
Arthur Cox LLP
INPLP member firm · Dublin 2, Ireland
Arthur Cox is an Irish corporate law firm headquartered in Dublin, with offices in Belfast, London, New York City, and San Francisco. Colin Rooney is Head of the Technology and Innovation Group at Arthur Cox. He advises on data protection and privacy, information technology, outsourcing, cloud computing and e-business matters. Colin has extensive experience advising domestic and international clients on information management issues, with his data protection and information technology practice covering all aspects of data processing across all industry sectors. His practice also has a strong emphasis on commercial IT agreements. Aoife Coll is a senior associate in the Technology and Innovation Group and has extensive technology law experience including in data protection and privacy, artificial intelligence, information technology and e-business matters. Aoife advises corporates, technology companies and the public sector on a wide range of data protection matters including data subject rights requests, international transfers of personal data, governance arrangements and high-risk processing activities. Aoife has a particular focus on regulatory engagement and has advised numerous large tech, banking and public bodies on large-scale and cross-border regulatory inquiries from the initial stages of an investigation, through to draft decisions and final outcomes. Aoife has in-depth market and practical experience from working on secondment with large tech and private equity clients.
Representatives

Colin Rooney
member

Aoife Coll
partner
Contact
Publications
- Brillen Rottler – A review of the DSAR mechanismOn 19 March 2026, the Court of Justice of the European Union (CJEU) delivered its judgment in Brillen Rottler GmbH & Co KG v TC (Case C-526/24) addressing key issues surrounding data subject access requests (DSAR) and abusive practices. This decision has been anticipated as a potential opportunity to provide further guidance on balancing the right of access under Article 15 GDPR with controllers’ competing rights.2 July 2026
- The Right to Compensation Under the GDPR: Key Takeaways from Recent Case Law of the Court of Justice of the European UnionOver the course of several preliminary references during 2023 and 2024, the Court of Justice of the European Union (“CJEU”) has clarified the circumstances in which data subjects will be entitled to compensation under Article 82 of the General Data Protection Regulation (“GDPR”). The following six decisions wilal be of interest to controllers who are concerned about litigation by data subjects claiming compensation for an infringement of the GDPR, particularly in cases where the controller claims that they are not responsible for the breach and where the claimant suffers non-material damage.4 July 2024
- Processing Children’s Data Correctly: Takeaways from the Recent TikTok DecisionIn September 2023, the Irish Data Protection Commission (“DPC”) adopted its final decision in an own-volition inquiry into the processing by TikTok Technology Limited (“TikTok”) of personal data relating to child users of the TikTok platform. The sanctions imposed on the social media platform include an administrative fine totalling €345 million, a reprimand and an order to bring processing into compliance within a period of three months.31 January 2024
- The Data Protection Commission’s 2022 Annual ReportOn 7 March 2023, the Data Protection Commission (“DPC”) released its 2022 Annual Report. We have summarized the key points from the 90-page Report below.11 May 2023
- ‘Mere Upset’ Not Sufficient for GDPR Compensation ClaimsOn 6 October 2022, Advocate General Manuel Campos Sánchez-Bordona issued an opinion concerning the right to compensation for non-material damage under the GDPR (the “Opinion”). The Advocate General found that data subjects are not entitled to compensation for non-material damage by showing “mere upset” at an infringement of the GDPR. Article 82(1) GDPR provides that a data subject has the right to receive compensation for material or non-material damage suffered as a result of a breach of the GDPR.7 February 2023
- Seven Key figures from the Irish Data Protection Commission’s 2021 Annual ReportOn 24 February 2022, the Data Protection Commission released its 2021 Annual Report (the “Report”) running to over one hundred pages. We pick seven figures from the Report that provide an insight into the work of the Ireland’s Data Protection Commission (“DPC”), the challenges it faces, and its focus for 2022.6 June 2022
Join the network
Applications from qualified privacy practices are reviewed individually by the INPLP board.