facebook-pixel

DPC Ireland: How to File a Privacy Complaint (2026 Guide)

L
Lunyb Security Team
··9 min read

If a company mishandled your personal data, ignored a subject access request, or refused to delete your information, you have the right to complain to the Data Protection Commission (DPC) in Ireland. As Ireland's independent data protection authority — and the lead European regulator for many of the world's largest tech companies — the DPC handles thousands of complaints every year. This guide walks you through exactly how to file a complaint, what evidence you need, how long it takes, and what outcomes to realistically expect.

What Is the DPC and What Does It Do?

The Data Protection Commission (DPC) is Ireland's national independent authority responsible for upholding the fundamental right of individuals in the EU to have their personal data protected. It enforces the General Data Protection Regulation (GDPR), the Irish Data Protection Act 2018, and the ePrivacy Regulations.

Because so many multinational tech companies — including Meta, Google, TikTok, Microsoft, and LinkedIn — have their European headquarters in Dublin, the DPC acts as the "lead supervisory authority" for cross-border complaints under GDPR's one-stop-shop mechanism. This means an Irish complaint can sometimes affect users across the entire European Economic Area (EEA).

Key Responsibilities of the DPC

  • Investigating complaints from individuals about data processing
  • Auditing organisations for compliance
  • Issuing fines and corrective orders for GDPR breaches
  • Providing guidance to controllers and processors
  • Cooperating with other EU data protection authorities

When You Can File a Complaint With the DPC

You can file a complaint with the DPC if you believe an organisation has violated your data protection rights under GDPR or Irish law. The organisation must either be based in Ireland or fall under the DPC's jurisdiction as lead supervisory authority.

Common Grounds for a Complaint

  1. Ignored data subject rights requests — access, erasure ("right to be forgotten"), rectification, portability, or restriction requests that were denied or unanswered within one month.
  2. Unlawful processing — a company processing your data without a valid legal basis such as consent, contract, or legitimate interest.
  3. Data breaches — you were affected by a breach that wasn't handled properly or wasn't disclosed.
  4. Unwanted direct marketing — emails, SMS, or calls after you unsubscribed or without valid consent.
  5. Excessive data collection — a service demanding more personal information than necessary.
  6. Cookie and tracking violations — websites setting non-essential cookies without proper consent.
  7. CCTV and workplace monitoring — disproportionate surveillance by employers, landlords, or neighbours.

Step-by-Step: How to File a Complaint With the DPC

Step 1: Contact the Organisation First

The DPC strongly recommends — and in practice usually requires — that you first attempt to resolve the issue directly with the organisation. Send a written complaint (email is fine) to their Data Protection Officer (DPO) or privacy contact. Larger organisations must publish DPO contact details in their privacy policy.

Give them a reasonable time to respond — typically 30 days under GDPR. Keep copies of everything you send and receive. If they refuse, ignore you, or give an unsatisfactory response, you can then escalate.

Step 2: Gather Your Evidence

Before you file, compile a clear evidence pack. Well-organised complaints move faster.

  • Copies of correspondence with the organisation (with dates)
  • Screenshots of the offending processing, marketing message, or website behaviour
  • The organisation's privacy policy at the relevant date
  • Any account records, receipts, or contracts showing your relationship
  • A short written timeline of events

When you share screenshots publicly or with third parties, be careful not to expose sensitive tracking links. Using a privacy-respecting link shortener like Lunyb can help you share evidence URLs without leaking additional metadata. You can read more about the service in our honest Lunyb review.

Step 3: Choose the Right Complaint Channel

The DPC offers several ways to raise a concern. Choose based on the seriousness and formality of your issue.

ChannelBest ForResponse Time
Webform (dataprotection.ie)Formal complaints requiring investigationAcknowledgement within ~10 working days
Email (info@dataprotection.ie)General queries and informal issues1–3 weeks
Postal letterComplaints with physical evidence2–4 weeks
Breach Notification PortalControllers reporting their own breachesImmediate acknowledgement

Step 4: Submit the Formal Complaint

Go to dataprotection.ie and select "Raise a Concern" or "Lodge a Complaint." You'll be asked to provide:

  1. Your full name and contact details
  2. The name and address of the organisation you're complaining about
  3. A description of what happened, in chronological order
  4. The specific data protection right you believe was breached
  5. Copies of your prior correspondence with the organisation
  6. The outcome you're seeking (deletion, correction, compensation referral, etc.)

Be factual, concise, and unemotional. Cite specific GDPR articles if you know them (e.g., Article 15 for access, Article 17 for erasure), but this isn't mandatory.

Step 5: Wait for Acknowledgement and Assessment

The DPC will acknowledge your complaint, usually within two weeks. A case officer then assesses whether it falls within the DPC's remit and whether it has substance. Simple cases may be resolved via "amicable resolution" — the DPC contacts the organisation and mediates. Complex or systemic cases may proceed to a formal statutory inquiry.

What Happens After You File

The DPC uses a tiered approach. Understanding the stages helps set realistic expectations.

Amicable Resolution

Roughly two-thirds of DPC complaints are resolved through informal mediation. The case officer contacts the controller, explains the issue, and negotiates a fix — usually deletion of data, correction of records, or a policy change. This is fast (often 1–4 months) but produces no fine.

Statutory Inquiry

If amicable resolution fails, or the issue is serious or systemic, the DPC opens a formal inquiry under Section 110 of the Data Protection Act 2018. Inquiries involve detailed evidence gathering, submissions from both sides, and a draft decision that can be appealed internally before finalisation.

Cross-border inquiries involving Big Tech routinely take 2–4 years due to the GDPR cooperation procedure with other EU authorities.

Possible Outcomes

  • Reprimand or warning
  • Order to comply (e.g., delete data, stop processing)
  • Administrative fine (up to €20 million or 4% of global turnover, whichever is higher)
  • Ban on specific data transfers
  • Referral to other authorities

Importantly, the DPC does not award compensation to individuals. If you want damages, you must bring a civil claim in the Circuit Court or High Court, though a DPC finding significantly strengthens your case.

How Long Does a DPC Complaint Take?

Timelines vary enormously depending on complexity. Here's a realistic overview based on published DPC annual reports.

Complaint TypeTypical Duration
Simple access/erasure dispute with an Irish SME2–6 months
Direct marketing or cookie complaint3–9 months
CCTV or workplace monitoring6–12 months
Cross-border complaint against a multinational18 months – 4+ years
Data breach investigation12–36 months

Pros and Cons of Filing With the DPC

Pros

  • Free of charge — no legal fees to lodge a complaint
  • Statutory powers to compel evidence from controllers
  • Can result in large fines that deter future breaches
  • Written decisions strengthen any later civil claim
  • You don't need a lawyer to file
  • Cross-border reach for EEA-wide issues

Cons

  • Long timelines, especially for cross-border cases
  • No direct compensation to the complainant
  • Limited feedback during ongoing investigations
  • The DPC has been criticised for slow handling of Big Tech cases
  • Some complaints get dismissed as "frivolous" or "vexatious"

Tips to Strengthen Your Complaint

  1. Be specific. Vague complaints like "they misuse my data" go nowhere. Name the exact processing activity.
  2. Reference GDPR articles. Even one or two citations show you've done your homework.
  3. Attach a timeline. A one-page chronological summary makes the case officer's job easier.
  4. Keep it professional. Emotional or accusatory language weakens credibility.
  5. Follow up politely. If you haven't heard back in 8 weeks, email your case reference and ask for a status update.
  6. Preserve evidence securely. Store screenshots and emails in a dedicated folder with clear filenames.

Alternatives and Complementary Actions

Filing with the DPC isn't your only option. Depending on the circumstances, you may also consider:

  • Civil litigation — sue for material or non-material damages under Section 117 of the Data Protection Act 2018.
  • ComReg — for issues involving telecoms providers or unsolicited communications.
  • An Garda Síochána — if the misuse involves criminal offences like identity theft or stalking.
  • The Workplace Relations Commission — for employment-related privacy issues.
  • Your bank or card provider — for fraud arising from a data breach.

You should also review your own digital hygiene. Use encrypted DNS resolvers, private browsers, and privacy-focused tools for everyday tasks like link sharing — see our 2026 buyer's guide to URL shorteners for privacy-respecting options, or explore feature comparisons in our Rebrandly review.

Common Mistakes to Avoid

  • Skipping the direct-to-organisation step and going straight to the DPC
  • Submitting a complaint without any evidence
  • Expecting monetary compensation from the DPC itself
  • Complaining about issues outside GDPR scope (e.g., commercial disputes)
  • Filing anonymously — you must identify yourself
  • Missing the effective time limit (complaints should generally be raised within a reasonable time of the incident)

Frequently Asked Questions

How much does it cost to file a complaint with the DPC?

Nothing. Lodging a complaint with the Data Protection Commission is entirely free. You do not need a solicitor, and there are no filing fees at any stage of the process. Costs only arise if you choose to pursue a separate civil claim for damages.

Can I file a DPC complaint against a company based outside Ireland?

Yes, if the company has its EU main establishment in Ireland (making the DPC the lead supervisory authority), or if the processing specifically affected you in Ireland. For companies with a main establishment in another EU country, you can still file with the DPC — it will forward the complaint to the appropriate authority under the GDPR one-stop-shop mechanism.

Will the organisation know I complained?

Yes. To investigate, the DPC must share the substance of your complaint with the organisation, and this usually includes your identity. Anonymous complaints cannot generally be progressed, though the DPC may use the information to inform wider regulatory activity.

Can I get compensation through the DPC?

No. The DPC has no power to award damages. However, a DPC decision confirming a breach of your rights is extremely useful evidence if you later bring a civil claim in the Irish courts under Section 117 of the Data Protection Act 2018, where you can seek both material and non-material damages.

What if I disagree with the DPC's final decision?

You have a statutory right to appeal a formal DPC decision to the Circuit Court within 28 days of being notified. You can also seek judicial review in the High Court on procedural grounds. If you're the complainant and the DPC declines to investigate, you can request a review or, in limited circumstances, challenge that decision as well.

Final Thoughts

Filing a privacy complaint with the DPC is one of the strongest tools EU residents have to hold organisations accountable for how they handle personal data. It's free, it doesn't require a lawyer, and — with well-organised evidence — it can produce meaningful outcomes, from data deletion to multi-million-euro fines against major platforms. The keys to success are patience, precision, and preparation: contact the organisation first, document everything, and present a clean, factual narrative when you escalate. Your data protection rights are only as strong as your willingness to enforce them.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles