Network and Information Security Directive (NIS2)

🇮🇪Network and Information Security Directive in Ireland

A comprehensive guide to Network and Information Security Directive compliance for organisations operating in Ireland. Understand local enforcement, the national data protection authority, key focus areas, and notable enforcement actions.

About Network and Information Security Directive

The updated EU cybersecurity directive that expands security requirements to a broader range of sectors and imposes stricter obligations on essential and important entities.

Effective: 18 October 2024Max penalty: €10,000,000 or 2% of total annual worldwide turnover
Full Network and Information Security Directive overview

Network and Information Security Directive Enforcement in Ireland

Ireland's DPC holds outsized importance in EU data protection as the lead supervisory authority for most major US technology companies with European headquarters in Ireland, including Meta, Google, Apple, Microsoft, TikTok, and Twitter/X. The DPC has been both criticised for the pace of its investigations and praised for the scale and impact of its eventual decisions, which have included some of Europe's largest GDPR fines. The Irish Data Protection Act 2018 supplements the GDPR with provisions on children's data (age of consent set at 16), law enforcement processing, and exemptions for journalism and research. The DPC's cross-border decisions frequently trigger the GDPR's consistency mechanism, involving other EU DPAs and sometimes the European Data Protection Board (EDPB) through binding dispute resolution.

NIS2 Transposition Status in Ireland

In Progress

Data Protection Authority

Key Enforcement Focus Areas in Ireland

  • Big Tech enforcement (Meta, Google, Apple, Microsoft, TikTok)
  • Cross-border enforcement and EDPB cooperation
  • Children's data protection
  • International data transfers to the US
  • Behavioural advertising and consent mechanisms

Notable Enforcement Actions in Ireland

Meta Platforms Ireland (Facebook)

€1,200,000,000(2023)

Transferring EU user data to the US without adequate data protection safeguards following Schrems II

Meta Platforms Ireland (Instagram)

€405,000,000(2022)

Processing children's personal data including phone numbers and email addresses of minors with public accounts

Meta Platforms Ireland (WhatsApp)

€225,000,000(2021)

Transparency failures in informing users and non-users about WhatsApp's data processing practices

TikTok Technology Limited

€345,000,000(2023)

Failing to protect children's privacy by defaulting minors' accounts to public and enabling features exposing them

Check Your Compliance Status

Take our free assessment to evaluate your organisation's compliance posture. Get a personalised report with actionable recommendations in minutes — no sign-up required.

Start Free Assessment

Disclaimer: The information on this page is for educational purposes and does not constitute legal advice. For specific compliance guidance, consult a qualified legal professional in your jurisdiction.

Other Regulations Affecting Ireland