DPC Ireland: How to File a Privacy Complaint (2026 Guide)
If a company has mishandled your personal data, ignored a subject access request, or refused to delete your information, you have the right to complain to Ireland's Data Protection Commission (DPC). As the lead supervisory authority for many of the world's largest tech firms — including Meta, Google, TikTok and Apple — the Irish DPC plays an outsized role in enforcing the GDPR across the EU. This guide walks you through exactly how to file a privacy complaint with the DPC in 2026, what evidence to prepare, and how long the process typically takes.
What Is the Data Protection Commission (DPC)?
The Data Protection Commission is Ireland's independent national authority responsible for upholding the fundamental right of individuals in the EU to have their personal data protected. Established under the Data Protection Act 2018, the DPC enforces the General Data Protection Regulation (GDPR), the ePrivacy Regulations, and the Law Enforcement Directive within Ireland.
Because Ireland hosts the European headquarters of many global technology companies, the DPC often acts as the "lead supervisory authority" for cross-border complaints under the GDPR's one-stop-shop mechanism. This means a complaint filed in Dublin can result in enforcement action affecting users across the entire European Economic Area.
Key Facts About the DPC
- Headquarters: 21 Fitzwilliam Square South, Dublin 2, D02 RD28
- Current Commissioners: Dr Des Hogan and Dale Sunderland (Chairperson)
- Website: dataprotection.ie
- Phone: +353 (0)761 104 800 or 1800 437 737 (Lo-call)
- Cost to complain: Free
When You Can File a Complaint With the DPC
You can lodge a complaint with the DPC any time you believe an organisation has infringed your data protection rights under the GDPR or Irish data protection law. The organisation does not have to be based in Ireland — if the DPC is the lead authority, it can handle complaints from anywhere in the EU.
Common Grounds for Complaint
- Unlawful processing — a company using your data without a valid legal basis (consent, contract, legitimate interest, etc.).
- Refusal of a Subject Access Request (SAR) — you asked for a copy of your data and were ignored or refused without proper justification.
- Refusal to erase data — the "right to be forgotten" was denied where it should apply.
- Data breaches — you were affected by a breach and believe the controller failed to protect your data or notify you appropriately.
- Direct marketing — you received unsolicited emails, SMS or calls after opting out.
- Excessive CCTV or workplace monitoring.
- Cookies and tracking — non-compliant consent banners on Irish websites.
- Inaccurate data — the controller refuses to correct wrong information about you.
Before You File: Contact the Organisation First
The DPC strongly encourages complainants to raise the issue directly with the organisation (the "data controller") before escalating. In many cases, this is the fastest route to resolution — and the DPC may ask what steps you took before it accepts your complaint.
Step 1: Identify the Data Protection Officer (DPO)
Most medium-to-large organisations must appoint a DPO under Article 37 GDPR. Their contact details are usually in the privacy policy, often at the footer of the website. Address your initial concern to them in writing.
Step 2: Send a Clear, Written Request
Keep it factual. Include:
- Your full name and any account identifiers
- What right you are exercising (access, erasure, objection, etc.)
- The specific issue and dates
- A reasonable deadline — the GDPR gives controllers one month to respond
Step 3: Keep Everything
Screenshots, email chains, postal receipts, chat transcripts and reference numbers all become evidence if you later escalate to the DPC.
How to File a Complaint With the DPC: Step by Step
Filing a complaint with the Irish DPC is free and can be done entirely online. Here is the current 2026 process.
Step 1: Gather Your Evidence
Before opening the form, collect:
- Copies of correspondence with the controller
- Proof of the original request (email timestamps, tracked post)
- The controller's response — or evidence they did not respond
- Screenshots showing the alleged infringement
- Any relevant privacy policy sections
Step 2: Use the Official Webform or Email
Go to dataprotection.ie and select "Contact Us" > "Raise a Concern." You can:
- Complete the online webform (recommended — generates a case reference automatically)
- Email info@dataprotection.ie
- Post a letter to 21 Fitzwilliam Square South, Dublin 2, D02 RD28
Step 3: Describe the Complaint Clearly
Structure your submission like this:
- Who you are — name, address, contact details.
- Who the controller is — full legal name and address if known.
- What happened — a chronological, factual summary.
- Which GDPR right is at issue — cite the article if you can (e.g. Article 15 for access, Article 17 for erasure).
- What you have already done — attach prior correspondence.
- What outcome you want — deletion, correction, compensation acknowledgment, etc.
Step 4: Submit and Save Your Reference Number
You will receive an acknowledgment, usually within a few working days, along with a case reference. Quote this number in all future correspondence.
What Happens After You File?
Once received, your complaint enters a defined workflow. Understanding the stages helps you set realistic expectations.
Stage 1: Assessment
The DPC reviews whether the complaint falls within its remit and is sufficiently substantiated. If it is a cross-border matter, it may be routed through the one-stop-shop with other EU regulators.
Stage 2: Amicable Resolution
Under Section 109 of the Data Protection Act 2018, the DPC attempts an amicable resolution first — essentially mediating between you and the controller. Many complaints close at this stage.
Stage 3: Formal Inquiry
If amicable resolution fails or the matter is serious (e.g. a major breach), the DPC opens a formal statutory inquiry. This can lead to reprimands, corrective orders, or administrative fines up to €20 million or 4% of global turnover.
Stage 4: Decision and Appeal
You receive a written decision. Either party can appeal to the Circuit Court (or the High Court for larger matters) within 28 days.
Timelines: How Long Does It Take?
| Stage | Typical Duration | Notes |
|---|---|---|
| Acknowledgment | 3–10 working days | Automated for webform submissions |
| Initial assessment | 1–3 months | Depends on complexity |
| Amicable resolution | 3–6 months | Most straightforward cases resolve here |
| Formal inquiry | 12–36 months | Cross-border Big Tech cases can take longer |
| Appeal window | 28 days from decision | Circuit or High Court |
Your Rights Under the GDPR — Quick Reference
Knowing which right you are relying on strengthens your complaint. Here is a quick summary of the eight core data subject rights.
| Right | GDPR Article | What It Means |
|---|---|---|
| Information | 13 & 14 | Be told how your data is used |
| Access | 15 | Get a copy of your data |
| Rectification | 16 | Correct inaccurate data |
| Erasure | 17 | Have data deleted where applicable |
| Restriction | 18 | Limit how data is used |
| Portability | 20 | Receive data in a portable format |
| Object | 21 | Stop certain processing (e.g. marketing) |
| Automated decisions | 22 | Not be subject to solely automated decisions |
Pros and Cons of Filing With the Irish DPC
Pros
- Free of charge — no legal fees required to lodge a complaint.
- Powerful jurisdiction — leads inquiries against Meta, Google, TikTok, Apple, Microsoft and LinkedIn.
- EU-wide impact — decisions can affect all EU users.
- Strong enforcement powers — fines exceeding €1.2 billion have been issued.
- Multiple channels — webform, email, phone and post.
Cons
- Slow for complex cases — cross-border inquiries can take years.
- Backlog — the DPC handles a disproportionate share of EU-wide complaints.
- No direct compensation — you must pursue damages separately in civil court.
- Amicable resolution required first — extra step before formal action.
Practical Tips for a Strong Complaint
- Be concise and chronological. Investigators handle high volumes — a clear timeline helps them act faster.
- Cite the specific article of the GDPR you believe was breached.
- Attach evidence, do not just describe it.
- Redact irrelevant personal data of third parties from screenshots.
- Follow up politely at reasonable intervals (every 6–8 weeks).
- Keep a case diary of every interaction with the DPC and controller.
Reducing Your Data Exposure in the First Place
Complaints are a last resort. The best privacy strategy is minimising how much of your data reaches third parties. A few practical habits:
- Use a private browser with tracker blocking (Brave, Firefox with strict mode, or LibreWolf).
- Configure encrypted DNS (DoH or DoT) on your devices and router.
- Prefer email aliasing services so a breach at one site does not expose your primary inbox.
- Avoid unnecessary account creation — use guest checkout where possible.
- When sharing links, consider a privacy-respecting shortener like Lunyb, which keeps analytics minimal and does not resell click data. You can read our honest review of Lunyb or browse the 2026 buyer's guide to URL shorteners if you want to compare options.
What the DPC Cannot Do
It is important to set expectations. The DPC:
- Cannot award you financial compensation — that requires civil proceedings.
- Cannot force a company to reinstate a closed account unless data protection law directly requires it.
- Cannot handle complaints about journalism, artistic or literary expression where the relevant exemption applies.
- Cannot investigate matters outside its jurisdiction — for example, purely UK-based controllers now fall under the ICO.
Frequently Asked Questions
How much does it cost to file a complaint with the DPC?
Nothing. Lodging a complaint with the Data Protection Commission is completely free, whether you use the webform, email or post. You only incur costs if you later choose to appeal a decision to the courts or pursue civil damages through a solicitor.
Can I file a complaint with the DPC if I do not live in Ireland?
Yes. Because Ireland is the lead supervisory authority for many multinational tech firms, EU and EEA residents regularly complain to the DPC directly. Alternatively, you can complain to your local data protection authority, and if the case is cross-border, it may be transferred to the DPC through the GDPR's one-stop-shop mechanism.
How long do I have to file a complaint?
The GDPR does not set a strict statutory time limit, but you should complain as soon as reasonably possible after becoming aware of the issue. Old complaints are harder to investigate because evidence and logs are often deleted after standard retention periods (typically 6–24 months).
Will the company find out I complained?
Yes. The DPC will normally share your complaint and identity with the controller, because they have a right to respond to the allegations. Anonymous complaints are generally not investigated in the same formal way, though you can still flag general concerns.
What if I am unhappy with the DPC's decision?
You have 28 days from the date of the decision to appeal to the Circuit Court, or the High Court for more significant matters. You can also make a complaint about the DPC's handling of your case to the Office of the Ombudsman if you believe there was maladministration.
Final Thoughts
The Irish DPC is one of the most influential data protection regulators in the world, and filing a complaint is genuinely accessible — no lawyer required. The key to success is preparation: exhaust the direct route with the controller first, gather clean evidence, cite the relevant GDPR article, and be patient with the process. Even when individual cases take time, DPC decisions have shaped how global platforms treat billions of users' data, so your complaint may have a wider impact than you realise.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
OAIC Complaints: How to Report a Privacy Breach in Australia
If an Australian organisation has mishandled your personal information, you have the right to complain to the OAIC. This step-by-step guide explains what qualifies as a privacy breach, how to gather evidence, and how the complaint process works from lodgement to determination.
Australian Data Breach Notification Scheme: Complete 2026 Guide
Australia's Notifiable Data Breaches scheme requires organisations to notify the OAIC and affected individuals when a breach is likely to cause serious harm. This guide covers obligations, timelines, penalties up to AUD $50 million, and how to build a compliant response plan.
UK Online Safety Act: What It Means for Your Privacy
The UK Online Safety Act reshapes how platforms moderate content, verify ages and handle private messages. Here's what it means for your privacy in 2026 — and the practical steps every UK user can take to protect their data.
Australia Privacy Act 2026: Your Rights Explained
The Australia Privacy Act 2026 introduces enforceable individual rights, a fair and reasonable test, and tough new penalties. Learn how the reforms affect you, how to exercise your rights, and what organisations must do to comply.