DPC Ireland: How to File a Privacy Complaint (2026 Guide)
If an organisation has mishandled your personal data, ignored a subject access request, or failed to respect your privacy rights, you can file a formal complaint with the Data Protection Commission (DPC) in Ireland. As Ireland's independent supervisory authority for GDPR, the DPC has the power to investigate, mediate, and issue binding decisions against controllers ranging from local businesses to the world's largest technology companies headquartered in Dublin.
This guide walks you through exactly how to prepare and submit a complaint, what happens after the DPC receives it, and how to strengthen your case with the right evidence.
What Is the Data Protection Commission (DPC)?
The Data Protection Commission is Ireland's national independent authority responsible for upholding the fundamental right of individuals to have their personal data protected. It enforces the General Data Protection Regulation (GDPR), the Data Protection Act 2018, and the ePrivacy Regulations.
Because many multinational technology companies — including Meta, Google, TikTok, Microsoft, and LinkedIn — have their EU headquarters in Ireland, the DPC often acts as the "lead supervisory authority" for cross-border cases affecting hundreds of millions of Europeans under the GDPR's one-stop-shop mechanism.
What the DPC Can Do
- Investigate suspected breaches of data protection law
- Order controllers to comply with your rights (e.g., release your data, delete it, or stop processing)
- Issue reprimands, warnings, and administrative fines up to €20 million or 4% of global turnover
- Mediate disputes between individuals and organisations
- Refer matters to court or the European Data Protection Board
When Should You File a Complaint With the DPC?
You should consider a formal complaint when an organisation has failed to respect your data protection rights and hasn't resolved the issue directly. Common reasons include:
- Ignored subject access request (SAR): The controller didn't respond within one month or provided incomplete data.
- Refusal to delete data: You exercised your right to erasure and were denied without valid legal grounds.
- Unlawful marketing: You continue to receive emails, SMS, or calls after opting out.
- Data breach: An organisation exposed your personal data or failed to notify you.
- Excessive data collection: A service demands data that isn't necessary for its purpose.
- Cookie violations: A website sets non-essential cookies without valid consent.
- CCTV and workplace monitoring: Disproportionate surveillance without transparency.
Try Direct Resolution First
The DPC strongly encourages you to raise the issue with the organisation's Data Protection Officer (DPO) or privacy team before escalating. This isn't strictly required by law, but a documented attempt at resolution accelerates the DPC's handling of your case and demonstrates good faith. Send your request in writing, keep copies, and give the organisation a reasonable timeframe (typically 30 days) to respond.
How to File a Privacy Complaint With the DPC Ireland: Step-by-Step
Filing a complaint is free and can be done entirely online, by post, or by email. Here is the process in order:
- Identify the controller. Determine the legal name and address of the organisation processing your data. Check their privacy policy for the Irish or EU entity.
- Attempt direct contact. Email the organisation's DPO with a clear description of the issue and the outcome you want. Wait for their response or for the statutory one-month deadline to pass.
- Gather evidence. Collect emails, screenshots, marketing messages, timestamps, and copies of any requests you made.
- Draft your complaint. Write a factual, chronological summary of what happened, which rights were violated, and what remedy you seek.
- Submit to the DPC. Use the official webform at dataprotection.ie, or send by email to info@dataprotection.ie, or post to 21 Fitzwilliam Square South, Dublin 2, D02 RD28.
- Receive acknowledgement. The DPC will confirm receipt, typically within a few working days, and assign a case reference number.
- Cooperate with the investigation. Respond promptly to any requests for clarification or additional evidence.
Information Your Complaint Must Include
- Your full name and contact details
- Name and contact details of the organisation
- A clear description of the alleged infringement
- The date(s) the issue occurred
- Copies of correspondence with the organisation
- Any supporting documentation (screenshots, emails, letters)
- The outcome you are seeking
DPC Complaint Channels Compared
The DPC accepts complaints through several channels. Choose the one that best matches your evidence format and preference.
| Channel | Best For | Response Speed | Attachment Limit |
|---|---|---|---|
| Online webform (dataprotection.ie) | Most individuals; guided fields | Fastest acknowledgement | Limited file sizes |
| Email (info@dataprotection.ie) | Complex cases with many attachments | 2–5 working days | Standard email limits (~25 MB) |
| Post (Fitzwilliam Square) | Individuals without digital access; sensitive originals | 1–2 weeks | No limit |
| Breach notification portal | Controllers reporting breaches (not individuals) | N/A | N/A |
What Happens After You File
Once the DPC receives your complaint, it moves through several defined stages. Understanding this pipeline helps you set realistic expectations.
1. Intake and Admissibility Review
A case handler reviews whether the complaint falls within the DPC's jurisdiction, whether you have standing, and whether enough information has been provided. If anything is missing, they'll contact you for clarification.
2. Amicable Resolution
For many complaints, the DPC first attempts an informal or amicable resolution — contacting the organisation, presenting your concerns, and negotiating a fix. This is often the fastest route and resolves the majority of cases within 2–4 months.
3. Statutory Inquiry
If amicable resolution fails, or the matter is serious, the DPC may open a formal statutory inquiry under Section 110 of the Data Protection Act 2018. This involves evidence-gathering, submissions from both sides, and a draft decision.
4. Decision and Enforcement
The DPC issues a binding decision that can include reprimands, corrective orders, bans on processing, and administrative fines. You'll receive a copy and can appeal to the Circuit Court within 28 days.
5. Cross-Border Cooperation
If your complaint involves a controller with establishments in multiple EU countries, the DPC coordinates with other supervisory authorities under the one-stop-shop mechanism. This can extend timelines but ensures a single, EU-wide decision.
How Long Does a DPC Complaint Take?
Timelines vary widely based on complexity. Straightforward complaints — such as ignored SARs or unlawful marketing — are often resolved in 2 to 6 months. Formal statutory inquiries against large tech companies can take 2 to 4 years, particularly when cross-border coordination is required. The DPC publishes annual reports that break down average handling times by case type.
Protecting Your Privacy Before You Need to Complain
The best privacy complaint is the one you never need to file. A few habits significantly reduce your exposure:
- Use privacy-focused browsers like Firefox or Brave with tracker blocking enabled.
- Enable encrypted DNS (DNS-over-HTTPS) in your browser or router to prevent network-level surveillance.
- Limit account creation — use guest checkout where possible, and email aliases for signups.
- Review app permissions monthly on iOS and Android.
- Shorten and control shared links using a privacy-respecting service. Tools like Lunyb let you share URLs without exposing your original address, reducing referrer leakage and enabling you to disable a link if it starts being abused. See our 2026 buyer's guide for a full comparison.
- Read privacy policies — at least the sections on data retention, third-party sharing, and international transfers.
- Exercise your rights routinely. Submit an SAR once a year to major services you use; it keeps organisations honest.
Writing a Strong Complaint: Tips From Case Handlers
DPC case handlers process thousands of complaints each year. The ones that move quickly share several characteristics:
- Be specific. "On 3 March 2026 I emailed dpo@example.com requesting erasure of my account. I received no reply within 30 days" is far stronger than "they ignored me."
- Cite the right. Reference the article of the GDPR you believe was breached (e.g., Article 15 for access, Article 17 for erasure, Article 21 for objection).
- Attach, don't describe. Provide the actual email or screenshot rather than paraphrasing.
- State the remedy. Do you want your data deleted? A marketing list removal? A written apology? Clarity helps the DPC frame its request.
- Stay factual. Emotional language weakens otherwise strong complaints. Let the facts do the work.
Alternatives and Escalation Options
The DPC is not your only route. Depending on the harm suffered, you can also:
- Take civil action in the Irish courts under Section 117 of the Data Protection Act 2018 for compensation, including for non-material damage such as distress.
- Contact ComReg for issues involving electronic communications and marketing.
- Report scams to An Garda Síochána if the misuse of your data constitutes a criminal offence.
- Complain to another EU authority if you reside in another Member State — they will coordinate with the DPC under the one-stop-shop mechanism.
Common Mistakes to Avoid
- Skipping the direct approach. The DPC will usually ask whether you've contacted the organisation first.
- Sending unrelated grievances. The DPC only handles data protection issues, not general consumer disputes.
- Missing deadlines. If the DPC asks for more information and you don't respond, the case can be closed.
- Expecting compensation. The DPC cannot award monetary damages — for that, you need the courts.
- Filing anonymously. Anonymous complaints are usually not admissible; the DPC needs to verify your identity and standing.
Frequently Asked Questions
Is it free to file a complaint with the DPC?
Yes. Filing a complaint with the Data Protection Commission is entirely free. There are no filing fees, and you do not need a solicitor, although you may choose to instruct one for complex matters.
Can I file a complaint against a company based outside Ireland?
Yes, if the company has its EU main establishment in Ireland or targets Irish residents. For companies established in other EU Member States, the DPC will forward your complaint or coordinate with the relevant lead supervisory authority under the GDPR's one-stop-shop mechanism.
How long do I have to file a complaint?
There is no strict statutory deadline, but the DPC recommends filing as soon as possible after the incident. Older complaints are harder to investigate because evidence and witnesses become less reliable, and organisations may have deleted relevant records in line with their retention schedules.
Will the organisation know I complained?
Yes. To investigate, the DPC must share your complaint (and often your identity) with the controller. If confidentiality is critical — for example in workplace situations — flag this in your submission and the DPC will consider what can be redacted, though full anonymity is rarely possible.
Can I appeal a DPC decision I disagree with?
Yes. You can appeal a DPC decision to the Circuit Court within 28 days of receiving it. For decisions of significant public interest or those involving large fines, cases may ultimately be referred to the High Court, Court of Appeal, or the Court of Justice of the European Union.
Final Thoughts
Filing a complaint with the DPC Ireland is one of the most powerful, and underused, rights every resident holds under the GDPR. The process is free, accessible, and — when supported by clear evidence — genuinely effective. Whether you're dealing with a persistent marketer, a silent DPO, or a serious data breach, the DPC exists to hold controllers accountable on your behalf.
Prepare your evidence, follow the steps above, and remember that every well-documented complaint contributes to a stronger data protection culture in Ireland and across the EU.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
OAIC Complaints: How to Report a Privacy Breach in Australia
A step-by-step Australian guide to lodging a privacy complaint with the OAIC — including preparation, timelines, evidence, remedies and realistic outcomes. Learn exactly what to do when an organisation mishandles your personal information under the Privacy Act.
PIPEDA vs GDPR: Canadian Privacy Law Explained (2026 Guide)
PIPEDA and the GDPR both protect personal data, but they differ sharply on consent, individual rights, and penalties. This guide compares Canada's privacy law to Europe's GDPR and shows Canadian businesses exactly what compliance looks like in 2026.
Singapore PDPA: Your Personal Data Protection Rights Explained
Singapore's PDPA gives you clear rights over your personal data — from access and correction to data portability and breach notification. This guide explains each right, how to exercise it, and how to file a complaint with the PDPC in 2026.
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
A step-by-step guide to filing a privacy complaint with Ireland's Data Protection Commission (DPC), including what evidence to gather, how to submit, and what to expect at each stage. Learn timelines, appeal rights, and practical privacy tips for Irish residents.