facebook-pixel

DPC Ireland: How to File a Privacy Complaint (2026 Guide)

L
Lunyb Security Team
··10 min read

If your personal data has been mishandled by a company or organisation operating in Ireland, you have the right to file a formal complaint with the Data Protection Commission (DPC). As Ireland's independent supervisory authority for data protection, the DPC plays a critical role in enforcing the General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018 — not just for Irish residents, but often for EU-wide cases involving tech giants headquartered in Dublin.

This comprehensive guide walks you through exactly how to file a privacy complaint with the DPC Ireland, what happens after you submit, and how to strengthen your case with solid evidence.

What Is the Data Protection Commission (DPC)?

The Data Protection Commission is Ireland's national independent authority responsible for upholding the fundamental right of individuals in the EU to have their personal data protected. Established under the Data Protection Act 2018, the DPC is the lead supervisory authority for many major technology companies with European headquarters in Ireland, including Meta, Google, TikTok, LinkedIn, and Apple.

The DPC has the power to investigate complaints, issue reprimands, order corrective measures, and levy administrative fines of up to €20 million or 4% of a company's global annual turnover — whichever is higher.

When Should You File a Complaint With the DPC?

You should consider filing a complaint if you believe an organisation has violated your data protection rights. Common grounds include:

  • An organisation refused or ignored your Subject Access Request (SAR)
  • Your personal data was shared without consent
  • You continued receiving marketing communications after opting out
  • A company failed to notify you of a data breach affecting your information
  • Your right to erasure ("right to be forgotten") was denied
  • CCTV footage or biometric data was used unlawfully
  • Your data was transferred outside the EEA without adequate safeguards

Before You File: Contact the Organisation First

The DPC generally expects complainants to raise the issue directly with the organisation before escalating. This gives the data controller a chance to remedy the situation and demonstrates good faith on your part.

Steps to Take Before Contacting the DPC

  1. Identify the Data Protection Officer (DPO): Most organisations list their DPO or privacy contact in their privacy policy.
  2. Submit a written complaint: Email is preferred because it creates a timestamped record. Clearly state your concern and the outcome you want.
  3. Reference your rights: Cite the specific GDPR articles (e.g., Article 15 for access, Article 17 for erasure).
  4. Give them time to respond: Organisations have up to one month to respond, extendable by two further months for complex requests.
  5. Save all correspondence: Keep copies of every email, letter, and response for your evidence file.

If the organisation fails to respond, provides an unsatisfactory answer, or outright denies your rights, you're ready to bring the matter to the DPC.

How to File a Privacy Complaint With the DPC Ireland

Filing a complaint with the DPC is free, straightforward, and can be done online, by post, or by email. There's no legal requirement to hire a solicitor, though you may choose to do so for complex cases.

Step-by-Step Complaint Filing Process

  1. Visit the official DPC website: Go to dataprotection.ie and navigate to the "Contact/Complaint" section.
  2. Choose your submission method: Use the online webform, download the PDF complaint form, or write a detailed letter.
  3. Provide your personal details: Full name, address, email, and phone number. Anonymous complaints are generally not accepted.
  4. Identify the organisation: Include the company name, address, and any relevant contact details.
  5. Describe the issue clearly: Provide a chronological account of what happened, when it happened, and how it affected you.
  6. Attach supporting evidence: Include copies of emails, screenshots, letters, and the organisation's response (or proof they failed to respond).
  7. State the outcome you seek: For example, deletion of data, an apology, a fine, or a change in the organisation's practices.
  8. Submit and record your reference number: Once filed, the DPC will acknowledge your complaint and provide a case reference.

DPC Contact Details

Here are the official channels to submit your complaint:

MethodDetails
Online FormAvailable at dataprotection.ie/en/contact/how-make-complaint
Emailinfo@dataprotection.ie
Post (Dublin Office)21 Fitzwilliam Square South, Dublin 2, D02 RD28
Post (Portarlington Office)Canal House, Station Road, Portarlington, R32 AP23 Co. Laois
Phone+353 (0)761 104 800 or 1800 437 737

What Happens After You File a Complaint

Once the DPC receives your complaint, it moves through a defined internal process. Understanding this timeline helps you set realistic expectations.

The DPC Complaint Handling Timeline

  1. Acknowledgement (within a few weeks): The DPC confirms receipt and assigns a case officer.
  2. Initial assessment: The DPC determines whether the complaint falls within its jurisdiction and whether it has enough information to proceed.
  3. Amicable resolution phase: The DPC often attempts to resolve the matter informally by contacting the organisation and seeking a mutually acceptable outcome.
  4. Formal investigation (if needed): If informal resolution fails, the DPC may launch a statutory inquiry under Section 110 of the Data Protection Act 2018.
  5. Draft decision: Both parties are given a chance to respond to preliminary findings.
  6. Final decision: The Commissioner issues a binding decision, which may include reprimands, corrective orders, or fines.

Cases can take anywhere from a few months to several years. Cross-border cases involving major tech platforms often take longer due to the GDPR's One-Stop-Shop mechanism, which requires cooperation with other EU supervisory authorities.

Strengthening Your Complaint: Evidence Best Practices

The quality of your evidence directly affects the strength of your complaint. The DPC handles thousands of complaints each year, and well-documented submissions are prioritised and resolved faster.

What Evidence to Include

  • Written correspondence: All emails, letters, and chat transcripts with the organisation.
  • Screenshots: Of privacy settings, marketing emails, or web pages showing the issue — with timestamps visible.
  • Copies of the privacy policy: Especially the version in force when the alleged violation occurred.
  • Proof of identity: If the complaint concerns a Subject Access Request, include proof you verified your identity to the organisation.
  • Timeline document: A one-page chronological summary of events.

When sharing evidence links (e.g., archived web pages or cloud-stored screenshots), consider using a trusted link management tool. Services like Lunyb allow you to create short, trackable links to your evidence files — useful if you need to include them in a submission form with character limits. You can read our honest review of Lunyb to learn more about its features.

Your Rights During the Complaint Process

As a complainant, you have several important rights throughout the DPC's investigation.

Key Complainant Rights

  • Right to be informed: The DPC must update you on the progress of your complaint within three months of submission and periodically thereafter.
  • Right to a decision: You are entitled to a formal outcome, whether the DPC upholds your complaint or not.
  • Right to appeal: If you disagree with the DPC's decision, you can appeal to the Circuit Court or the High Court within 28 days.
  • Right to seek compensation: Under Article 82 of the GDPR, you can pursue damages in civil court, independent of any DPC action.
  • Right to confidentiality: Your identity is protected during the process, though the organisation being complained about will typically know who filed.

Comparing DPC Complaints With Other Remedies

Filing with the DPC isn't your only option. Depending on the harm suffered, you may have multiple avenues for redress.

RemedyBest ForCostTypical Timeline
DPC ComplaintRegulatory action, fines, corrective ordersFree3 months to 3+ years
Civil Court ActionFinancial compensation for damageLegal fees apply1–3 years
Small Claims CourtMinor financial losses (under €2,000)€25 filing fee2–6 months
Direct NegotiationQuick resolution, apologiesFreeDays to weeks
European Data Protection BoardCross-border disputes over lead authorityFreeVaries

Common Reasons DPC Complaints Are Rejected

Not every complaint results in an investigation. Understanding common rejection grounds helps you avoid pitfalls.

Pros of Filing With the DPC

  • Completely free of charge
  • No legal representation needed
  • Can lead to major regulatory action against big tech
  • Creates official record even if no fine is issued
  • Supports systemic change in how organisations handle data

Cons and Limitations

  • Investigations can be slow, especially cross-border cases
  • No direct financial compensation awarded through DPC
  • Some complaints are dismissed without investigation
  • Limited transparency during ongoing inquiries
  • Complex cases may require legal advice regardless

Complaints are typically rejected when they fall outside GDPR scope (e.g., personal or household activities), when the complainant hasn't first contacted the organisation, when the matter is more than a few years old, or when the issue is trivial or frivolous.

Practical Tips for Protecting Your Data Going Forward

While filing a complaint addresses past violations, prevention is the strongest defence for your future privacy.

Everyday Privacy Practices

  1. Read privacy policies before signing up: At least skim the sections on data sharing and retention.
  2. Use encrypted DNS and privacy-focused browsers: Tools like DNS-over-HTTPS and browsers such as Firefox or Brave reduce tracking.
  3. Minimise data sharing: Only provide the minimum information required for a service to function.
  4. Regularly exercise your access rights: Submit annual Subject Access Requests to see what companies hold on you.
  5. Use link shorteners with privacy in mind: When sharing URLs publicly, tools like Lunyb offer tracking transparency without excessive data collection. See our 2026 buyer's guide to URL shorteners for comparisons.
  6. Enable two-factor authentication: Reduces the risk of breaches that would give rise to complaints in the first place.

Frequently Asked Questions

How long does it take the DPC to resolve a complaint?

Simple complaints handled through amicable resolution can be resolved within three to six months. Formal statutory inquiries, particularly cross-border cases involving multinational tech companies, can take one to three years or longer. The DPC is required to keep you informed of progress every few months.

Can non-Irish residents file a complaint with the DPC?

Yes. If the organisation you're complaining about has its main EU establishment in Ireland (as is the case for Meta, Google, TikTok, and many others), the DPC often acts as the lead supervisory authority under the GDPR's One-Stop-Shop mechanism. However, you may find it more convenient to file with your local data protection authority, which will forward the complaint to the DPC.

Do I need a solicitor to file a DPC complaint?

No. The complaint process is designed to be accessible to the public without legal representation. However, for complex cases — particularly those involving significant financial harm or where you're seeking damages in parallel civil proceedings — consulting a solicitor with GDPR expertise can be valuable.

Will the organisation know I filed the complaint?

Yes, in most cases. To investigate properly, the DPC needs to share your complaint with the data controller so they can respond. Your identity is generally not made public, but the organisation itself will typically know you filed. If you have safety concerns, notify the DPC when submitting your complaint.

Can I withdraw my complaint after filing?

Yes. You can withdraw your complaint at any point by writing to the DPC. However, the DPC may continue investigating on its own initiative if it believes the matter raises significant public interest or ongoing regulatory concerns.

Conclusion

Filing a privacy complaint with the DPC Ireland is a powerful way to hold organisations accountable for how they handle your personal data. Whether you're dealing with an ignored access request, unwanted marketing, or a serious data breach, the DPC provides a free, structured route to seek regulatory redress.

The key to a successful complaint is preparation: contact the organisation first, gather thorough evidence, submit a clear and chronological account, and follow up as needed. Combined with everyday privacy practices — mindful data sharing, encrypted communications, and use of privacy-respecting tools — you can meaningfully protect your rights in the digital age.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles