Legal & Compliance

Ireland’s DPC reports a sharp jump in direct-marketing enforcement

Ireland’s Data Protection Commission (DPC) published its Annual Report for 2025 on 30 June 2026, and buried within the headline GDPR numbers is a figure that should register with every email marketing team operating in or from Ireland. The regulator concluded 275 electronic direct-marketing investigations in 2025, an 88 per cent increase on 2024, and issued 50 warning letters to companies over unsolicited marketing communications. The report also records 245 new complaints in the category. For a regulator best known internationally as lead supervisory authority for the technology giants established in Dublin, the numbers show domestic e-privacy enforcement scaling up sharply alongside the marquee caseload.

The numbers in context

The trajectory is what matters. In 2024 the DPC concluded 146 electronic direct-marketing investigations and issued 49 warning letters. A year later the investigation count has nearly doubled while the warning-letter output held steady, which suggests the regulator is working through a larger caseload rather than simply escalating everything it touches. The 2024 complaint data also tells email teams where the exposure sits: of the 198 direct-marketing complaints received that year, 70 per cent concerned unsolicited email and 24 per cent unsolicited SMS.

The wider report describes a regulator under unprecedented demand. The DPC received 16,160 new cases from individuals in 2025, a 45 per cent increase on 2024, and concluded 11,734. It closed 208 valid cross-border complaints as EU and EEA lead supervisory authority, up 43 per cent. Administrative fines reached €530.77 million for the year, dominated by two TikTok penalties totalling €530 million connected to transfers of user data to China, bringing cumulative fines since May 2018 to €4.04 billion.

How the enforcement pipeline works

The DPC investigates and prosecutes direct-marketing offences under Ireland’s ePrivacy Regulations 2011, and its established pattern gives senders a clear map of the escalation path. Warning letters come first. Prosecution follows for companies that received a prior warning and failed to fix inadequate marketing processes. In 2024 the DPC prosecuted eight companies for sending unsolicited marketing without consent, with the courts directing charitable contributions totalling €9,725 in lieu of conviction and fine. Every one of those eight had been warned beforehand.

The financial penalties are modest by Australian or American standards. The consequence that matters is different. A prosecution under the ePrivacy Regulations is a criminal matter, it is public, and it lands on companies that ignored a regulator’s direct instruction to fix their consent and suppression handling. Fifty warning letters issued in 2025 means fifty companies now sitting one failure away from that outcome.

Part of a global pattern

Ireland’s numbers arrive in the same season as escalating everyday-marketing enforcement elsewhere. Within Europe, the DPC’s caseload sits alongside the CNIL and Garante tracking pixel rules and the EDPB’s transparency sweep, a landscape we mapped in our analysis of why the real email crackdown came from Paris and Rome, not Brussels. Further afield, Australia’s ACMA has extracted more than A$12 million in spam and telemarketing penalties over 18 months, including the A$3.96 million Latitude Finance penalty and this week’s [A$2.7 million action against TAB](INTERNAL LINK: TAB/ACMA story), and we have tracked the broader shift towards sustained regulatory oversight of routine campaign mechanics. In the United States, the Washington CEMA litigation wave applies private-action pressure to the same behaviours. Different jurisdictions, different instruments, one consistent target: consent, suppression, and identification failures in ordinary marketing programmes.

What this means for senders with Irish entities

International ESPs, publishers, retailers, and SaaS vendors with Irish establishments should stop treating Ireland purely as a big-tech GDPR jurisdiction. The annual report describes an operational posture actively focused on everyday direct-marketing compliance, and that raises the risk profile for programmes with weak unsubscribe handling, poor channel governance, or unclear lawful-basis records. Irish establishment has been treated by some pan-European messaging operations as a quiet compliance base while the DPC’s attention sat elsewhere. The 2025 numbers say otherwise. Teams should expect scrutiny of routine campaign mechanics, document their consent and suppression logic end to end, and treat a DPC warning letter, if one arrives, as the final opportunity it is designed to be.

Subscribe

Personalise your own newsletter

Step 1 of 3

What would you like to receive?

Pick the option that suits you best. You can always change this later.

Strategic Partners

Enterprise Members

Vendor Directory