Ireland's DPC and Meta's AI Training: What Was Actually Decided
9 min read · updated August 11, 2026
“The Irish regulator approved Meta training on public posts” is the version that circulates. There is no published decision approving anything. There is a pause, an opinion the DPC itself requested, a set of measures, and a statement — and the distinction between those and a decision is the entire point of this page.
The sequence, with dates
In May 2024 Meta notified users in the EU and EEA that from late June it intended to use public posts, comments and other public content from adult accounts to train its generative AI models, relying on legitimate interests as its lawful basis and offering an objection form rather than asking for consent. The privacy group NOYB filed complaints across multiple member states.
In June 2024 the Data Protection Commission, as Meta’s lead supervisory authority under the GDPR’s one-stop-shop, requested that the rollout be paused. Meta paused it. The DPC then referred the general question to the European Data Protection Board, which adopted Opinion 28/2024 on 17 December 2024, addressing model anonymity, the availability of legitimate interests for developing and deploying AI models, and the consequences of unlawfully processed training data.
In April and May 2025 the DPC said its engagement with Meta had concluded with a set of measures in place, and Meta began training on public EU content from 27 May 2025. Separately, on 23 May 2025 the Higher Regional Court of Cologne refused an urgent injunction sought by a German consumer association to stop the training. The DPC publishes its statements at dataprotection.ie, which is the only place worth reading them.
The legal basis in question
The claim is that training on user content is necessary for the purposes of legitimate interests pursued by the controller, under Article 6(1)(f) of the GDPR, and that those interests are not overridden by the interests or fundamental rights of the data subjects. That is a three-part test: a legitimate interest, necessity, and a balancing exercise. Each part is contested here.
The balancing test is where the argument sits. Against Meta’s interest in building models sits the reasonable expectation of a person who posted publicly in 2011 and could not have contemplated the content becoming training data; the scale of the corpus; the difficulty of removing a contribution once a model is trained; and the presence of special-category material under Article 9 in ordinary public posts, which legitimate interests cannot lawfully cover on its own.
The mitigations run the other way: only public content from adult accounts, exclusion of private messages, an unconditional objection mechanism going beyond the Article 21(1) requirement to state grounds, and delay to allow objections to be lodged. EDPB Opinion 28/2024 does not bless or reject any of this. It sets out the factors a supervisory authority should weigh and leaves the case-by-case assessment to the authority.
What the DPC actually said
The DPC’s public position, in substance, is that it engaged extensively with Meta, that Meta made changes to its transparency notices and its objection mechanism, that the DPC would keep the processing under review, and that it expected to assess the effectiveness of the measures in practice. That is supervisory language, and it is deliberately supervisory language.
What it is not is an inquiry decision under section 111 of the Irish Data Protection Act 2018, or a draft decision circulated to concerned supervisory authorities under Article 60 of the GDPR, or an Article 65 binding EDPB dispute resolution. Those produce a reasoned finding on lawfulness that other authorities have had a chance to object to. None of that machinery ran here.
Why this is not a ruling you can rely on
- No finding of lawfulness was made. A regulator declining to block processing while it monitors is not a regulator holding the processing lawful. The complaints alleging otherwise were not adjudicated by the statement.
- It is specific to one controller’s facts. The measures were negotiated against Meta’s corpus, notice reach and objection tooling. A smaller company copying the basis without the reach or the tooling is not in the same position.
- National courts are not bound by it. The Cologne court’s refusal of an injunction was an urgent-relief decision on the balance of interests at that stage, not a final ruling that the processing complies with the GDPR.
- It is genuinely unresolved. Whether legitimate interests can support large-scale training on user-generated content will be settled by a reasoned decision that is appealed, or by the Court of Justice, and neither has happened. Anyone telling you the question is closed in either direction is ahead of the record.
If you are relying on legitimate interests yourself
The transferable part is procedural. Whatever the eventual answer, the controllers who survive scrutiny will be the ones who can produce a written balancing assessment made before processing started, showing the interest, why the processing was necessary rather than merely convenient, what the alternatives were, and what mitigations were applied — the legitimate interest assessment for AI training covers the structure of that document.
Two connected questions decide most of the outcome and neither is Meta-specific: whether your source data is genuinely public and lawfully collected, which is the subject of the web-scraping lawful basis question, and whether your objection route actually works before the training run rather than after it, which is where the right to object bites. An objection that arrives after the weights exist is the hardest problem in this area, because the GDPR’s remedies assume data can be erased and a trained model does not straightforwardly allow it.