The High Court (Court) has delivered its first judgment concerning the operation of Ireland’s representative actions procedure under the Representative Actions for the Protection of the Collective Interests of Consumers Act 2023 (2023 Act).
In Irish Council for Civil Liberties Company Limited by Guarantee v Microsoft Ireland Operations Limited [2026] IEHC 640, the Court delivered a preliminary judgment addressing a number of important procedural issues arising in a representative action alleging infringements of the General Data Protection Regulation (GDPR), namely:
- Whether the GDPR’s accountability framework (under Articles 5(2) and 24(1)) alters the traditional burden of proof in civil proceedings;
- Whether parties to a representative GDPR action are subject to any special pleading requirements; and
- The operation of certain procedural aspects of the representative actions regime.
Background
The proceedings were commenced by the Irish Council for Civil Liberties (ICCL), a qualified entity designated under the 2023 Act. ICCL alleges that Microsoft’s operation of its Xandr real-time bidding platform involves processing personal data in a manner that infringes various provisions of the GDPR.
Before commencing the proceedings, ICCL obtained an ex parte order deeming the proceedings to be an admissible representative action and was granted leave to issue a plenary summons. Following the exchange of pleadings, a dispute arose between the parties regarding the adequacy of their respective pleadings and the allocation of the burden of proof in circumstances where the GDPR imposes obligations on data controllers to demonstrate compliance with the GDPR.
The parties agreed that the Court should determine a number of preliminary legal issues before the proceedings progressed further.
GDPR accountability and compliance
A central issue before the Court was the effect of the GDPR’s accountability principle. Data controllers are not only required to comply with the GDPR but, under Articles 5(2) and 24(1) GDPR, must also demonstrate that they have done so. ICCL argued that those provisions mean that, once certain matters have been established, the burden falls on the data controller to show that its processing activities comply with the GDPR. Microsoft argued that the burden of proving an alleged infringement of the GDPR remained with the plaintiff.
The Court rejected the argument that the GDPR creates a general reversal of the burden of proof. It observed that a plaintiff cannot simply allege a breach of the GDPR and require a defendant to prove compliance. However, the Court accepted that Articles 5(2) and 24(1) impose “substantive obligations” on a data controller, thereby placing the burden on the data controller to demonstrate compliance with the GDPR. Accordingly, where a plaintiff establishes the matters necessary to engage a particular GDPR obligation, the data controller bears the burden of demonstrating compliance with that obligation.
In practical terms, this aspect of the judgment is a reminder that organisations are required not only to comply with the GDPR, but also to be in a position to evidence that compliance if challenged.
Pleadings
The parties also sought guidance on the interaction between the GDPR, the 2023 Act and the ordinary rules governing pleadings (under Order 19 of the Rules of the Superior Courts (RSC)).
Both parties accepted that the existing Order 19 RSC are sufficiently flexible to accommodate representative actions and that those rules satisfy the EU law principles of equivalence and efficiency.
The Court found that the ordinary pleading rules apply to both parties in representative actions. In that context, the Court noted that while a defendant is generally entitled to deny allegations that a plaintiff is required to prove, a defendant wishing to advance a positive case of GDPR compliance must plead the material facts on which it relies.
Guidance on the operation of the 2023 Act
The judgment contains some other helpful judicial observations on the operation of the 2023 Act.
In particular, the Court observed that a defendant has no “stand-alone entitlement” to seek further information concerning the matters identified in section 19(10) of the 2023 Act (such as the source of funding, the nature of the claim, the class of consumers affected). However, a defendant is not precluded from challenging the admissibility of a representative action and may seek to have the admissibility order set aside or raise it in its defence. In support of that position, the defendant may avail of the procedural mechanisms ordinarily available in litigation, including discovery and, where applicable, disclosure under section 34(2) of the 2023 Act.
Concluding remarks
The judgment does not determine whether Microsoft has complied with its alleged GDPR obligations; rather, it provides helpful guidance on the operation of Ireland’s representative actions regime and the practical effect of the GDPR’s accountability principle on such litigation.
The judgment comes at an early stage in the development of Ireland’s representative actions procedures. It follows the recent publication of new rules in the RSC governing representative actions, which come into operation on 12 October 2026. These rules set out the practice and procedure around representative actions, including admissibility applications, injunctive relief, redress measures and settlement. The long-term impact of the 2023 Act remains uncertain. However, the judgment and the new court rules mark an important step in giving practical effect to the 2023 Act.
If you would like to discuss this judgment or its implications for representative actions, data protection litigation, or the new court rules in more detail, please contact Adele Hall, Rachel Hayes or your usual William Fry contact.
Contributed by Joseph Walshe



