facebook-pixel

DPC Ireland: How to File a Privacy Complaint (2026 Guide)

L
Lunyb Security Team
··9 min read

If an organisation has mishandled your personal data, you have the right to complain to the Data Protection Commission (DPC), Ireland's independent authority for upholding EU and Irish data protection law. This guide explains exactly how to file a privacy complaint with the DPC in 2026, what evidence to gather, how long the process takes, and what outcomes to expect.

What Is the DPC in Ireland?

The Data Protection Commission (DPC) is Ireland's national independent supervisory authority responsible for enforcing the General Data Protection Regulation (GDPR) and the Data Protection Act 2018. Because many of the world's largest technology companies have their European headquarters in Dublin, the DPC also acts as the lead supervisory authority for cross-border complaints against firms such as Meta, Google, TikTok, LinkedIn, and Microsoft under the GDPR's one-stop-shop mechanism.

The DPC's core functions include:

  • Investigating complaints from individuals (called "data subjects")
  • Conducting inquiries into potential breaches of data protection law
  • Issuing fines, reprimands, and corrective orders
  • Providing guidance to organisations and the public
  • Cooperating with other EU supervisory authorities

When Should You File a Complaint with the DPC?

You should consider filing a complaint with the DPC when an organisation processes your personal data unlawfully or refuses to respect your GDPR rights. Personal data includes anything that identifies you — your name, email, IP address, phone number, health records, financial information, or online identifiers.

Common Grounds for a DPC Complaint

  • Refusal of a subject access request (SAR) — an organisation has ignored or partially answered your request for a copy of your data.
  • Unlawful direct marketing — unwanted emails, SMS, or calls without consent.
  • Failure to delete data — the organisation ignored your right to erasure ("right to be forgotten").
  • Data breaches — your data was exposed and you were not properly notified.
  • Excessive data collection — a service asks for more information than it needs.
  • CCTV misuse — a neighbour or business is recording you without lawful basis.
  • Employer surveillance — monitoring workplace communications or activity without transparency.
  • Cookie and tracking violations — a website drops non-essential cookies without valid consent.

Step 1: Contact the Organisation First

Before the DPC will formally investigate, you must normally try to resolve the issue directly with the organisation. This is a mandatory step under Section 109 of the Data Protection Act 2018 — the DPC has to give the parties an opportunity to reach an amicable resolution.

How to Contact the Data Controller

  1. Locate the organisation's Data Protection Officer (DPO) or privacy contact in its privacy policy.
  2. Send a clear written request by email (keep a copy). State exactly what right you are exercising — access, erasure, objection, rectification, or restriction.
  3. Include enough information to identify yourself, but no more than necessary.
  4. Give them the statutory deadline: one calendar month to respond under Article 12(3) GDPR (extendable by two further months for complex requests).

If they refuse, ignore you, or the response is inadequate, you can escalate to the DPC.

Step 2: Gather Your Evidence

The strength of your DPC complaint depends heavily on documentation. A well-evidenced file allows the DPC to open an inquiry quickly; a vague complaint may be closed with no action.

Prepare the following before filing:

  • The full name and postal address of the organisation you are complaining about
  • Copies of all correspondence (emails, letters, screenshots, ticket numbers)
  • Dates on which you contacted the organisation and any responses received
  • A clear, chronological summary of what happened
  • The specific GDPR articles or rights you believe were breached (if known)
  • Any supporting materials — marketing emails, screenshots of dark-pattern consent banners, CCTV photos, breach notification letters

If you are complaining about tracking links or shortened URLs used in unsolicited marketing, save the original messages with full headers. Reputable providers such as Lunyb publish clear privacy practices and abuse-reporting channels, which makes it easier to trace and evidence misuse.

Step 3: Submit Your Complaint to the DPC

The DPC accepts complaints through three official channels. All are free of charge — you never have to pay to lodge a complaint.

Online Webform (Recommended)

The fastest method is the online complaint form at dataprotection.ie under "Contact / Raise a Concern." The webform guides you through structured questions and lets you upload attachments up to a set size limit.

By Email

You can email info@dataprotection.ie with a full written complaint and attachments. Use a clear subject line such as "Formal Complaint under Section 108 Data Protection Act 2018 — [Organisation Name]."

By Post

Written complaints can be sent to:
Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland.

What to Include in Your Complaint

  1. Your full name, postal address, email, and phone number
  2. The organisation's name and address
  3. A concise description of the issue (what, when, where, how)
  4. Copies of your prior correspondence with the organisation
  5. The outcome you are seeking (e.g. deletion, access, cessation of marketing)
  6. A signed declaration that the information is accurate (for postal submissions)

Step 4: What Happens After You File

Once received, the DPC will send an acknowledgement, usually within a few working days, along with a case reference number. From there, the process typically follows these stages:

1. Assessment and Handling Team Review

A caseworker assesses whether the complaint falls within the DPC's remit and whether you have already contacted the organisation. If not, they may ask you to do so first.

2. Amicable Resolution

The DPC will normally contact the organisation and attempt to broker a resolution — for example, requiring them to answer your access request or delete your data. Many complaints are closed at this stage.

3. Statutory Inquiry

If amicable resolution fails, or if the matter involves a serious or systemic issue, the DPC can open a formal statutory inquiry under Section 110 of the Data Protection Act 2018. This may include on-site inspections, document requests, and legal analysis.

4. Decision

At the end of an inquiry, the DPC issues a legally binding decision. Possible outcomes include:

  • A finding of infringement
  • A reprimand or warning
  • An order to bring processing into compliance
  • An administrative fine (up to €20 million or 4% of global turnover, whichever is higher)
  • A ban on specific processing activities

How Long Does a DPC Complaint Take?

Timelines vary considerably. Straightforward complaints resolved amicably may close within 2–6 months. Cross-border cases involving major tech companies often take 18 months to several years because they require cooperation with other EU authorities under the GDPR one-stop-shop.

Complaint TypeTypical TimelineLikely Outcome
Access request refusal2–4 monthsData disclosed under DPC pressure
Unsolicited marketing3–6 monthsRemoval from lists; possible fine
Erasure refusal3–6 monthsData deleted or lawful basis confirmed
CCTV disputes4–9 monthsCamera repositioned or removed
Cross-border tech case1.5–4+ yearsFormal decision, often with fine

Your Rights During the Process

Throughout the DPC's handling of your complaint, you are entitled to:

  • Be kept informed of progress
  • Receive a legally binding decision within a reasonable time
  • Appeal the DPC's decision to the Circuit Court or High Court within 28 days
  • Withdraw your complaint at any time
  • Seek compensation separately through the courts under Article 82 GDPR

Pros and Cons of Filing a DPC Complaint

Pros

  • Completely free — no legal fees required
  • You do not need a solicitor
  • The DPC has strong enforcement powers, including major fines
  • Complaints can trigger systemic change benefiting other users
  • Decisions are legally binding

Cons

  • Complex cases can take years
  • The DPC does not award compensation — you must sue separately
  • Outcomes may be limited to a reprimand rather than a fine
  • You may need to disclose personal details as part of the process

Tips for a Strong Complaint

  1. Be concise and factual. Caseworkers handle hundreds of complaints — a two-page summary with attachments outperforms a twenty-page rant.
  2. Cite the right. Name the specific GDPR right you are exercising (Article 15 access, Article 17 erasure, Article 21 objection, etc.).
  3. Preserve evidence. Do not delete emails or accounts until the complaint is resolved.
  4. Follow up politely. If you have not heard from the DPC in 8 weeks, request a status update using your case reference.
  5. Stay patient. Resolution is rarely fast, especially for cross-border matters.

Protecting Your Privacy Going Forward

Filing a complaint addresses past harm, but reducing your data footprint prevents future issues. Consider these practical steps:

  • Use encrypted DNS (DoH or DoT) to prevent ISP-level tracking
  • Choose privacy-respecting browsers like Firefox or Brave with tracker blocking enabled
  • Prefer end-to-end encrypted messaging and email services
  • Use short-lived aliases for signups on unfamiliar sites
  • Choose link tools transparent about analytics — for a comparison of options, see our 2026 URL shortener buyer's guide
  • Regularly review app permissions on your devices

Frequently Asked Questions

Is there a deadline for filing a DPC complaint?

There is no strict statutory deadline, but the DPC encourages complaints to be filed promptly. Delays can weaken evidence and make investigation harder. As a rule of thumb, act within 12 months of the incident where possible.

Can I file a DPC complaint anonymously?

No. To open a formal complaint you must identify yourself so the DPC can verify facts and communicate with you. However, you can report concerns anonymously as "intelligence" that may feed into wider inquiries, though this will not result in an individual case being opened on your behalf.

Can I complain about a company outside Ireland?

Yes, if the company has its EU main establishment in Ireland (as many US tech firms do), the DPC is the lead authority. For companies based elsewhere in the EU, you can still file with the DPC and it will be transferred to the correct authority under the one-stop-shop mechanism, or you can file directly with the supervisory authority in your country of residence.

Will I get compensation if the DPC upholds my complaint?

The DPC cannot award compensation. If you have suffered material or non-material damage, you must pursue a separate civil claim under Article 82 GDPR in the Circuit Court or Higher Court. A favourable DPC decision can, however, strengthen such a claim.

What if I disagree with the DPC's decision?

You have the right to appeal a legally binding DPC decision to the Circuit Court within 28 days of notification. For questions of EU law, the case can ultimately be referred to the Court of Justice of the European Union.

Final Thoughts

Filing a privacy complaint with the DPC is one of the most powerful tools Irish and EU residents have to hold organisations accountable for how they handle personal data. The process is free, does not require a lawyer, and can lead to real change — from having your data deleted to triggering multi-million-euro fines against global companies. The key is preparation: contact the organisation first, gather clear evidence, cite the right GDPR provision, and be patient as the process unfolds.

Your data is yours. If it has been mishandled, the DPC exists to help you enforce that.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles