← News & Insights / Industry News

DPC Enforcement Actions Are Rising: What Your Business Needs to Know About GDPR Compliance

The Data Protection Commission is stepping up enforcement. Here's what small businesses need to do now to stay compliant and avoid penalties.

DPC Enforcement Actions Are Rising: What Your Business Needs to Know About GDPR Compliance

If you’ve noticed the Data Protection Commission (DPC) has been busier lately, you’re not imagining it. Over the past 18 months, enforcement actions against Irish and EU-based companies have accelerated. And unlike the early days of GDPR, when many smaller businesses flew under the radar, the DPC is now actively pursuing cases across all company sizes.

The message is clear: compliance isn’t optional, and it’s not just for big tech companies anymore.

Why the DPC Is Cracking Down Now

The DPC has three main enforcement priorities these days:

  • Cross-border data transfers – especially the frameworks businesses use to move customer data outside the EU
  • Cookie consent and tracking – making sure websites aren’t sneaking tracking pixels past users
  • Data subject rights – ensuring people can actually access, correct, or delete their personal data when they ask

For a typical SME, the first and third points probably matter most. If you use cloud services (even basic things like Google Workspace or Microsoft 365), you’re dealing with data transfers. And if a customer ever asks for their data or wants you to delete it, you need a proper process.

What Penalties Actually Look Like

This is where it gets real. The DPC can issue fines up to €20 million or 4% of global annual turnover – whichever is higher. For most small businesses, that’s catastrophic.

But fines aren’t the only consequence. The DPC also issues corrective orders, which force you to change how you handle data. If you ignore one, that’s when fines pile on. And there’s the reputational hit: enforcement actions are public, and customers notice.

Three Things You Should Do This Month

1. Audit your cloud services

Write down every tool your team uses that stores customer or employee data. That includes email, file storage, CRM systems, and even accounting software. For each one, check whether your service agreement includes a Data Processing Agreement (DPA). If it doesn’t, contact the vendor and ask for one. If they won’t provide it, you may need to find an alternative.

2. Check your consent mechanisms

If your website collects email addresses, uses forms, or has analytics running, you need proper consent. A pop-up that pre-ticks a box doesn’t count. Consent must be active, informed, and freely given. If your website was built more than two years ago, it probably needs updating.

3. Document your data handling

The DPC expects you to show your working. You need a simple record of:

  • What personal data you collect
  • Why you collect it
  • How long you keep it
  • Who has access to it
  • What you do if someone asks for it back or wants it deleted

You don’t need a 50-page manual. A simple spreadsheet or document is fine, as long as it exists and your team knows where to find it.

The Honest Truth

GDPR compliance doesn’t have to be expensive or complicated for a small business. But it does require attention. The businesses getting penalized aren’t usually the ones trying their best – they’re the ones ignoring the issue or hoping no one notices.

If you’re genuinely unsure where your business stands, a single compliance review with your IT provider is a sensible investment. It costs far less than a DPC investigation.

More from Industry News

Related articles

✓ Message sent — we'll be in touch shortly.