
Data Protection, Privacy and Cyber
We are consistently ranked as the market-leading data protection, data privacy and cyber group in Ireland, acting for many of the world’s highest profile data controllers with their main EU establishments in Ireland.
Quick Links
Quick Links
Data Protection and Privacy
We have advised on GDPR compliance projects on a global scale and we are actively advising many clients in relation to their response to regulatory investigations and enforcement actions undertaken by the Data Protection Commission and by other EU Data Protection supervisory authorities.
Our Group also provides strategic advice on the range of civil and criminal actions and investigations, as well as public law issues, that may arise under data protection legislation.
Cyber
We have advised on some of the highest profile data breach incidents in Ireland and internationally. We have acquired a depth of experience in cybersecurity matters, including incorporating proactive steps to comply with security laws and standards, responding to a cyber incident, engaging with law enforcement and data protection authorities and defending associated litigation.
We are regularly instructed in the immediate aftermath of a cyber-attack or data breach to advise on the legal and regulatory steps to be taken and to guide the board and senior management of an organisation through the containment, mitigation, investigation and resolution stages of a cyber-attack or breach.

Relevant Experience
- Advising on Legislative Compliance – including compliance with the Data Protection Acts 1988 to 2018 and the EU GDPR, the laws governing ePrivacy, the right to privacy established by the Irish Constitution and the right to private correspondence under Article 8 of the European Convention on Human Rights, including their interaction with other applicable laws of EU AI Act, Digital Services Act etc.
- Advising on Defending Enforcement Actions – we have market leading experience in advising domestic and multi-national clients on enquiries, investigations, prosecution, dawn raids and other enforcement actions undertaken by the Data Protection Commission and EU Data Protection Supervisory Authorities
- Advising on International Data Transfers – Ireland as a corporate data centre and trans border data flows, including Model Clauses, Binding Corporate Rules, EU-US Privacy Shield and other permitted means to legitimise the export and disclosure of personal data
- Advising on cyber-response policies and procedures and on incident management and regulatory reporting, having regard to legal obligations under the EU data protection and cyber security law, including the NIS2 Directive including the provision of cyber readiness workshop training to clients and boards of directors
- Advising on Data Protection in the Workplace – we have acted for some of the highest profile cases involving the theft or abuse of data in the workplace, working closely with our colleagues in our market leading Employment Group
- Advising on the procurement of technologies for regulated clients, having regard to obligations under DORA, the NIS Directives and the Cybersecurity Act, as applicable
- Advising on the containment, mitigation and investigation of cyber attacks and breaches, including advising on the legal and regulatory notifications to be issued and coordinating with An Garda Síochána Cyber Unit and the National Cyber Security Centre on the reporting and investigation of an attack where required
- Advising on any legal claims or proceedings arising from cyber incidents, such as negligence claims against third party providers or defence of compensation claims from affected individuals or other third parties
- Advising clients (corporates, financial institutions, state agencies) in legal actions arising from the unlawful use of confidential data by former employees and third parties
- Advising a range of technology and other clients in defending civil actions for alleged breach of the Data Protection Acts 1988 to 2018 and EU GDPR
Our Expertise
Related Content

Recent EU Digital Fairness Fitness Check Shines Light on Deceptive Patterns

Employee Monitoring at Work: Regulatory enforcement actions against excessive employee monitoring practices continue

Navigating Age Assurance in the Online World: A Statement from the EDPB

Spring Cleaning: Legislative Plans for Cybersecurity, Business Data, AI, and e-Evidence

The EU Commission Guidelines on prohibited AI practices under the AI Act – Part One

ePrivacy Regulation and AI Liability Directive potentially shelved

Circuit Court Considers GDPR Non Material Damages at the ‘Serious End of the Scale’

All the small things: EU – US transfers and non-material damages

“Manifestly Excessive” Requests Under the GDPR: Numbers Alone Are Not Enough

Summary of 2024’s Key CJEU Data Protection Judgments

SCCs in the Driving Seat: The Uber Decision

Are you Cyber Ready? Key Points of the NIS2 Directive

The e-Evidence Package: A New Regime for Cross-Border Law Enforcement Requests

Charities Law Update: Key Changes in the New Charities (Amendment) Act 2024

The Right to Compensation Under the GDPR: Key Takeaways from Recent Case Law of the Court of Justice of the European Union

Arthur Cox shortlisted in the FT Innovative Lawyers Awards Europe 2024

The Data Protection Commission’s 2023 Annual Report

European Data Protection Board’s Opinion on “Pay-or-Consent” models: a critical analysis

Recent CJEU Data Protection Decisions

New UK Addendum to EU Binding Corporate Rules

Watching the Clock – Employee Monitoring at Work

AI & Practical Legal Tips: Contracting Considerations in the Procurement of AI Solutions

Jurisdiction to hear data protection actions extended to the District Court

Data and Digital Leadership Video Series

Data and Digital Leadership Survey results launched

Arthur Cox and the 8th Annual International Network of Privacy Law Professionals Conference

Processing Children’s Personal Data Correctly: Some Takeaways from the Data Protection Commission’s recent TikTok Decision

The Future of One Stop Shop: Part 1

Changes for ‘Over The Top’ communications services following their inclusion within the European Electronic Communications Code

Digital Reform Video Series

Data transfers to the United States under the GDPR following adoption of the adequacy decision on 10 July 2023

‘Modest’ Compensation for GDPR Non-Material Damage Claim: New Guidance from the Irish Courts

Digital Reform – Preparing for a New Data-Driven World: The Data Governance Act

Collective Litigation in Ireland: A Guide to the new Representative Actions Mechanism

Key considerations for fintech providers

Records of Processing Activities – DPC issues Welcome Guidance

GDPR Enforcement: The Use of Reprimands by the Data Protection Commission

The Data Protection Commission’s 2022 Annual Report

Security Matters business combination with Lionheart III Corp

Circuit Court grants stay awaiting the Court of Justice of the European Union decisions on data breach claims for non-material damages

Security Matters Limited merger with Lionheart III Corp

Cambrex Corporation acquisition of Q1 Scientific Limited

Stanford Digital Economy Best Practices Conference

Ensuring cyber resilience for connected products

Withdrawal of Consent – What Steps Must a Controller Take?

‘Mere Upset’ Not Sufficient for GDPR Compensation Claims

When one thing leads to another: Employer’s use of CCTV Footage in Disciplinary Hearings

Update on key EU operational resilience and cybersecurity legislative developments

New Corporate Enforcement Authority established in Ireland

The Data Protection Commission’s 2021 Annual Report

Introduction of New UK Standard Contractual Clauses for Personal Data Transfer

Practical Law Global Guide: Doing Business in Ireland

EDPB draft guidelines on data subject access requests (“DSARs”): key points

Arthur Cox contributes to impact assessment for the proposal for the EU Data Act

International Comparative Legal Guide: Digital Health 2022

Lloyd v Google LLC [2021] UKSC 50: UK Supreme Court holds that “loss of control” of personal data is not compensable per se

The Irish Courts strengthen their position as a jurisdiction for resolving IP and technology disputes

The Corporate Enforcement Authority: An Important Step Towards Corporate Crime Enforcement Reform

ePrivacy: EU Regulation Introduced to Allow Companies to Tackle Online Child Sexual Abuse

Arthur Cox contributes to ICLG Data Protection 2021

Permanent changes for the WRC and the wider implications of the recent Supreme Court decision in Zalewski

Employer entitled to use WhatsApp messages, uncovered during criminal investigation, in subsequent workplace investigation

Beyond Schrems II: A recent French decision considers data transfer rules where personal data is hosted by a subsidiary of a US company in the EU

Data Protection Commission: Emerging Views on Legal Privilege

Data Protection Commission Investigations: Insights from the Annual Report

Legal Privilege and Regulators – The DPC Speaks

Data Protection Commission Publishes Decisions from 2020

The Data Protection Commission’s 2020 Annual Report at a Glance

Reach of the GDPR: UK Case Examines Territorial Scope

Article 49 Derogations for Data Transfers: Time for a reassessment?

Children’s Data: A Comparison of the DPC and ICO’s Approaches

Fun-damentals and Games: The DPC’s Fundamentals for Processing of Children’s Data

GDPR: No changes to the application of One-Stop Shop for cross-border processing in recent Opinion of Advocate General

EU-UK Trade and Cooperation Agreement defers application of UK’s status as a ‘third country’ under GDPR

Enhanced powers for investigating corporate crime on the horizon

Staying on the Right Side of the Law: Responding to Law Enforcement Requests in Compliance with the GDPR

Court of Appeal finds memoranda relating to an audit are not personal data on foot of data access request

The Ruling in Schrems II

Trends in GDPR Enforcement

Keeping Data Secure While Working Remotely

UK Supreme Court allows appeal in landmark decision on employers’ liability in class action for mass data breach by employee

DPC Publishes Guidance on Cookies and Report on Cookie Sweep

“Members only club”: Court of appeal upholds appropriateness of confidentiality rings/clubs for discovery

DPC doing its homework – Public Consultation promotes protection of children’s personal data

Data Protection: EU Regulatory Update and Horizon Scanning

Financial Services and Cyber Security Obligations under the Network and Information Systems Directive in Ireland

Representing The Class: New Procedural Rules For Representative Actions Under The Data Protection Act 2018

Can we Protect our Businesses from Cyber Threats? New EU Cyber Security Regulations Published
Insights Blog

Representative Actions in Ireland: 2024 in Review

GDPR Compensation: Some Welcome Clarity from the CJEU

Criminal Sanction for Data Protection Issues

New ICO Guidance on Children’s Data

Individuals are entitled to know the specific recipients of their personal data

No Blue Ticks: Limitations to Employer Use of Employee WhatsApp Messages in Litigation
