DPC Ireland: How to File a Privacy Complaint (2026 Guide)
If your personal data has been mishandled by a company or organisation operating in Ireland — or anywhere in the EU that falls under Irish jurisdiction — you have the right to file a complaint with the Data Protection Commission (DPC). This guide explains exactly how to lodge a complaint with DPC Ireland, what evidence you need, and what happens after you submit it.
What Is the Data Protection Commission (DPC)?
The Data Protection Commission is Ireland's national independent authority responsible for upholding the fundamental right of individuals in the EU to have their personal data protected. It enforces the General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018.
Because many of the world's largest technology companies — Meta, Google, Apple, TikTok, LinkedIn, X, Microsoft — have their European headquarters in Dublin, the DPC also acts as the lead supervisory authority for cross-border complaints under the GDPR's one-stop-shop mechanism. That means an Irish complaint against Facebook or Google can have Europe-wide consequences.
When Should You Contact the DPC?
You should consider filing a complaint if you believe an organisation has:
- Processed your personal data unlawfully or without a valid legal basis.
- Refused or ignored a subject access request (SAR).
- Failed to delete your data after a valid erasure request.
- Sent you unsolicited marketing emails, SMS, or calls.
- Suffered a data breach involving your information without notifying you appropriately.
- Used cookies or tracking technologies without proper consent.
- Shared your data with third parties you did not consent to.
Before You File: Contact the Organisation First
The DPC strongly recommends — and in most cases expects — that you attempt to resolve the issue directly with the organisation before escalating. This is not just a formality; the DPC will often ask for evidence of your prior correspondence.
Step 1: Identify the Data Controller
The "data controller" is the organisation that determines why and how your personal data is processed. Check the company's privacy policy, which should list a contact address and, where required, a Data Protection Officer (DPO).
Step 2: Submit a Formal Written Request
Send a clear, dated, written request — email is fine — describing your concern. Depending on the issue, this may be:
- A subject access request asking for a copy of your data.
- An erasure request ("right to be forgotten") asking them to delete your data.
- A rectification request asking them to correct inaccurate data.
- An objection to processing for marketing or profiling.
The organisation has one calendar month to respond under the GDPR. They may extend this by two further months for complex requests, but they must tell you why within the original month.
Step 3: Keep Records
Save every email, letter, and screenshot. The DPC will ask for this evidence when you file. Without documentation, your complaint is much harder to progress.
How to File a Complaint With DPC Ireland
Once you have given the organisation a fair chance to respond and are still dissatisfied, you can escalate to the DPC. Filing is free, and you do not need a solicitor.
Option 1: Online Webform (Recommended)
Visit dataprotection.ie and use the "Raise a Concern" webform. This is the fastest route and creates an automatic case reference. You will need:
- Your full name and contact details.
- The name of the organisation you are complaining about.
- A clear description of what happened and when.
- Copies of your correspondence with the organisation.
- Any supporting evidence (screenshots, receipts, marketing messages).
Option 2: By Post
You can also write to the DPC at:
Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland.
Postal complaints take longer to log but are equally valid.
Option 3: By Email
General queries can be sent to info@dataprotection.ie, though for formal complaints the webform is preferred because it structures the information the case handlers need.
What Information to Include in Your Complaint
A well-structured complaint gets processed faster. Include the following, in this order:
- Your identity: Name, address, phone, email.
- The respondent: Full legal name of the organisation and, if known, the DPO.
- Chronology of events: Dates and a factual timeline.
- The GDPR right or rule at issue: For example, Article 15 (access), Article 17 (erasure), Article 6 (lawful basis).
- Evidence: Attach PDFs or images of correspondence and screenshots.
- The outcome you want: Deletion of data, an apology, a corrected record, a marketing opt-out, etc.
Common Mistakes That Delay Complaints
- Not contacting the organisation first.
- Vague descriptions like "they misused my data" without specifics.
- Missing dates or attachments.
- Complaining about an entity outside the DPC's jurisdiction.
- Submitting duplicate complaints to multiple EU authorities.
What Happens After You File
The DPC follows a defined handling process. Here is what to expect at each stage.
| Stage | What Happens | Typical Timeframe |
|---|---|---|
| Acknowledgement | DPC confirms receipt and assigns a case reference. | 1–4 weeks |
| Initial assessment | Case officer reviews jurisdiction and merits. | 1–3 months |
| Amicable resolution | DPC contacts the organisation to seek a voluntary fix. | 2–6 months |
| Formal inquiry | Opened if no resolution; can lead to binding decisions and fines. | 6 months – 3+ years |
| Decision | Written decision issued; may include reprimand, order, or fine. | Varies |
Amicable Resolution
Most individual complaints are resolved at this stage. The DPC contacts the organisation, explains the concern, and the organisation typically deletes the data, apologises, or updates its practices. This is fast and effective for straightforward issues.
Statutory Inquiry
If the matter is serious, systemic, or unresolved, the DPC may open a formal statutory inquiry under Section 110 of the Data Protection Act 2018. These inquiries can result in enforcement notices, reprimands, and administrative fines of up to €20 million or 4% of global annual turnover.
Your Rights If You Are Not Satisfied
You do not have to accept the DPC's outcome. Options include:
- Judicial review in the Irish High Court if you believe the DPC acted unlawfully or irrationally.
- A civil action under Section 117 of the Data Protection Act 2018 for compensation for material or non-material damage (including distress).
- Escalation to the European Data Protection Board (EDPB) for cross-border complaints where you disagree with the lead authority's handling.
Special Cases: Cross-Border and Big Tech Complaints
Because Ireland hosts the EU headquarters of most major tech firms, complaints against companies like Meta, Google, TikTok, or LinkedIn are typically handled by the DPC as "lead supervisory authority" under the GDPR's one-stop-shop mechanism.
You can still file with your local supervisory authority in your own EU country, and they will forward the case to Dublin. However, filing directly with the DPC can sometimes streamline the process. The DPC coordinates with concerned authorities across Europe, and final decisions can bind the company across the entire EU/EEA.
Marketing and Nuisance Communications
Unsolicited marketing emails, SMS, and phone calls fall under both GDPR and the ePrivacy Regulations (SI 336/2011). The DPC actively prosecutes offenders in the District Court, and this remains one of the fastest tracks for individual complaints to be resolved.
Protecting Yourself Going Forward
Filing a complaint is reactive. Reducing the amount of personal data you expose is proactive. A few practical habits:
- Use disposable email aliases when signing up for services you do not fully trust.
- Enable encrypted DNS (DNS over HTTPS) in your browser to reduce network-level tracking.
- Review app permissions on your phone every few months.
- When sharing links publicly, use a link management platform that lets you track and revoke access. Tools like Lunyb allow you to shorten and manage URLs with analytics, so you know who is clicking what — useful evidence if a link is later misused. For a broader look at options, see our 2026 buyer's guide to URL shorteners.
- Check company privacy policies before submitting sensitive information.
Practical Example: A Sample Complaint Timeline
To make this concrete, here is what a typical marketing-email complaint looks like end to end:
- Day 0: You receive an unsolicited marketing email from a company you never signed up with.
- Day 1: You reply asking how they got your data and demanding erasure under Article 17.
- Day 30: No adequate response, or a dismissive one.
- Day 31: You file with the DPC via the online webform, attaching the original email and your reply.
- Day 45: DPC acknowledges and assigns a case number.
- Day 90: DPC contacts the company. They typically confirm removal from lists and update their opt-in records.
- Day 120: Case closed with a written summary sent to you.
FAQ
Is filing a complaint with the DPC free?
Yes. There is no fee to submit a complaint to the Data Protection Commission, and you do not need legal representation. The DPC is funded by the Irish state to handle complaints from members of the public.
How long does the DPC take to resolve a complaint?
Simple complaints — such as marketing opt-outs or ignored access requests — are often resolved amicably within 3 to 6 months. Complex cross-border inquiries against large tech companies can take several years, especially if they involve coordination with other EU authorities or judicial appeals.
Can I complain anonymously?
No. The DPC requires your identity so it can correspond with you, verify your standing, and share necessary details with the respondent organisation. Your information is treated confidentially, but the organisation being complained about will generally learn who filed.
Can I claim compensation through the DPC?
The DPC itself does not award financial compensation. If you want damages — including for distress caused by a breach — you must bring a civil action under Section 117 of the Data Protection Act 2018 in the Circuit Court or High Court. A DPC decision in your favour can strengthen such a case.
What if the company is based outside Ireland?
If the company has its EU main establishment in Ireland, the DPC has lead jurisdiction. If it is based in another EU member state, you can still file with the DPC and they will forward the case, or you can file directly with that country's supervisory authority. For non-EU companies targeting Irish residents, the DPC can generally still act under GDPR's territorial scope (Article 3).
Final Thoughts
Filing a privacy complaint with DPC Ireland is straightforward if you prepare properly: contact the organisation first, document everything, and use the online webform with clear evidence. Whether your issue is a nuisance marketing message or a serious data breach, the DPC provides a free, structured route to enforce your rights under the GDPR — and, thanks to Ireland's role as EU tech headquarters, its decisions often shape privacy standards across the entire continent.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
OAIC Complaints: How to Report a Privacy Breach in Australia
A step-by-step Australian guide to lodging a privacy complaint with the OAIC — including preparation, timelines, evidence, remedies and realistic outcomes. Learn exactly what to do when an organisation mishandles your personal information under the Privacy Act.
PIPEDA vs GDPR: Canadian Privacy Law Explained (2026 Guide)
PIPEDA and the GDPR both protect personal data, but they differ sharply on consent, individual rights, and penalties. This guide compares Canada's privacy law to Europe's GDPR and shows Canadian businesses exactly what compliance looks like in 2026.
Singapore PDPA: Your Personal Data Protection Rights Explained
Singapore's PDPA gives you clear rights over your personal data — from access and correction to data portability and breach notification. This guide explains each right, how to exercise it, and how to file a complaint with the PDPC in 2026.
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
A step-by-step guide to filing a privacy complaint with Ireland's Data Protection Commission (DPC), including what evidence to gather, how to submit, and what to expect at each stage. Learn timelines, appeal rights, and practical privacy tips for Irish residents.