OUT-LAW NEWS 2 min. read

AI deployment raises transparency issues in Ireland

River Liffey in central Dublin

Dublin, Ireland. pawel.gaul/iStock.


Businesses operating in Ireland may need to update their privacy notices to account for new guidance on AI issued by the country’s data protection authority, an expert has said.

Nicola Barden of Pinsent Masons in Dublin, who specialises in data protection and AI, was commenting after Ireland’s Data Protection Commission (DPC) published a new report on responsible AI innovation (75-page / 5MB PDF).  

The report contains insights drawn from the DPC’s own technology multinational supervisory unit (TMSU), which sits within the authority’s supervisory function. The TMSU is tasked with engaging with the large multinational tech companies that are based in Ireland. The insights detailed in the report draw specifically on the TMSU’s engagement with those companies over their release of AI products and services between 2021 and 2025.  

The DPC said the report “serves as both a record of the DPC’s actions in regulating emerging technologies such as AI, and as guidelines for controllers”. Barden highlighted how the report contains a bullet point list of key takeaways that offer organisations “clear, accessible, and practical compliance guidance that can be quickly understood and acted upon”. 

According to the DPC, it saw “a significant increase in AI-related engagements” between 2021 and 2025 amidst the rapid growth in development of generative AI, with the TMSU overseeing the launch of approximately 180 AI products and services during the period. Its engagement led to it making hundreds of recommendations to the companies. Of those recommendations, 72% concerned transparency issues, the DPC said. 

“The DPC experienced reticence on the part of some controllers to inform users about the processing of personal data by AI,” according to the report. “In some cases, this was for reasons the controllers believed were legitimate. For example, AI that is intended to detect fraud or illegal activities could potentially be evaded by bad actors if they learn of the existence of the AI or if they can figure out how it works.” 

“The DPC has emphasised to controllers that no amount of post-processing transparency will relieve a controller of its obligations to provide transparency prior to processing under Articles 5, 12, 13, and 14 of the GDPR,” it added. 

Barden said the DPC has “expressed a pragmatic understanding of the commercial need for timely product launches” and that it had further highlighted that “thorough documentation and proactive engagement enable the DPC to assess compliance more quickly and effectively”. She said controllers should “review their privacy notices to check if the new report means they have to add more detail to meet transparency requirements”.  

Barden said: “The DPC has stated that controllers may need to explain the technology but also educate the data subjects on the data protection implications and risks. In relation to processing by AI and LLMs, it states that controllers have a duty to explain the data protection risks to data subjects. This aligns with broader EU regulatory thinking on the requirement to ensure data subjects can determine the scope and consequences of the processing of their personal data.” 

“The DPC relates privacy notices presented to individuals to the expectations of those individuals. For historical personal data, controllers need to consider the transparency information provided and the historical conditions,” she added.

We are processing your request. \n Thank you for your patience. An error occurred. This could be due to inactivity on the page - please try again.