
William Fry
INPLP member firm · Dublin, Ireland
Leading law firm William Fry has over 320 legal and tax professionals and over 460 staff. Our client-focused service combines technical excellence with commercial awareness and a practical, constructive approach to business issues. We advise leading domestic and international corporations, financial institutions and government organisations. We regularly act on complex, multi-jurisdictional transactions and commercial disputes. Strong client relationships and high quality advice are the hallmarks of our business. We are ranked by international directories, clients and market commentators alike as being a leader in our main areas of work: Corporate & M&A, Banking & Finance, Litigation & Dispute Resolution, Asset Management & Investment Funds, Real Estate, Insurance, Competition & Regulation, Tax, Projects & Construction, Employment & Benefits and Technology. Our head office is in Dublin and in May 2019 we opened an office in Cork, enabling us to further service our clients in the Cork and wider Munster region. We have offices in London, New York, Silicon Valley and San Francisco and a global law firm network to service our clients at home and abroad. Our capability is enhanced by our alliance with Tughans, Northern Ireland’s largest law firm, through which we provide an all island solution. The Firm's priorities are focused on the need to achieve results for clients. Continued investment in people, technology and research maintain the Firm's ability to provide practical and prompt solutions, while devoting exacting attention to details. Leo is head of the William Fry Technology Group and has 20+ years experience in advising domestic and multinational companies on technology, data protection, intellectual property, and commercial contract law matters. Operating at the convergence point of technology, data and IP, Leo advises domestic and multi-national companies on digital transformation, software and technology licensing and development, Internet of Things, apps and smart technology, e-commerce, cloud computing and systems integration. His extensive experience on data protection includes advising "big data" and other companies on privacy and data protection compliance, DPIA's, GDPR compliance programmes, marketing and international transfers. Leo manages large IP portfolios for leading global and Irish enterprises and provides strategic advice and assistance on IP protection, exploitation strategies, licensing and brand management. Leo is a member of iTechLaw, the International Association of Privacy Professionals ("IAPP") and of the International Trade Mark Association ("INTA"). He is also a registered Irish and European Trade Mark and Design Attorney. Leo is noted as a leading lawyer in Ireland in IP, Technology and Data Protection in leading legal directories such as Chambers Europe and Legal 500. Rachel is a partner in the Technology Group at William Fry LLP. Her practice is dedicated to privacy & data protection, and by extension, the ever-evolving areas of cybersecurity, AI, data and content regulation. Rachel works closely with indigenous and multinational clients on all matters concerning data protection & privacy. Her extensive experience ranges from advising on global projects, complex data transfers, direct marketing, multi-jurisdictional personal data breaches / cyber incidents & reputation management, regulatory investigations & inquiries, individual complaints & rights requests, data subject claims & privacy litigation and general compliance matters. Rachel also has in-depth experience in drafting and implementing new legislation for public sector clients. Rachel regularly speaks at events, authors articles and provides training on her practice areas. In Legal 500 EMEA 2023, she was ranked as the Rising Star (Ireland) for privacy and data protection.
Representatives

Leo Moore
partner

Rachel Hayes
member
Contact
Publications
- A Record-breaking Year: 2025 Annual Report of Ireland’s Data Protection RegulatorIreland’s Data Protection Commission (DPC) published its Annual Report outlining its regulatory activities in 2025. Highlights include: a 45% increase in complaints, the arrival of AI-driven complaints, a decrease in reported breaches, the DPC’s international and growing inter-regulatory role and reprimands as the chosen enforcement power.9 July 2026
- Firm But Fair: Irish DPC Publishes 2024 Annual ReportOn 19 June 2025, the Data Protection Commission published its Annual Report for 2024, and the popular Case Studies Booklet 2024. The report indicates a fair, consistent regulatory approach by the DPC, which also encompasses a willingness to decisively pursue enforcement measures.22 July 2025
- AI, ChatGPT and the EDPB: Regulatory Insights from Taskforce ReportReport on ChatGPT outlines European data protection regulator's preliminary views and early indicators about the direction of regulatory travel regarding the co-existence of GDPR and Artificial Intelligence / EU AI Act.3 September 2024
- AdTech Update: CJEU landmark data protection ruling for online and behavioral advertisingOnline advertising is one of the largest online industries. However, it also has long faced issues with data protection regulators. The CJEU has handed down a landmark ruling that clarifies what legal bases controllers can rely on for online and behavioral advertising. This development follows several decisions relating to appropriate legal bases for processing data in the context of online and behavioral advertising.2 October 2023
- Non-material Damage for Data Protection Breaches before the Irish and EU Courts – Clarity Ahead?Data protection claims are in the dock. The Irish Circuit Court has temporarily halted proceedings for non-material damage claims pending clarity from decisions by the Court of Justice of the European Union on compensation for non-material damage in relation to 'mere upset' as a result of data privacy infringement.4 April 2023
- EU Regulators Elevate the Threshold of Compliance around Data Subject Access Requests.The European Data Protection Board and the Irish Data Protection Commission have recently published guidelines for businesses in relation to Data Subject Access Requests ("DSARs"). Both sets of guidlines signal that high standards of compliance are expected from controllers when handling DSARs. The publications are a key indicator that DSARs are very much in the spotlight from a regulatory enforcement perspective.4 November 2022
- Access Granted: DSAR changes for data controllers granting access to health dataUpdated regulations in Ireland regarding data subjects' access to their health data emerged in March 2022. The new regulations have changed the obligations on data controllers getting health practioners to sign off on data subject access requests.13 July 2022
- Athletes' Performance Data & Project Red CardThis article provides an insight to the ever increasing market of performance analysis and the intersection with athlete's performance data. A tool and resource used by sports clubs across the world, this article explains the current state of the market; how performance data is used and its value; and whether sports clubs may be in for a data protection 'red card' in the near future.23 January 2022
- GDPR Fines: Ramping up and DPAs Setting standardsEuropean Supervisory Authorities imposed more than €158m in fines under the GDPR during 2020; close to a 40% increase on the previous 20-month period. This brings the total amount of fines to more than €272m in the period from May 2018 to end 2020. Businesses now have greater insight into, and detail about, the amount of potential financial penalties for failing to comply with the GDPR.23 April 2021
- A Path Forward – Draft Guidance Published For Dealing With International Data Transfers Post-Schrems IIIn the wake of the decision of the Court of Justice of the European Union (CJEU) in Schrems II, controllers and processors have been working closely with legal advisors to find a compliant way to transfer personal data outside of the European Economic Area (EEA).10 December 2020
- First GDPR fines in Ireland: Big Tech Fines on the horizonIn May 2020 the Data Protection Commission (DPC) in Ireland issued its first fines under the GDPR, just prior to the second anniversary of the GDPR coming into effect. Additionally, extensive work has been under way for many months on cross border fines against big tech companies whose main establishments are in Ireland. Larger fines are expected to be announced later this year.6 July 2020
- GDPR IN NUMBERS – The Irish PerspectiveTo mark the occasion of GDPR's first anniversary, findings and statistics tracked from May 2018 to May 2019 concerning awareness, compliance and enforcement of the new rules throughout the EU have been emerging from the European Commission and the Irish data protection supervisory authority ("DPA"). The Irish Data Protection Commission ("DPC") has had a significant role to play in EU privacy oversight and enforcement for several reasons, most notably because some of the world's largest digital and cloud companies have located their European headquarters in Ireland. The DPC's 2018 Annual Report alongside its updated 2019 statistics make for an interesting comparison between Ireland's reaction to the GDPR and that of our EU counterparts.28 June 2019
- GDPR With an Irish Flavour – The Irish Data Protection Act 2018Ireland's Data Protection Act 2018 (the "DPA"), which implements elements of the European Union's General Data Protection Regulation (the "GDPR"), was formally passed in the nick of time on 24 May 2018 and together the DPA and the GDPR will have significant impact for the operations of those working in the cloud in or through Ireland. Here we outline and clarify some of the key aspects of the DPA.5 September 2018
Join the network
Applications from qualified privacy practices are reviewed individually by the INPLP board.