DPC Ireland: How to File a Privacy Complaint (2026 Guide)
If you believe an organisation has mishandled your personal data, Ireland's Data Protection Commission (DPC) is the statutory body that investigates complaints under the GDPR and the Irish Data Protection Act 2018. Because so many global tech companies (Meta, Google, TikTok, Microsoft, LinkedIn and others) have their EU headquarters in Dublin, the DPC is also the lead supervisory authority for a huge share of European privacy complaints. This guide explains exactly how to file a complaint, what evidence to prepare, and what happens after you submit.
What Is the DPC and What Does It Do?
The Data Protection Commission (An Coimisiún um Chosaint Sonraí) is Ireland's independent regulator responsible for upholding the rights of individuals under EU and Irish data protection law. It enforces the General Data Protection Regulation (GDPR), the Data Protection Act 2018, and the ePrivacy Regulations 2011.
The DPC handles three broad types of work:
- Complaint handling — investigating individual complaints from data subjects.
- Inquiries and enforcement — opening own-volition inquiries into systemic issues, issuing fines and corrective orders.
- Guidance and consultation — publishing guidance for controllers, processors and the public.
As of 2026, the DPC operates from offices in Dublin and Portarlington and has significantly expanded its investigative staff following criticism of enforcement delays in prior years.
When Can You File a Complaint With the DPC?
You can file a complaint with the DPC if you are a data subject (a living individual whose personal data is being processed) and you believe an organisation has breached your rights under data protection law. Common grounds include:
- An organisation refusing or ignoring a Subject Access Request (SAR).
- Failure to erase your data after a valid deletion request.
- Unlawful direct marketing (unsolicited emails, SMS or calls).
- A data breach that exposed your personal information.
- Excessive CCTV surveillance by a neighbour, employer or business.
- Unlawful sharing of your data with third parties.
- Cookies or tracking without valid consent.
- Employers accessing personal communications or monitoring beyond what is proportionate.
You do not need to be an Irish resident. Any EU/EEA citizen can complain to the DPC if the controller has its main EU establishment in Ireland — which is why the DPC receives complaints from across Europe about the major US tech platforms.
When You Should Complain Elsewhere First
Under GDPR, you generally have the right to complain directly to your local supervisory authority. However, for many issues the DPC will expect you to have first raised the matter with the organisation itself — typically via their Data Protection Officer (DPO). If they fail to respond within one month, or their response is inadequate, you can escalate to the DPC.
Step-by-Step: How to File a Complaint With the DPC
The DPC accepts complaints through an online webform, by post, or by email. Here is the recommended process:
- Contact the organisation first. Write to their DPO or privacy team stating what right you are exercising (access, erasure, objection, etc.) and give them one calendar month to respond.
- Gather your evidence. Save copies of emails, screenshots, letters, timestamps and any reference numbers.
- Visit the DPC website at dataprotection.ie and open the "Contact / Raise a Concern" section.
- Complete the online complaint form. You will be asked for your identity, the organisation involved, a description of the issue, the outcome you are seeking, and supporting documents.
- Submit and record your reference number. The DPC will issue an acknowledgement, usually within a few working days.
- Respond to any follow-up questions from the DPC case handler promptly to keep the file moving.
What Information You Need to Provide
- Your full name and contact details.
- The name and (if known) address of the organisation you are complaining about.
- A clear, chronological summary of what happened.
- Copies of correspondence with the organisation, including their final response (or evidence they did not respond).
- The specific right or provision you believe has been breached (e.g. Article 15 GDPR — right of access).
- The outcome you want (erasure, access, compensation via the courts, corrective action, etc.).
DPC Complaint Channels at a Glance
| Channel | Best For | Typical Acknowledgement |
|---|---|---|
| Online webform (dataprotection.ie) | Most individuals — fastest route | 2–5 working days |
| Email (info@dataprotection.ie) | Complaints with large attachments | 5–10 working days |
| Postal letter (Portarlington or Dublin office) | Individuals without digital access | 2–3 weeks |
| Local supervisory authority (for non-IE residents) | Cross-border complaints via one-stop-shop | Varies by country |
What Happens After You File
Once your complaint is received, the DPC follows a structured handling process. Understanding the stages helps set realistic expectations.
Stage 1: Assessment
A case officer reviews the complaint to confirm it falls within the DPC's remit. They may ask you for more information, or clarify whether you first contacted the organisation. If the complaint is outside their jurisdiction (for example, a matter for the Workplace Relations Commission or the Gardaí), they will redirect you.
Stage 2: Amicable Resolution
Under Section 109(2) of the Data Protection Act 2018, the DPC is required to try to resolve most complaints amicably. This means the case officer will contact the organisation, put your allegations to them, and attempt to broker a resolution — often an apology, disclosure of data, deletion of records, or a change of practice.
A large majority of DPC complaints are resolved at this stage without a formal decision.
Stage 3: Formal Investigation / Inquiry
If amicable resolution fails, or if the complaint reveals a serious or systemic breach, the DPC can open a statutory inquiry under Section 110. This is a formal process that can lead to binding decisions, corrective orders, reprimands, bans on processing, and administrative fines of up to €20 million or 4% of global turnover.
Stage 4: Decision and Appeal
A final decision is issued in writing. If you are dissatisfied, you have a right of appeal to the Circuit Court or High Court within 28 days. Organisations can appeal too, and cross-border decisions may be referred to the European Data Protection Board (EDPB) under the GDPR's consistency mechanism.
How Long Does a DPC Complaint Take?
Timelines vary considerably. Straightforward complaints resolved amicably often close within 3–6 months. Formal inquiries — especially cross-border cases against large tech companies — can take 2–4 years. The DPC has published statutory case-handling procedures aiming to close routine matters within a year, but complex cases requiring cooperation with other EU authorities remain slower.
Tips to Strengthen Your Complaint
The quality of your submission has a direct impact on how quickly it is triaged and how seriously it is investigated. Best practices include:
- Be specific and chronological. Dates, names and reference numbers matter far more than emotive language.
- Cite the relevant GDPR articles if you can — e.g. Article 6 (lawfulness), Article 15 (access), Article 17 (erasure), Article 21 (objection).
- Attach documentary evidence. Screenshots with visible URLs and timestamps are ideal. If you need to share long tracking or evidence links, a privacy-respecting shortener like Lunyb can make your evidence bundle tidier without sending readers through ad-heavy redirect services.
- State the remedy you want. Access to data? Erasure? A stop to marketing? A finding of infringement?
- Keep copies of everything you send and receive, including postal receipts.
- Do not exaggerate or include irrelevant grievances. Stick to the data protection issue.
Common Complaint Scenarios and How the DPC Treats Them
Unanswered Subject Access Requests
A controller must respond to an SAR within one month (extendable by two months for complex requests). If they miss the deadline or refuse without valid reason, this is one of the most straightforward DPC complaints and is usually resolved quickly through amicable resolution.
Neighbour CCTV Overlooking Your Property
CCTV that captures the public road or a neighbour's private space engages the GDPR. The DPC will typically ask the neighbour to reposition cameras, mask areas, or reduce recording windows. Purely domestic CCTV that only films the owner's property is outside GDPR scope.
Direct Marketing Without Consent
Under the ePrivacy Regulations, unsolicited marketing emails, SMS and calls are a criminal offence in Ireland. The DPC can and does prosecute repeat offenders in the District Court. Keep the marketing messages, note the sender, and include them in your complaint.
Data Breaches Affecting You
If a company suffers a breach exposing your data and fails to notify you when required, or handles the aftermath poorly, you can complain. The DPC will already have received the mandatory 72-hour breach notification from the controller and can factor your complaint into any wider inquiry.
Pros and Cons of Complaining to the DPC
Pros
- Free of charge — no fees at any stage.
- No lawyer required to file.
- Statutory powers to compel evidence and impose fines.
- Amicable resolution route often produces fast practical outcomes.
- Decisions can create binding precedent that benefits others.
Cons
- Complex cases can take years.
- The DPC cannot award you personal compensation — that requires a separate civil action.
- Cross-border cooperation with other EU regulators adds delay.
- Communication during long inquiries can feel opaque.
Can You Claim Compensation?
The DPC itself does not award damages. However, Section 117 of the Data Protection Act 2018 gives you the right to bring a "data protection action" in the Circuit Court or High Court for compensation, including for non-material damage such as distress. A DPC finding of infringement — even at the amicable resolution stage — can strengthen a subsequent civil claim significantly.
Protecting Your Privacy Day to Day
Filing a complaint is a reactive step. Reducing the data you expose in the first place is equally important. Practical measures include using a privacy-focused browser, enabling encrypted DNS (DoH or DoT), being cautious with app permissions, minimising the personal information you provide on forms, and using link-management tools that do not profile your clicks. For a comparison of shorteners that respect user data, see our 2026 buyer's guide to URL shorteners and our honest review of Lunyb. If you are also weighing branded-link tools, our Rebrandly review discusses their data-handling posture too.
Frequently Asked Questions
Is there a deadline to file a complaint with the DPC?
There is no strict statutory deadline in the GDPR, but the DPC will generally decline to investigate matters that are more than 12 months old unless there is a good reason for the delay. File as soon as possible after the organisation's final response.
Can I file a complaint anonymously?
No. The DPC needs your identity to investigate and to correspond with you. However, your identity will normally only be shared with the organisation being complained about, and only to the extent necessary to investigate.
What if the company is based outside Ireland?
If the controller has its main EU establishment in Ireland, the DPC is the lead authority. If it is established in another EU country, you can still lodge your complaint with the DPC and it will be transferred under the GDPR's one-stop-shop mechanism, or you can complain directly to that country's regulator.
Can I complain about a public body such as a hospital, school or government department?
Yes. Public sector bodies are subject to GDPR and the Data Protection Act 2018 just like private companies. Note that administrative fines against public bodies in Ireland are capped at €1 million, but corrective orders and reprimands still apply.
Do I need a solicitor to file a complaint?
No. The DPC's process is designed to be accessible to individuals without legal representation. You only need a solicitor if you decide to pursue a separate civil action for compensation, or to appeal a DPC decision to the courts.
Final Thoughts
Filing a complaint with the DPC is one of the most powerful tools Irish and EU residents have to hold organisations accountable for how they handle personal data. The process is free, does not require a lawyer, and — for straightforward cases — often produces a practical remedy within months. Prepare your evidence carefully, contact the organisation first, cite the relevant GDPR articles, and be patient with the process. Even where enforcement is slow, every well-documented complaint contributes to the wider pressure that shapes how organisations treat your data.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
GDPR in Ireland: Your Privacy Rights Explained
The General Data Protection Regulation gives people in Ireland powerful rights over their personal data. This guide explains what those rights are, how the Data Protection Commission enforces them, and the practical steps you can take to protect your privacy online.
Australia Privacy Act 2026: Your Rights Explained
The Australia Privacy Act 2026 gives Australians stronger rights over their personal information, including the right to erasure, a direct right to sue for serious privacy invasions, and enhanced protections for children. This guide explains what's changed, who's covered, and what individuals and businesses need to do now.
How Canadian Businesses Should Handle Data Privacy in 2026
Canadian businesses face a rapidly evolving privacy landscape in 2026, from PIPEDA and Quebec's Law 25 to the anticipated CPPA. This guide covers the laws that apply, common compliance mistakes, and a practical framework for building a defensible data privacy program.
Singapore PDPA vs GDPR: Key Differences Every Business Must Know
Singapore's PDPA and the EU's GDPR both protect personal data, but differ sharply in scope, consent, penalties, and breach rules. This guide compares the two laws side-by-side and shows Singapore businesses how to build a unified compliance strategy.