Ireland: Compliance

Subscribe
Business law and corporate law thought leadership, articles, podcasts, videos and webinars from expert sources across the legal world. Explore insights covering topics that involve business and corporate law produced by specialists working in this area every day.
Article
Cyber Resilience Act: New Vulnerability Reporting Requirements Now In Force
The EU Cyber Resilience Act introduces mandatory reporting obligations for manufacturers of digital products, requiring them to notify authorities within 24 hours of discovering actively exploited vulnerabilities or severe security incidents. This regulation establishes strict timelines for early warnings, detailed vulnerability notifications, and final reports, fundamentally changing how manufacturers must respond to cybersecurity threats.
Ireland Technology
BJ
Browne Jacobson
Article
Fitness And Probity Thematic Assessment: What MiFID Firms Need To Know
The Central Bank of Ireland's thematic assessment of the Fitness and Probity regime within the MiFID investment firm sector reveals critical gaps in governance documentation and evidence. Firms are struggling to demonstrate adequate due diligence processes, policy implementation, and Management Responsibility Map compliance. Can your organization withstand regulatory scrutiny of its F&P framework?
Ireland Finance
M
Matheson
Article
The EU Cyber Resilience Act: Reporting Obligations Take Effect
The EU Cyber Resilience Act introduces mandatory vulnerability and incident reporting obligations for products with digital elements starting September 2026. Economic operators developing, importing, or distributing such products in the EU face strict compliance deadlines, substantial penalties for non-compliance, and must implement security-by-design principles throughout product lifecycles.
European Union Media & IT
M
Matheson
Article
AG Opinion Flags New Data Retention Compliance Risks For Irish Telecoms
The European Court of Justice's Advocate General has delivered an opinion suggesting that the proportionality of data retention regimes should be assessed not only by the categories of data retained, but also by the technical arrangements surrounding that retention. This opinion raises questions about whether Ireland's 2022 Communications (Retention of Data) (Amendment) Act provides sufficiently...
Ireland Privacy
M
Matheson
Article
NCSC Guidance On Cyber Governance: What Management Boards Of NIS2 Entities Need To Know
Ireland's National Cyber Security Centre has issued comprehensive guidance on NIS2 compliance, placing cybersecurity firmly in the boardroom. With potential fines reaching €10 million or 2% of global turnover for essential entities, management boards must now actively oversee cyber risk strategies, incident response capabilities, and supply chain vulnerabilities. The guidance provides a structured framework for organisations to assess their readiness before the National Cyber Security Bill takes effec
Ireland Media & IT
AC
Arthur Cox
Article
CJEU Clarifies The Limits Of The Hosting Safe Harbour For Online Platforms
The Court of Justice of the European Union has delivered landmark judgments that fundamentally reshape how online platforms can claim immunity from liability for user-generated content. These decisions establish that algorithmic content distribution and commercial partnerships with creators may strip platforms of their safe harbour protections, forcing a reassessment of how social media companies, video-sharing services, and digital marketplaces structure their operations and revenue models.
Ireland Technology
M
Matheson
Article
Raising The Bar: Irish Supreme Court Confirms “strong Case” Test For Pre-trial Stays Of Regulatory Decisions
Ireland's Supreme Court has established a significantly higher threshold for obtaining interim stays on regulatory decisions that affect broad public interests. Companies challenging decisions by bodies like the Data Protection Commission must now demonstrate a "strong case" likely to succeed at trial, rather than merely an "arguable case," before courts will even consider granting temporary relief.
Ireland Litigation
M
Matheson
Article
Central Bank Of Ireland Review Of Delegation By Fund Management Companies
The Central Bank of Ireland has completed its review of delegation practices across fund management companies, examining how the sector's dramatic growth to €5.6 trillion in assets has impacted oversight and governance frameworks. With 9,000 authorized funds now supported by 121 FMCs, the regulator has identified both effective practices and areas requiring enhancement across five critical operational domains. FMCs must now benchmark their policies against these supervisory expectations and implement
Ireland Wealth Mgt
D
Dechert
Article
Offshore Update: General Scheme Of Marine Protected Areas Legislation Published
The Irish Government has published the General Scheme of the Maritime Area Planning (Marine Protected Areas) (Amendment) Bill 2026, which would integrate marine protected area designation into Ireland's existing maritime spatial planning framework. This legislative proposal aims to protect 30% of Irish waters by 2030 while establishing new compliance obligations for public bodies and consultation mechanisms for stakeholders with maritime interests.
Ireland Environment
AC
Arthur Cox
Video
Video: Protected Disclosures In Ireland – Episode 5
When a worker raises a protected disclosure in Ireland, employers must follow specific legal procedures under the Protected Disclosures Act 2014. This video outlines the critical steps organisations need to take, from establishing internal reporting channels to conducting proper investigations and avoiding criminal offences. Understanding these requirements is essential for maintaining compliance and protecting both whistleblowers and the organisation.
Ireland Employment
WF
William Fry
Article
Irish Gambling Regulatory Regime – Implementation Update
Ireland's Gambling Regulatory Authority is now actively licensing operators and enforcing the comprehensive regulatory framework established by the Gambling Regulation Act 2024. With remote operators already transitioned and in-person operators facing a December 2026 deadline, the GRAI has implemented wide-ranging enforcement powers including administrative sanctions up to €20 million and criminal provisions for unlicensed activities. Recent CJEU case law highlights critical compliance considerations
Worldwide Media & IT
M
Matheson
Article
New CJEU Guidance On Dawn Raid Powers And Seizure Of Business Emails
The Court of Justice of the European Union has ruled on the extent of competition authorities' powers to seize business emails during antitrust investigations without prior judicial authorization. This landmark decision addresses fundamental questions about the balance between effective competition law enforcement and the protection of corporate communications under EU fundamental rights law.
Ireland Anti-trust
AC
Arthur Cox
See more