DPC Ireland: How to File a Privacy Complaint (2026 Guide)
If a company has mishandled your personal data, ignored your access request, or sent you marketing you never signed up for, you have the right to complain to Ireland's Data Protection Commission (DPC). As the lead supervisory authority for many of the world's biggest tech companies headquartered in Dublin, the DPC handles complaints that ripple across Europe. This guide walks you through exactly how to file a privacy complaint with the DPC in 2026, what to include, and what happens next.
What Is the Data Protection Commission (DPC)?
The Data Protection Commission is Ireland's independent authority responsible for upholding the fundamental right of individuals to have their personal data protected. It enforces the General Data Protection Regulation (GDPR), the Irish Data Protection Act 2018, and the ePrivacy Regulations 2011.
Because companies like Meta, Google, TikTok, LinkedIn, Apple, and Microsoft have their EU headquarters in Ireland, the DPC often acts as the lead supervisory authority for cross-border complaints under the GDPR's one-stop-shop mechanism. This makes it one of the most influential regulators in Europe.
What the DPC Can Do
- Investigate complaints against organisations (public and private)
- Issue reprimands, warnings, and corrective orders
- Impose administrative fines up to €20 million or 4% of global annual turnover
- Suspend data flows to non-EU countries
- Mediate between you and the organisation you're complaining about
What the DPC Cannot Do
- Award you compensation (that's a matter for the Circuit Court)
- Force criminal prosecution (though it can refer serious cases)
- Resolve purely contractual disputes unrelated to data protection
When Should You File a Complaint with the DPC?
You can file a complaint whenever you believe an organisation has infringed your data protection rights under the GDPR or Irish law. Common grounds include:
- Ignored data subject requests — the company failed to respond to your access, erasure, rectification, or portability request within one month.
- Unlawful processing — your personal data is being used without a valid legal basis (consent, contract, legitimate interest, etc.).
- Unwanted marketing — you keep receiving emails, texts, or calls after unsubscribing.
- Data breaches — a company lost, leaked, or exposed your data and didn't handle it properly.
- Excessive data collection — a service demands far more information than it needs.
- Cookie violations — a website drops tracking cookies without valid consent.
- CCTV misuse — a business, landlord, or neighbour is filming you inappropriately.
Step 1: Contact the Organisation First
Before the DPC will formally investigate, it expects you to have raised the matter directly with the organisation involved. This is not just a bureaucratic hurdle — many complaints are resolved at this stage.
How to Approach the Organisation
- Find the company's Data Protection Officer (DPO) or privacy contact. This is usually in their privacy policy, often listed as privacy@company.com or dpo@company.com.
- Write a clear, dated request explaining what you want (e.g. "Please delete all personal data you hold about me under Article 17 GDPR").
- Give them one calendar month to respond. This is the statutory deadline under Article 12(3) GDPR.
- Keep copies of everything — emails, letters, screenshots, and any responses (or lack thereof).
When sharing evidence links or long screenshots with the DPO, it can help to send tidy, trackable links rather than raw URLs. Tools like Lunyb let you shorten and organise reference links so your complaint file stays clean and readable.
Step 2: Gather Your Evidence
A well-documented complaint is far more likely to succeed. Before contacting the DPC, assemble the following:
- Your identity details — full name, address, email, and phone number.
- The organisation's details — legal name, registered address, website, and any correspondence contacts.
- A timeline of events — dates you contacted them, dates they replied (or didn't).
- Copies of correspondence — emails, letters, chat logs, screenshots.
- The specific right or provision breached — e.g. "failure to comply with Article 15 (right of access)."
- The outcome you want — deletion, correction, cessation of processing, etc.
Step 3: File the Complaint with the DPC
The DPC accepts complaints through several channels. All are free of charge.
Online Webform
The fastest route is the DPC's online complaint form at dataprotection.ie. You'll be asked to describe the issue, upload supporting documents, and confirm you've already contacted the organisation.
You can email info@dataprotection.ie with a written complaint and attachments. Use a clear subject line such as "Formal Complaint under Section 108 of the Data Protection Act 2018."
Post
Write to: Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland. This is useful if you have bulky paper evidence.
What to Include in Your Complaint
| Section | Details Required |
|---|---|
| Your contact information | Full name, postal address, email, phone |
| Respondent details | Company name, address, website, DPO contact |
| Nature of complaint | Which GDPR right or Irish law provision is breached |
| Chronology | Dated summary of what happened |
| Evidence | Emails, screenshots, letters, receipts |
| Prior contact | Proof you contacted the organisation first |
| Desired remedy | What outcome you're seeking |
Step 4: What Happens After You File
Once the DPC receives your complaint, the process typically follows these stages:
- Acknowledgement — you'll receive confirmation, usually within a few working days, along with a case reference number.
- Assessment — a case officer reviews whether the complaint falls within the DPC's remit and whether it's admissible.
- Amicable resolution — Section 109 of the Data Protection Act 2018 requires the DPC to try to resolve complaints amicably where possible. The case officer will contact the organisation and act as an intermediary.
- Formal inquiry — if amicable resolution fails, or the case is serious, the DPC can open a formal statutory inquiry under Section 110.
- Decision — the DPC issues a decision that may include reprimands, orders, or fines. You'll be informed of the outcome.
- Appeal — either party can appeal the decision to the Irish Circuit Court within 28 days.
How Long Does It Take?
Simple complaints resolved amicably can conclude in a few months. Complex cross-border investigations — especially those involving large tech platforms — routinely take one to three years, sometimes longer. The DPC publishes an annual report with statistics on average handling times.
Cross-Border Complaints and the One-Stop-Shop
If your complaint is about a company with its main EU establishment in Ireland (Meta, TikTok, Google, X, LinkedIn, and many more), the DPC will act as the lead supervisory authority even if you live elsewhere in the EU. You can:
- File directly with the DPC in Ireland, or
- File with your local supervisory authority (e.g. CNIL in France, BfDI in Germany), which will forward the case to the DPC.
Either route works. Filing locally is often easier if you're not comfortable in English, since your national authority will translate and coordinate.
Common Reasons Complaints Fail
Not every complaint results in action. The DPC may close a case without a formal decision if:
- You didn't contact the organisation first
- The complaint is vexatious, excessive, or manifestly unfounded
- Insufficient evidence is provided
- The matter falls outside data protection law (e.g. defamation, employment disputes)
- The issue has already been resolved
- Too much time has passed since you became aware of the infringement
Protecting Your Privacy Going Forward
Filing a complaint fixes a specific incident, but preventing future privacy problems requires ongoing habits. Consider these steps:
- Use encrypted DNS — services like Cloudflare 1.1.1.1 or Quad9 prevent your internet provider from logging every domain you visit.
- Choose a privacy-respecting browser — Firefox, Brave, or Safari with strict tracking prevention enabled.
- Audit app permissions monthly — revoke location, microphone, and contacts access from apps that don't need them.
- Read privacy policies before signing up — pay attention to data sharing with third parties.
- Use short-lived, trackable links for public sharing — instead of exposing personal URLs, a shortener like Lunyb lets you share links with analytics you control, rather than handing tracking data to a third-party platform.
- Enable multi-factor authentication everywhere it's offered.
- Exercise your GDPR rights regularly — send access and deletion requests to accounts you no longer use.
Your Rights Under GDPR: Quick Reference
| Right | Article | What It Means |
|---|---|---|
| Access | Article 15 | Get a copy of the data held about you |
| Rectification | Article 16 | Correct inaccurate personal data |
| Erasure | Article 17 | Have data deleted ("right to be forgotten") |
| Restriction | Article 18 | Limit how data is processed |
| Portability | Article 20 | Receive data in a machine-readable format |
| Object | Article 21 | Object to processing, especially marketing |
| Automated decisions | Article 22 | Not be subject to solely automated decisions |
Compensation: Going Beyond the DPC
The DPC cannot award you money. If you have suffered material or non-material damage (including distress) as a result of a GDPR infringement, Article 82 gives you the right to sue the organisation directly in the Irish Circuit Court. You can pursue this in parallel with a DPC complaint, or after the DPC has ruled. Consider seeking legal advice, especially for high-value claims.
Further Reading
- Best URL Shorteners Reviewed and Compared: 2026 Buyer's Guide
- Is Lunyb Legit? An Honest Review of the URL Shortener in 2026
- Rebrandly Review 2026: Is It Worth the Price?
Frequently Asked Questions
Is filing a complaint with the DPC free?
Yes. The DPC does not charge any fee to file, investigate, or decide on a data protection complaint. You may choose to pay a solicitor to help you prepare the complaint, but this is entirely optional.
Can I file a DPC complaint anonymously?
No. The DPC requires your identity so it can correspond with you and verify the complaint. However, your details are not shared publicly, and in cross-border cases the DPC coordinates confidentially with other EU regulators.
How long do I have to file a complaint?
There is no strict statutory deadline, but the DPC prefers complaints to be filed within a reasonable time of you becoming aware of the issue — generally within a year. Delayed complaints may be harder to investigate because evidence and logs fade.
What if the DPC rules against me?
You have 28 days to appeal a DPC decision to the Circuit Court in Ireland. You can also pursue a civil compensation claim under Article 82 GDPR independently of the DPC's finding.
Can I complain about a company outside the EU?
Yes, if the company offers goods or services to people in Ireland or the EU, or monitors their behaviour, it is subject to the GDPR under Article 3. The DPC can investigate, although enforcement against non-EU entities without an EU establishment is more difficult in practice.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
GDPR in Ireland: Your Privacy Rights Explained
Ireland enforces some of the strongest data protection laws in the world through the GDPR and the Data Protection Commission. This guide explains your eight core privacy rights, how to file a complaint, and practical steps to safeguard your personal data.
PIPEDA vs GDPR: Canadian Privacy Law Explained
PIPEDA and GDPR both protect personal information but differ sharply in consent, penalties, and individual rights. This guide breaks down the key differences and what Canadian businesses need to do to stay compliant in 2026.
UK Data Protection Act vs GDPR Explained: Key Differences for 2026
The UK Data Protection Act 2018 and the GDPR share the same foundations but differ in scope, exemptions, and enforcement. This 2026 guide explains the key differences, overlaps, and what UK businesses must do to stay compliant.
GDPR After Brexit: What Changed for UK Businesses in 2026
GDPR did not disappear after Brexit — it split into two parallel regimes. This guide explains the UK GDPR, how it differs from the EU version, and what British businesses must do in 2026 to stay compliant with data protection, international transfers and ICO enforcement.