Who Proves What? High Court clarifies burden of proof in first Representative Action

On 25 September 2026, Justice Rory Mulcahy delivered a significant judgment in Irish Council for Civil Liberties CLG v Microsoft Ireland Operations Limited [2026] IEHC 640.

The case concerns a representative action brought by the Irish Council for Civil Liberties ("ICCL"), a designated qualified entity, against Microsoft Ireland Operations Limited ("Microsoft") under the Representative Actions for the Protection of the Collective Interests of Consumers Act 2023 ("the 2023 Act").   ICCL alleges that Microsoft has infringed the General Data Protection Regulation ("GDPR" or the “Regulation”) in its processing of personal data through its Xandr real-time bidding advertising platform.

The judgment addresses a preliminary trial of agreed issues concerning the allocation of the burden of proof in GDPR proceedings and the consequential implications for the rules of pleading.

Key Issues

The Court was asked to determine the following principal issues:

  • Whether the GDPR accountability provisions (Articles 5(2) and 24(1)) reverse the legal or evidential burden of proof in a representative action seeking injunctive relief under the 2023 Act.
  • The effect of those GDPR provisions on the application of the rules of pleading under Order 19, rules 3, 5 and 7 of the Rules of the Superior Courts.
  • Whether the "peculiar knowledge principle" reverses the burden of proof in such proceedings.
  • Whether the defendant is entitled to seek information regarding the section 19(10) requirements of the 2023 Act after proceedings have been deemed admissible.

Burden of Proof Issues

The Court held that there is no "general reversal" of the legal or evidential burden of proof in proceedings alleging infringement of the GDPR.  A plaintiff cannot simply issue proceedings against a defendant claiming a breach of the GDPR and require the defendant to prove that it has not breached the Regulation.  The plaintiff must establish that the obligations of the GDPR are engaged in respect of the defendant.

The Court found that where a plaintiff discharges its burden of proving that:

  • the defendant is a data controller;
  • there is processing of personal data which triggers obligations under the GDPR; and
  • the relevant GDPR obligations are thereby engaged,

the legal and evidential burden of demonstrating compliance with those obligations then falls to the controller.  Critically, the Court held that this is not merely a shifting evidential burden in the sense discussed in Koger v O'Donnell [2013] IESC 28 but rather represents the imposition of the ultimate legal burden and the associated evidential burden on the controller in respect of the discrete issue of GDPR compliance.

Pleading Issues

The Court confirmed that the ordinary rules of pleading under Order 19 of the Rules of the Superior Courts, apply to both parties.  Each party must plead the material facts on which it relies to establish the matters it must prove.

Importantly, the Court held that where Microsoft bears the burden of proving compliance with GDPR obligations, if it wishes to make an affirmative case of compliance by way of defence, it must plead the material facts upon which it will rely for that purpose.  The Court drew attention to the established principle from AIB plc v AIG Europe Limited [2019] 3 IR 650 that the pleading requirements reflect the burden of proof: a party that bears the burden of proof on an issue must plead the facts supporting its case and cannot rely on bare denials.

The Court further noted the risk, following Duffy v Ridley Properties [2008] 4 IR 282, that a party which fails to plead necessary material facts may subsequently be precluded from making a positive case at trial.

The Peculiar Knowledge Principle

This long-established principle provides that the onus of proof can be reversed where a matter is not within the means of knowledge of one party and is peculiarly within the knowledge of the opposing party.  Here, the Court declined to determine whether the “peculiar knowledge principle” reverses the burden of proof, holding that whether the principle applies in any given case is a question of fact. As there was no agreement in relation to any facts which would enable the court to determine whether it should apply in this case, the Court declined to determine this issue. 

Defendant's Entitlement to Seek Information Under Sections 19(10) and 19(11) of the 2023 Act

Section 19 of the 2023 Act addresses the capacity of qualified entities to take representative actions, and in particular section 19(10) requires a qualified entity when seeking to have a representative action deemed admissible to provide specified information to the Court.  Section 19(11) of the 2023 Act requires a qualified entity to provide the court with sufficient information regarding the consumers affected by the alleged infringement. 

The Court held that sections 19(10) and 19(11) of the 2023 Act do not give a defendant a standalone entitlement to seek the disclosure of further information by a plaintiff about the information required by section 19(10) of the 2023 Act.  However, the Court confirmed that this does not preclude a defendant from seeking particulars, discovery, or disclosure under section 34(2) of the 2023 Act (where the requirements governing those procedures are satisfied), or from seeking to set aside an order deeming proceedings admissible.   

Conclusion

As the first substantive decision under the 2023 Act, this judgment provides useful early guidance on the procedural framework for representative actions in Ireland. It also clarifies an important point for GDPR litigation: once a plaintiff establishes that the GDPR's obligations are engaged, the burden of proving compliance falls on the data controller. While the ruling on the burden of proof follows a well-established line of CJEU authority, its application in the context of Irish proceedings is a helpful clarification. Many aspects of the 2023 Act's procedural architecture remain untested, and the substantive action itself, including the question as to whether Microsoft is the data controller, is still to be tried.

Also contributed to by Gabrielle Wall

This content has been prepared by McCann FitzGerald LLP for general guidance only and should not be regarded as a substitute for professional advice. Such advice should always be taken before acting on any of the matters discussed.

Key Contacts