DPC Ireland: How to File a Privacy Complaint (2026 Guide)
If an organisation has mishandled your personal data, you have the right to complain to the Data Protection Commission (DPC), Ireland's independent authority for upholding EU and Irish data protection law. This guide explains exactly how to file a privacy complaint with the DPC in 2026, what evidence to gather, how long the process takes, and what outcomes to expect.
What Is the DPC in Ireland?
The Data Protection Commission (DPC) is Ireland's national independent supervisory authority responsible for enforcing the General Data Protection Regulation (GDPR) and the Data Protection Act 2018. Because many of the world's largest technology companies have their European headquarters in Dublin, the DPC also acts as the lead supervisory authority for cross-border complaints against firms such as Meta, Google, TikTok, LinkedIn, and Microsoft under the GDPR's one-stop-shop mechanism.
The DPC's core functions include:
- Investigating complaints from individuals (called "data subjects")
- Conducting inquiries into potential breaches of data protection law
- Issuing fines, reprimands, and corrective orders
- Providing guidance to organisations and the public
- Cooperating with other EU supervisory authorities
When Should You File a Complaint with the DPC?
You should consider filing a complaint with the DPC when an organisation processes your personal data unlawfully or refuses to respect your GDPR rights. Personal data includes anything that identifies you — your name, email, IP address, phone number, health records, financial information, or online identifiers.
Common Grounds for a DPC Complaint
- Refusal of a subject access request (SAR) — an organisation has ignored or partially answered your request for a copy of your data.
- Unlawful direct marketing — unwanted emails, SMS, or calls without consent.
- Failure to delete data — the organisation ignored your right to erasure ("right to be forgotten").
- Data breaches — your data was exposed and you were not properly notified.
- Excessive data collection — a service asks for more information than it needs.
- CCTV misuse — a neighbour or business is recording you without lawful basis.
- Employer surveillance — monitoring workplace communications or activity without transparency.
- Cookie and tracking violations — a website drops non-essential cookies without valid consent.
Step 1: Contact the Organisation First
Before the DPC will formally investigate, you must normally try to resolve the issue directly with the organisation. This is a mandatory step under Section 109 of the Data Protection Act 2018 — the DPC has to give the parties an opportunity to reach an amicable resolution.
How to Contact the Data Controller
- Locate the organisation's Data Protection Officer (DPO) or privacy contact in its privacy policy.
- Send a clear written request by email (keep a copy). State exactly what right you are exercising — access, erasure, objection, rectification, or restriction.
- Include enough information to identify yourself, but no more than necessary.
- Give them the statutory deadline: one calendar month to respond under Article 12(3) GDPR (extendable by two further months for complex requests).
If they refuse, ignore you, or the response is inadequate, you can escalate to the DPC.
Step 2: Gather Your Evidence
The strength of your DPC complaint depends heavily on documentation. A well-evidenced file allows the DPC to open an inquiry quickly; a vague complaint may be closed with no action.
Prepare the following before filing:
- The full name and postal address of the organisation you are complaining about
- Copies of all correspondence (emails, letters, screenshots, ticket numbers)
- Dates on which you contacted the organisation and any responses received
- A clear, chronological summary of what happened
- The specific GDPR articles or rights you believe were breached (if known)
- Any supporting materials — marketing emails, screenshots of dark-pattern consent banners, CCTV photos, breach notification letters
If you are complaining about tracking links or shortened URLs used in unsolicited marketing, save the original messages with full headers. Reputable providers such as Lunyb publish clear privacy practices and abuse-reporting channels, which makes it easier to trace and evidence misuse.
Step 3: Submit Your Complaint to the DPC
The DPC accepts complaints through three official channels. All are free of charge — you never have to pay to lodge a complaint.
Online Webform (Recommended)
The fastest method is the online complaint form at dataprotection.ie under "Contact / Raise a Concern." The webform guides you through structured questions and lets you upload attachments up to a set size limit.
By Email
You can email info@dataprotection.ie with a full written complaint and attachments. Use a clear subject line such as "Formal Complaint under Section 108 Data Protection Act 2018 — [Organisation Name]."
By Post
Written complaints can be sent to:
Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland.
What to Include in Your Complaint
- Your full name, postal address, email, and phone number
- The organisation's name and address
- A concise description of the issue (what, when, where, how)
- Copies of your prior correspondence with the organisation
- The outcome you are seeking (e.g. deletion, access, cessation of marketing)
- A signed declaration that the information is accurate (for postal submissions)
Step 4: What Happens After You File
Once received, the DPC will send an acknowledgement, usually within a few working days, along with a case reference number. From there, the process typically follows these stages:
1. Assessment and Handling Team Review
A caseworker assesses whether the complaint falls within the DPC's remit and whether you have already contacted the organisation. If not, they may ask you to do so first.
2. Amicable Resolution
The DPC will normally contact the organisation and attempt to broker a resolution — for example, requiring them to answer your access request or delete your data. Many complaints are closed at this stage.
3. Statutory Inquiry
If amicable resolution fails, or if the matter involves a serious or systemic issue, the DPC can open a formal statutory inquiry under Section 110 of the Data Protection Act 2018. This may include on-site inspections, document requests, and legal analysis.
4. Decision
At the end of an inquiry, the DPC issues a legally binding decision. Possible outcomes include:
- A finding of infringement
- A reprimand or warning
- An order to bring processing into compliance
- An administrative fine (up to €20 million or 4% of global turnover, whichever is higher)
- A ban on specific processing activities
How Long Does a DPC Complaint Take?
Timelines vary considerably. Straightforward complaints resolved amicably may close within 2–6 months. Cross-border cases involving major tech companies often take 18 months to several years because they require cooperation with other EU authorities under the GDPR one-stop-shop.
| Complaint Type | Typical Timeline | Likely Outcome |
|---|---|---|
| Access request refusal | 2–4 months | Data disclosed under DPC pressure |
| Unsolicited marketing | 3–6 months | Removal from lists; possible fine |
| Erasure refusal | 3–6 months | Data deleted or lawful basis confirmed |
| CCTV disputes | 4–9 months | Camera repositioned or removed |
| Cross-border tech case | 1.5–4+ years | Formal decision, often with fine |
Your Rights During the Process
Throughout the DPC's handling of your complaint, you are entitled to:
- Be kept informed of progress
- Receive a legally binding decision within a reasonable time
- Appeal the DPC's decision to the Circuit Court or High Court within 28 days
- Withdraw your complaint at any time
- Seek compensation separately through the courts under Article 82 GDPR
Pros and Cons of Filing a DPC Complaint
Pros
- Completely free — no legal fees required
- You do not need a solicitor
- The DPC has strong enforcement powers, including major fines
- Complaints can trigger systemic change benefiting other users
- Decisions are legally binding
Cons
- Complex cases can take years
- The DPC does not award compensation — you must sue separately
- Outcomes may be limited to a reprimand rather than a fine
- You may need to disclose personal details as part of the process
Tips for a Strong Complaint
- Be concise and factual. Caseworkers handle hundreds of complaints — a two-page summary with attachments outperforms a twenty-page rant.
- Cite the right. Name the specific GDPR right you are exercising (Article 15 access, Article 17 erasure, Article 21 objection, etc.).
- Preserve evidence. Do not delete emails or accounts until the complaint is resolved.
- Follow up politely. If you have not heard from the DPC in 8 weeks, request a status update using your case reference.
- Stay patient. Resolution is rarely fast, especially for cross-border matters.
Protecting Your Privacy Going Forward
Filing a complaint addresses past harm, but reducing your data footprint prevents future issues. Consider these practical steps:
- Use encrypted DNS (DoH or DoT) to prevent ISP-level tracking
- Choose privacy-respecting browsers like Firefox or Brave with tracker blocking enabled
- Prefer end-to-end encrypted messaging and email services
- Use short-lived aliases for signups on unfamiliar sites
- Choose link tools transparent about analytics — for a comparison of options, see our 2026 URL shortener buyer's guide
- Regularly review app permissions on your devices
Frequently Asked Questions
Is there a deadline for filing a DPC complaint?
There is no strict statutory deadline, but the DPC encourages complaints to be filed promptly. Delays can weaken evidence and make investigation harder. As a rule of thumb, act within 12 months of the incident where possible.
Can I file a DPC complaint anonymously?
No. To open a formal complaint you must identify yourself so the DPC can verify facts and communicate with you. However, you can report concerns anonymously as "intelligence" that may feed into wider inquiries, though this will not result in an individual case being opened on your behalf.
Can I complain about a company outside Ireland?
Yes, if the company has its EU main establishment in Ireland (as many US tech firms do), the DPC is the lead authority. For companies based elsewhere in the EU, you can still file with the DPC and it will be transferred to the correct authority under the one-stop-shop mechanism, or you can file directly with the supervisory authority in your country of residence.
Will I get compensation if the DPC upholds my complaint?
The DPC cannot award compensation. If you have suffered material or non-material damage, you must pursue a separate civil claim under Article 82 GDPR in the Circuit Court or Higher Court. A favourable DPC decision can, however, strengthen such a claim.
What if I disagree with the DPC's decision?
You have the right to appeal a legally binding DPC decision to the Circuit Court within 28 days of notification. For questions of EU law, the case can ultimately be referred to the Court of Justice of the European Union.
Final Thoughts
Filing a privacy complaint with the DPC is one of the most powerful tools Irish and EU residents have to hold organisations accountable for how they handle personal data. The process is free, does not require a lawyer, and can lead to real change — from having your data deleted to triggering multi-million-euro fines against global companies. The key is preparation: contact the organisation first, gather clear evidence, cite the right GDPR provision, and be patient as the process unfolds.
Your data is yours. If it has been mishandled, the DPC exists to help you enforce that.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Bill C-27 Digital Charter: What You Need to Know in 2026
Bill C-27, Canada's Digital Charter Implementation Act, will replace PIPEDA with modern privacy rules, algorithmic transparency, and Canada's first federal AI law. Here's what businesses and individuals need to know about compliance, penalties, and preparation.
OAIC Complaints: How to Report a Privacy Breach in Australia
A step-by-step Australian guide to OAIC complaints: what counts as a privacy breach, how to complain to the organisation first, how to lodge with the regulator, and what outcomes to expect. Includes evidence tips, timelines, and answers to common questions.
ICO Fines 2026: Biggest Data Protection Penalties in the UK
The ICO has issued record-breaking data protection fines in 2026, targeting healthcare providers, retailers and marketers. We break down the biggest UK penalties, the compliance failures behind them, and the practical steps every organisation should take to stay off the enforcement page.
Australia Privacy Act 2026: Your Rights Explained
The Australia Privacy Act 2026 delivers the biggest overhaul of Australian data protection law in decades. This guide explains your new rights — including erasure, direct legal action and protections around automated decisions — plus what businesses must do to comply.