DPC Ireland: How to File a Privacy Complaint (Step-by-Step Guide)
If a company has mishandled your personal data, ignored your access request, or exposed your information in a breach, you have the right to complain to Ireland's Data Protection Commission (DPC). As the lead supervisory authority for many of the world's largest tech companies headquartered in Dublin, the DPC is one of the most influential privacy regulators in Europe — and it is remarkably accessible to ordinary members of the public.
This guide walks you through exactly how to file a complaint with the DPC, what evidence to gather, how long the process takes, and what outcomes you can realistically expect.
What Is the Data Protection Commission (DPC)?
The Data Protection Commission is Ireland's independent public authority responsible for upholding the fundamental right of individuals in the European Union to have their personal data protected. It enforces the General Data Protection Regulation (GDPR), the Irish Data Protection Act 2018, and the ePrivacy Regulations 2011.
Because companies such as Meta, Google, TikTok, X, LinkedIn, Microsoft, and Apple have their EU headquarters in Ireland, the DPC acts as the lead supervisory authority for cross-border complaints against them under the GDPR's "one-stop-shop" mechanism. That means a complaint filed in Dublin can affect users across the entire EU and EEA.
What the DPC Can Do
- Investigate complaints against organisations processing personal data
- Issue reprimands, warnings, and binding orders
- Impose administrative fines of up to €20 million or 4% of global annual turnover
- Order a company to stop processing your data or to erase it
- Refer criminal matters to the Director of Public Prosecutions
What the DPC Cannot Do
- Award you financial compensation (that must be pursued through the courts)
- Handle complaints about matters that fall outside data protection law
- Act as your legal representative
When Should You File a Complaint With the DPC?
You can file a complaint whenever you believe an organisation has breached your rights under the GDPR or Irish data protection law. Common grounds include:
- Unanswered Subject Access Request (SAR) — you asked for a copy of your data and the controller did not respond within one month.
- Refusal to delete data — you exercised your "right to be forgotten" but the organisation refused without valid justification.
- Unlawful marketing — you received unsolicited emails, SMS, or calls without consent.
- Data breach — your information was exposed and you were not notified or the response was inadequate.
- Excessive data collection — a service is collecting more data than it needs.
- Cookie violations — a website is dropping non-essential cookies without valid consent.
- CCTV and workplace surveillance — you are being recorded without a lawful basis.
The 'Complain to the Controller First' Rule
Before contacting the DPC, you are generally expected to raise the issue directly with the organisation (the "data controller"). Ask them in writing to fix the problem within one month. This step matters for two reasons: it often resolves matters quickly, and it creates a paper trail the DPC will ask to see.
Step-by-Step: How to File a Complaint With DPC Ireland
The complaint process is free, and you do not need a solicitor. Here is the full workflow.
Step 1: Gather Your Evidence
Before you write anything, collect everything relevant:
- Copies of any correspondence with the organisation
- Screenshots of the website, app, email, or notice in question
- Dates and times of the incidents
- Reference numbers from your original request
- The organisation's full legal name and registered address
- The name of their Data Protection Officer (DPO), if listed
Step 2: Contact the Organisation First
Send a written complaint (email is fine) to the organisation's DPO or privacy team. State clearly:
- What happened
- Which right under the GDPR you believe was breached (cite the article number if you can — for example, Article 15 for access, Article 17 for erasure)
- What you want them to do
- A deadline (one month is standard)
Step 3: Prepare Your DPC Complaint
If the organisation does not respond or their response is unsatisfactory, you can escalate to the DPC. The DPC accepts complaints through several channels:
- Online webform at dataprotection.ie (fastest and recommended)
- Email to info@dataprotection.ie
- Post to 21 Fitzwilliam Square South, Dublin 2, D02 RD28
Step 4: Complete the Complaint Form
The DPC's webform will ask for:
- Your full name, address, phone, and email
- Proof of identity (a scan of a passport or driving licence)
- The name and contact details of the organisation you are complaining about
- A clear description of the issue, in chronological order
- Copies of your prior correspondence with the organisation
- The outcome you are seeking
Be concise but complete. A one to two page summary supported by attached evidence is more effective than a ten-page narrative.
Step 5: Submit and Record Your Reference Number
Once submitted, you will receive an acknowledgement and a case reference number, usually within a few working days. Keep this number safe — you will need it for every future interaction.
Step 6: Cooperate With the DPC's Enquiries
A case officer will be assigned. They may:
- Ask you clarifying questions
- Attempt "amicable resolution" between you and the organisation
- Open a formal statutory inquiry if the matter is serious or unresolved
What to Expect: Timelines and Outcomes
The DPC handles thousands of complaints each year, and turnaround times vary widely depending on complexity.
| Complaint Type | Typical Timeline | Likely Outcome |
|---|---|---|
| Simple SAR non-response | 1–3 months | Amicable resolution; data provided |
| Marketing / ePrivacy | 3–6 months | Warning or fine to the controller |
| Cookie consent complaint | 6–12 months | Order to change consent mechanism |
| Cross-border tech complaint | 1–4+ years | Statutory inquiry, possible large fine |
| Data breach complaint | 3–9 months | Reprimand or corrective order |
Amicable Resolution
Most straightforward complaints are closed at this stage. The DPC contacts the organisation, and the organisation usually complies — providing the data, deleting the record, or fixing the process. You will be asked whether you accept the outcome.
Statutory Inquiry
If amicable resolution fails, or if the issue is systemic, the DPC can open a formal inquiry. This can lead to a binding decision, corrective orders, and administrative fines. Recent inquiries have produced fines exceeding €1 billion against major platforms.
Your Rights Under the GDPR — A Quick Reference
Knowing which right applies makes your complaint far stronger.
| GDPR Article | Right | What It Means |
|---|---|---|
| Article 13/14 | Right to be informed | Organisations must tell you how they use your data |
| Article 15 | Right of access | Get a copy of your personal data |
| Article 16 | Right to rectification | Correct inaccurate data |
| Article 17 | Right to erasure | Have your data deleted |
| Article 18 | Right to restriction | Limit how data is processed |
| Article 20 | Right to portability | Receive your data in a portable format |
| Article 21 | Right to object | Stop processing (especially marketing) |
| Article 22 | Automated decisions | Not be subject to solely automated decisions |
Tips for a Strong Complaint
Do
- Stick to the facts, in chronological order
- Cite the specific GDPR article you believe was breached
- Attach all supporting documents as PDFs
- Redact other people's personal data from screenshots
- State clearly the outcome you want (deletion, access, apology, systemic change)
Don't
- Send emotional or accusatory language — it weakens your case
- Submit dozens of unrelated grievances in a single complaint
- Expect compensation from the DPC — that requires a civil action
- Assume the process will be quick, especially for cross-border cases
Reducing Your Data Exposure in the First Place
Filing a complaint is a powerful remedy, but preventing unnecessary data collection is even better. A few practical habits go a long way:
- Use a private, tracker-blocking browser and switch on encrypted DNS
- Provide only the minimum data required to sign up for any service
- Use email aliases so you can burn a compromised address without losing your identity
- Shorten and control the links you share so you can revoke them later — services like Lunyb let you generate privacy-respecting short links you can disable at any time, which is useful if you don't want a raw URL (and any tracking parameters attached to it) sitting in someone's inbox forever
- Regularly review the privacy dashboards of the major platforms you use
If you're evaluating link tools with data protection in mind, our 2026 buyer's guide to URL shorteners and our honest review of Lunyb both cover data handling and retention in detail.
What Happens If You Are Unhappy With the DPC's Decision?
If your complaint results in a decision you disagree with, you have options:
- Appeal to the Circuit Court — you can appeal a legally binding decision within 28 days.
- Judicial review — challenge the process the DPC followed.
- Civil claim — sue the controller directly for material or non-material damage under Article 82 of the GDPR.
- European Data Protection Board (EDPB) — in cross-border cases, other EU authorities can trigger the EDPB dispute resolution mechanism.
Frequently Asked Questions
Is there a fee to file a complaint with the DPC?
No. Filing a complaint with the Data Protection Commission is entirely free, and you do not need to hire a solicitor. If you later choose to pursue compensation through the courts, legal costs may apply.
Can I file a DPC complaint if I don't live in Ireland?
Yes. Because many major tech companies have their EU headquarters in Ireland, the DPC handles cross-border complaints from anywhere in the EU or EEA. However, you can also file with your local data protection authority, which may then forward the case to the DPC under the one-stop-shop mechanism.
How long does the DPC take to resolve a complaint?
Simple matters such as ignored access requests are often resolved amicably within one to three months. Complex statutory inquiries against large platforms can take multiple years, especially when they involve cross-border consultation with other EU regulators.
Can the DPC award me compensation?
No. The DPC's role is regulatory — it can reprimand, order corrective action, and impose fines payable to the state. To claim compensation for damage suffered, you must bring a civil claim in the Irish courts under Article 82 GDPR and Section 117 of the Data Protection Act 2018.
Will the organisation know I complained about them?
Yes. The DPC will normally share the substance of your complaint and your identity with the organisation, because they need an opportunity to respond. If you have serious concerns about retaliation — for example, in an employment context — raise this with the case officer, but full anonymity is generally not possible.
What if the organisation is based outside the EU?
If the organisation offers goods or services to people in the EU, the GDPR still applies, and the DPC can investigate. Enforcement against non-EU entities can be more difficult in practice, but many global companies comply voluntarily to protect their EU market access.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
GDPR After Brexit: What Changed for UK Businesses and Data Protection
GDPR did not disappear after Brexit—it split into two parallel regimes. This guide explains how UK GDPR differs from EU GDPR, what adequacy decisions mean for data transfers, and the practical compliance steps every British business should take in 2026.
Data Protection Act 2018 Ireland: Complete Guide
Ireland's Data Protection Act 2018 gives effect to the GDPR under Irish law and empowers the Data Protection Commission to enforce it. This complete guide covers scope, individual rights, penalties, breach notification, and a step-by-step compliance roadmap for Irish organisations.
OAIC Complaints: How to Report a Privacy Breach in Australia
If an Australian organisation has mishandled your personal information, you have the right to complain to the OAIC. This step-by-step guide explains what qualifies as a privacy breach, how to gather evidence, and how the complaint process works from lodgement to determination.
Australian Data Breach Notification Scheme: Complete 2026 Guide
Australia's Notifiable Data Breaches scheme requires organisations to notify the OAIC and affected individuals when a breach is likely to cause serious harm. This guide covers obligations, timelines, penalties up to AUD $50 million, and how to build a compliant response plan.