DPC Ireland: How to File a Privacy Complaint (2026 Guide)
If you believe an organisation has mishandled your personal data, you have the right to complain to Ireland's Data Protection Commission (DPC). As the lead supervisory authority for many of the world's largest tech companies, the DPC plays a central role in enforcing the GDPR across the EU. This guide explains exactly how to file a privacy complaint with the DPC Ireland, what evidence you need, how long the process takes, and what remedies you can expect.
What Is the Data Protection Commission (DPC)?
The Data Protection Commission is Ireland's independent statutory authority responsible for upholding the fundamental right of individuals to have their personal data protected. Established under the Data Protection Act 2018, the DPC enforces the EU General Data Protection Regulation (GDPR), the Law Enforcement Directive, and the ePrivacy Regulations within Ireland.
Because many multinational technology companies — including Meta, Google, TikTok, Microsoft, and LinkedIn — have their European headquarters in Dublin, the DPC often acts as the "lead supervisory authority" for cross-border complaints under the GDPR's one-stop-shop mechanism. This gives the Irish regulator outsized influence over how data protection law is applied across Europe.
What the DPC Can Do
- Investigate complaints from individuals (data subjects).
- Conduct own-volition inquiries into organisations.
- Issue reprimands, warnings, and corrective orders.
- Impose administrative fines of up to €20 million or 4% of global annual turnover.
- Refer disputes to the European Data Protection Board (EDPB).
When Should You File a Complaint with the DPC?
You can file a complaint with the DPC if you believe your rights under the GDPR or Data Protection Act 2018 have been violated by a data controller or processor. Before filing, however, the DPC generally expects you to have first raised the issue directly with the organisation involved.
Common Grounds for a DPC Complaint
- Refusal or delay of a Subject Access Request (SAR): The organisation didn't respond within one month or provided incomplete data.
- Unauthorised disclosure: Your data was shared with third parties without a lawful basis or consent.
- Direct marketing without consent: Unwanted emails, SMS, or calls in breach of ePrivacy Regulations.
- Refusal to delete data: The company ignored your right to erasure ("right to be forgotten").
- Data breach: The organisation lost, leaked, or exposed your personal information.
- Excessive data collection: Processing that goes beyond what's necessary for the stated purpose.
- Inaccurate data: Refusal to correct wrong information the organisation holds about you.
- CCTV or workplace monitoring: Disproportionate surveillance without proper notice.
Step 1: Contact the Organisation First
The DPC expects complainants to first exercise their rights directly with the data controller. This gives the organisation an opportunity to fix the issue and often resolves matters faster than a formal investigation.
How to Contact the Data Controller
- Find the Data Protection Officer (DPO) contact details in the organisation's privacy policy.
- Send your request in writing (email is fine) so you have a record.
- Clearly state which right you are exercising — for example, "I am making a Subject Access Request under Article 15 GDPR."
- Include proof of identity if requested.
- Wait one calendar month for a response (extendable by two months for complex requests, but they must tell you).
Keep every email, letter, and screenshot. This correspondence forms the backbone of your evidence if you later escalate to the DPC.
Step 2: Prepare Your Complaint
A well-prepared complaint significantly increases the chance of a swift, favourable outcome. The DPC's caseworkers handle thousands of complaints each year, so clarity and organisation matter.
Information You'll Need
- Your details: Full name, address, email, and phone number.
- The organisation: Legal name, address, and (if known) DPO contact.
- Description of the issue: A clear, chronological account of what happened.
- The GDPR right at issue: Access, erasure, rectification, objection, etc.
- Evidence: Emails, screenshots, letters, contracts, marketing messages.
- Outcome sought: Deletion, correction, apology, or investigation.
Tips for Writing a Strong Complaint
- Stick to the facts — avoid emotional language.
- Use dates and reference numbers where possible.
- Number your exhibits ("Exhibit A: Email from 3 March 2026").
- Be specific about what article of the GDPR you believe was breached.
- Keep it concise — two to four pages is usually enough.
Step 3: Submit Your Complaint to the DPC
The DPC accepts complaints through multiple channels. As of 2026, the fastest and most trackable route is the online webform on dataprotection.ie.
Submission Methods
| Method | Details | Best For |
|---|---|---|
| Online webform | dataprotection.ie/en/contact/how-make-complaint | Most complaints; fastest acknowledgement |
| info@dataprotection.ie | Attaching multiple documents | |
| Post | 21 Fitzwilliam Square South, Dublin 2, D02 RD28 | Formal or sensitive matters |
| Phone (guidance only) | +353 (0)761 104 800 | Initial questions, not formal complaints |
Phone calls are useful for asking procedural questions, but the DPC will not formally register a complaint over the phone — it must be in writing.
Step 4: The DPC Handling Process
Once your complaint is submitted, the DPC follows a structured process defined by Section 109 of the Data Protection Act 2018.
Stages of a DPC Complaint
- Acknowledgement (within a few working days): You receive a case reference number.
- Assessment: A caseworker reviews whether the DPC has jurisdiction and whether the complaint is well-founded.
- Amicable resolution: The DPC often tries to resolve matters informally by contacting the organisation on your behalf. Many cases end here.
- Formal investigation: If informal resolution fails, the DPC may open a statutory inquiry.
- Decision: The DPC issues a legally binding decision, which can include corrective measures and fines.
- Appeal: Either party can appeal to the Circuit Court or High Court within 28 days.
How Long Does It Take?
Simple complaints — such as an unanswered SAR — are often resolved amicably within 3 to 6 months. Complex cross-border investigations involving large tech firms can take 2 to 5 years, particularly if they involve the EDPB's dispute resolution mechanism. The DPC publishes an annual report each spring with statistics on case duration.
Cross-Border Complaints and the One-Stop-Shop
If your complaint concerns a company with its main EU establishment in Ireland — Meta, Google, TikTok, Apple, and others — the DPC will typically act as the lead supervisory authority under the GDPR's one-stop-shop mechanism, even if you live in another EU member state.
You can still lodge your complaint with your local data protection authority (for example, CNIL in France or the Garante in Italy), which will forward it to the DPC. The final decision is then coordinated across all concerned authorities. This can add months to the timeline but ensures a single, consistent outcome across the EU.
What Remedies Can You Expect?
The DPC has a wide range of enforcement tools, though not all are used in every case. Individual complainants should have realistic expectations — most complaints result in corrective action rather than financial compensation.
Typical Outcomes
- Order to comply: The organisation must fulfil your SAR, delete your data, or stop the offending processing.
- Reprimand: A formal warning recorded against the organisation.
- Administrative fine: Paid to the state, not to you.
- Ban on processing: Rare but possible in serious cases.
Getting Compensation
The DPC itself cannot award you money. To seek damages for material or non-material harm caused by a GDPR breach, you must bring a separate civil action in the Circuit Court under Section 117 of the Data Protection Act 2018. A DPC decision in your favour can be strong evidence in such proceedings.
Protecting Your Privacy Going Forward
Filing a complaint addresses past harm — but reducing your exposure to future privacy issues is equally important. A few practical steps go a long way:
- Use encrypted DNS resolvers (such as those from Cloudflare or Quad9) to prevent your ISP from logging every domain you visit.
- Prefer privacy-focused browsers like Firefox or Brave with tracker blocking enabled.
- Use unique email aliases for signups so you can trace which service leaked your data.
- When sharing links publicly — for example on social media or in newsletters — consider a privacy-respecting URL shortener like Lunyb that doesn't build advertising profiles from click data. See our honest Lunyb review for more detail, and our 2026 buyer's guide for alternatives.
- Review app permissions on your phone every few months.
- Exercise your GDPR rights routinely — a well-timed SAR can reveal what companies actually hold about you.
Common Mistakes That Weaken a Complaint
Even legitimate complaints can be dismissed or delayed due to avoidable errors. Watch out for these pitfalls:
- Not contacting the organisation first. The DPC may refuse to progress the complaint until you do.
- Missing evidence. Verbal conversations are hard to prove — always follow up in writing.
- Vague allegations. "They misused my data" is not enough. Specify what happened, when, and how.
- Complaining about non-GDPR issues. Consumer disputes, defamation, or contract breaches fall outside the DPC's remit.
- Waiting too long. While there's no strict deadline, evidence and memories fade quickly.
Frequently Asked Questions
Is there a fee to file a complaint with the DPC?
No. Filing a complaint with the Data Protection Commission is completely free. You do not need a solicitor either, though legal advice can help in complex or high-value cases where you plan to pursue civil damages afterwards.
Can I file a complaint anonymously?
Generally, no. The DPC needs to verify your identity and your relationship to the data in question, and the organisation being investigated typically has a right to know the substance of the complaint. However, you can request that the DPC keep your identity confidential to the extent legally possible, and tips about systemic issues can sometimes be handled as own-volition inquiries.
What if the DPC rejects my complaint?
If the DPC dismisses your complaint or you disagree with the outcome, you have the right to an effective judicial remedy under Article 78 of the GDPR. You can appeal the decision to the Circuit Court (for most matters) or the High Court within 28 days of receiving the decision. You may also bring a separate civil action for damages regardless of the DPC's finding.
Can I complain to the DPC if I live outside Ireland?
Yes, if the organisation you're complaining about has its main EU establishment in Ireland. Otherwise, you should file with your local supervisory authority, which will coordinate with the DPC if needed. EU residents can always choose to lodge complaints with the authority in their country of residence, workplace, or where the alleged infringement occurred.
How do I check the status of my complaint?
Once you receive your case reference number, you can email info@dataprotection.ie quoting that number to request an update. The DPC aims to provide meaningful progress updates every few months, though complex investigations may go through longer quiet periods while evidence is being gathered and analysed.
Final Thoughts
Filing a complaint with the DPC is one of the most powerful tools EU residents have to hold organisations accountable for how they handle personal data. The process is free, doesn't require a lawyer, and can lead to real change — from a company finally answering your access request to multi-million-euro fines against the world's largest tech firms.
The keys to success are simple: try to resolve the issue directly first, document everything in writing, be specific about which GDPR right has been breached, and be patient with the timelines. Your right to data protection is a fundamental one under EU law — the DPC exists to help you enforce it.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Data Protection Act 2018 Ireland: Complete Guide
A complete guide to the Data Protection Act 2018 in Ireland: what it covers, how it works with the GDPR, the rights it gives individuals, and what organisations must do to stay compliant. Includes penalties, DPC enforcement, and a practical compliance checklist.
OAIC Complaints: How to Report a Privacy Breach in Australia
A step-by-step Australian guide to lodging a privacy complaint with the OAIC after a data breach. Covers eligibility, evidence, timelines, possible compensation and common mistakes that weaken claims.
Singapore Online Safety Act 2026: Complete Guide for Users and Businesses
Singapore's Online Safety Act 2026 introduces sweeping new rules for platforms, deepfakes, and scam content. This complete guide explains who must comply, the new obligations, penalties, and practical steps businesses and users should take to prepare.
ePrivacy Regulations Ireland: Latest Updates for 2026
A practical 2026 guide to ePrivacy Regulations in Ireland — covering cookie consent, direct marketing rules, DPC enforcement trends, and what's next as the EU ePrivacy Regulation approaches. Includes a compliance checklist for Irish organisations.