The object is not "GDPR is fake," and it is not "Ireland is captured." It is a catalogue of individual rights — access, erasure, objection, complaint — whose enforcement office, for a global processor, is a national data-protection authority. For Meta, that office is Ireland's Data Protection Commission, because GDPR Article 56 makes the authority of the main EU establishment the lead. The right exists on paper in every member state. The office that can actually stop a transfer sits in one of them, funded as a national public body, facing processors that operate worldwide.
Domain: fundamental-rights enforcement against cross-border commercial processing, especially transfers of personal data to third countries under GDPR Chapter V, where a Commission adequacy decision or standard contractual clauses can be swapped in while a complaint is still open.
If that reading is right, a complaint that a transfer is unlawful would have a clock with a consequence if the lead authority does not act. A later Commission finding that a third country is "adequate" would not automatically replace a pending order to stop a named controller's transfers. The office that can suspend a flow would not be sized only by the host member state's budget. You would see that change in whether a transfer actually stops, not in the length of the rights list.
Ostensive specimen: Judgment of the Court (Grand Chamber) of 16 July 2020, Case C-311/18, Data Protection Commissioner v Facebook Ireland Limited and Maximillian Schrems ("Schrems II"), ECLI:EU:C:2020:559. The Court invalidates Commission Implementing Decision (EU) 2016/1250 (the EU-US Privacy Shield). Standard contractual clauses remain valid, but a supervisory authority is required to suspend or prohibit a transfer where those clauses cannot be complied with in the third country and the required protection cannot be ensured by other means, if the exporter has not itself stopped the transfer. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62018CJ0311 Court press release No 91/20: https://curia.europa.eu/jcms/upload/docs/application/pdf/2020-07/cp200091en.pdf
The same complaint, ten years earlier: Maximillian Schrems lodged it with the Irish Commissioner on 25 June 2013, after the Snowden disclosures, seeking to stop Facebook Ireland sending his data to the United States under Safe Harbour. Schrems I, Case C-362/14, Grand Chamber, 6 October 2015, ECLI:EU:C:2015:650, declared Commission Decision 2000/520 (Safe Harbour) invalid. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:62014CJ0362 The 2013 complaint: https://noyb.eu/sites/default/files/2020-07/complaint-PRISM-facebook_2013.pdf
What the Irish office then did with Schrems II: Data Protection Commission inquiry IN-20-8-1, commenced 28 August 2020, decision of 12 May 2023. Meta Ireland infringed Article 46(1) GDPR by continuing EU/EEA-to-US Facebook transfers after Schrems II, including under the 2021 standard contractual clauses plus supplementary measures. Four of 47 peer authorities objected that a fine was also required. The European Data Protection Board settled that dispute. The DPC, on the basis of Binding Decision 1/2023 (13 April 2023), ordered Meta Ireland to suspend future transfers within five months, to cease unlawful processing including storage in the US within six months, and imposed an administrative fine of €1.2 billion. https://www.dataprotection.ie/en/dpc-guidance/decisions/inquiry-concerning-data-transfers-eueea-us-meta-platforms-ireland-limited-its-facebook-service EDPB Binding Decision 1/2023: https://www.edpb.europa.eu/documents/edpb-binding-decisions/binding-decision-12023-on-the-dispute-submitted-by-the-irish-sa-on_en
Inside that five-month window: Commission Implementing Decision (EU) 2023/1795 of 10 July 2023 finds that the United States ensures an adequate level of protection for transfers to organisations on the Data Privacy Framework List. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32023D1795 Meta's public statement, updated 7 September 2023: from that date it relies on the Data Privacy Framework for Facebook user data and related transfers from the EU to the US. https://about.fb.com/news/2023/05/our-response-to-the-decision-on-facebooks-eu-us-data-transfers/
The rights themselves: Regulation (EU) 2016/679, Chapter III (Articles 12–22), the complaint right in Article 77, lead authority in Article 56, corrective powers including suspension of third-country flows in Article 58(2)(j), cooperation in Article 60, Board dispute resolution in Article 65, adequacy in Article 45. https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32016R0679
This post is the public case, not a recap of an essay. One related diagnostic, not the object: https://kunnas.com/articles/rights-bubble