facebook-pixel

DPC Ireland: How to File a Privacy Complaint (2026 Guide)

L
Lunyb Security Team
··9 min read

If a company has mishandled your personal data, ignored your access request, or refused to delete your information, you have the right to lodge a formal complaint with the Data Protection Commission (DPC) in Ireland. As the lead supervisory authority for many of the world's largest tech firms, the DPC handles thousands of complaints each year — and knowing how to file one correctly can significantly improve your chances of a meaningful outcome.

This guide walks you through everything you need to know to file a privacy complaint with the DPC Ireland: who can complain, what qualifies, how to prepare your evidence, the exact submission process, and what happens after you file.

What Is the Data Protection Commission (DPC)?

The Data Protection Commission is Ireland's national independent authority responsible for upholding the fundamental right of individuals in the EU to have their personal data protected. Established under the Data Protection Act 2018, the DPC enforces the General Data Protection Regulation (GDPR) and the ePrivacy Regulations across all organisations that process personal data within Ireland.

Because many multinational technology companies — including Meta, Google, TikTok, LinkedIn, Apple, and Microsoft — have their European headquarters in Dublin, the DPC also acts as the lead supervisory authority for cross-border complaints involving these firms under the GDPR's one-stop-shop mechanism.

Key Responsibilities of the DPC

  • Investigating complaints from individuals about data protection breaches
  • Conducting audits and inquiries into organisations
  • Issuing fines and enforcement notices for GDPR violations
  • Providing guidance to controllers and processors
  • Cooperating with other EU data protection authorities

When Can You File a Complaint with the DPC?

You can lodge a complaint with the DPC if you believe an organisation has infringed your data protection rights under the GDPR or the Data Protection Act 2018. Common grounds for a complaint include the following.

Valid Reasons to File a Complaint

  1. Unlawful processing: A company processed your data without a lawful basis (e.g. no consent, no legitimate interest).
  2. Ignored subject access request (SAR): You asked for a copy of your data and received no response within one month.
  3. Refusal to delete data: The organisation rejected a valid right-to-erasure request.
  4. Excessive data collection: The controller collected more information than necessary for its stated purpose.
  5. Data breach: Your personal information was exposed and you were not properly notified.
  6. Unsolicited marketing: You received emails, SMS, or calls after unsubscribing or without ever consenting.
  7. Cookie violations: A website tracked you without a valid consent banner.
  8. Cross-border transfers: Your data was sent outside the EEA without appropriate safeguards.

Important Prerequisite: Contact the Organisation First

Before escalating to the DPC, you are generally expected to raise the issue directly with the organisation's Data Protection Officer (DPO) or privacy team. The DPC will often ask for evidence that you attempted to resolve the matter before they open a formal case. Give the organisation at least one month to respond.

How to File a Complaint with the DPC: Step-by-Step

The DPC offers several submission channels, but the fastest and most reliable route is the online webform. Here is the complete process from preparation to submission.

Step 1: Gather Your Evidence

Before filing, collect everything that supports your case. The stronger your documentation, the more likely the DPC is to progress the complaint quickly.

  • Copies of emails, letters, or messages exchanged with the organisation
  • Screenshots of the offending content, website, or app behaviour
  • Dates of relevant events (when you consented, when you withdrew consent, when you submitted a request)
  • Any reference numbers provided by the company
  • Your original data request and their response (or lack thereof)

If you are sharing links to online evidence with the DPC or any third party, avoid pasting messy tracking-heavy URLs. A clean shortened link from a privacy-respecting service like Lunyb keeps your submission tidy and easier to review.

Step 2: Write a Clear Statement of Complaint

Your complaint should be factual, chronological, and specific. Include:

  • Your full name and contact details
  • The name and address of the organisation you are complaining about
  • A clear description of what happened, in date order
  • Which GDPR right you believe was infringed (e.g. Article 15 — access, Article 17 — erasure)
  • The outcome you are seeking (deletion, correction, apology, compensation, etc.)

Step 3: Submit via the DPC's Preferred Channel

The DPC accepts complaints through the following methods:

ChannelDetailsBest For
Online webformdataprotection.ie/en/individuals/raising-concern-commissionMost complaints — fastest
Emailinfo@dataprotection.ieStraightforward issues with attachments
Post21 Fitzwilliam Square South, Dublin 2, D02 RD28Sensitive matters or hard-copy evidence
Phone+353 (0)761 104 800Initial guidance only — not formal filing

Step 4: Await Acknowledgement

The DPC typically acknowledges receipt within 5–10 working days. You will receive a case reference number, which you should keep for all future correspondence.

Step 5: Cooperate with the Investigation

The DPC may contact you for additional information, or ask you to attempt further engagement with the organisation. Respond promptly — delays on your side can slow or close the case.

What Happens After You File?

The DPC follows a structured procedure once a complaint is received. Understanding the stages helps set realistic expectations.

The DPC Complaint Lifecycle

  1. Intake and triage: DPC staff assess whether the complaint falls within their remit.
  2. Amicable resolution attempt: Under Section 109 of the Data Protection Act 2018, the DPC will often try to broker a resolution between you and the organisation.
  3. Formal inquiry: If no resolution is reached, or if the matter is serious, the DPC opens an inquiry under Section 110.
  4. Draft decision: The DPC issues a preliminary finding, which both parties can respond to.
  5. Final decision: A binding decision is issued, potentially including corrective orders and administrative fines.
  6. Appeal window: Either party can appeal to the Irish Circuit Court within 28 days.

Typical Timelines

Simple complaints (e.g. unanswered SARs) can be resolved in 2–4 months. Complex cross-border investigations — particularly against large tech firms — can take 18 months to several years. The DPC has been criticised for slow throughput on major cases, though reforms and expanded staffing since 2022 have improved turnaround.

Pros and Cons of Filing with the DPC

Pros

  • Free of charge — no filing fees
  • Handles the world's largest tech companies as lead authority
  • Enforceable outcomes including multi-million euro fines
  • You can complain in English or Irish
  • No need for a solicitor

Cons

  • Investigation timelines can be very long for major cases
  • You cannot claim monetary compensation directly through the DPC — that requires a separate civil action
  • Outcomes for individual complainants can feel modest even when fines are large
  • Cross-border cases involve coordination with other EU authorities, adding complexity

Alternatives and Complementary Actions

Filing with the DPC is not your only option. Depending on your situation, you may combine or substitute the following.

Civil Court Action

Under Section 117 of the Data Protection Act 2018, you can bring a data protection action directly in the Circuit Court or High Court to seek compensation for material or non-material damage (including distress). This is separate from a DPC complaint and can proceed in parallel.

Complain to Another EU Authority

If you live in another EU country, you can file with your local data protection authority, which will coordinate with the DPC under the one-stop-shop rules. This can sometimes be more responsive for individual queries.

Reduce Your Exposure Proactively

Prevention beats complaint. Use encrypted DNS providers, a hardened browser, a password manager, and privacy-respecting tools for everyday tasks. For example, when sharing links, a tracker-free shortener helps limit the personal data leaked through referral chains. See our 2026 buyer's guide to URL shorteners for a comparison of privacy-focused options, or read our honest review of Lunyb for a deeper look at one such service.

Common Mistakes to Avoid

  1. Skipping the organisation: Filing with the DPC before contacting the company almost guarantees your complaint will be redirected.
  2. Vague descriptions: "They misused my data" is not enough. Cite specific events, dates, and articles of the GDPR.
  3. Missing evidence: Verbal claims without documentation are hard to investigate.
  4. Filing multiple duplicate complaints: This slows triage. One well-documented complaint is more effective than five vague ones.
  5. Ignoring DPC follow-ups: If the DPC asks for clarification and you do not respond, they may close the case.

Your GDPR Rights at a Glance

Knowing which right has been infringed helps you frame your complaint precisely.

GDPR ArticleRightWhat It Means
Article 15Right of accessGet a copy of your personal data
Article 16Right to rectificationCorrect inaccurate data
Article 17Right to erasureHave your data deleted
Article 18Right to restrictionLimit how your data is processed
Article 20Right to portabilityReceive your data in a machine-readable format
Article 21Right to objectStop processing for marketing or legitimate interest
Article 22Automated decision-makingNot be subject to purely automated decisions

Frequently Asked Questions

Is there a deadline for filing a complaint with the DPC?

There is no strict statutory deadline, but complaints should be filed as soon as reasonably possible after the incident. The DPC may decline to investigate matters that occurred many years ago if evidence has degraded or the issue is no longer current.

Can I file a complaint anonymously?

No. The DPC requires your identity to investigate properly, though your details will be handled confidentially. In some circumstances, the DPC can withhold your name from the organisation being complained about, but this must be requested with justification.

Will I get compensation if my complaint is upheld?

Not directly through the DPC. The DPC can order corrective actions and issue fines to the organisation, but any monetary compensation for you personally must be pursued through a separate civil claim under Section 117 of the Data Protection Act 2018.

Can I file a complaint about a company based outside Ireland?

Yes, if the company has its main EU establishment in Ireland (as many large tech firms do), the DPC is the lead authority. Otherwise, you can file with the DPC and they will forward the matter to the appropriate EU authority under the one-stop-shop mechanism.

Does filing a complaint cost anything?

No. Lodging a complaint with the DPC is completely free. You do not need legal representation, although for complex or high-value matters you may wish to consult a solicitor specialising in data protection law.

Final Thoughts

Filing a complaint with the DPC is one of the most powerful tools individuals in Ireland have to enforce their privacy rights. While the process requires patience — particularly for cross-border cases — a well-documented, clearly-argued complaint can lead to real change, from data deletion to multi-million euro fines against non-compliant organisations.

Start by contacting the company, gather your evidence, cite the specific GDPR rights involved, and submit through the DPC's online portal. Whether you are challenging an ignored access request or a large-scale data breach, your complaint contributes to a broader culture of accountability across the digital economy.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles