facebook-pixel

DPC Ireland: How to File a Privacy Complaint (2026 Guide)

L
Lunyb Security Team
··9 min read

If a company has mishandled your personal data, ignored your access request, or sent you marketing you never signed up for, you have the right to complain to Ireland's Data Protection Commission (DPC). As the lead supervisory authority for many of the world's biggest tech companies headquartered in Dublin, the DPC handles complaints that ripple across Europe. This guide walks you through exactly how to file a privacy complaint with the DPC in 2026, what to include, and what happens next.

What Is the Data Protection Commission (DPC)?

The Data Protection Commission is Ireland's independent authority responsible for upholding the fundamental right of individuals to have their personal data protected. It enforces the General Data Protection Regulation (GDPR), the Irish Data Protection Act 2018, and the ePrivacy Regulations 2011.

Because companies like Meta, Google, TikTok, LinkedIn, Apple, and Microsoft have their EU headquarters in Ireland, the DPC often acts as the lead supervisory authority for cross-border complaints under the GDPR's one-stop-shop mechanism. This makes it one of the most influential regulators in Europe.

What the DPC Can Do

  • Investigate complaints against organisations (public and private)
  • Issue reprimands, warnings, and corrective orders
  • Impose administrative fines up to €20 million or 4% of global annual turnover
  • Suspend data flows to non-EU countries
  • Mediate between you and the organisation you're complaining about

What the DPC Cannot Do

  • Award you compensation (that's a matter for the Circuit Court)
  • Force criminal prosecution (though it can refer serious cases)
  • Resolve purely contractual disputes unrelated to data protection

When Should You File a Complaint with the DPC?

You can file a complaint whenever you believe an organisation has infringed your data protection rights under the GDPR or Irish law. Common grounds include:

  1. Ignored data subject requests — the company failed to respond to your access, erasure, rectification, or portability request within one month.
  2. Unlawful processing — your personal data is being used without a valid legal basis (consent, contract, legitimate interest, etc.).
  3. Unwanted marketing — you keep receiving emails, texts, or calls after unsubscribing.
  4. Data breaches — a company lost, leaked, or exposed your data and didn't handle it properly.
  5. Excessive data collection — a service demands far more information than it needs.
  6. Cookie violations — a website drops tracking cookies without valid consent.
  7. CCTV misuse — a business, landlord, or neighbour is filming you inappropriately.

Step 1: Contact the Organisation First

Before the DPC will formally investigate, it expects you to have raised the matter directly with the organisation involved. This is not just a bureaucratic hurdle — many complaints are resolved at this stage.

How to Approach the Organisation

  1. Find the company's Data Protection Officer (DPO) or privacy contact. This is usually in their privacy policy, often listed as privacy@company.com or dpo@company.com.
  2. Write a clear, dated request explaining what you want (e.g. "Please delete all personal data you hold about me under Article 17 GDPR").
  3. Give them one calendar month to respond. This is the statutory deadline under Article 12(3) GDPR.
  4. Keep copies of everything — emails, letters, screenshots, and any responses (or lack thereof).

When sharing evidence links or long screenshots with the DPO, it can help to send tidy, trackable links rather than raw URLs. Tools like Lunyb let you shorten and organise reference links so your complaint file stays clean and readable.

Step 2: Gather Your Evidence

A well-documented complaint is far more likely to succeed. Before contacting the DPC, assemble the following:

  • Your identity details — full name, address, email, and phone number.
  • The organisation's details — legal name, registered address, website, and any correspondence contacts.
  • A timeline of events — dates you contacted them, dates they replied (or didn't).
  • Copies of correspondence — emails, letters, chat logs, screenshots.
  • The specific right or provision breached — e.g. "failure to comply with Article 15 (right of access)."
  • The outcome you want — deletion, correction, cessation of processing, etc.

Step 3: File the Complaint with the DPC

The DPC accepts complaints through several channels. All are free of charge.

Online Webform

The fastest route is the DPC's online complaint form at dataprotection.ie. You'll be asked to describe the issue, upload supporting documents, and confirm you've already contacted the organisation.

Email

You can email info@dataprotection.ie with a written complaint and attachments. Use a clear subject line such as "Formal Complaint under Section 108 of the Data Protection Act 2018."

Post

Write to: Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland. This is useful if you have bulky paper evidence.

What to Include in Your Complaint

SectionDetails Required
Your contact informationFull name, postal address, email, phone
Respondent detailsCompany name, address, website, DPO contact
Nature of complaintWhich GDPR right or Irish law provision is breached
ChronologyDated summary of what happened
EvidenceEmails, screenshots, letters, receipts
Prior contactProof you contacted the organisation first
Desired remedyWhat outcome you're seeking

Step 4: What Happens After You File

Once the DPC receives your complaint, the process typically follows these stages:

  1. Acknowledgement — you'll receive confirmation, usually within a few working days, along with a case reference number.
  2. Assessment — a case officer reviews whether the complaint falls within the DPC's remit and whether it's admissible.
  3. Amicable resolution — Section 109 of the Data Protection Act 2018 requires the DPC to try to resolve complaints amicably where possible. The case officer will contact the organisation and act as an intermediary.
  4. Formal inquiry — if amicable resolution fails, or the case is serious, the DPC can open a formal statutory inquiry under Section 110.
  5. Decision — the DPC issues a decision that may include reprimands, orders, or fines. You'll be informed of the outcome.
  6. Appeal — either party can appeal the decision to the Irish Circuit Court within 28 days.

How Long Does It Take?

Simple complaints resolved amicably can conclude in a few months. Complex cross-border investigations — especially those involving large tech platforms — routinely take one to three years, sometimes longer. The DPC publishes an annual report with statistics on average handling times.

Cross-Border Complaints and the One-Stop-Shop

If your complaint is about a company with its main EU establishment in Ireland (Meta, TikTok, Google, X, LinkedIn, and many more), the DPC will act as the lead supervisory authority even if you live elsewhere in the EU. You can:

  • File directly with the DPC in Ireland, or
  • File with your local supervisory authority (e.g. CNIL in France, BfDI in Germany), which will forward the case to the DPC.

Either route works. Filing locally is often easier if you're not comfortable in English, since your national authority will translate and coordinate.

Common Reasons Complaints Fail

Not every complaint results in action. The DPC may close a case without a formal decision if:

  • You didn't contact the organisation first
  • The complaint is vexatious, excessive, or manifestly unfounded
  • Insufficient evidence is provided
  • The matter falls outside data protection law (e.g. defamation, employment disputes)
  • The issue has already been resolved
  • Too much time has passed since you became aware of the infringement

Protecting Your Privacy Going Forward

Filing a complaint fixes a specific incident, but preventing future privacy problems requires ongoing habits. Consider these steps:

  1. Use encrypted DNS — services like Cloudflare 1.1.1.1 or Quad9 prevent your internet provider from logging every domain you visit.
  2. Choose a privacy-respecting browser — Firefox, Brave, or Safari with strict tracking prevention enabled.
  3. Audit app permissions monthly — revoke location, microphone, and contacts access from apps that don't need them.
  4. Read privacy policies before signing up — pay attention to data sharing with third parties.
  5. Use short-lived, trackable links for public sharing — instead of exposing personal URLs, a shortener like Lunyb lets you share links with analytics you control, rather than handing tracking data to a third-party platform.
  6. Enable multi-factor authentication everywhere it's offered.
  7. Exercise your GDPR rights regularly — send access and deletion requests to accounts you no longer use.

Your Rights Under GDPR: Quick Reference

RightArticleWhat It Means
AccessArticle 15Get a copy of the data held about you
RectificationArticle 16Correct inaccurate personal data
ErasureArticle 17Have data deleted ("right to be forgotten")
RestrictionArticle 18Limit how data is processed
PortabilityArticle 20Receive data in a machine-readable format
ObjectArticle 21Object to processing, especially marketing
Automated decisionsArticle 22Not be subject to solely automated decisions

Compensation: Going Beyond the DPC

The DPC cannot award you money. If you have suffered material or non-material damage (including distress) as a result of a GDPR infringement, Article 82 gives you the right to sue the organisation directly in the Irish Circuit Court. You can pursue this in parallel with a DPC complaint, or after the DPC has ruled. Consider seeking legal advice, especially for high-value claims.

Further Reading

Frequently Asked Questions

Is filing a complaint with the DPC free?

Yes. The DPC does not charge any fee to file, investigate, or decide on a data protection complaint. You may choose to pay a solicitor to help you prepare the complaint, but this is entirely optional.

Can I file a DPC complaint anonymously?

No. The DPC requires your identity so it can correspond with you and verify the complaint. However, your details are not shared publicly, and in cross-border cases the DPC coordinates confidentially with other EU regulators.

How long do I have to file a complaint?

There is no strict statutory deadline, but the DPC prefers complaints to be filed within a reasonable time of you becoming aware of the issue — generally within a year. Delayed complaints may be harder to investigate because evidence and logs fade.

What if the DPC rules against me?

You have 28 days to appeal a DPC decision to the Circuit Court in Ireland. You can also pursue a civil compensation claim under Article 82 GDPR independently of the DPC's finding.

Can I complain about a company outside the EU?

Yes, if the company offers goods or services to people in Ireland or the EU, or monitors their behaviour, it is subject to the GDPR under Article 3. The DPC can investigate, although enforcement against non-EU entities without an EU establishment is more difficult in practice.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles