O'Brien v The Data Protection Commission and Ors (Approved) [2026] IEHC 250 (20 February 2026)

O'Brien v The Data Protection Commission and Ors (Approved) [2026] IEHC 250 (20 February 2026)

Section 60(3)(a)(iv) of the Data Protection Act 2018 is compatible with Article 23 GDPR as it incorporates the requirements of necessity and proportionality, identifies the scope and purpose of the restriction, and is sufficiently specific for its context; the DPC correctly applied the law in upholding Red Flag's refusal to disclose data revealing its client's identity, and the assertion of confidentiality falls within the permissible restrictions under Article 15(4) GDPR.

Citation
[2026] IEHC 250
Parties
Appellant: Denis O'Brien; Respondent: The Data Protection Commission; First Named Notice Party: Red Flag Consulting Limited; Second Named Notice Party: The Attorney General
Jurisdiction
Ireland
Judgment Date
20 February 2026
Procedural Posture
Statutory Appeal Under Section 150 of the Data Protection Act 2018 / High Court Judgment on Appeal
Outcome
Appeal dismissed
Legal Topics
GDPR Article 15 Access Rights, GDPR Article 23 Restrictions, Legal Professional Privilege, Confidentiality, Proportionality, Statutory Interpretation

Case Brief

Summary, issues, holding and outcome

More case intelligence is available

Unlock the full research layer for this judgment.

Full judgment text Downloadable case file Legal principles 5 Authorities cited 16 Party arguments 2
Sign in to unlock

Parties

Denis O'Brien

Appellant

The Data Protection Commission

Respondent

Red Flag Consulting Limited

First Named Notice Party

The Attorney General

Second Named Notice Party

Procedural Posture

Statutory Appeal Under Section 150 of the Data Protection Act 2018 / High Court Judgment on Appeal

  1. 1 Whether Section 60(3)(a)(iv) of the Data Protection Act 2018 is compatible with Article 23 GDPR
  2. 2 Whether the DPC correctly dealt with documents claimed to be subject to legal professional privilege
  3. 3 Whether Red Flag's refusal to provide data revealing its client's identity was justified under Article 15(4) GDPR

Ratio Decidendi

Section 60(3)(a)(iv) of the Data Protection Act 2018 is compatible with Article 23 GDPR as it incorporates the requirements of necessity and proportionality, identifies the scope and purpose of the restriction, and is sufficiently specific for its context; the DPC correctly applied the law in upholding Red Flag's refusal to disclose data revealing its client's identity, and the assertion of confidentiality falls within the permissible restrictions under Article 15(4) GDPR.

Court Disposition

Appeal dismissed

Orders

  • Appellant to bear the costs of the Respondent and Red Flag
  • Attorney General to bear his own costs