Doing Business In..._2026

IRELAND Law and Practice Contributed by: Philip Tully, Emma Doherty, Alice Duffy, Simon Shinkwin and Marie McGinley, Matheson LLP

Where a trade secret is unlawfully used, various rem - edies under Irish law, including injunctions, orders for accounts of profit, corrective measures such as recall or destruction of infringing goods and damages, are available to protect the trade secret owner. A per - son who contravenes or fails to comply with court orders commits an offence and is liable to a fine and/ or imprisonment for up to six months. The EU (Protection of Trade Secrets) Regulations 2018 gave effect to the EU Trade Secrets Directive and came into force on 9 June 2018 by way of SI No 188/2018. The Regulations provide civil remedies in circumstances where a trade secret is unlawfully used and allow for measures limiting access to court hear - ings and documents to ensure the confidentiality of trade secrets in court proceedings, including making it a criminal offence to contravene such measures. The principal data protection legislation in Ireland is Regulation (EU) 2016/679 (the General Data Protec - tion Regulation or GDPR), as supplemented by the Irish Data Protection Acts 1988 to 2018 (DPA) as amended. Irish law-specific nuances, as permitted or required under the GDPR, as well as the administrative powers and procedures of the local supervisory authority, the Data Protection Commission, are set out in the DPA. The GDPR has general application to the processing of personal data in the EU, setting out extensive obli - gations on controllers and processors and providing strengthened protections for data subjects. The GDPR carries the potential for large fines of up to 4% of a firm’s worldwide annual turnover from the preceding financial year, or EUR20 million (whichever is higher). In May 2023, the CJEU judgment of UI v Osterreichis- che Post AG (Case C-300/21) confirmed that a mere infringement of the GDPR does not give rise to the right to compensation in itself but that there must be a breach, some damage and a causal link between the 8. Data Protection 8.1 Applicable Regulations Principal Data Protection Laws

two, as in most negligence cases. Claimants do have to prove damage of some kind in order to recover compensation for non-material loss following a GDPR infringement. On 5 December 2025 the Circuit Court in Walsh v Irish Prison Service [2025] IECC 8 affirmed this view and applied the principle set out in Kaminski v Ballymagu- ire Foods [2023] IECC 5 that “mere upset” is not suf - ficient non-material harm to warrant compensation under the GDPR. The European Commission is required to conduct a review of GDPR rules every four years. As part of this process, the Commission will likely look at prob - lematic areas identified, such as the exercise of Data Subject Access Requests, the applicability of GDPR to SMEs, and international data transfers. Other Relevant Legislation Ireland has transposed the ePrivacy Directive via SI No 336/2011 – European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011 (the “ePrivacy Regulations”). The ePrivacy Regulations deal with security and data breach reporting obliga - tions for certain telecommunications companies and, more generally, electronic direct marketing rules. The same implementing legislation addresses the local Irish requirements around obtaining consent for the use of cookies and similar technologies. Social welfare legislation such as the Social Welfare Act 2005 strictly prohibits the use of the Irish Personal Public Services Number (PPSN) for purposes other than dealing with specified government bodies. 8.2 Geographical Scope The GDPR applies to the processing of personal data by controllers and processors established in the EU (regardless of whether the processing itself takes place in the EU). The GDPR also applies to controllers and processors not established in the EU, where the organisation’s processing activities involve either the offering of goods or services to data subjects in the EU or the monitoring of the behaviour of data subjects in the EU.

505 CHAMBERS.COM

Powered by