Ireland’s DPC Calls for Greater Transparency in AI Development
Ireland’s Data Protection Commission (DPC) has published the findings of its AI Review, emphasizing the need for stronger transparency requirements and clearer guidance on the use of personal data to train artificial intelligence systems. The review examined the DPC’s work with data controllers involved in developing and deploying approximately 180 AI products and services between 2021 and 2025. The process included reviewing thousands of pages of briefings, risk assessments, technical safeguards, organizational measures, and other compliance documents.
Two issues appeared repeatedly: the use of legitimate interests as a legal basis for AI training and the difficulty many organizations face in meeting their transparency obligations. According to the DPC, 72% of decisions made by its Supervision Function involved transparency concerns. Some organizations argued that full disclosure could create security risks, particularly where AI systems are used to detect fraud or illegal activity.
The DPC acknowledged that revealing too much information about certain systems could help malicious actors avoid detection or understand how controls operate. However, it stressed that later explanations or post-processing disclosures do not remove a controller’s obligation to provide appropriate information before processing begins. These duties arise under Articles 5, 12, 13, and 14 of the General Data Protection Regulation (GDPR).
Transparency must be meaningful and directed at the people whose data is being processed. The DPC warned organizations against relying on notices that are difficult to locate, are not written for the relevant users, or describe features that individuals do not actually use.
The legal basis for AI training was another major concern. In May 2024, Meta announced plans to use users’ personal data to train AI systems based on legitimate interests under Article 6(1)(f) GDPR. The DPC did not accept that position without further safeguards. It issued recommendations covering measures such as data filtering and de-identification before training, which Meta ultimately implemented.
The DPC also reported that it had engaged with five controllers regarding the launch of agentic AI systems in the European Union. Although the authority has already issued recommendations in several cases, it said common themes were still developing. Repeated concerns included limited transparency, insufficient clarity about how AI systems process personal data, uncertainty about how systems function, and inadequate information about possible effects on individuals’ rights.
The authority further cautioned that data protection law should not be treated as a substitute for broader ethical and social standards. This is particularly important in cases involving the creation of non-consensual intimate or sexualized images, where other legal rules and social protections may also be relevant.
Ireland’s DPC has a significant supervisory role because many major technology companies have their European headquarters in Ireland. Its review covered work involving companies such as Airbnb, Apple, DeepSeek, Google, LinkedIn, Meta, Microsoft, OpenAI, Pinterest, TikTok, and X.
The DPC concluded that innovation and strong data protection can coexist. Its supervision work has led to improvements in lawful processing, transparency, data minimization, and protections for children across a range of AI systems, including large language models and recommender systems.