DPC Ireland: How to File a Privacy Complaint (2026 Guide)
If a company has mishandled your personal data, ignored your access request, or sent you marketing you never signed up for, you have the right to complain to Ireland's Data Protection Commission (DPC). As the lead supervisory authority for many of the world's biggest tech firms headquartered in Dublin, the DPC handles complaints ranging from small local disputes to landmark cases against Meta, Google, TikTok, and LinkedIn.
This guide walks you through exactly how to file a privacy complaint with the DPC Ireland, what evidence to gather, how long the process takes, and what outcomes you can realistically expect in 2026.
What Is the DPC and What Does It Do?
The Data Protection Commission (DPC) is Ireland's independent regulator responsible for enforcing the General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018. It investigates complaints, audits organisations, issues fines, and provides guidance on privacy rights.
Because Ireland hosts the European headquarters of many multinational technology companies, the DPC often acts as the "lead supervisory authority" for cross-border cases affecting hundreds of millions of EU citizens. In recent years, the DPC has imposed fines exceeding €1 billion on companies including Meta and TikTok for GDPR violations.
Rights You Can Enforce Through the DPC
- Right of access — get a copy of the personal data an organisation holds about you.
- Right to erasure ("right to be forgotten") — request deletion of your data.
- Right to rectification — correct inaccurate data.
- Right to object — stop processing for direct marketing or other purposes.
- Right to data portability — receive your data in a machine-readable format.
- Right to restrict processing — pause how your data is used.
- Right not to be subject to automated decision-making, including profiling.
Before You File: Contact the Organisation First
The DPC strongly recommends — and in practice usually requires — that you contact the organisation directly before escalating. This gives the data controller a chance to resolve the issue and creates a paper trail that strengthens your complaint.
Step 1: Identify the Data Controller
The data controller is the organisation that decides how and why your data is processed. This is usually named in the company's privacy policy. If you're unsure, look for a "Data Protection Officer" (DPO) contact email or a dedicated privacy request form.
Step 2: Submit a Formal Request or Complaint
Send a clear, written request by email (keep copies). State:
- Your full name and any account identifiers.
- Which right you are exercising (e.g., "I am making a Subject Access Request under Article 15 GDPR").
- The specific information or action you want.
- A reasonable deadline — GDPR gives controllers one month to respond (extendable to three months for complex requests).
Step 3: Wait for the Statutory Deadline
The organisation has one calendar month to respond. If they miss the deadline, refuse without valid reason, or provide an incomplete response, you have grounds for a DPC complaint.
How to File a Complaint With the DPC Ireland
Filing a complaint is free and can be done entirely online, by post, or by email. There is no legal requirement to use a solicitor, though for complex commercial disputes it can help.
Method 1: Online Webform (Recommended)
The fastest way is via the DPC's official website at dataprotection.ie. Navigate to "Contact Us" and select "Raise a Concern." The webform will ask for:
- Your contact details.
- The name and contact details of the organisation you're complaining about.
- A description of what happened and when.
- Which of your rights you believe were breached.
- Copies of correspondence with the organisation.
- Any supporting evidence (screenshots, emails, letters).
Method 2: Email
You can email info@dataprotection.ie with the same information. Use a clear subject line such as "Formal Complaint — [Organisation Name] — GDPR Article [X]".
Method 3: Post
Send a written complaint to:
Data Protection Commission
21 Fitzwilliam Square South
Dublin 2, D02 RD28
Ireland
The DPC also has a Portarlington office, but Dublin is the primary correspondence address.
What to Include in Your Complaint
A well-documented complaint moves faster and is more likely to result in enforcement action. The DPC receives thousands of complaints annually and prioritises those with clear evidence.
Essential Documents
| Document | Why It Matters |
|---|---|
| Original request to the organisation | Proves you gave them a chance to resolve it |
| The organisation's response (or lack of) | Shows why escalation is needed |
| Screenshots of the issue | Visual evidence of unlawful processing |
| Copy of the privacy policy at the time | Establishes what the company promised |
| Timeline of events | Helps the case officer understand quickly |
| Marketing emails or cookies logs (if relevant) | Demonstrates specific violations |
Writing a Clear Narrative
Structure your complaint chronologically. Start with a one-paragraph summary, then a numbered timeline, then attach evidence. Reference specific GDPR articles where possible — for example, Article 15 (access), Article 17 (erasure), Article 21 (objection to marketing), or Article 32 (security of processing).
What Happens After You File
Once submitted, your complaint enters the DPC's intake system. Here's the typical process:
- Acknowledgement (within 1–2 weeks): You receive a case reference number.
- Initial assessment (2–8 weeks): A case officer reviews whether the complaint falls within the DPC's remit and whether you've contacted the organisation first.
- Amicable resolution phase: The DPC may attempt to mediate between you and the organisation. Many complaints are resolved here without formal investigation.
- Formal inquiry (if needed): If mediation fails or the breach is serious, the DPC opens a statutory inquiry. This can take months or, for cross-border cases, years.
- Decision and enforcement: Outcomes include reprimands, corrective orders, bans on processing, or administrative fines up to €20 million or 4% of global turnover.
Realistic Timelines
Simple domestic complaints (e.g., a local business ignoring an access request) are often resolved in 3–6 months. Cross-border cases involving major tech companies routinely take 2–5 years due to the GDPR's cooperation and consistency mechanisms with other EU regulators.
Common Types of Complaints the DPC Handles
Unsolicited Marketing
Emails, texts, or calls you never consented to — or that continue after you unsubscribed — are among the most common complaints. The ePrivacy Regulations 2011 give the DPC power to prosecute directly for marketing offences.
Ignored Access or Erasure Requests
If a company fails to respond within one month, or provides an inadequate response, this is a clear GDPR violation.
Data Breaches
If you've been notified (or discovered) that your data was leaked or accessed without authorisation, you can complain about how the breach occurred and how it was handled.
Excessive Data Collection
Companies collecting more data than necessary for their stated purpose — including via tracking cookies without valid consent — breach the principle of data minimisation.
CCTV and Workplace Surveillance
Neighbours' cameras pointing into your garden, or employers monitoring staff excessively, generate significant DPC caseloads each year.
Protecting Your Privacy Proactively
Filing a complaint is a reactive remedy. Preventing privacy problems in the first place is easier. Practical steps include using encrypted DNS resolvers, choosing privacy-focused browsers like Firefox or Brave, reviewing app permissions monthly, and being selective about which links you click or share.
When sharing links publicly — on social media, in newsletters, or across marketing campaigns — using a trustworthy link management tool matters. Services like Lunyb offer URL shortening without invasive tracking, giving you cleaner analytics without exposing your audience to third-party surveillance. For a deeper look at how it compares, see our honest Lunyb review or the wider 2026 URL shortener buyer's guide.
DPC Complaint vs. Court Action: Which Should You Choose?
You have two main routes to enforce your data rights in Ireland: complain to the DPC, or sue directly in the Circuit Court or High Court under Section 117 of the Data Protection Act 2018.
| Feature | DPC Complaint | Court Action |
|---|---|---|
| Cost | Free | Legal fees, court filing costs |
| Speed | Months to years | Typically 12–24 months |
| Compensation | DPC cannot award damages | Court can award material and non-material damages |
| Enforcement | Fines, orders, reprimands | Damages, injunctions |
| Legal representation | Not required | Strongly recommended |
| Best for | Systemic issues, no financial loss | Personal harm, quantifiable damages |
Pros and Cons of the DPC Route
Pros:
- Free and accessible without a lawyer.
- DPC has investigative powers you don't have as an individual.
- Outcomes can force systemic change benefiting many users.
- No risk of adverse legal costs.
Cons:
- No personal compensation.
- Cross-border cases can drag on for years.
- You have limited influence over how the investigation is conducted.
- Outcomes may be confidential.
Appealing a DPC Decision
If you're unhappy with the DPC's decision, you can appeal to the Circuit Court within 28 days of being notified. Appeals are heard on points of law and fact. You can also complain to the Ombudsman about the DPC's handling of your case (as distinct from the substantive decision).
Additionally, under the GDPR's one-stop-shop mechanism, if the case involves cross-border processing, other EU data protection authorities may weigh in via the European Data Protection Board (EDPB), which can override the DPC's draft decision.
Tips to Strengthen Your Complaint
- Be specific. "Company X sent me 14 marketing emails between March 1 and April 12 after I unsubscribed on February 28" beats "they keep spamming me."
- Cite GDPR articles where you can. Case officers appreciate legally literate complaints.
- Keep emotion out of the narrative. Facts, dates, and evidence carry more weight.
- Preserve everything. Never delete relevant emails, screenshots, or correspondence.
- Follow up politely. If you haven't heard back in 6–8 weeks, email the DPC quoting your case reference.
- Consider group complaints. If many people are affected, coordinated complaints (e.g., via NGOs like Digital Rights Ireland or noyb) carry more weight.
Frequently Asked Questions
How much does it cost to file a complaint with the DPC Ireland?
Filing a complaint with the Data Protection Commission is completely free. You do not need a solicitor, and there are no processing fees. The only costs would be optional legal advice or postage if you choose to file by mail.
How long does the DPC take to resolve a complaint?
Simple domestic complaints are typically resolved within 3–6 months through the DPC's amicable resolution process. Formal statutory inquiries take longer — often 12–24 months for domestic cases, and 2–5 years for cross-border cases involving major multinationals due to EU cooperation mechanisms.
Can the DPC award me compensation?
No. The DPC can issue fines, reprimands, and corrective orders, but the fines go to the Irish exchequer, not to complainants. If you want personal compensation for material or non-material damage, you must bring a civil claim under Section 117 of the Data Protection Act 2018 in the Circuit Court or High Court.
Do I have to contact the company before complaining to the DPC?
In almost all cases, yes. The DPC expects you to have raised the issue with the data controller first and given them a reasonable opportunity to respond — typically the statutory one-month window for a GDPR rights request. Exceptions exist for serious breaches or where contacting the controller would be inappropriate, but these are rare.
Can I complain to the DPC if I don't live in Ireland?
Yes, if the organisation you're complaining about has its EU main establishment in Ireland — which applies to Meta, Google, TikTok, LinkedIn, Apple's EU operations, and many others. For companies without an Irish presence, you should generally complain to your own country's data protection authority, which may then coordinate with the DPC under the one-stop-shop mechanism.
What if the DPC doesn't investigate my complaint?
If the DPC declines to investigate or issues a decision you disagree with, you have 28 days to appeal to the Circuit Court. You can also raise concerns about how your case was handled with the Office of the Ombudsman, though this is separate from appealing the substantive decision.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Privacy Rights in Canada 2026: A Complete Guide to PIPEDA, CPPA and Your Digital Protections
A comprehensive 2026 guide to privacy rights in Canada, covering PIPEDA, Quebec's Law 25, CPPA reforms and AI accountability. Learn what your rights are, how to exercise them, and practical steps to protect your personal data online.
GDPR After Brexit: What Changed for UK Businesses and Data Protection
Brexit created two parallel data protection regimes: the EU GDPR and the UK GDPR. This guide explains what actually changed, from adequacy decisions and international transfer rules to enforcement trends, and outlines what UK businesses must do to stay compliant in 2026.
ICO Fines 2026: Biggest Data Protection Penalties in the UK
The Information Commissioner's Office has issued some of its largest penalties yet in 2026, targeting firms across healthcare, retail and adtech. This guide breaks down the biggest ICO fines of the year, the breaches behind them, and the compliance lessons every UK business should learn.
OAIC Complaints: How to Report a Privacy Breach in Australia
A step-by-step guide to lodging an OAIC complaint about a privacy breach in Australia — including evidence to gather, timeframes, possible remedies and what to expect from the process. Learn your rights under the Privacy Act 1988 and the Australian Privacy Principles.