SOVEREIGNTY LAW ATLAS — IE
Ireland
The verdict.
FOUR DOMAINS · CONFIDENCE-LABELLED · AS CAPTURED 2026-08-04Ireland is the EU's data-center hub and its lead-authority jurisdiction — EU law applies, but enforcement culture and US-provider concentration are the real variables.
ATLAS RECOMMENDATION — DOCUMENTED CONTROL · Concentrated US-provider exposure — zero-reach default. Seeded into the configurator; adjust anything.
The dossier.
SOURCES FOOTNOTED · EVIDENCE STATE LABELLEDDomains
D1 — Data residency & localization
GDPR Chapter V governs transfers: adequacy decisions, standard contractual clauses, or derogations.1 The national layer is the Data Protection Act 2018, which also establishes the DPC's enforcement powers.2 Transfers to the US currently ride the EU–US Data Privacy Framework; its durability under court challenge is a standing watch item. (REPORTED)
D2 — AI-specific regulation
The EU AI Act applies directly in Ireland without national implementing legislation for most obligations, phased from February 2025 (prohibitions) to August 2026 (general application).3 Demo scope captures EU provisions inline within the member record; a factored EU spine is a Phase 2 decision.
D3 — Cloud & procurement sovereignty
No national sovereign-cloud certification scheme. Public procurement follows EU rules; providers cite EU-level or German/French certifications when selling to Irish government.
D4 — Export & access
Ireland hosts the EU headquarters of most US hyperscalers and platform companies — meaning the entities holding European customer data are US-controlled, and the CLOUD Act reaches them regardless of data location. The Irish DPC is simultaneously the lead regulator for those same companies. Both facts matter more than any residency rule.
Extraterritorial exposure
The exposure is structural, not incidental: "hosted in Ireland" and "outside US legal reach" are independent questions, because the controlling entities are US-incorporated. A buyer requiring insulation from US lawful access needs EU-controlled provision, not merely EU location. US reference record deferred to Phase 2.
Disclaimer
This dossier describes the law as captured on 2026-08-04; it is not legal advice, and no compliance determination is made or implied.
- Regulation (EU) 2016/679 (GDPR), Ch. V — EUR-Lex CELEX 32016R0679 — fetch blocked by EUR-Lex bot-gating (202), cited to official source. (REPORTED) ↑
- Data Protection Act 2018 (No. 7 of 2018) — Irish Statute Book — not vaulted (HTML source). (REPORTED) ↑
- Regulation (EU) 2024/1689 (AI Act) — EUR-Lex CELEX 32024R1689 — fetch blocked by EUR-Lex bot-gating (202), cited to official source. (REPORTED) ↑
The instruments.
3 ON RECORD · 1 GAPSRegulation (EU) 2016/679 (GDPR), Chapter V — transfers to third countries
REPORTEDData Protection Act 2018 (No. 7 of 2018)
REPORTEDRegulation (EU) 2024/1689 (AI Act)
REPORTEDNo national sovereign-cloud certification scheme
This dossier describes the law as captured 2026-08-04; it is not legal advice, and no compliance determination is made or implied.