Key Facts
Overview
Ireland's SI 336/2011 is uniquely significant because the DPC serves as the lead supervisory authority for major tech companies headquartered in Ireland, including Meta, Google, Apple, and Microsoft. Ireland also has one of the shortest cookie consent validity periods in the EU at just 6 months.
What This Means for Your Website
- Prior informed consent is required before placing non-essential cookies on Irish visitors
- Cookie consent expires after 6 months and must be refreshed — significantly shorter than most EU countries
- Specific consent is required for each processing purpose; general blanket consent is insufficient
- Cookie-or-pay models cannot force tracking consent as a condition of access
- The DPC's 2020 cookie sweep found the majority of Irish companies non-compliant
Key Requirements
The DPC enforces SI 336/2011 with penalties of up to EUR 250,000 on conviction on indictment. GDPR fines also apply. The 6-month consent validity requirement is notably shorter than the typical 12-month period recommended elsewhere in the EU. As the lead authority for major tech companies, Irish enforcement decisions have outsized impact across Europe.
How ConsentStack Handles This
ConsentStack automatically manages the 6-month consent validity period for Irish visitors, re-collecting consent when it expires. The platform applies purpose-specific consent categories and blocks all non-essential cookies until explicit consent is given.
Penalties
Up to EUR 250,000 on conviction on indictment. GDPR penalties also apply (up to EUR 20 million / 4% global turnover).
Key Requirements
- Prior informed consent before placing non-essential cookies
- Consent limited to 6 months then must be refreshed
- Specific consent required for each purpose
- Clear and comprehensive information about cookie usage
- Cookie-or-pay models cannot force tracking consent
Notable Provisions
- Consent limited to 6 months — one of the shortest in the EU
- Lead supervisory authority for Meta, Google, Apple, Microsoft
- DPC 2020 cookie sweep found majority of companies non-compliant
Other ePrivacy Directive Related Regulations
Other Europe Regulations
Frequently Asked Questions
How long is cookie consent valid in Ireland?
Only 6 months. Ireland has one of the shortest cookie consent validity periods in the EU. ConsentStack automatically re-collects consent when it expires.
Why is Irish cookie enforcement important?
The DPC is the lead supervisory authority for Meta, Google, Apple, and Microsoft, making Irish enforcement decisions highly influential across all of Europe.
What are the cookie penalties in Ireland?
Up to EUR 250,000 on conviction on indictment under SI 336/2011. GDPR penalties of up to EUR 20 million or 4% of global turnover also apply.
Did the DPC find widespread cookie non-compliance?
Yes. The DPC's 2020 cookie sweep found the majority of Irish companies non-compliant with cookie consent requirements.
Stay compliant with SI 336/2011
ConsentStack helps you implement Opt-in consent for Ireland automatically.