checks what cookies fire before consent using the same fresh-session approach regulators use. Get your report in under a minute.

Scan your site free →