facebook-pixel

DPC Ireland: How to File a Privacy Complaint (2026 Guide)

L
Lunyb Security Team
··9 min read

If a company has mishandled your personal data, ignored a subject access request, or continues to send you unwanted marketing, you have the right to complain to Ireland's Data Protection Commission (DPC). This guide walks you through exactly how to file a privacy complaint with the DPC, what evidence you need, how long the process takes, and what outcomes to expect.

What Is the Data Protection Commission (DPC)?

The Data Protection Commission is Ireland's independent supervisory authority responsible for enforcing the General Data Protection Regulation (GDPR) and the Data Protection Act 2018. Because many of the world's largest technology companies — including Meta, Google, TikTok, Microsoft, and Apple — have their European headquarters in Dublin, the DPC acts as the lead supervisory authority for most cross-border data protection matters in the EU.

The DPC has three core functions:

  • Investigating complaints from individuals about how their personal data has been handled.
  • Supervising organisations to ensure ongoing compliance with data protection law.
  • Imposing sanctions, including administrative fines that can reach €20 million or 4% of global annual turnover.

When Should You File a Complaint With the DPC?

You can file a complaint with the DPC whenever you believe an organisation has breached your rights under the GDPR or the Data Protection Act 2018. Common grounds for complaint include:

  • Ignored subject access requests — an organisation failed to respond within one month to a request for a copy of your data.
  • Unlawful direct marketing — you continue to receive emails, SMS, or calls after unsubscribing or withdrawing consent.
  • Data breaches — your information was leaked, stolen, or exposed without adequate protection.
  • Excessive data collection — a company is gathering more information than necessary for its stated purpose.
  • Refusal to erase data — the organisation will not honour your right to be forgotten.
  • Inaccurate data — the controller refuses to correct information you have shown to be wrong.
  • Unlawful CCTV or surveillance — a neighbour, employer, or business is recording you without a lawful basis.
  • Cookies and tracking — a website drops non-essential cookies without valid consent.

Try to Resolve It Directly First

The DPC strongly encourages complainants to raise the issue directly with the organisation before escalating. Most controllers have a Data Protection Officer (DPO) or a dedicated privacy contact. Give them at least one calendar month to respond. Keep copies of every email — this correspondence forms the backbone of your evidence file.

How to File a Privacy Complaint With DPC Ireland: Step by Step

The DPC accepts complaints through an online webform, by post, and by email. Here is the exact process to follow in 2026.

Step 1: Gather Your Evidence

Before you contact the DPC, assemble a clear evidence pack. This should include:

  1. A written timeline of what happened and when.
  2. Copies of any subject access request, erasure request, or complaint you sent to the organisation.
  3. The organisation's response (or proof that no response was received).
  4. Screenshots, emails, letters, or SMS messages relevant to the issue.
  5. Your identification details so the DPC can verify you are the data subject.

Step 2: Identify the Correct Data Controller

You need to name the specific organisation responsible. For a website, this is usually listed in the privacy policy. For social platforms operating out of Ireland (Meta Ireland Limited, TikTok Technology Limited, Google Ireland Limited), use the legal entity name — not the brand.

Step 3: Complete the DPC Complaint Form

Visit dataprotection.ie and open the "Raise a Concern" or "Contact / Complaint" webform. You will be asked to provide:

  • Your full name and contact details.
  • The name of the organisation you are complaining about.
  • A clear description of the issue, in plain language.
  • What outcome you are seeking (erasure, correction, an apology, an investigation).
  • Attachments — the DPC accepts PDF, JPG, and PNG files.

Step 4: Submit and Await Acknowledgement

After submission, the DPC will send an automated acknowledgement, usually within a few business days. A case handler is then assigned. You will receive a reference number — keep this for all future correspondence.

Step 5: Engage With the Amicable Resolution Process

Under Section 109 of the Data Protection Act 2018, the DPC must first attempt to resolve complaints amicably between you and the organisation. The case handler will typically contact the controller, share your complaint, and mediate a response. Many cases are resolved at this stage without a formal decision.

Step 6: Formal Investigation (if Needed)

If amicable resolution fails, the DPC may open a formal statutory inquiry. This can result in a legally binding decision, a reprimand, an enforcement notice, or an administrative fine. Complex cross-border cases may take 12–24 months or longer.

DPC Complaint Channels at a Glance

ChannelBest ForTypical Response Time
Online webform (dataprotection.ie)Most complaints — fastest route5–10 business days for acknowledgement
Email (info@dataprotection.ie)Follow-up correspondence, sending additional evidence10–15 business days
Postal mail (21 Fitzwilliam Square South, Dublin 2, D02 RD28)Formal legal correspondence, hard-copy evidence2–4 weeks
Phone (+353 578 684 800)General queries — not for lodging complaintsImmediate for queries

What Information Should Your Complaint Include?

A well-structured complaint dramatically improves your chances of a quick, favourable outcome. Include the following sections in your submission:

  1. Your identity — full name, address, email, and phone number.
  2. The controller's identity — legal name, registered address if known.
  3. The facts — a chronological, factual account. Avoid emotive language.
  4. The legal basis of your complaint — cite specific GDPR articles if you can (e.g., Article 15 for access, Article 17 for erasure, Article 21 for objection).
  5. Steps already taken — details of your direct contact with the organisation.
  6. Your desired resolution — what you want the DPC to require of the controller.
  7. Attachments list — a numbered index of the evidence you are submitting.

How Long Does a DPC Complaint Take?

Timelines vary significantly depending on complexity:

Complaint TypeTypical Duration
Simple domestic complaint (e.g., local business ignored SAR)2–6 months
Direct marketing complaint1–4 months
CCTV or workplace surveillance4–9 months
Cross-border complaint involving a Big Tech controller12–36 months
Formal statutory inquiry with fine18–48 months

What Outcomes Can the DPC Deliver?

The DPC has a broad enforcement toolkit. Possible outcomes include:

  • Amicable resolution — the controller apologises, complies with your request, or changes its practices.
  • Reprimand — a formal warning issued to the controller under Article 58(2)(b) GDPR.
  • Enforcement notice — a legally binding order requiring the controller to take specific action.
  • Administrative fine — up to €20 million or 4% of global turnover, whichever is higher.
  • Ban on processing — the DPC can order the controller to stop processing certain data.

Compensation and Damages

The DPC itself cannot award you monetary compensation. However, once the DPC has confirmed a breach, you may bring a separate civil action in the Circuit Court or High Court under Section 117 of the Data Protection Act 2018 to claim damages for material or non-material harm.

Protecting Your Privacy Before Problems Arise

Filing a complaint is a reactive step. Preventing exposure in the first place is far easier. A few practical habits will reduce the likelihood you'll ever need the DPC:

  • Use disposable or masked email addresses when signing up for services you don't fully trust.
  • Audit app permissions on your phone every quarter and revoke anything you no longer use.
  • Read privacy notices — especially the "legitimate interests" section, which often reveals data-sharing you can object to.
  • Shorten and cloak sensitive links when sharing them publicly. Tools like Lunyb let you create private, trackable short links that hide destination URLs — useful when you don't want scrapers or third parties to profile your onward traffic. For a deeper look at trusted shortening tools, see our 2026 URL shortener buyer's guide and our honest Lunyb review.
  • Enable encrypted DNS (DNS over HTTPS or DNS over TLS) in your browser and operating system to prevent your internet provider from logging every domain you visit.
  • Turn on two-factor authentication on every account holding sensitive data.

Common Mistakes When Complaining to the DPC

Avoid these pitfalls that often derail otherwise valid complaints:

  1. Skipping direct contact with the controller. The DPC will usually redirect you to try this first.
  2. Providing insufficient evidence. A one-line email will not persuade a case handler.
  3. Naming the wrong entity. "Facebook" is not a legal person; "Meta Platforms Ireland Limited" is.
  4. Using emotive rather than factual language. The DPC assesses law and facts, not feelings.
  5. Missing deadlines. Under Section 117, civil actions must generally be brought within six years, but shorter statutory windows may apply — act promptly.
  6. Failing to update contact details. Investigations can span years. Notify the DPC if you move house or change email.

Your Right to Appeal

If you are unhappy with the DPC's decision, you have two options:

  • Statutory appeal to the Circuit Court within 28 days of the decision under Section 150 of the Data Protection Act 2018.
  • Judicial review in the High Court if you believe the DPC acted unlawfully or unreasonably in the process.

You can also escalate to the European Data Protection Board (EDPB) in certain cross-border cases where the DPC is acting as lead authority.

Frequently Asked Questions

Is there a fee to file a complaint with DPC Ireland?

No. Filing a complaint with the Data Protection Commission is entirely free of charge. You are not required to hire a solicitor, although you may choose to do so for complex matters or if you intend to pursue a civil damages claim afterwards.

Can I file a complaint with the DPC if I don't live in Ireland?

Yes, if the organisation you are complaining about has its main EU establishment in Ireland. This is common with major tech platforms. Otherwise, you should generally complain to the supervisory authority in your own EU/EEA country, which will coordinate with the DPC through the GDPR's one-stop-shop mechanism.

How long do I have to make a complaint?

There is no strict statutory deadline for lodging a GDPR complaint, but the DPC expects complaints to be brought within a reasonable time — typically within 12 months of the incident or of you becoming aware of it. Delays make investigations harder and reduce the chance of a successful outcome.

Will the organisation know I complained about them?

Yes. To investigate, the DPC must share the substance of your complaint with the controller. Your identity is generally disclosed because the controller needs to identify you to respond meaningfully (for example, to locate the personal data at issue). Anonymous complaints are rarely actionable.

Can I withdraw my complaint after filing it?

Yes, you can withdraw a complaint at any point by writing to the DPC. However, if the case handler believes there is a wider public interest — for example, evidence of systemic wrongdoing affecting many people — the DPC may continue its inquiry on its own initiative.

Final Thoughts

The Data Protection Commission is one of the most powerful privacy regulators in the world, and lodging a complaint is a genuine, effective way to hold organisations accountable. Prepare your evidence carefully, engage with the amicable resolution stage in good faith, and be patient — especially for cross-border cases. In parallel, adopt sensible privacy habits so that fewer of your personal details end up in the wrong hands in the first place.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles