DPC Ireland: How to File a Privacy Complaint (2026 Guide)
If a company has mishandled your personal data, ignored your access request, or refused to delete your information, you have the right to file a complaint with the Data Protection Commission (DPC) of Ireland. As the lead supervisory authority for many of the world's largest technology companies headquartered in Dublin, the DPC handles complaints ranging from local nuisance calls to cross-border cases involving Meta, Google, TikTok and Microsoft.
This guide explains exactly how to file a privacy complaint with the DPC Ireland in 2026, what evidence to gather, how long the process takes, and what remedies you can realistically expect.
What Is the DPC and What Does It Do?
The Data Protection Commission (DPC) is Ireland's independent authority for upholding the fundamental right of individuals in the European Union to have their personal data protected. It enforces the General Data Protection Regulation (GDPR), the Irish Data Protection Act 2018, and the ePrivacy Regulations 2011.
The DPC has several core functions:
- Handling complaints from individuals whose data protection rights have been infringed.
- Investigating organisations that process personal data unlawfully.
- Issuing fines and corrective orders against controllers and processors in breach of GDPR.
- Acting as lead supervisory authority for tech giants with EU headquarters in Ireland, coordinating with other EU regulators under the One-Stop-Shop mechanism.
- Providing guidance to organisations and the public on data protection obligations and rights.
When Should You File a Complaint With the DPC?
You can lodge a complaint with the DPC whenever you believe an organisation has infringed your rights under data protection law. Before escalating, however, the DPC generally expects you to have first raised the issue directly with the organisation involved.
Common Grounds for a DPC Complaint
- Ignored subject access request (SAR) – you asked for a copy of your data and received no reply within one month.
- Refusal to delete data – you exercised your right to erasure and were denied without valid legal basis.
- Unlawful direct marketing – you received unsolicited emails, SMS or calls despite unsubscribing.
- Data breach affecting you – your data was exposed and you were not notified or the response was inadequate.
- Excessive data collection – an organisation collects more personal data than necessary for the stated purpose.
- CCTV misuse – a neighbour or business is filming areas they should not, or refuses to provide footage of you.
- Employer surveillance – covert monitoring or misuse of employee data.
- Cookie violations – a website sets tracking cookies without valid consent under the ePrivacy Regulations.
When the DPC Cannot Help
The DPC does not handle every grievance. It typically cannot assist with:
- Purely commercial disputes (billing errors, refunds) unrelated to personal data.
- Defamation or reputation matters – these belong in the civil courts.
- Complaints against An Garda Síochána relating to criminal investigations – those may fall under a separate oversight body.
- Journalism carried out in the public interest, which enjoys specific GDPR exemptions.
Step 1: Contact the Organisation First
Before filing with the DPC, you must attempt to resolve the matter directly with the controller. This is not just a courtesy – GDPR Article 77 grants you the right to complain to a supervisory authority, but the DPC's standard practice is to ask whether you have already engaged with the organisation.
- Identify the data controller. Check the privacy notice on the organisation's website. This will name the legal entity responsible and often provide the contact details of the Data Protection Officer (DPO).
- Write a clear request or complaint. Specify what you want: access to your data, erasure, correction, or an explanation of a breach.
- Send it in writing. Email is fine; keep timestamps. Registered post is stronger for high-value disputes.
- Wait one month. Under GDPR, controllers must respond within 30 days (extendable by two further months for complex cases, provided they tell you).
- Escalate if unsatisfied. If they refuse, ignore you, or the response is inadequate, you can proceed to the DPC.
Step 2: Gather Your Evidence
A well-documented complaint moves faster and carries more weight. Before submitting anything, collate the following:
- Copies of all correspondence with the organisation (emails, letters, chat transcripts).
- Screenshots of relevant web pages, cookie banners, marketing messages or account settings.
- Dates and reference numbers of your original request.
- Any privacy notice, terms of service or consent form you relied on.
- A short, factual timeline of events – the DPC processes hundreds of complaints and clarity matters.
- Details of the harm or distress caused (financial, emotional or reputational).
When sharing evidence links with the DPC or during correspondence, use short, trackable links so you can confirm receipt. Privacy-focused link tools like Lunyb let you shorten URLs without exposing you to invasive tracking scripts, which is useful when you are already dealing with a data protection dispute.
Step 3: File the Complaint With the DPC
There are three official ways to submit a complaint to the DPC Ireland.
Option 1: Webform (Recommended)
The DPC operates an online complaint form at dataprotection.ie. It guides you through the required fields and is the fastest way to open a case. You will need to create an account or provide a valid email address for correspondence.
Option 2: Email
You can email info@dataprotection.ie with your complaint. Include a clear subject line such as "Formal complaint under Article 77 GDPR – [Organisation Name]".
Option 3: Postal Submission
Write to: Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland. Postal submissions are slower but appropriate if you have physical documents or prefer not to use digital channels.
What to Include in Your Complaint
| Section | What to Provide |
|---|---|
| Your details | Full name, address, email, phone number |
| Organisation complained against | Legal name, address, DPO contact if known |
| Nature of complaint | Which GDPR right was infringed (access, erasure, marketing, etc.) |
| Timeline | Dates of original request, response deadlines, follow-ups |
| Evidence | Attached documents, screenshots, emails |
| Desired outcome | What resolution you seek (deletion, apology, corrective action) |
| Declaration | Confirmation the information is true and accurate |
Step 4: What Happens After You File
Once the DPC receives your complaint, the process typically unfolds in four stages.
1. Acknowledgement
Within a few working days, you should receive an acknowledgement with a case reference number. Keep this safe for all future correspondence.
2. Assessment
A case officer reviews whether the complaint falls within the DPC's remit and whether it is admissible. They may request additional information from you. In some cases, they will refer the matter back to the organisation for a further attempt at resolution (amicable resolution).
3. Investigation or Inquiry
If the complaint proceeds, the DPC may open a formal statutory inquiry. The organisation is compelled to provide records, policies and explanations. This stage can take months for straightforward cases and years for cross-border investigations into large tech platforms.
4. Decision
The DPC issues a decision. Possible outcomes include:
- No infringement found – case closed.
- Reprimand – a formal warning to the organisation.
- Corrective order – requiring deletion, correction or a change in processing practices.
- Administrative fine – up to €20 million or 4% of global annual turnover, whichever is higher.
- Referral to court – if criminal offences are suspected.
Cross-Border Complaints and the One-Stop-Shop
Because so many multinational tech companies have their EU headquarters in Dublin, the DPC often acts as lead supervisory authority under the GDPR's One-Stop-Shop mechanism. If you complain about Meta, Google, TikTok, LinkedIn, Airbnb or similar, your case may be handled by the DPC even if you live in another EU member state.
In practice, you can lodge your complaint with your local supervisory authority (for example the CNIL in France or the BfDI in Germany) and it will be transferred to the DPC. The DPC then leads the investigation but must consult other concerned authorities before issuing a binding decision. Disputes between regulators are resolved by the European Data Protection Board (EDPB).
Timelines: How Long Does It Really Take?
| Case Type | Typical Timeline |
|---|---|
| Simple domestic complaint (e.g. spam SMS) | 3–6 months |
| Access request dispute | 6–12 months |
| CCTV / neighbour dispute | 6–12 months |
| Employer data dispute | 9–18 months |
| Cross-border case (large tech company) | 2–5 years |
Under Section 150 of the Data Protection Act 2018, if the DPC has not concluded your complaint within a reasonable time (generally interpreted as three months), you may apply to the Circuit Court or High Court for a judicial remedy.
Costs and Legal Representation
Filing a complaint with the DPC is completely free. You do not need a solicitor. The DPC investigates on your behalf as a public function. However, if your case involves complex issues – employment law, defamation, or you plan to seek compensation in court – legal advice can be worthwhile.
You are also entitled to seek compensation directly through the courts under Article 82 GDPR for material or non-material damage caused by an infringement, independent of any DPC investigation.
Practical Tips to Strengthen Your Complaint
- Be specific. Vague grievances ("they misused my data") are harder to investigate than "On 3 March 2026 I submitted an access request; no response was received within 30 days."
- Cite the article. Reference the specific GDPR article you believe was breached (Article 15 for access, Article 17 for erasure, Article 21 for objection).
- Stay factual. Emotional language weakens your credibility. Let the facts do the work.
- Keep everything. Even after filing, log every subsequent interaction with the organisation.
- Follow up politely. If you have not heard from the DPC in 4–6 weeks, email quoting your reference number.
- Consider parallel action. For unpaid marketing consent violations, small claims may be quicker than waiting for a regulator's decision.
Protecting Your Privacy Going Forward
Filing a complaint addresses past infringements. To reduce future exposure:
- Read privacy notices before creating accounts – look for retention periods and third-party sharing.
- Use unique email aliases for different services so you can trace leaks.
- Set up encrypted DNS (such as Cloudflare's 1.1.1.1 or NextDNS) at router level to reduce network-level tracking.
- Prefer privacy-respecting browsers (Firefox, Brave) with strict tracking protection enabled.
- Use link-sharing tools that do not fingerprint visitors. Our review of Lunyb's URL shortener and the wider 2026 buyer's guide compares how different providers handle click data and personal information.
- Regularly exercise your access rights – knowing what companies hold about you helps you spot problems early.
Frequently Asked Questions
Can I file a complaint with the DPC anonymously?
No. The DPC needs to verify that you are the data subject whose rights have been infringed. However, your identity is not disclosed publicly, and you can ask the DPC to withhold your details from the organisation in exceptional circumstances (for example, cases involving domestic abuse or safeguarding concerns).
How much does it cost to file a complaint?
Nothing. There is no fee to lodge a complaint with the DPC, and you do not need legal representation. The DPC investigates as part of its statutory public function funded by the Irish state.
What if I live outside Ireland but the company is based there?
You have two options. You can complain directly to the DPC, or you can complain to the supervisory authority in your own EU member state, which will forward the case to the DPC under the One-Stop-Shop mechanism. If you live outside the EU, complain directly to the DPC.
Can the DPC award me compensation?
No. The DPC can order corrective measures and impose administrative fines paid to the state, but it cannot award personal compensation. To recover damages, you must bring a civil claim under Article 82 GDPR and Section 117 of the Data Protection Act 2018 in the Circuit Court or High Court.
What if I disagree with the DPC's decision?
You have the right to appeal a legally binding DPC decision to the Circuit Court within 28 days of notification. Judicial review in the High Court is also available where you believe the DPC acted unlawfully or unreasonably in handling your complaint.
Final Thoughts
The DPC Ireland is one of the most influential data protection regulators in the world, and its complaint process is genuinely accessible to ordinary residents. The key to success is preparation: engage the organisation first, gather clear evidence, and describe the infringement in specific legal terms. Whether you are dealing with a persistent spam caller or a global platform that has ignored your rights, filing a well-structured complaint is a powerful and free way to hold controllers accountable.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
GDPR in Ireland: Your Privacy Rights Explained
The General Data Protection Regulation gives people in Ireland powerful rights over their personal data. This guide explains what those rights are, how the Data Protection Commission enforces them, and the practical steps you can take to protect your privacy online.
Australia Privacy Act 2026: Your Rights Explained
The Australia Privacy Act 2026 gives Australians stronger rights over their personal information, including the right to erasure, a direct right to sue for serious privacy invasions, and enhanced protections for children. This guide explains what's changed, who's covered, and what individuals and businesses need to do now.
How Canadian Businesses Should Handle Data Privacy in 2026
Canadian businesses face a rapidly evolving privacy landscape in 2026, from PIPEDA and Quebec's Law 25 to the anticipated CPPA. This guide covers the laws that apply, common compliance mistakes, and a practical framework for building a defensible data privacy program.
Singapore PDPA vs GDPR: Key Differences Every Business Must Know
Singapore's PDPA and the EU's GDPR both protect personal data, but differ sharply in scope, consent, penalties, and breach rules. This guide compares the two laws side-by-side and shows Singapore businesses how to build a unified compliance strategy.