facebook-pixel

DPC Ireland: How to File a Privacy Complaint (2026 Guide)

L
Lunyb Security Team
··9 min read

If a company has mishandled your personal data, ignored a subject access request, or refused to delete your information, you have the right to complain to Ireland's Data Protection Commission (DPC). As the lead supervisory authority for many of the world's largest tech firms — including Meta, Google, TikTok and Apple — the Irish DPC plays an outsized role in enforcing the GDPR across the EU. This guide walks you through exactly how to file a privacy complaint with the DPC in 2026, what evidence to prepare, and how long the process typically takes.

What Is the Data Protection Commission (DPC)?

The Data Protection Commission is Ireland's independent national authority responsible for upholding the fundamental right of individuals in the EU to have their personal data protected. Established under the Data Protection Act 2018, the DPC enforces the General Data Protection Regulation (GDPR), the ePrivacy Regulations, and the Law Enforcement Directive within Ireland.

Because Ireland hosts the European headquarters of many global technology companies, the DPC often acts as the "lead supervisory authority" for cross-border complaints under the GDPR's one-stop-shop mechanism. This means a complaint filed in Dublin can result in enforcement action affecting users across the entire European Economic Area.

Key Facts About the DPC

  • Headquarters: 21 Fitzwilliam Square South, Dublin 2, D02 RD28
  • Current Commissioners: Dr Des Hogan and Dale Sunderland (Chairperson)
  • Website: dataprotection.ie
  • Phone: +353 (0)761 104 800 or 1800 437 737 (Lo-call)
  • Cost to complain: Free

When You Can File a Complaint With the DPC

You can lodge a complaint with the DPC any time you believe an organisation has infringed your data protection rights under the GDPR or Irish data protection law. The organisation does not have to be based in Ireland — if the DPC is the lead authority, it can handle complaints from anywhere in the EU.

Common Grounds for Complaint

  1. Unlawful processing — a company using your data without a valid legal basis (consent, contract, legitimate interest, etc.).
  2. Refusal of a Subject Access Request (SAR) — you asked for a copy of your data and were ignored or refused without proper justification.
  3. Refusal to erase data — the "right to be forgotten" was denied where it should apply.
  4. Data breaches — you were affected by a breach and believe the controller failed to protect your data or notify you appropriately.
  5. Direct marketing — you received unsolicited emails, SMS or calls after opting out.
  6. Excessive CCTV or workplace monitoring.
  7. Cookies and tracking — non-compliant consent banners on Irish websites.
  8. Inaccurate data — the controller refuses to correct wrong information about you.

Before You File: Contact the Organisation First

The DPC strongly encourages complainants to raise the issue directly with the organisation (the "data controller") before escalating. In many cases, this is the fastest route to resolution — and the DPC may ask what steps you took before it accepts your complaint.

Step 1: Identify the Data Protection Officer (DPO)

Most medium-to-large organisations must appoint a DPO under Article 37 GDPR. Their contact details are usually in the privacy policy, often at the footer of the website. Address your initial concern to them in writing.

Step 2: Send a Clear, Written Request

Keep it factual. Include:

  • Your full name and any account identifiers
  • What right you are exercising (access, erasure, objection, etc.)
  • The specific issue and dates
  • A reasonable deadline — the GDPR gives controllers one month to respond

Step 3: Keep Everything

Screenshots, email chains, postal receipts, chat transcripts and reference numbers all become evidence if you later escalate to the DPC.

How to File a Complaint With the DPC: Step by Step

Filing a complaint with the Irish DPC is free and can be done entirely online. Here is the current 2026 process.

Step 1: Gather Your Evidence

Before opening the form, collect:

  • Copies of correspondence with the controller
  • Proof of the original request (email timestamps, tracked post)
  • The controller's response — or evidence they did not respond
  • Screenshots showing the alleged infringement
  • Any relevant privacy policy sections

Step 2: Use the Official Webform or Email

Go to dataprotection.ie and select "Contact Us" > "Raise a Concern." You can:

  • Complete the online webform (recommended — generates a case reference automatically)
  • Email info@dataprotection.ie
  • Post a letter to 21 Fitzwilliam Square South, Dublin 2, D02 RD28

Step 3: Describe the Complaint Clearly

Structure your submission like this:

  1. Who you are — name, address, contact details.
  2. Who the controller is — full legal name and address if known.
  3. What happened — a chronological, factual summary.
  4. Which GDPR right is at issue — cite the article if you can (e.g. Article 15 for access, Article 17 for erasure).
  5. What you have already done — attach prior correspondence.
  6. What outcome you want — deletion, correction, compensation acknowledgment, etc.

Step 4: Submit and Save Your Reference Number

You will receive an acknowledgment, usually within a few working days, along with a case reference. Quote this number in all future correspondence.

What Happens After You File?

Once received, your complaint enters a defined workflow. Understanding the stages helps you set realistic expectations.

Stage 1: Assessment

The DPC reviews whether the complaint falls within its remit and is sufficiently substantiated. If it is a cross-border matter, it may be routed through the one-stop-shop with other EU regulators.

Stage 2: Amicable Resolution

Under Section 109 of the Data Protection Act 2018, the DPC attempts an amicable resolution first — essentially mediating between you and the controller. Many complaints close at this stage.

Stage 3: Formal Inquiry

If amicable resolution fails or the matter is serious (e.g. a major breach), the DPC opens a formal statutory inquiry. This can lead to reprimands, corrective orders, or administrative fines up to €20 million or 4% of global turnover.

Stage 4: Decision and Appeal

You receive a written decision. Either party can appeal to the Circuit Court (or the High Court for larger matters) within 28 days.

Timelines: How Long Does It Take?

StageTypical DurationNotes
Acknowledgment3–10 working daysAutomated for webform submissions
Initial assessment1–3 monthsDepends on complexity
Amicable resolution3–6 monthsMost straightforward cases resolve here
Formal inquiry12–36 monthsCross-border Big Tech cases can take longer
Appeal window28 days from decisionCircuit or High Court

Your Rights Under the GDPR — Quick Reference

Knowing which right you are relying on strengthens your complaint. Here is a quick summary of the eight core data subject rights.

RightGDPR ArticleWhat It Means
Information13 & 14Be told how your data is used
Access15Get a copy of your data
Rectification16Correct inaccurate data
Erasure17Have data deleted where applicable
Restriction18Limit how data is used
Portability20Receive data in a portable format
Object21Stop certain processing (e.g. marketing)
Automated decisions22Not be subject to solely automated decisions

Pros and Cons of Filing With the Irish DPC

Pros

  • Free of charge — no legal fees required to lodge a complaint.
  • Powerful jurisdiction — leads inquiries against Meta, Google, TikTok, Apple, Microsoft and LinkedIn.
  • EU-wide impact — decisions can affect all EU users.
  • Strong enforcement powers — fines exceeding €1.2 billion have been issued.
  • Multiple channels — webform, email, phone and post.

Cons

  • Slow for complex cases — cross-border inquiries can take years.
  • Backlog — the DPC handles a disproportionate share of EU-wide complaints.
  • No direct compensation — you must pursue damages separately in civil court.
  • Amicable resolution required first — extra step before formal action.

Practical Tips for a Strong Complaint

  1. Be concise and chronological. Investigators handle high volumes — a clear timeline helps them act faster.
  2. Cite the specific article of the GDPR you believe was breached.
  3. Attach evidence, do not just describe it.
  4. Redact irrelevant personal data of third parties from screenshots.
  5. Follow up politely at reasonable intervals (every 6–8 weeks).
  6. Keep a case diary of every interaction with the DPC and controller.

Reducing Your Data Exposure in the First Place

Complaints are a last resort. The best privacy strategy is minimising how much of your data reaches third parties. A few practical habits:

  • Use a private browser with tracker blocking (Brave, Firefox with strict mode, or LibreWolf).
  • Configure encrypted DNS (DoH or DoT) on your devices and router.
  • Prefer email aliasing services so a breach at one site does not expose your primary inbox.
  • Avoid unnecessary account creation — use guest checkout where possible.
  • When sharing links, consider a privacy-respecting shortener like Lunyb, which keeps analytics minimal and does not resell click data. You can read our honest review of Lunyb or browse the 2026 buyer's guide to URL shorteners if you want to compare options.

What the DPC Cannot Do

It is important to set expectations. The DPC:

  • Cannot award you financial compensation — that requires civil proceedings.
  • Cannot force a company to reinstate a closed account unless data protection law directly requires it.
  • Cannot handle complaints about journalism, artistic or literary expression where the relevant exemption applies.
  • Cannot investigate matters outside its jurisdiction — for example, purely UK-based controllers now fall under the ICO.

Frequently Asked Questions

How much does it cost to file a complaint with the DPC?

Nothing. Lodging a complaint with the Data Protection Commission is completely free, whether you use the webform, email or post. You only incur costs if you later choose to appeal a decision to the courts or pursue civil damages through a solicitor.

Can I file a complaint with the DPC if I do not live in Ireland?

Yes. Because Ireland is the lead supervisory authority for many multinational tech firms, EU and EEA residents regularly complain to the DPC directly. Alternatively, you can complain to your local data protection authority, and if the case is cross-border, it may be transferred to the DPC through the GDPR's one-stop-shop mechanism.

How long do I have to file a complaint?

The GDPR does not set a strict statutory time limit, but you should complain as soon as reasonably possible after becoming aware of the issue. Old complaints are harder to investigate because evidence and logs are often deleted after standard retention periods (typically 6–24 months).

Will the company find out I complained?

Yes. The DPC will normally share your complaint and identity with the controller, because they have a right to respond to the allegations. Anonymous complaints are generally not investigated in the same formal way, though you can still flag general concerns.

What if I am unhappy with the DPC's decision?

You have 28 days from the date of the decision to appeal to the Circuit Court, or the High Court for more significant matters. You can also make a complaint about the DPC's handling of your case to the Office of the Ombudsman if you believe there was maladministration.

Final Thoughts

The Irish DPC is one of the most influential data protection regulators in the world, and filing a complaint is genuinely accessible — no lawyer required. The key to success is preparation: exhaust the direct route with the controller first, gather clean evidence, cite the relevant GDPR article, and be patient with the process. Even when individual cases take time, DPC decisions have shaped how global platforms treat billions of users' data, so your complaint may have a wider impact than you realise.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles