GDPR Compliance Documentation: Preparing for DPC Audits in Ireland
Ireland's DPC is the EU's lead GDPR enforcer. Here's what documentation Irish organisations need, common gaps, and how to review systematically.
Ireland's Data Protection Commission (DPC) is the lead supervisory authority for some of the world's largest technology companies — Meta, Google, Apple, Microsoft, TikTok, and LinkedIn all have their EU headquarters in Ireland. The DPC has imposed billions of euros in fines, including a €1.2 billion penalty against Meta in 2023.
But GDPR compliance isn't just for Big Tech. Every Irish organisation — from SMEs to public bodies, from startups to established enterprises — must comply with the General Data Protection Regulation (GDPR) and the Data Protection Act 2018. The DPC conducts audits, investigates complaints, and can impose fines of up to €20 million or 4% of annual global turnover.
This guide covers what GDPR documentation Irish organisations need, where the DPC most commonly finds gaps, and how to build a documentation review process that keeps you audit-ready.
GDPR Documentation Requirements
The GDPR requires extensive documentation. This isn't bureaucracy for its own sake — Article 5(2) establishes the "accountability principle," meaning you must be able to demonstrate compliance, not just claim it.
Core Documentation
| Document | GDPR Article | Who Needs It | Purpose |
|---|---|---|---|
| Record of Processing Activities (ROPA) | Art. 30 | Organisations with 250+ employees, or any organisation processing sensitive data or data likely to result in risk | Maps all data processing activities |
| Privacy Notice | Art. 13/14 | All organisations collecting personal data | Informs individuals about data processing |
| Data Protection Impact Assessment (DPIA) | Art. 35 | Required for high-risk processing | Assesses and mitigates privacy risks |
| Data Processing Agreements (DPAs) | Art. 28 | Any organisation using data processors | Governs processor relationships |
| Breach Notification Procedures | Art. 33/34 | All organisations | Ensures timely breach response |
| Consent Records | Art. 7 | Organisations relying on consent | Proves valid consent was obtained |
| Legitimate Interest Assessments (LIAs) | Art. 6(1)(f) | Organisations relying on legitimate interest | Documents the balancing test |
| Data Retention Policy | Art. 5(1)(e) | All organisations | Defines how long data is kept |
| Subject Access Request Procedures | Art. 15 | All organisations | Handles individual rights requests |
Record of Processing Activities (ROPA)
The ROPA is your central compliance document. For each processing activity, document:
- Name and contact details of the controller (and DPO if appointed)
- Purposes of processing
- Categories of data subjects and personal data
- Categories of recipients
- Transfers to third countries (including safeguards)
- Retention periods
- Description of technical and organisational security measures
Common gap: Many organisations have a ROPA created during initial GDPR compliance in 2018 that hasn't been updated. New systems, new vendors, and new data types have been added without updating the ROPA.
Data Protection Impact Assessments (DPIAs)
DPIAs are mandatory when processing is "likely to result in a high risk" to individuals. The DPC has published guidance specifying that DPIAs are required for:
- Systematic and extensive profiling with significant effects
- Large-scale processing of sensitive data
- Systematic monitoring of publicly accessible areas
- New technologies (including AI and automated decision-making)
- Large-scale processing of children's data
Documentation required:
- Description of the processing and its purposes
- Assessment of necessity and proportionality
- Assessment of risks to individuals
- Measures to address risks
- Evidence of consultation with the DPO (if appointed)
Common gap: Organisations deploying AI tools without conducting DPIAs. Any use of automated decision-making that significantly affects individuals triggers the DPIA requirement.
Data Processing Agreements (DPAs)
Every processor relationship must be governed by a written contract containing specific GDPR-mandated provisions:
- Processing only on documented instructions from the controller
- Confidentiality obligations for processing staff
- Appropriate security measures
- Sub-processor restrictions and notification
- Assistance with data subject rights
- Deletion or return of data on termination
- Audit rights
- Breach notification obligations
Common gap: Using SaaS tools, cloud services, or marketing platforms without a compliant DPA in place. Every tool that processes personal data on your behalf needs one.
Where the DPC Finds Documentation Gaps
1. Transparency Failures
The DPC frequently finds privacy notices that:
- Are too long, too complex, or too legalistic for the average person
- Don't specify retention periods
- Don't identify all recipients or categories of recipients
- Don't adequately explain the legal basis for each processing activity
- Don't cover all processing activities (especially employee data)
- Are outdated and don't reflect current data practices
2. International Transfer Documentation
Since the Schrems II decision, transfers of personal data outside the EEA require specific safeguards:
- Standard Contractual Clauses (SCCs) — the new 2021 versions must be used
- Transfer Impact Assessments (TIAs) — documenting that the data will be adequately protected in the receiving country
- Supplementary measures where needed
Common gap: Organisations using US-based SaaS tools relying on the EU-US Data Privacy Framework without documenting their assessment of whether the framework applies to their specific transfers.
3. Consent Documentation
Where consent is the legal basis, the DPC expects:
- Evidence consent was freely given, specific, informed, and unambiguous
- Records showing what the individual consented to and when
- Evidence consent was not bundled with other terms
- Documented withdrawal mechanisms that are as easy as giving consent
- Separate consent for different processing purposes
4. Data Subject Rights Handling
The GDPR grants individuals extensive rights. Documentation gaps include:
- No documented procedures for handling Subject Access Requests (SARs)
- No tracking system for requests and response timelines (one month deadline)
- No documented identity verification process
- No process for handling requests that span multiple systems
- No documented approach for exemptions (e.g., legal privilege, third-party data)
5. Breach Response Documentation
The GDPR requires notification to the DPC within 72 hours of becoming aware of a breach (unless unlikely to result in risk). Common gaps:
- No documented breach response plan
- No breach register (all breaches must be recorded, even non-notifiable ones)
- No documented risk assessment methodology for determining if notification is required
- No pre-prepared notification templates
- No evidence of breach response testing
How to Review Your GDPR Documentation Systematically
Step 1: Audit Your ROPA
Your ROPA should be a living document. Review:
- Does it cover all processing activities (including HR, marketing, customer data, CCTV, cookies)?
- Has it been updated in the last 12 months?
- Does each entry include all Article 30 required fields?
- Are retention periods specified for each processing activity?
- Are international transfers identified with the safeguard mechanism?
- Does it reflect current vendors and systems?
Step 2: Review Privacy Notices
For each privacy notice (website, employee, customer, job applicant):
- Does it identify the controller and DPO contact details?
- Does it specify the legal basis for each processing purpose?
- Does it list retention periods (not just "as long as necessary")?
- Does it identify all recipients and categories of recipients?
- Does it explain international transfers and safeguards?
- Does it clearly explain all data subject rights?
- Is it written in plain, accessible language?
- Has it been updated to reflect current processing activities?
Step 3: Assess DPIA Coverage
- Identify all processing activities that may be high-risk
- Verify DPIAs exist for each
- Check DPIAs cover: description, necessity, proportionality, risks, mitigations
- Verify DPIAs are reviewed when processing changes
- Confirm DPO was consulted (if applicable)
Step 4: Verify Processor Documentation
- Complete inventory of all data processors
- DPA in place with each processor (using GDPR Article 28 provisions)
- SCCs in place for non-EEA processors (2021 version)
- Transfer Impact Assessments completed for non-EEA transfers
- Sub-processor lists maintained and up to date
Step 5: Test Rights and Breach Processes
- SAR handling procedure documented and tested
- Breach response plan exists with 72-hour notification workflow
- Breach register maintained (including non-notifiable breaches)
- All processes have been tested with tabletop exercises
Using AI to Review GDPR Documentation at Scale
Organisations with multiple business units, subsidiaries, or processing activities face a significant documentation challenge.
What AI-Assisted Review Can Do
- ROPA completeness checking — Does each processing activity entry include all Article 30 fields?
- Privacy notice compliance — Do notices cover all required elements for each audience?
- DPA consistency — Do processor agreements include all GDPR-mandated provisions?
- Plain language analysis — Are privacy notices accessible to the average person?
- Gap identification — Flagging missing DPIAs, outdated DPAs, or incomplete breach procedures
Practical Example: Building a GDPR Documentation Reviewer
In TeamBench, you could configure a reviewer for GDPR documentation:
Reviewer name: GDPR Documentation Compliance Reviewer
System prompt:
You are a GDPR documentation compliance reviewer for Irish organisations. Review privacy notices, ROPAs, DPIAs, and DPAs against GDPR requirements and DPC guidance. Check for Article 30 completeness in ROPAs, Article 13/14 compliance in privacy notices, Article 28 provisions in DPAs, and Article 35 methodology in DPIAs. Flag outdated references, missing elements, generic language, and gaps in international transfer documentation. Suggest specific improvements.
Evaluation criteria:
- Completeness (weight: 3) — All GDPR-required elements present
- Currency (weight: 3) — References current legislation, 2021 SCCs, current DPC guidance
- Specificity (weight: 2) — Tailored to the organisation's actual processing activities
- Plain Language (weight: 2) — Accessible to the average data subject
- International Transfers (weight: 1) — Transfer documentation including TIAs complete
Quality gate: Minimum score: 75.
Upload GDPR text, DPC guidance documents, and your ROPA into a Knowledge Base. You could also use the readability checker to verify privacy notices meet plain language standards.
Frequently Asked Questions
Does GDPR apply to all Irish businesses?
Yes. The GDPR applies to every organisation that processes personal data, regardless of size. The Data Protection Act 2018 supplements the GDPR in Ireland. There is no exemption for small businesses, though some obligations (like appointing a DPO) only apply in specific circumstances.
When is a DPIA required?
A DPIA is required when processing is "likely to result in a high risk" to individuals. This includes large-scale profiling, large-scale processing of sensitive data, systematic monitoring, new technologies (including AI), and processing children's data at scale. When in doubt, conduct one — it demonstrates accountability.
What are the penalties for non-compliance?
Up to €20 million or 4% of annual global turnover (whichever is higher) for the most serious violations. Lower-tier penalties of up to €10 million or 2% of turnover apply to less serious breaches. The DPC can also issue warnings, reprimands, and processing bans.
Do I need a Data Protection Officer?
A DPO is mandatory for public authorities, organisations whose core activities require regular and systematic monitoring of individuals at large scale, or organisations processing sensitive data at large scale. Even if not required, appointing a DPO is recommended best practice.
How quickly must I report a data breach?
You must notify the DPC within 72 hours of becoming aware of a breach that is likely to result in a risk to individuals' rights and freedoms. If you can't provide full details within 72 hours, you can provide information in phases. You must also notify affected individuals without undue delay if the breach is likely to result in a high risk.
What are Standard Contractual Clauses and when do I need them?
SCCs are pre-approved contractual terms for transferring personal data outside the EEA. You must use the 2021 version (the old 2010 versions are no longer valid). SCCs are needed whenever you transfer data to a processor or controller outside the EEA, unless another safeguard (like adequacy decisions or binding corporate rules) applies.
Can AI help with GDPR compliance documentation?
AI can assist with first-pass review — checking ROPAs for Article 30 completeness, verifying privacy notices include all required elements, ensuring DPAs contain mandatory provisions, and flagging outdated documentation. It cannot provide legal advice, verify implementation, or guarantee DPC audit outcomes.
Why is Ireland's DPC particularly important for GDPR?
Ireland is the lead supervisory authority for many of the world's largest tech companies (Meta, Google, Apple, Microsoft, TikTok) because their EU headquarters are in Ireland. This means the DPC handles cross-border enforcement cases affecting hundreds of millions of EU citizens, making it one of the most active and influential data protection regulators globally.
Key Takeaways
- Every Irish organisation must comply with GDPR — the DPC enforces against businesses of all sizes, not just tech giants.
- The ROPA is your central compliance document — it must be complete, current, and cover all processing activities including HR, marketing, and CCTV.
- DPIAs are mandatory for high-risk processing — any use of AI, automated decision-making, or large-scale profiling requires one.
- International transfer documentation is critical — 2021 SCCs and Transfer Impact Assessments are required for non-EEA transfers.
- The DPC expects plain language privacy notices — not legal documents. They must be specific about legal bases, retention periods, and recipients.
- Breach notification within 72 hours requires a pre-planned, tested response process. You cannot figure this out during a live incident.
- All breaches must be recorded — even non-notifiable ones. The breach register demonstrates accountability.
- AI-assisted review can screen documentation at scale, catching missing elements, outdated references, and plain language issues before the DPC does.
This article provides general information about GDPR documentation requirements in Ireland and is not legal advice. Always consult the Data Protection Commission directly for the most current guidance and seek qualified legal counsel for your specific situation.