DPC Ireland: How to File a Privacy Complaint (2026 Guide)
If a company has mishandled your personal data, ignored your access request, or refused to delete your information, you have the right to complain to Ireland's Data Protection Commission (DPC). As the lead supervisory authority for many of the world's largest tech firms — including Meta, Google, TikTok, LinkedIn, and Apple — the DPC handles some of the most significant privacy cases in Europe. This guide explains exactly how to file a privacy complaint with the DPC, what evidence you need, and what happens after you submit.
What Is the Data Protection Commission (DPC)?
The Data Protection Commission is Ireland's independent regulator responsible for enforcing the General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018. It investigates complaints, issues fines, and can order organisations to change how they handle personal data.
Because so many multinational technology companies have their European headquarters in Dublin, the DPC often acts as the "one-stop shop" regulator for cross-border cases affecting hundreds of millions of EU residents. This makes it one of the most influential data protection authorities in the world.
What the DPC Can Do
- Investigate any organisation processing personal data in Ireland
- Issue binding orders (e.g. to erase data, stop processing, or comply with a request)
- Impose administrative fines of up to €20 million or 4% of global annual turnover
- Refer cases to the Circuit Court or High Court
- Mediate between you and the organisation you're complaining about
What the DPC Cannot Do
- Award you personal compensation (that requires a civil court claim)
- Handle complaints outside the scope of data protection law (e.g. general consumer disputes)
- Prosecute individuals in most cases — it regulates organisations
When You Can File a Complaint With the DPC
You can lodge a complaint with the DPC whenever you believe an organisation has breached your data protection rights under GDPR or the Data Protection Act 2018. Common grounds include:
- Ignored subject access request: The organisation didn't respond within one month to your request for a copy of your data.
- Refused erasure (right to be forgotten): A company won't delete your data despite a valid request.
- Unlawful marketing: You keep receiving emails, texts, or calls after unsubscribing.
- Data breach: Your information was exposed and you weren't properly notified.
- Excessive data collection: A service is gathering more data than it needs.
- Cookie consent violations: A website drops tracking cookies before you consent.
- CCTV misuse: A neighbour, employer, or business is filming you inappropriately.
- Inaccurate data: An organisation refuses to correct wrong information about you.
Before You File: Contact the Organisation First
The DPC strongly encourages — and in practice usually requires — that you first raise the issue directly with the organisation before escalating. This is not just a formality; it's a legal step that gives you the paper trail you'll need.
Step 1: Find the Data Protection Officer (DPO)
Most medium and large organisations must appoint a DPO. Look for their contact details in the company's privacy policy, usually at the bottom of the website. If there's no dedicated DPO, email the address listed under "privacy" or "data protection".
Step 2: Send a Written Request
Always put your request in writing (email is fine). Be specific about:
- What right you are exercising (access, erasure, objection, etc.)
- The account, email address, or identifier the request relates to
- The date and a clear deadline (30 days under GDPR)
Step 3: Wait for a Response
The organisation has one calendar month to respond. They can extend this by two further months for complex requests, but they must tell you within the first month and explain why. If they miss the deadline or refuse without a valid reason, you're ready to escalate to the DPC.
How to File a Complaint With the DPC: Step-by-Step
The DPC offers three ways to submit a complaint. The online webform is the fastest and most efficient method.
Option 1: Online Webform (Recommended)
- Go to dataprotection.ie and click "Contact Us" then "Raise a Concern / Make a Complaint".
- Select the category that best matches your issue (e.g. access request, direct marketing, CCTV).
- Fill in your personal details — the DPC does not accept anonymous complaints.
- Describe the issue clearly and chronologically. Stick to the facts.
- Upload supporting evidence (see the checklist below).
- Submit and save the confirmation reference number.
Option 2: By Post
Send a signed letter with copies of your evidence to:
Data Protection Commission
21 Fitzwilliam Square South
Dublin 2
D02 RD28, Ireland
Never send original documents — only copies. Post is slower but is a valid route if you don't want to use the webform.
Option 3: Email
You can email info@dataprotection.ie with your complaint. Include all the same information you would put on the webform, and attach evidence as PDFs where possible.
Evidence Checklist
The strength of your complaint depends heavily on the evidence you provide. The DPC investigators are handling thousands of cases and appreciate well-organised submissions.
| Evidence Type | Why It Matters | Format |
|---|---|---|
| Copy of your original request to the organisation | Proves you tried to resolve the issue | Email export or PDF |
| Organisation's response (or lack of one) | Shows the breach or refusal | Email thread |
| Screenshots | Captures website behaviour, ads, or messages | PNG or PDF with timestamps |
| Privacy policy at the time | Shows what the company promised | PDF or archive.org link |
| Marketing emails received | Demonstrates unlawful contact | Full email with headers |
| Breach notification letter | Confirms exposure of your data | Original letter or email |
What Happens After You File
The DPC follows a defined process, though timelines vary depending on complexity and workload.
Stage 1: Acknowledgement (1-2 weeks)
You'll receive a case reference number and confirmation that your complaint has been logged. A case handler is usually assigned within a few weeks.
Stage 2: Assessment
The DPC decides whether your complaint falls within its remit. If it doesn't, they'll tell you and often signpost you to another body (for example, ComReg for telecoms issues).
Stage 3: Amicable Resolution
For many complaints, the DPC's first step is to contact the organisation and try to broker a resolution. This is often the quickest outcome — you might get your data, an apology, or removal from a marketing list within a few weeks.
Stage 4: Formal Inquiry
If amicable resolution fails, or if the issue is serious, the DPC can open a formal statutory inquiry. This is a full investigation that can result in binding decisions, corrective orders, and fines. Formal inquiries can take months or, for complex cross-border cases, years.
Stage 5: Decision and Appeal
You'll receive a written decision. If you disagree with the outcome, you have the right to appeal to the Circuit Court within 28 days.
Cross-Border Complaints and the One-Stop Shop
If your complaint concerns a company headquartered in another EU country, you can still file with the DPC as an Irish resident. The DPC will forward it to the lead supervisory authority. Conversely, because so many tech giants are based in Ireland, complaints from across the EU often end up with the DPC as the lead regulator.
This system, known as the "one-stop shop", is designed to give organisations a single point of contact but has been criticised for creating bottlenecks. Expect longer timelines on cross-border tech cases.
Tips to Strengthen Your Complaint
- Be concise and factual. A two-page summary beats a twenty-page rant. Investigators triage cases quickly.
- Use a timeline. Bullet-pointed dates make your story easy to follow.
- Cite the specific right. Mention the relevant GDPR article (e.g. Article 15 for access, Article 17 for erasure).
- Quantify harm where possible. Financial loss, identity theft risk, or distress all matter.
- Preserve everything. Don't delete emails or accounts while the complaint is live.
- Reduce your digital footprint going forward. Use privacy-respecting tools — for example, a link shortener like Lunyb that doesn't build a tracking profile on your clicks, or a privacy-focused browser and encrypted DNS resolver. See our honest Lunyb review for details.
Common Reasons Complaints Fail
Not every complaint results in action. Understanding why cases get dismissed can help you avoid the same pitfalls.
- No prior contact with the organisation. The DPC will usually redirect you to raise it with the company first.
- Insufficient evidence. "I think they have my data" isn't enough — you need proof.
- Out of scope. Consumer disputes, defamation, or workplace grievances that don't involve personal data may fall outside the DPC's remit.
- Time-barred issues. While GDPR doesn't set a strict limitation period, very old incidents are harder to investigate.
- Vexatious or repeat complaints. The DPC can decline complaints it considers abusive or already resolved.
Can You Claim Compensation?
The DPC itself cannot award you money. However, under Article 82 GDPR and Section 117 of the Data Protection Act 2018, you have the right to bring a civil claim in the Circuit Court for material or non-material damage caused by a breach of your rights. A successful DPC decision confirming a breach can strengthen such a claim significantly.
Frequently Asked Questions
How long does the DPC take to resolve a complaint?
Simple complaints resolved through amicable means can close in 4-12 weeks. Formal inquiries typically take 6-18 months, and complex cross-border cases against major tech companies can take several years.
Is filing a DPC complaint free?
Yes, filing a complaint with the Data Protection Commission is completely free. You do not need a solicitor, though you may choose to consult one for complex cases or if you intend to pursue civil damages afterwards.
Can I file a complaint anonymously?
No. The DPC requires your name and contact details to investigate. Your identity may need to be shared with the organisation being investigated so it can respond to the specific facts. However, the DPC will not publish your name.
What if the company is based outside the EU?
If the organisation offers goods or services to people in the EU or monitors their behaviour, GDPR still applies and the DPC can investigate. For companies with no EU presence at all, enforcement is harder, but the DPC can still refer matters to international counterparts.
Should I complain to the DPC or go straight to court?
For most people, the DPC route is cheaper, easier, and lower risk. A DPC finding in your favour can also strengthen a later civil claim for compensation. Court action is usually reserved for cases where you've suffered significant, quantifiable harm.
Final Thoughts
Filing a complaint with Ireland's Data Protection Commission is one of the most powerful tools EU residents have to hold organisations accountable for how they handle personal data. The process is free, well-defined, and — when you go in with clear evidence and a calm timeline — genuinely effective. Combine formal complaints with everyday privacy hygiene: minimise what you share, prefer services that don't monetise your data, and keep your own records. Your rights only work if you use them.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Singapore PDPA: Your Personal Data Protection Rights Explained
Singapore's PDPA gives you powerful rights over your personal data. Learn what those rights are, how to exercise them, and what penalties organisations face for breaches in this comprehensive 2026 guide.
PIPEDA vs GDPR: Canadian Privacy Law Explained (2026 Guide)
PIPEDA and GDPR both protect personal data, but they differ sharply in consent rules, individual rights, breach timelines, and penalties. This guide explains the key differences and shows Canadian businesses how to build a compliance program that satisfies both laws in 2026.
Singapore PDPA vs GDPR: Key Differences for Businesses in 2026
Singapore's PDPA and the EU's GDPR both protect personal data, but they differ significantly in consent, penalties, breach notification, and cross-border transfers. This guide breaks down the key differences so businesses can build a unified compliance strategy.
GDPR After Brexit: What Changed for UK Businesses and Data Protection
GDPR did not disappear after Brexit—it split into two parallel regimes. This guide explains how UK GDPR differs from EU GDPR, what adequacy decisions mean for data transfers, and the practical compliance steps every British business should take in 2026.