Background
The Irish Council for Civil Liberties (“ICCL”), a qualified entity under the Representative Actions for the Protection of the Collective Interests of Consumers Act 2023, brought a representative action seeking injunctive relief against Microsoft Ireland Operations Limited. ICCL alleged that Microsoft infringed the GDPR when processing personal data through Xandr, a platform used to sell online advertising space by real-time bidding. Microsoft disputed, among other matters, that it was the relevant data controller.
The High Court had previously deemed the action admissible and granted ICCL leave to issue proceedings on an ex parte application. After the parties exchanged pleadings, disputes arose over ICCL’s particularisation of its allegations, Microsoft’s denials and non-admissions, the allocation of proof under Articles 5(2) and 24(1) GDPR, and Microsoft’s demand for further information under sections 19(10) and 19(11) of the 2023 Act. The court conducted a preliminary trial of agreed legal questions; it did not decide whether Microsoft was a controller or had infringed the GDPR.
The Court’s Holding
The High Court held that Articles 5(2) and 24(1) GDPR do not produce a general reversal of the legal or evidential burden of proof. ICCL bears the burden of proving matters for which it is responsible, including that Microsoft is the relevant controller. If ICCL establishes the necessary predicate matters and the court must determine actual compliance, however, Microsoft bears the onus of proving compliance with obligations imposed by Article 5(1), and that its processing accords with the GDPR within Article 24(1).
Ordinary pleading rules apply to both parties: each must plead the material facts supporting the matters it must prove. Accordingly, if Microsoft advances a positive defence of GDPR compliance, it must plead the material facts on which that defence relies. The court declined, without an adequate factual basis and fuller argument, to decide the consequences of failing to plead those facts or whether the “peculiar knowledge” principle shifted any burden in this case.
The court also held that sections 19(10) and 19(11) do not give a defendant a standalone right to compel further information about a representative action’s funding, alleged infringements, or affected consumer classes after the court has accepted the information as sufficient for admissibility. Microsoft remained free to challenge admissibility or seek particulars, discovery, or disclosure under section 34(2) where the applicable procedural requirements were met, and could seek to set aside the ex parte leave order.
Key Takeaways
- A claimant alleging GDPR infringement must prove the matters assigned to it, including that the defendant is the relevant controller; Articles 5(2) and 24(1) do not reverse every burden of proof.
- Once the necessary predicate matters are established and compliance is in issue, the controller bears the onus of demonstrating compliance with the applicable GDPR obligations.
- A defendant making a positive case of GDPR compliance must plead the material facts supporting that defence.
- The 2023 Act does not create a standalone entitlement for defendants to demand additional section 19(10) information, although ordinary challenges to admissibility and established disclosure procedures remain available.
Why It Matters
The judgment clarifies how Ireland’s ordinary rules of proof and pleading operate in a GDPR representative action. The accountability duties imposed on controllers can place the onus of demonstrating compliance on a defendant once the claimant has established the matters it must prove, but they do not excuse a representative claimant from properly pleading and proving its own case.
It also delineates the procedural effect of an ex parte admissibility order under Ireland’s new collective-redress regime. Defendants may contest admissibility and use established mechanisms to obtain relevant material, but sections 19(10) and 19(11) are not independent post-admission disclosure powers.