DPC Ireland: How to File a Privacy Complaint (2026 Guide)
If a company has mishandled your personal data, ignored your access request, or refused to delete your information, you have the right to lodge a formal complaint with the Data Protection Commission (DPC) in Ireland. As the lead supervisory authority for many of the world's largest tech firms, the DPC handles thousands of complaints each year — and knowing how to file one correctly can significantly improve your chances of a meaningful outcome.
This guide walks you through everything you need to know to file a privacy complaint with the DPC Ireland: who can complain, what qualifies, how to prepare your evidence, the exact submission process, and what happens after you file.
What Is the Data Protection Commission (DPC)?
The Data Protection Commission is Ireland's national independent authority responsible for upholding the fundamental right of individuals in the EU to have their personal data protected. Established under the Data Protection Act 2018, the DPC enforces the General Data Protection Regulation (GDPR) and the ePrivacy Regulations across all organisations that process personal data within Ireland.
Because many multinational technology companies — including Meta, Google, TikTok, LinkedIn, Apple, and Microsoft — have their European headquarters in Dublin, the DPC also acts as the lead supervisory authority for cross-border complaints involving these firms under the GDPR's one-stop-shop mechanism.
Key Responsibilities of the DPC
- Investigating complaints from individuals about data protection breaches
- Conducting audits and inquiries into organisations
- Issuing fines and enforcement notices for GDPR violations
- Providing guidance to controllers and processors
- Cooperating with other EU data protection authorities
When Can You File a Complaint with the DPC?
You can lodge a complaint with the DPC if you believe an organisation has infringed your data protection rights under the GDPR or the Data Protection Act 2018. Common grounds for a complaint include the following.
Valid Reasons to File a Complaint
- Unlawful processing: A company processed your data without a lawful basis (e.g. no consent, no legitimate interest).
- Ignored subject access request (SAR): You asked for a copy of your data and received no response within one month.
- Refusal to delete data: The organisation rejected a valid right-to-erasure request.
- Excessive data collection: The controller collected more information than necessary for its stated purpose.
- Data breach: Your personal information was exposed and you were not properly notified.
- Unsolicited marketing: You received emails, SMS, or calls after unsubscribing or without ever consenting.
- Cookie violations: A website tracked you without a valid consent banner.
- Cross-border transfers: Your data was sent outside the EEA without appropriate safeguards.
Important Prerequisite: Contact the Organisation First
Before escalating to the DPC, you are generally expected to raise the issue directly with the organisation's Data Protection Officer (DPO) or privacy team. The DPC will often ask for evidence that you attempted to resolve the matter before they open a formal case. Give the organisation at least one month to respond.
How to File a Complaint with the DPC: Step-by-Step
The DPC offers several submission channels, but the fastest and most reliable route is the online webform. Here is the complete process from preparation to submission.
Step 1: Gather Your Evidence
Before filing, collect everything that supports your case. The stronger your documentation, the more likely the DPC is to progress the complaint quickly.
- Copies of emails, letters, or messages exchanged with the organisation
- Screenshots of the offending content, website, or app behaviour
- Dates of relevant events (when you consented, when you withdrew consent, when you submitted a request)
- Any reference numbers provided by the company
- Your original data request and their response (or lack thereof)
If you are sharing links to online evidence with the DPC or any third party, avoid pasting messy tracking-heavy URLs. A clean shortened link from a privacy-respecting service like Lunyb keeps your submission tidy and easier to review.
Step 2: Write a Clear Statement of Complaint
Your complaint should be factual, chronological, and specific. Include:
- Your full name and contact details
- The name and address of the organisation you are complaining about
- A clear description of what happened, in date order
- Which GDPR right you believe was infringed (e.g. Article 15 — access, Article 17 — erasure)
- The outcome you are seeking (deletion, correction, apology, compensation, etc.)
Step 3: Submit via the DPC's Preferred Channel
The DPC accepts complaints through the following methods:
| Channel | Details | Best For |
|---|---|---|
| Online webform | dataprotection.ie/en/individuals/raising-concern-commission | Most complaints — fastest |
| info@dataprotection.ie | Straightforward issues with attachments | |
| Post | 21 Fitzwilliam Square South, Dublin 2, D02 RD28 | Sensitive matters or hard-copy evidence |
| Phone | +353 (0)761 104 800 | Initial guidance only — not formal filing |
Step 4: Await Acknowledgement
The DPC typically acknowledges receipt within 5–10 working days. You will receive a case reference number, which you should keep for all future correspondence.
Step 5: Cooperate with the Investigation
The DPC may contact you for additional information, or ask you to attempt further engagement with the organisation. Respond promptly — delays on your side can slow or close the case.
What Happens After You File?
The DPC follows a structured procedure once a complaint is received. Understanding the stages helps set realistic expectations.
The DPC Complaint Lifecycle
- Intake and triage: DPC staff assess whether the complaint falls within their remit.
- Amicable resolution attempt: Under Section 109 of the Data Protection Act 2018, the DPC will often try to broker a resolution between you and the organisation.
- Formal inquiry: If no resolution is reached, or if the matter is serious, the DPC opens an inquiry under Section 110.
- Draft decision: The DPC issues a preliminary finding, which both parties can respond to.
- Final decision: A binding decision is issued, potentially including corrective orders and administrative fines.
- Appeal window: Either party can appeal to the Irish Circuit Court within 28 days.
Typical Timelines
Simple complaints (e.g. unanswered SARs) can be resolved in 2–4 months. Complex cross-border investigations — particularly against large tech firms — can take 18 months to several years. The DPC has been criticised for slow throughput on major cases, though reforms and expanded staffing since 2022 have improved turnaround.
Pros and Cons of Filing with the DPC
Pros
- Free of charge — no filing fees
- Handles the world's largest tech companies as lead authority
- Enforceable outcomes including multi-million euro fines
- You can complain in English or Irish
- No need for a solicitor
Cons
- Investigation timelines can be very long for major cases
- You cannot claim monetary compensation directly through the DPC — that requires a separate civil action
- Outcomes for individual complainants can feel modest even when fines are large
- Cross-border cases involve coordination with other EU authorities, adding complexity
Alternatives and Complementary Actions
Filing with the DPC is not your only option. Depending on your situation, you may combine or substitute the following.
Civil Court Action
Under Section 117 of the Data Protection Act 2018, you can bring a data protection action directly in the Circuit Court or High Court to seek compensation for material or non-material damage (including distress). This is separate from a DPC complaint and can proceed in parallel.
Complain to Another EU Authority
If you live in another EU country, you can file with your local data protection authority, which will coordinate with the DPC under the one-stop-shop rules. This can sometimes be more responsive for individual queries.
Reduce Your Exposure Proactively
Prevention beats complaint. Use encrypted DNS providers, a hardened browser, a password manager, and privacy-respecting tools for everyday tasks. For example, when sharing links, a tracker-free shortener helps limit the personal data leaked through referral chains. See our 2026 buyer's guide to URL shorteners for a comparison of privacy-focused options, or read our honest review of Lunyb for a deeper look at one such service.
Common Mistakes to Avoid
- Skipping the organisation: Filing with the DPC before contacting the company almost guarantees your complaint will be redirected.
- Vague descriptions: "They misused my data" is not enough. Cite specific events, dates, and articles of the GDPR.
- Missing evidence: Verbal claims without documentation are hard to investigate.
- Filing multiple duplicate complaints: This slows triage. One well-documented complaint is more effective than five vague ones.
- Ignoring DPC follow-ups: If the DPC asks for clarification and you do not respond, they may close the case.
Your GDPR Rights at a Glance
Knowing which right has been infringed helps you frame your complaint precisely.
| GDPR Article | Right | What It Means |
|---|---|---|
| Article 15 | Right of access | Get a copy of your personal data |
| Article 16 | Right to rectification | Correct inaccurate data |
| Article 17 | Right to erasure | Have your data deleted |
| Article 18 | Right to restriction | Limit how your data is processed |
| Article 20 | Right to portability | Receive your data in a machine-readable format |
| Article 21 | Right to object | Stop processing for marketing or legitimate interest |
| Article 22 | Automated decision-making | Not be subject to purely automated decisions |
Frequently Asked Questions
Is there a deadline for filing a complaint with the DPC?
There is no strict statutory deadline, but complaints should be filed as soon as reasonably possible after the incident. The DPC may decline to investigate matters that occurred many years ago if evidence has degraded or the issue is no longer current.
Can I file a complaint anonymously?
No. The DPC requires your identity to investigate properly, though your details will be handled confidentially. In some circumstances, the DPC can withhold your name from the organisation being complained about, but this must be requested with justification.
Will I get compensation if my complaint is upheld?
Not directly through the DPC. The DPC can order corrective actions and issue fines to the organisation, but any monetary compensation for you personally must be pursued through a separate civil claim under Section 117 of the Data Protection Act 2018.
Can I file a complaint about a company based outside Ireland?
Yes, if the company has its main EU establishment in Ireland (as many large tech firms do), the DPC is the lead authority. Otherwise, you can file with the DPC and they will forward the matter to the appropriate EU authority under the one-stop-shop mechanism.
Does filing a complaint cost anything?
No. Lodging a complaint with the DPC is completely free. You do not need legal representation, although for complex or high-value matters you may wish to consult a solicitor specialising in data protection law.
Final Thoughts
Filing a complaint with the DPC is one of the most powerful tools individuals in Ireland have to enforce their privacy rights. While the process requires patience — particularly for cross-border cases — a well-documented, clearly-argued complaint can lead to real change, from data deletion to multi-million euro fines against non-compliant organisations.
Start by contacting the company, gather your evidence, cite the specific GDPR rights involved, and submit through the DPC's online portal. Whether you are challenging an ignored access request or a large-scale data breach, your complaint contributes to a broader culture of accountability across the digital economy.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Data Protection Act 2018 Ireland: Complete Guide for Businesses
A complete, practical guide to the Data Protection Act 2018 in Ireland — covering its scope, principles, individual rights, DPC enforcement, breach notifications, and compliance steps for Irish businesses. Learn how to align your organisation with Ireland's data protection framework and avoid costly penalties.
OAIC Complaints: How to Report a Privacy Breach in Australia
A step-by-step Australian guide to lodging a privacy complaint with the OAIC — from contacting the organisation first, to evidence gathering, timelines, and possible compensation outcomes. Learn how to protect yourself after a breach and strengthen your case.
Bill C-27 Digital Charter: What Canadian Businesses Need to Know
Bill C-27, the Digital Charter Implementation Act, will reshape Canadian privacy law through the CPPA, a new tribunal, and AIDA — Canada's first federal AI law. Here's what businesses need to know about new rights, penalties up to 5% of global revenue, and practical steps to prepare.
Australia Privacy Act 2026: Your Rights Explained
The Australia Privacy Act 2026 introduces new rights to access, correct, erase and de-index personal data, plus a statutory tort for serious privacy invasions. Here's a plain-English guide to what's changed, what businesses must do, and how Australians can protect themselves.