DPC Ireland: How to File a Privacy Complaint (2026 Guide)
If a company has mishandled your personal data, ignored your access request, or refused to delete your information, you have the right to lodge a formal complaint with the Data Protection Commission (DPC) in Ireland. As the lead supervisory authority for many of the world's largest tech companies headquartered in Dublin, the DPC is one of the most influential privacy regulators in Europe.
This guide walks you through exactly how to file a privacy complaint with the DPC, what evidence to gather, what to expect during the investigation, and how to escalate if you're unsatisfied with the outcome.
What Is the Data Protection Commission (DPC)?
The Data Protection Commission is Ireland's independent national authority responsible for upholding the fundamental right of individuals to have their personal data protected. It enforces the General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018.
Because giants like Meta, Google, TikTok, Microsoft, and LinkedIn have their European headquarters in Ireland, the DPC often acts as the lead regulator for cross-border investigations affecting hundreds of millions of EU citizens. It has issued some of the largest GDPR fines in history, including a €1.2 billion penalty against Meta in 2023.
What the DPC Can and Cannot Do
- Can: Investigate complaints, issue reprimands, impose administrative fines, order companies to comply, and refer cases to the courts.
- Cannot: Award financial compensation to individuals (you must pursue that separately in the Irish courts).
When You Can File a Complaint with the DPC
You can lodge a complaint with the DPC when you believe an organisation has breached your rights under the GDPR or the Data Protection Act 2018. Common grounds include:
- Unlawful processing — a company is using your data without a valid legal basis (consent, contract, legal obligation, etc.).
- Access request ignored — you submitted a Subject Access Request (SAR) and got no reply within one month, or received an incomplete response.
- Refusal to delete data — the organisation ignored your right to erasure ("right to be forgotten").
- Data breach affecting you — your data was leaked, lost, or exposed and you weren't notified appropriately.
- Unwanted marketing — you continue to receive emails, texts, or calls after unsubscribing.
- CCTV or surveillance concerns — inappropriate monitoring at work, in public, or by a neighbour.
- Inaccurate data — a company refuses to correct incorrect information about you.
Try to Resolve It Directly First
The DPC strongly recommends you contact the organisation directly before filing a complaint. GDPR gives companies one month to respond to data subject requests. If they refuse, delay, or ignore you, that refusal itself becomes evidence for your complaint.
Step-by-Step: How to File a DPC Complaint
Filing a complaint with the DPC is free, and you don't need a solicitor. Here's the full process from start to finish.
Step 1: Gather Your Evidence
Before you write anything, collect:
- Copies of emails to and from the organisation
- Screenshots of websites, apps, or messages
- The date you submitted your original request (SAR, erasure, etc.)
- Any response — or proof there was no response
- Details of the data involved and how it was mishandled
Step 2: Contact the Organisation's DPO
Most organisations have a Data Protection Officer (DPO) or a dedicated privacy contact. Send a clear written complaint by email, referencing GDPR rights, and give them a reasonable deadline (typically 30 days). Keep a copy.
Step 3: Complete the DPC Complaint Form
Go to dataprotection.ie and download the "Complaint Handling Form" (also called the eComplaints form). You can submit it:
- Online via the DPC's webform
- By email to info@dataprotection.ie
- By post to: Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28
Step 4: Provide the Required Information
Your complaint should include:
- Your full name and contact details
- The name and address of the organisation you're complaining about
- A clear description of what happened, in chronological order
- Which GDPR rights you believe were breached (Articles 12–22 cover most individual rights)
- Copies of all relevant correspondence and evidence
- The outcome you are seeking (deletion, correction, explanation, etc.)
Step 5: Await Acknowledgement
The DPC typically acknowledges complaints within a few working days. You'll receive a case reference number. Keep it — you'll need it for all future correspondence.
What Happens After You File
The DPC's handling process has evolved significantly under GDPR. Here's what to expect at each stage.
Amicable Resolution Phase
The DPC will usually attempt to facilitate an "amicable resolution" between you and the organisation first. This is faster and less formal than a full investigation. The organisation may apologise, delete the data, or provide the requested information at this stage.
Formal Investigation
If amicable resolution fails, or if the complaint is serious enough, the DPC may open a formal statutory inquiry. This can take months or, for complex cross-border cases, years. The DPC has powers to:
- Compel the organisation to hand over documents
- Interview staff
- Conduct on-site inspections
- Issue binding decisions
Possible Outcomes
| Outcome | What It Means |
|---|---|
| No infringement found | The DPC concludes the organisation acted within the law. You can appeal to the Circuit Court. |
| Reprimand | A formal warning noting the breach but no fine. |
| Corrective order | The organisation is ordered to comply — e.g., delete data, provide access, or stop a processing activity. |
| Administrative fine | Financial penalty up to €20 million or 4% of global annual turnover. |
| Ban on processing | The organisation must stop a specific data activity entirely. |
Cross-Border Complaints and the One-Stop-Shop
If your complaint involves a company headquartered outside Ireland but operating in the EU, you can still file with the DPC if the organisation's EU main establishment is in Ireland (as with Meta, Google, TikTok, etc.). Under GDPR's "one-stop-shop" mechanism, the DPC coordinates with other EU regulators, and the final decision applies across all affected member states.
You can also file with your local supervisory authority in another EU country — they will forward it to the DPC where appropriate.
How Long Does It Take?
Timescales vary dramatically:
- Amicable resolution: 2–6 months on average
- Standard investigation: 6–18 months
- Complex cross-border inquiries: 2–5 years
The DPC has been criticised for delays, but reforms and increased staffing have improved throughput since 2023.
Common Mistakes to Avoid
- Skipping the direct contact stage. The DPC will often send you back to the organisation first.
- Vague descriptions. Be specific about dates, actions, and which right was breached.
- Missing evidence. Include everything up front — chasing documents later slows things down.
- Expecting compensation. The DPC cannot award damages. For that, you need civil proceedings under Section 117 of the Data Protection Act 2018.
- Filing anonymously. The DPC generally cannot investigate anonymous complaints, though your identity can be kept confidential from the organisation in some cases.
Protecting Your Privacy Going Forward
Filing a complaint is a reactive step. To reduce the risk of future privacy violations, take proactive measures:
- Use privacy-respecting tools. Choose services that minimise data collection and are transparent about processing. For example, when sharing links, tools like Lunyb allow you to shorten URLs without exposing your original destination in every share, and don't sell click data to advertisers. See our honest Lunyb review for more on how it handles user data.
- Read privacy notices. Yes, they're tedious — but the section on "legal basis" and "third-party recipients" is often revealing.
- Exercise your rights regularly. Submit SARs periodically to see what companies actually hold on you.
- Enable encrypted DNS and use privacy-focused browsers. These reduce passive data collection at the network level.
- Compare link tools carefully. Not all URL shorteners protect user data equally. Our 2026 shortener comparison looks at privacy alongside features.
Appealing a DPC Decision
If you disagree with the DPC's decision on your complaint, you have the right to appeal to the Irish Circuit Court within 28 days of receiving the decision. You can also make a separate application to the High Court in cases involving significant legal questions. Legal advice is strongly recommended at this stage.
Frequently Asked Questions
Is there a fee to file a complaint with the DPC?
No. Filing a complaint with the Data Protection Commission is completely free. You do not need a solicitor, although legal advice can help with complex or high-stakes cases.
Can I file a DPC complaint from outside Ireland?
Yes. Anyone whose personal data is processed by an organisation with its EU main establishment in Ireland (such as Meta or Google) can file directly with the DPC. Alternatively, you can complain to your local supervisory authority and they'll route it through the one-stop-shop mechanism.
How long do I have to file a complaint?
There is no strict statutory deadline, but the DPC recommends filing as soon as possible after the incident. Delays can weaken your case and make evidence harder to preserve. For related civil claims for compensation, the general limitation period in Ireland is six years.
Will the company know I complained about them?
Generally, yes. To investigate properly, the DPC usually needs to share your complaint with the organisation. However, in sensitive situations (e.g., workplace complaints), you can request that certain details be kept confidential — the DPC will do what it can while still enabling a fair investigation.
Can the DPC force a company to pay me compensation?
No. The DPC can impose fines that go to the state, order corrective action, and issue reprimands, but it cannot award you personal damages. For compensation, you must bring a civil action under Section 117 of the Data Protection Act 2018 in the Circuit or High Court.
Final Thoughts
Filing a complaint with the DPC is one of the most powerful tools EU citizens have to hold organisations accountable for how they handle personal data. The process is free, well-documented, and — while sometimes slow — genuinely capable of producing meaningful results, from forced deletions to record-breaking fines.
Whether you're dealing with an ignored access request, unwanted marketing, or a serious data breach, the key is preparation: gather evidence, be specific, exhaust internal channels first, then submit a clear, factual complaint. Ireland's role as home to Europe's biggest tech firms means your complaint may have implications reaching far beyond your own case.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
GDPR in Ireland: Your Privacy Rights Explained
The General Data Protection Regulation gives people in Ireland powerful rights over their personal data. This guide explains what those rights are, how the Data Protection Commission enforces them, and the practical steps you can take to protect your privacy online.
Australia Privacy Act 2026: Your Rights Explained
The Australia Privacy Act 2026 gives Australians stronger rights over their personal information, including the right to erasure, a direct right to sue for serious privacy invasions, and enhanced protections for children. This guide explains what's changed, who's covered, and what individuals and businesses need to do now.
How Canadian Businesses Should Handle Data Privacy in 2026
Canadian businesses face a rapidly evolving privacy landscape in 2026, from PIPEDA and Quebec's Law 25 to the anticipated CPPA. This guide covers the laws that apply, common compliance mistakes, and a practical framework for building a defensible data privacy program.
Singapore PDPA vs GDPR: Key Differences Every Business Must Know
Singapore's PDPA and the EU's GDPR both protect personal data, but differ sharply in scope, consent, penalties, and breach rules. This guide compares the two laws side-by-side and shows Singapore businesses how to build a unified compliance strategy.