AIGovHub
Vendor Tracker
CCM PlatformSentinelProductsPricing
AIGovHub

The AI Compliance & Trust Stack Knowledge Engine. Helping companies become AI Act-ready.

Tools

  • AI Act Checker
  • Questionnaire Generator
  • Vendor Tracker

Resources

  • Blog
  • Guides
  • Best Tools

Company

  • About
  • Pricing
  • How We Evaluate
  • Contact

Legal

  • Privacy Policy
  • Terms of Service
  • Affiliate Disclosure

© 2026 AIGovHub. All rights reserved.

Some links on this site are affiliate links. See our disclosure.

Former Meta Lobbyist Appointed as Irish Data Protection Commissioner: Conflict of Interest Concerns
Irish DPC
Meta lobbyist
GDPR enforcement
data protection commissioner
conflict of interest

Former Meta Lobbyist Appointed as Irish Data Protection Commissioner: Conflict of Interest Concerns

AIGovHub EditorialMay 3, 20266 views

What Happened

In a controversial move, Niamh Sweeney, a former senior Meta lobbyist who spent over six years at the company, has been appointed as a commissioner at the Irish Data Protection Commission (DPC). Sweeney previously served as head of public policy for Facebook Ireland and director of public policy for WhatsApp Europe. Her appointment began in October.

The DPC serves as the EU's lead privacy regulator for most US Big Tech companies, including Meta, Google, and Microsoft, due to their European headquarters being located in Ireland.

Why It Matters

Privacy activists, including Max Schrems of noyb, have raised serious conflict of interest concerns. Sweeney defended Meta during major cases, including the Cambridge Analytica scandal and proceedings that resulted in €390 million and €1.2 billion fines—both currently under appeal between the DPC and Meta. Critics argue this appointment demonstrates Ireland's pro-business stance toward US tech giants and raises questions about regulatory capture.

The DPC has historically been criticized for ineffective GDPR enforcement against Big Tech. Despite issuing fines totaling billions of euros, it has collected only 0.6% of those penalties. The appointment of a former Meta lobbyist to oversee ongoing cases against her former employer undermines public trust in the data protection commissioner's impartiality.

What Organizations Should Do

While the DPC's enforcement record may be questioned, businesses should not relax their data protection efforts. Key compliance takeaways include:

  • Review data processing activities to ensure compliance with GDPR requirements, including data subject rights and consent mechanisms.
  • Conduct Data Protection Impact Assessments (DPIAs) for high-risk processing activities.
  • Maintain robust documentation of processing activities and lawful bases.
  • Monitor regulatory developments as scrutiny may intensify across EU member states.

For organizations seeking to streamline GDPR compliance, platforms like AIGovHub offer data privacy compliance tools that help monitor obligations and manage regulatory changes across multiple jurisdictions.

Related Resources

  • TikTok DSA Breach: AI Governance Lessons for Tech Companies
  • EU AI Office Recruitment: Scientific Panel for AI Governance
  • EU AI Act Compliance Roadmap: Implementation Guide