Ireland's privacy regulator investigated 88% more marketing complaints last year
The Irish DPC's 2025 annual report shows a sharp jump in direct-marketing enforcement, including dozens of warning letters over unsolicited email and messaging.
By Norbelys Chirinos, Co-founder
Founder-reviewed ·How we research and correct articles
Ireland’s Data Protection Commission published its Annual Report for 2025 at the end of June 2026, and buried in it is a number that should get more attention from anyone sending commercial email to European recipients: the DPC concluded 275 electronic direct-marketing investigations over the year, an 88% jump from 2024, and sent out 50 formal warning letters over unsolicited marketing communications. Ireland’s DPC isn’t a regional afterthought here, either — it’s the lead supervisory authority for a large share of the tech and SaaS companies headquartered or incorporated in the EU, which makes its enforcement posture a genuine bellwether for how GDPR’s direct-marketing rules are actually being applied, not just how they read on paper.
Irish Data Protection Commission, Annual Report 2025 (published 30 June 2026), via emailexpert.
Why this number is worth taking seriously
An 88% year-over-year jump in concluded investigations is a large move for any regulator to make in a single reporting period, and it doesn’t happen by accident. Investigation volume tracks two things: how many complaints a regulator receives, and how much capacity it chooses to allocate to acting on them. A jump this size plausibly reflects both — continued growth in consumer awareness of the right to complain about unwanted marketing, paired with a deliberate enforcement push. Either way, the direction is the same for anyone sending commercial email into the EU through an Irish-regulated entity: the odds of an unsolicited-marketing complaint actually turning into a formal investigation went up meaningfully in the space of one year, not down.
What actually triggers one of these investigations
GDPR’s direct-marketing rules aren’t new, and neither is the underlying standard the DPC is enforcing against: for most B2C electronic marketing, and for a meaningful share of B2B outreach depending on the specific legal basis relied on, you need a valid legal basis to email someone commercially, a working way for them to object, and you need to actually honor that objection promptly when they do. What generates a complaint — as opposed to just a violation sitting undetected — is almost always one of the same handful of patterns: marketing sent after someone unsubscribed, marketing sent with no clear opt-out at all, marketing to a purchased or scraped list with no legitimate relationship to justify it, or marketing dressed up to look like a transactional message to dodge opt-out expectations in the first place.
The part most senders get wrong: honoring the objection, not just offering it
Having an unsubscribe link is table stakes; nearly every commercial sender clears that bar today. What actually generates a DPC complaint more often is what happens after someone clicks it — a delayed suppression that lets one or two more messages through, a suppression that only covers one campaign or list while the recipient keeps getting mail from a different one inside the same company, or a re-engagement or “we miss you” sequence that technically counts as new marketing to someone who already opted out. Each of those is defensible as an accident from the sender’s side and indefensible from the regulator’s, because GDPR’s standard isn’t “did you build an opt-out mechanism,” it’s “did the person’s objection actually take effect.” A complaint-driven investigation doesn’t care that your suppression failure was a bug in one list-sync job rather than a deliberate choice.
What this means if you’re not sure your own suppression is airtight
The honest test isn’t whether you have an unsubscribe link — it’s whether you could confidently answer “does every list and every campaign in our system check the same suppression record before sending” without having to go look. If that answer takes more than a few seconds, or if the honest answer is “mostly, except for one older list,” that’s the gap a rising DPC investigation count should make you want to close before a complaint does it for you.
A five-minute audit worth doing this week
List every place a contact's opt-out could live
Count your active lists, segments, and any exported CSVs sitting in a shared drive. Every separate place a contact record exists is a place a suppression flag can fail to propagate.
Test one real opt-out end to end
Unsubscribe a test contact from one campaign, then check whether a different list or sequence in the same account would still be able to email them. If the answer is yes, you've found the gap.
Check how fast the suppression actually takes effect
GDPR doesn't specify an exact number of hours, but a suppression that takes days to propagate — or requires a manual export/import step — is the kind of delay that turns an intended opt-out into a complaint.
Confirm re-engagement sequences respect the same flag
Win-back and re-engagement campaigns are the single most common place a technically-unsubscribed contact gets emailed again, because they're often built and maintained separately from the main suppression list.
Frequently asked questions
Does this DPC data cover email specifically, or all electronic marketing?
The DPC's reported figure covers electronic direct-marketing investigations broadly, which includes email alongside other electronic channels like SMS. The underlying source doesn't break the 275 figure down by channel, so the email-specific share isn't separately confirmed — but email marketing complaints are a well-established, ongoing driver of this category.
Does this affect companies outside the EU?
It can. GDPR's direct-marketing rules apply based on where the recipient is located, not where the sender is based, and Ireland's DPC is the lead supervisory authority for a large share of companies with an EU establishment there. A non-EU company marketing into the EU without a valid legal basis and working opt-out is exposed to the same underlying rules, even if Ireland specifically isn't the regulator that ends up investigating.
What's the single highest-leverage fix if my suppression handling is inconsistent across lists?
Centralize suppression at the platform level so every campaign and list checks one shared record before sending, rather than maintaining separate opt-out lists per campaign that can drift out of sync. That single change closes the most common failure mode behind marketing complaints: technically honoring one opt-out while a different list or sequence keeps sending.
One suppression list, checked automatically, every time
The failure pattern behind most direct-marketing complaints isn’t a missing unsubscribe link — it’s a suppression record that doesn’t actually cover every list and every sequence a contact is on. Norbelys enforces suppression automatically across your entire audience, not per-campaign, so an opt-out or bounce anywhere in your account takes effect everywhere, immediately, without relying on someone remembering to sync a spreadsheet. Paired with honest analytics that show you real engagement instead of inflated open counts, you get the compliance posture that actually holds up if a regulator with an 88%-larger investigation caseload ever looks your way. Start sending with Norbelys and stop maintaining suppression logic by hand across lists that can quietly fall out of sync.