DPC Ireland: How to File a Privacy Complaint (2026 Guide)
If an organisation has mishandled your personal data, ignored a subject access request, or refused to delete your information, you have the legal right to complain to Ireland's Data Protection Commission (DPC). As the lead supervisory authority for many of the world's largest tech companies headquartered in Dublin, the DPC handles complaints from Irish residents and, in cross-border cases, from data subjects across the EU.
This guide walks you through exactly how to file a privacy complaint with the DPC Ireland, what evidence you need, how long the process takes, and what outcomes to realistically expect.
What Is the Data Protection Commission (DPC)?
The Data Protection Commission is Ireland's independent statutory authority responsible for upholding the fundamental right of individuals to have their personal data protected. It enforces the General Data Protection Regulation (GDPR), the Data Protection Act 2018, and the ePrivacy Regulations 2011.
Because many multinational technology firms — including Meta, Google, TikTok, LinkedIn, Microsoft, and Apple — have their EU headquarters in Ireland, the DPC often acts as the "lead supervisory authority" for cross-border complaints under the GDPR's one-stop-shop mechanism. This means an Irish complaint can trigger investigations affecting hundreds of millions of European users.
What the DPC Can and Cannot Do
- Can: Investigate data controllers, order compliance, impose administrative fines (up to €20 million or 4% of global turnover), and require deletion or correction of data.
- Cannot: Award you personal compensation — that requires a separate civil court action.
- Cannot: Handle complaints about non-personal data, freedom of information requests, or matters outside the GDPR's scope.
When Should You File a Complaint With the DPC?
You should consider filing a complaint with the DPC when a data controller has breached your rights under GDPR and has failed to resolve the issue directly. Typical grounds include:
- Unlawful processing — an organisation processed your data without a valid legal basis (consent, contract, legitimate interest, etc.).
- Ignored subject access request (SAR) — the controller did not respond within one month or refused without justification.
- Failure to erase data — your right-to-be-forgotten request was denied or ignored.
- Data breach affecting you — your data was leaked, lost, or exposed and you weren't notified appropriately.
- Unwanted marketing — you continued to receive emails, SMS, or calls after unsubscribing.
- Inaccurate data — a controller refused to correct incorrect personal information.
- Excessive CCTV or surveillance — including workplace monitoring without proper notice.
Step 1: Try to Resolve the Issue Directly First
The DPC strongly encourages complainants to raise the matter with the organisation's Data Protection Officer (DPO) or privacy contact before escalating. In fact, the DPC may reject your complaint if you haven't attempted this step.
How to Contact the Data Controller
- Locate the DPO email in the organisation's privacy policy (usually at the footer of their website).
- Send a clear, dated written request stating your rights (SAR, erasure, objection, etc.).
- Give them one calendar month to respond, as required by Article 12(3) GDPR.
- Keep copies of every message — you'll need them as evidence.
If the controller responds inadequately, ignores you, or explicitly refuses, you have the grounds you need to escalate to the DPC.
Step 2: Gather Your Evidence
A well-documented complaint gets processed faster. Before you file, assemble the following:
- Identification — proof you are the data subject (name, address, contact details).
- Name of the organisation and, if known, its registered address and DPO contact.
- Chronology — dates of the original request, responses received, and any follow-ups.
- Copies of correspondence — emails, letters, screenshots, or forms.
- Description of the issue — what happened, when, and which of your rights you believe were breached.
- Desired outcome — erasure, correction, cessation of processing, or an explanation.
Step 3: How to File the Complaint With DPC Ireland
The DPC accepts complaints through several channels. You do not need a solicitor, and there is no fee to lodge a complaint.
Online Webform (Recommended)
Visit dataprotection.ie and navigate to "Contact us" → "Raise a Concern". The online form asks for:
- Your contact details.
- The organisation being complained about.
- A summary of the concern.
- Evidence uploads (PDF, DOCX, JPG accepted, usually up to 10 MB per file).
- Confirmation that you contacted the organisation first.
By Post
Send a written complaint to:
Data Protection Commission
21 Fitzwilliam Square South
Dublin 2, D02 RD28
Ireland
By Email
You can also email info@dataprotection.ie, though the webform is more efficient because it routes your case directly into the DPC's case-management system.
Step 4: What Happens After You File
Once submitted, your complaint enters a formal process. Here's the typical lifecycle:
| Stage | What Happens | Typical Timeframe |
|---|---|---|
| Acknowledgement | DPC confirms receipt and assigns a case reference. | 1–4 weeks |
| Assessment | Case officer reviews admissibility and whether the DPC has jurisdiction. | 1–3 months |
| Amicable resolution | DPC attempts to mediate a resolution between you and the controller. | 3–6 months |
| Formal inquiry | If no resolution, the DPC may launch a statutory inquiry under Section 110 of the 2018 Act. | 6 months – 3+ years |
| Decision | Binding decision issued, potentially including reprimand, order, or fine. | Varies |
Note: cross-border cases involving Big Tech often take significantly longer because they involve consultation with other EU supervisory authorities under Article 60 GDPR.
Step 5: If You're Not Satisfied With the Outcome
You have several avenues if you disagree with the DPC's handling of your complaint:
- Request an internal review from a more senior DPC officer.
- Judicial review in the Irish High Court within three months of the decision.
- Statutory appeal under Section 150 of the Data Protection Act 2018 to the Circuit Court or High Court.
- Civil action for damages under Article 82 GDPR — you can sue the controller directly for material or non-material damages (including distress).
Common Types of Complaints Handled by the DPC
1. Subject Access Request Failures
By far the most common category. Organisations frequently miss the one-month deadline or provide incomplete responses. The DPC treats these seriously because SARs underpin all other rights.
2. Direct Marketing Without Consent
Under Statutory Instrument 336/2011 (ePrivacy Regulations), unsolicited electronic marketing without consent is a criminal offence in Ireland. The DPC has prosecuted numerous companies in the District Court.
3. CCTV and Workplace Monitoring
Employers must have a documented lawful basis, conduct a Data Protection Impact Assessment (DPIA), and inform staff. Excessive monitoring — including keystroke logging or covert cameras — is a frequent complaint source.
4. Data Breaches
Under Article 33 GDPR, controllers must notify the DPC within 72 hours of becoming aware of a breach. If your data was involved and you weren't told, you can complain.
Tips to Strengthen Your Complaint
- Be specific. Cite the exact GDPR article you believe was breached (e.g., Article 15 for access, Article 17 for erasure).
- Stick to facts. Emotional language weakens rather than strengthens a case.
- Provide a timeline. Bullet-point every relevant date.
- Redact sensitive third-party info before uploading documents.
- Keep your own copy of everything you send.
Protecting Your Privacy Going Forward
Filing a complaint addresses a past breach — but reducing your digital exposure prevents future ones. Practical steps include using encrypted DNS resolvers, private-by-design browsers like Brave or Firefox with strict tracking protection, minimising the personal data you share online, and being cautious with the links you click and share.
When sharing links publicly — whether on social media, in support tickets, or on forms — consider using a privacy-focused link shortener like Lunyb, which doesn't harvest visitor data or build advertising profiles from click behaviour. If you're evaluating options, our 2026 buyer's guide to URL shorteners compares the leading services on privacy and features, and our honest review of Lunyb covers what it does and doesn't collect.
DPC Ireland vs. Other EU Regulators
Because of the one-stop-shop principle, if the organisation you're complaining about has its EU main establishment in Ireland, the DPC will usually take the lead even if you live in another EU country. However, you can lodge the complaint with your local supervisory authority, which will forward it to the DPC.
| Scenario | Where to Complain |
|---|---|
| Irish resident, Irish company | DPC Ireland |
| Irish resident, EU company based in another Member State | DPC Ireland (will liaise with lead authority) |
| Non-Irish EU resident, company based in Ireland | Local authority OR DPC directly |
| Complaint about a UK company post-Brexit | UK ICO |
Frequently Asked Questions
How long does the DPC take to resolve a complaint?
Simple complaints — such as an ignored subject access request — are often resolved amicably within three to six months. Complex cross-border investigations involving large tech platforms can take two to five years, particularly when they involve consultation with other EU supervisory authorities and the European Data Protection Board.
Does it cost anything to file a complaint?
No. Filing a complaint with the DPC is completely free. You do not need a solicitor, though for complex matters (especially if you're pursuing damages in court) legal advice can be helpful.
Can I remain anonymous when filing?
No. The DPC requires your identity to investigate a complaint, and the controller must be told who is complaining so they can respond. However, the DPC will handle your information confidentially and only share what is strictly necessary for the investigation.
Can I get compensation through the DPC?
The DPC itself cannot award you personal compensation. To claim damages for material loss or distress caused by a GDPR breach, you must bring a civil action under Article 82 GDPR in the Circuit Court or High Court. A DPC decision in your favour can strengthen such a case considerably.
What if the company I'm complaining about is outside the EU?
If the company offers goods or services to people in the EU or monitors their behaviour, GDPR still applies. The company should have appointed an EU representative, and the DPC can still investigate if Ireland is the appropriate forum. If not, the DPC will refer you to the correct authority.
Can I withdraw a complaint after filing?
Yes, you can withdraw at any time by writing to the DPC. However, the DPC may still choose to continue an investigation on its own initiative if it believes there is a broader public-interest issue at stake.
Final Thoughts
The right to complain to a supervisory authority is one of the cornerstones of GDPR, and the DPC provides a genuinely accessible route for Irish residents and, in many cross-border cases, for citizens across Europe. While the process can be slow — particularly for complaints involving major tech platforms — it is free, procedurally simple, and increasingly effective as the DPC continues to build enforcement capacity.
If you believe your data rights have been breached, don't dismiss the process as futile. Document everything, contact the controller first, and if that fails, lodge your complaint. Every well-documented case contributes to the broader enforcement landscape and helps hold organisations accountable for how they handle your personal information.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
UK Data Protection Act vs GDPR Explained: A 2026 Compliance Guide
The UK Data Protection Act 2018 and the GDPR work hand-in-hand to govern personal data in the UK, but they aren't identical. This guide explains the key differences, overlaps, penalties, and practical compliance steps every UK organisation should take in 2026.
PIPEDA vs GDPR: Canadian Privacy Law Explained (2026 Guide)
PIPEDA and GDPR both protect personal data, but they differ dramatically in scope, consent rules, and penalties. This guide compares Canada's federal privacy law with Europe's GDPR and shows Canadian businesses how to comply with both in 2026.
Singapore PDPA vs GDPR: Key Differences for Businesses in 2026
Singapore's PDPA and the EU's GDPR share a common goal but differ significantly in scope, penalties, and individual rights. This guide breaks down the key differences and offers practical compliance tips for businesses operating in both regions.
GDPR After Brexit: What Changed for UK Businesses in 2026
GDPR after Brexit lives on in the UK as the UK GDPR, with the ICO as regulator and the IDTA replacing EU SCCs for international transfers. This guide explains what changed, what stayed the same, and how UK businesses can stay compliant in 2026.