The Data Protection Commission's 2024 annual report records €652 million in fines concluded during the year, 32,152 contacts received, and 89 statutory inquiries open at year end. The large fines went to large platforms, which is why most Irish SMEs read the headline and move on.
The number they should read is the composition of complaints. Subject access requests — a person asking what data you hold about them — were the single largest category. That is not a technology-company problem. Any business with customers or staff can receive one, and the clock is one month.
An access request is an operational test disguised as a legal one. It asks whether you can find every record relating to one individual across your systems within thirty days. If customer data lives in a CRM, an inbox, a shared drive, a WhatsApp thread and a legacy quoting tool, you cannot answer it accurately no matter how good your privacy policy reads. Firms fail here not through bad intent but through fragmentation.
The same fragmentation drives the other frequent complaint areas: data kept long after any purpose, marketing sent to people who withdrew consent, and disclosure of data to the wrong person. All three are symptoms of not having one authoritative record per individual — the same missing foundation that blocks CRM adoption and AI usefulness.
The remediation is therefore shared. Consolidate to one customer record. Record the lawful basis and consent state as fields on that record rather than as a note in an inbox. Set retention rules that actually delete. Log which systems hold personal data and who can reach them. This is a week of work at fifty people and a project at five hundred.
Framed correctly, this is not compliance overhead. The exact same work that makes an access request answerable in an afternoon is the work that makes retention analysis, personalisation and automation possible. Governance and growth need the same underlying asset: data you can trust and locate.
Sources
- 1.Annual Report 2024Data Protection Commission (Ireland) · 2024
- 2.GDPR, Article 15 – Right of accessEUR-Lex · 2016