facebook-pixel

DPC Ireland: How to File a Privacy Complaint (Step-by-Step Guide)

L
Lunyb Security Team
··9 min read

If a company has mishandled your personal data, ignored your access request, or exposed your information in a breach, you have the right to complain to Ireland's Data Protection Commission (DPC). As the lead supervisory authority for many of the world's largest tech companies headquartered in Dublin, the DPC is one of the most influential privacy regulators in Europe — and it is remarkably accessible to ordinary members of the public.

This guide walks you through exactly how to file a complaint with the DPC, what evidence to gather, how long the process takes, and what outcomes you can realistically expect.

What Is the Data Protection Commission (DPC)?

The Data Protection Commission is Ireland's independent public authority responsible for upholding the fundamental right of individuals in the European Union to have their personal data protected. It enforces the General Data Protection Regulation (GDPR), the Irish Data Protection Act 2018, and the ePrivacy Regulations 2011.

Because companies such as Meta, Google, TikTok, X, LinkedIn, Microsoft, and Apple have their EU headquarters in Ireland, the DPC acts as the lead supervisory authority for cross-border complaints against them under the GDPR's "one-stop-shop" mechanism. That means a complaint filed in Dublin can affect users across the entire EU and EEA.

What the DPC Can Do

  • Investigate complaints against organisations processing personal data
  • Issue reprimands, warnings, and binding orders
  • Impose administrative fines of up to €20 million or 4% of global annual turnover
  • Order a company to stop processing your data or to erase it
  • Refer criminal matters to the Director of Public Prosecutions

What the DPC Cannot Do

  • Award you financial compensation (that must be pursued through the courts)
  • Handle complaints about matters that fall outside data protection law
  • Act as your legal representative

When Should You File a Complaint With the DPC?

You can file a complaint whenever you believe an organisation has breached your rights under the GDPR or Irish data protection law. Common grounds include:

  1. Unanswered Subject Access Request (SAR) — you asked for a copy of your data and the controller did not respond within one month.
  2. Refusal to delete data — you exercised your "right to be forgotten" but the organisation refused without valid justification.
  3. Unlawful marketing — you received unsolicited emails, SMS, or calls without consent.
  4. Data breach — your information was exposed and you were not notified or the response was inadequate.
  5. Excessive data collection — a service is collecting more data than it needs.
  6. Cookie violations — a website is dropping non-essential cookies without valid consent.
  7. CCTV and workplace surveillance — you are being recorded without a lawful basis.

The 'Complain to the Controller First' Rule

Before contacting the DPC, you are generally expected to raise the issue directly with the organisation (the "data controller"). Ask them in writing to fix the problem within one month. This step matters for two reasons: it often resolves matters quickly, and it creates a paper trail the DPC will ask to see.

Step-by-Step: How to File a Complaint With DPC Ireland

The complaint process is free, and you do not need a solicitor. Here is the full workflow.

Step 1: Gather Your Evidence

Before you write anything, collect everything relevant:

  • Copies of any correspondence with the organisation
  • Screenshots of the website, app, email, or notice in question
  • Dates and times of the incidents
  • Reference numbers from your original request
  • The organisation's full legal name and registered address
  • The name of their Data Protection Officer (DPO), if listed

Step 2: Contact the Organisation First

Send a written complaint (email is fine) to the organisation's DPO or privacy team. State clearly:

  1. What happened
  2. Which right under the GDPR you believe was breached (cite the article number if you can — for example, Article 15 for access, Article 17 for erasure)
  3. What you want them to do
  4. A deadline (one month is standard)

Step 3: Prepare Your DPC Complaint

If the organisation does not respond or their response is unsatisfactory, you can escalate to the DPC. The DPC accepts complaints through several channels:

  • Online webform at dataprotection.ie (fastest and recommended)
  • Email to info@dataprotection.ie
  • Post to 21 Fitzwilliam Square South, Dublin 2, D02 RD28

Step 4: Complete the Complaint Form

The DPC's webform will ask for:

  • Your full name, address, phone, and email
  • Proof of identity (a scan of a passport or driving licence)
  • The name and contact details of the organisation you are complaining about
  • A clear description of the issue, in chronological order
  • Copies of your prior correspondence with the organisation
  • The outcome you are seeking

Be concise but complete. A one to two page summary supported by attached evidence is more effective than a ten-page narrative.

Step 5: Submit and Record Your Reference Number

Once submitted, you will receive an acknowledgement and a case reference number, usually within a few working days. Keep this number safe — you will need it for every future interaction.

Step 6: Cooperate With the DPC's Enquiries

A case officer will be assigned. They may:

  • Ask you clarifying questions
  • Attempt "amicable resolution" between you and the organisation
  • Open a formal statutory inquiry if the matter is serious or unresolved

What to Expect: Timelines and Outcomes

The DPC handles thousands of complaints each year, and turnaround times vary widely depending on complexity.

Complaint TypeTypical TimelineLikely Outcome
Simple SAR non-response1–3 monthsAmicable resolution; data provided
Marketing / ePrivacy3–6 monthsWarning or fine to the controller
Cookie consent complaint6–12 monthsOrder to change consent mechanism
Cross-border tech complaint1–4+ yearsStatutory inquiry, possible large fine
Data breach complaint3–9 monthsReprimand or corrective order

Amicable Resolution

Most straightforward complaints are closed at this stage. The DPC contacts the organisation, and the organisation usually complies — providing the data, deleting the record, or fixing the process. You will be asked whether you accept the outcome.

Statutory Inquiry

If amicable resolution fails, or if the issue is systemic, the DPC can open a formal inquiry. This can lead to a binding decision, corrective orders, and administrative fines. Recent inquiries have produced fines exceeding €1 billion against major platforms.

Your Rights Under the GDPR — A Quick Reference

Knowing which right applies makes your complaint far stronger.

GDPR ArticleRightWhat It Means
Article 13/14Right to be informedOrganisations must tell you how they use your data
Article 15Right of accessGet a copy of your personal data
Article 16Right to rectificationCorrect inaccurate data
Article 17Right to erasureHave your data deleted
Article 18Right to restrictionLimit how data is processed
Article 20Right to portabilityReceive your data in a portable format
Article 21Right to objectStop processing (especially marketing)
Article 22Automated decisionsNot be subject to solely automated decisions

Tips for a Strong Complaint

Do

  • Stick to the facts, in chronological order
  • Cite the specific GDPR article you believe was breached
  • Attach all supporting documents as PDFs
  • Redact other people's personal data from screenshots
  • State clearly the outcome you want (deletion, access, apology, systemic change)

Don't

  • Send emotional or accusatory language — it weakens your case
  • Submit dozens of unrelated grievances in a single complaint
  • Expect compensation from the DPC — that requires a civil action
  • Assume the process will be quick, especially for cross-border cases

Reducing Your Data Exposure in the First Place

Filing a complaint is a powerful remedy, but preventing unnecessary data collection is even better. A few practical habits go a long way:

  • Use a private, tracker-blocking browser and switch on encrypted DNS
  • Provide only the minimum data required to sign up for any service
  • Use email aliases so you can burn a compromised address without losing your identity
  • Shorten and control the links you share so you can revoke them later — services like Lunyb let you generate privacy-respecting short links you can disable at any time, which is useful if you don't want a raw URL (and any tracking parameters attached to it) sitting in someone's inbox forever
  • Regularly review the privacy dashboards of the major platforms you use

If you're evaluating link tools with data protection in mind, our 2026 buyer's guide to URL shorteners and our honest review of Lunyb both cover data handling and retention in detail.

What Happens If You Are Unhappy With the DPC's Decision?

If your complaint results in a decision you disagree with, you have options:

  1. Appeal to the Circuit Court — you can appeal a legally binding decision within 28 days.
  2. Judicial review — challenge the process the DPC followed.
  3. Civil claim — sue the controller directly for material or non-material damage under Article 82 of the GDPR.
  4. European Data Protection Board (EDPB) — in cross-border cases, other EU authorities can trigger the EDPB dispute resolution mechanism.

Frequently Asked Questions

Is there a fee to file a complaint with the DPC?

No. Filing a complaint with the Data Protection Commission is entirely free, and you do not need to hire a solicitor. If you later choose to pursue compensation through the courts, legal costs may apply.

Can I file a DPC complaint if I don't live in Ireland?

Yes. Because many major tech companies have their EU headquarters in Ireland, the DPC handles cross-border complaints from anywhere in the EU or EEA. However, you can also file with your local data protection authority, which may then forward the case to the DPC under the one-stop-shop mechanism.

How long does the DPC take to resolve a complaint?

Simple matters such as ignored access requests are often resolved amicably within one to three months. Complex statutory inquiries against large platforms can take multiple years, especially when they involve cross-border consultation with other EU regulators.

Can the DPC award me compensation?

No. The DPC's role is regulatory — it can reprimand, order corrective action, and impose fines payable to the state. To claim compensation for damage suffered, you must bring a civil claim in the Irish courts under Article 82 GDPR and Section 117 of the Data Protection Act 2018.

Will the organisation know I complained about them?

Yes. The DPC will normally share the substance of your complaint and your identity with the organisation, because they need an opportunity to respond. If you have serious concerns about retaliation — for example, in an employment context — raise this with the case officer, but full anonymity is generally not possible.

What if the organisation is based outside the EU?

If the organisation offers goods or services to people in the EU, the GDPR still applies, and the DPC can investigate. Enforcement against non-EU entities can be more difficult in practice, but many global companies comply voluntarily to protect their EU market access.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles