O’Brien v DPC: What Ireland’s High Court Data Protection Judgment Means for ICS Members

4–6 minutes

by Kieran Harte

The High Court’s decision in O’Brien v The Data Protection Commission and Ors [2026] IEHC 250 is one of the most significant Irish data protection judgments of recent years.  In a ruling that will be of particular interest to ICT leaders, data protection practitioners, cybersecurity professionals, software developers and digital governance specialists, the Court confirmed that organisations may rely on certain exemptions within the Data Protection Act 2018 when responding to Data Subject Access Requests (DSARs). 

The judgment (which is subject to appeal) upheld the Data Protection Commission’s (DPC) decision that Red Flag Consulting was entitled to withhold certain information requested by Denis O’Brien under the GDPR, relying on statutory exemptions relating to legal claims, legal professional privilege and the protection of third-party rights.  Crucially, the Court also confirmed that these Irish statutory provisions are compatible with Article 23 GDPR, which allows Member States to restrict certain data subject rights where necessary and proportionate.

While the case arose from a high-profile legal dispute, its implications extend well beyond the courtroom and into the day-to-day operations of organisations across Ireland.

Why This Case Matters

For many organisations, DSARs have become a routine part of GDPR compliance.  Requests can involve thousands of emails, documents, messages and records spread across multiple systems.  Until now, uncertainty existed regarding how far organisations could rely on the exemptions contained in Ireland’s Data Protection Act 2018 without risking regulatory challenge.

The Court held that Section 60(3)(a)(iv) of the 2018 Act, which permits restrictions on data subject rights where necessary and proportionate in connection with legal claims or proceedings, is a valid implementation of Article 23 GDPR.  It also confirmed that Section 162, which protects legally privileged material, operates as a separate and distinct exemption rather than merely duplicating Section 60. 

Equally important, the Court recognised that the confidentiality rights of third parties may justify withholding information under Article 15(4) GDPR, which states that access rights must not adversely affect the rights and freedoms of others. 

Practical Implications for Irish Computer Society Members

For members of the Irish Computer Society, the judgment has several important practical consequences.

1.  Technology Teams Must Build DSAR Processes That Support Exemptions

Many organisations have invested heavily in DSAR management tools, automated search capabilities and digital records management systems.  However, the judgment highlights that responding to a DSAR is not simply a technical exercise.

ICT professionals must ensure that systems allow organisations to:

  • Identify personal data accurately;
  • Segregate information that may be legally privileged;
  • Protect confidential third-party information;
  • Record decisions relating to exemptions; and
  • Demonstrate compliance if challenged by regulators or courts.

Technology solutions that simply extract all information relating to an individual may not be sufficient.  The ability to apply legal and confidentiality assessments during the review process is becoming increasingly important.

2.  Data Governance and Information Architecture Matter More Than Ever

The ruling reinforces the importance of strong information governance frameworks.

Organisations need to understand:

  • What personal data they hold;
  • Where it is stored;
  • Who has access to it;
  • Whether it forms part of legal proceedings; and
  • Whether disclosure could reveal confidential relationships or third-party information.

Poor data classification practices can dramatically increase the cost and complexity of processing DSARs.  For ICT governance professionals, this judgment is another reminder that effective records management is a foundational GDPR requirement.

3.  Privacy Professionals Must Document Decision-Making

A key theme running through the judgment is proportionality.

The Court did not establish blanket rights for organisations to refuse access requests.  Instead, it confirmed that any limitation on data subject rights must be justified on a case-by-case basis and supported by appropriate safeguards.

For Data Protection Officers, governance teams and privacy specialists, this means maintaining clear records explaining:

  • Which exemption was relied upon;
  • Why it applied;
  • The balancing exercise undertaken; and
  • Why the restriction was necessary and proportionate.

This documentation may prove essential if a complaint reaches the DPC or the courts.

4.  Cybersecurity and Compliance Functions Must Work Closely Together

The case also highlights the growing intersection between privacy, confidentiality and information security.

Protecting confidential client relationships, commercially sensitive information and legal privilege often requires cooperation between legal, compliance and cybersecurity teams.  Access control mechanisms, audit trails, encryption and secure document repositories all play a role in ensuring sensitive information can be appropriately identified and protected when responding to access requests.

The Court’s Key Findings

The High Court made several important findings that will influence future DSAR handling in Ireland:

  • Section 60(3)(a)(iv) of the Data Protection Act 2018 is compatible with Article 23 GDPR.
  • Section 60 and Section 162 are distinct exemptions with different purposes and scopes.
  • Section 60 may apply more broadly than legal professional privilege alone.
  • Third-party confidentiality rights can fall within the “rights and freedoms of others” protected by Article 15(4) GDPR.
  • A partial refusal is not necessarily a blanket refusal where only exempt information is withheld.

Looking Ahead

Although the decision has been welcomed by many organisations, the Court was equally clear that statutory exemptions should not be treated as automatic barriers to disclosure.  Any restriction on access rights must remain necessary, proportionate and capable of justification.

For Irish Computer Society members, the judgment serves as a timely reminder that GDPR compliance is no longer solely a legal issue.  It is a multidisciplinary challenge involving technology architecture, data governance, cybersecurity, records management and organisational accountability.

As DSAR volumes continue to grow and data ecosystems become increasingly complex, organisations that combine robust technical controls with sound governance practices will be best positioned to meet both regulatory expectations and stakeholder trust.

The O’Brien judgment provides welcome legal clarity, but it also raises the bar for how organisations manage personal data, document decisions and balance competing rights in an increasingly data-driven world.

Resources

Image: Giuseppe Milo, CC BY 3.0 https://creativecommons.org/licenses/by/3.0, via Wikimedia Commons

Discover more from Irish Computer Society

Subscribe now to keep reading and get access to the full archive.

Continue reading