facebook-pixel

DPC Ireland: How to File a Privacy Complaint (2026 Guide)

L
Lunyb Security Team
··9 min read

If a company has mishandled your personal data, ignored your access request, or refused to delete your information, you have the right to complain to Ireland's Data Protection Commission (DPC). As the lead supervisory authority for many of the world's largest tech firms — including Meta, Google, TikTok, LinkedIn, and Apple — the DPC handles some of the most significant privacy cases in Europe. This guide explains exactly how to file a privacy complaint with the DPC, what evidence you need, and what happens after you submit.

What Is the Data Protection Commission (DPC)?

The Data Protection Commission is Ireland's independent regulator responsible for enforcing the General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018. It investigates complaints, issues fines, and can order organisations to change how they handle personal data.

Because so many multinational technology companies have their European headquarters in Dublin, the DPC often acts as the "one-stop shop" regulator for cross-border cases affecting hundreds of millions of EU residents. This makes it one of the most influential data protection authorities in the world.

What the DPC Can Do

  • Investigate any organisation processing personal data in Ireland
  • Issue binding orders (e.g. to erase data, stop processing, or comply with a request)
  • Impose administrative fines of up to €20 million or 4% of global annual turnover
  • Refer cases to the Circuit Court or High Court
  • Mediate between you and the organisation you're complaining about

What the DPC Cannot Do

  • Award you personal compensation (that requires a civil court claim)
  • Handle complaints outside the scope of data protection law (e.g. general consumer disputes)
  • Prosecute individuals in most cases — it regulates organisations

When You Can File a Complaint With the DPC

You can lodge a complaint with the DPC whenever you believe an organisation has breached your data protection rights under GDPR or the Data Protection Act 2018. Common grounds include:

  1. Ignored subject access request: The organisation didn't respond within one month to your request for a copy of your data.
  2. Refused erasure (right to be forgotten): A company won't delete your data despite a valid request.
  3. Unlawful marketing: You keep receiving emails, texts, or calls after unsubscribing.
  4. Data breach: Your information was exposed and you weren't properly notified.
  5. Excessive data collection: A service is gathering more data than it needs.
  6. Cookie consent violations: A website drops tracking cookies before you consent.
  7. CCTV misuse: A neighbour, employer, or business is filming you inappropriately.
  8. Inaccurate data: An organisation refuses to correct wrong information about you.

Before You File: Contact the Organisation First

The DPC strongly encourages — and in practice usually requires — that you first raise the issue directly with the organisation before escalating. This is not just a formality; it's a legal step that gives you the paper trail you'll need.

Step 1: Find the Data Protection Officer (DPO)

Most medium and large organisations must appoint a DPO. Look for their contact details in the company's privacy policy, usually at the bottom of the website. If there's no dedicated DPO, email the address listed under "privacy" or "data protection".

Step 2: Send a Written Request

Always put your request in writing (email is fine). Be specific about:

  • What right you are exercising (access, erasure, objection, etc.)
  • The account, email address, or identifier the request relates to
  • The date and a clear deadline (30 days under GDPR)

Step 3: Wait for a Response

The organisation has one calendar month to respond. They can extend this by two further months for complex requests, but they must tell you within the first month and explain why. If they miss the deadline or refuse without a valid reason, you're ready to escalate to the DPC.

How to File a Complaint With the DPC: Step-by-Step

The DPC offers three ways to submit a complaint. The online webform is the fastest and most efficient method.

Option 1: Online Webform (Recommended)

  1. Go to dataprotection.ie and click "Contact Us" then "Raise a Concern / Make a Complaint".
  2. Select the category that best matches your issue (e.g. access request, direct marketing, CCTV).
  3. Fill in your personal details — the DPC does not accept anonymous complaints.
  4. Describe the issue clearly and chronologically. Stick to the facts.
  5. Upload supporting evidence (see the checklist below).
  6. Submit and save the confirmation reference number.

Option 2: By Post

Send a signed letter with copies of your evidence to:

Data Protection Commission
21 Fitzwilliam Square South
Dublin 2
D02 RD28, Ireland

Never send original documents — only copies. Post is slower but is a valid route if you don't want to use the webform.

Option 3: Email

You can email info@dataprotection.ie with your complaint. Include all the same information you would put on the webform, and attach evidence as PDFs where possible.

Evidence Checklist

The strength of your complaint depends heavily on the evidence you provide. The DPC investigators are handling thousands of cases and appreciate well-organised submissions.

Evidence TypeWhy It MattersFormat
Copy of your original request to the organisationProves you tried to resolve the issueEmail export or PDF
Organisation's response (or lack of one)Shows the breach or refusalEmail thread
ScreenshotsCaptures website behaviour, ads, or messagesPNG or PDF with timestamps
Privacy policy at the timeShows what the company promisedPDF or archive.org link
Marketing emails receivedDemonstrates unlawful contactFull email with headers
Breach notification letterConfirms exposure of your dataOriginal letter or email

What Happens After You File

The DPC follows a defined process, though timelines vary depending on complexity and workload.

Stage 1: Acknowledgement (1-2 weeks)

You'll receive a case reference number and confirmation that your complaint has been logged. A case handler is usually assigned within a few weeks.

Stage 2: Assessment

The DPC decides whether your complaint falls within its remit. If it doesn't, they'll tell you and often signpost you to another body (for example, ComReg for telecoms issues).

Stage 3: Amicable Resolution

For many complaints, the DPC's first step is to contact the organisation and try to broker a resolution. This is often the quickest outcome — you might get your data, an apology, or removal from a marketing list within a few weeks.

Stage 4: Formal Inquiry

If amicable resolution fails, or if the issue is serious, the DPC can open a formal statutory inquiry. This is a full investigation that can result in binding decisions, corrective orders, and fines. Formal inquiries can take months or, for complex cross-border cases, years.

Stage 5: Decision and Appeal

You'll receive a written decision. If you disagree with the outcome, you have the right to appeal to the Circuit Court within 28 days.

Cross-Border Complaints and the One-Stop Shop

If your complaint concerns a company headquartered in another EU country, you can still file with the DPC as an Irish resident. The DPC will forward it to the lead supervisory authority. Conversely, because so many tech giants are based in Ireland, complaints from across the EU often end up with the DPC as the lead regulator.

This system, known as the "one-stop shop", is designed to give organisations a single point of contact but has been criticised for creating bottlenecks. Expect longer timelines on cross-border tech cases.

Tips to Strengthen Your Complaint

  • Be concise and factual. A two-page summary beats a twenty-page rant. Investigators triage cases quickly.
  • Use a timeline. Bullet-pointed dates make your story easy to follow.
  • Cite the specific right. Mention the relevant GDPR article (e.g. Article 15 for access, Article 17 for erasure).
  • Quantify harm where possible. Financial loss, identity theft risk, or distress all matter.
  • Preserve everything. Don't delete emails or accounts while the complaint is live.
  • Reduce your digital footprint going forward. Use privacy-respecting tools — for example, a link shortener like Lunyb that doesn't build a tracking profile on your clicks, or a privacy-focused browser and encrypted DNS resolver. See our honest Lunyb review for details.

Common Reasons Complaints Fail

Not every complaint results in action. Understanding why cases get dismissed can help you avoid the same pitfalls.

  1. No prior contact with the organisation. The DPC will usually redirect you to raise it with the company first.
  2. Insufficient evidence. "I think they have my data" isn't enough — you need proof.
  3. Out of scope. Consumer disputes, defamation, or workplace grievances that don't involve personal data may fall outside the DPC's remit.
  4. Time-barred issues. While GDPR doesn't set a strict limitation period, very old incidents are harder to investigate.
  5. Vexatious or repeat complaints. The DPC can decline complaints it considers abusive or already resolved.

Can You Claim Compensation?

The DPC itself cannot award you money. However, under Article 82 GDPR and Section 117 of the Data Protection Act 2018, you have the right to bring a civil claim in the Circuit Court for material or non-material damage caused by a breach of your rights. A successful DPC decision confirming a breach can strengthen such a claim significantly.

Frequently Asked Questions

How long does the DPC take to resolve a complaint?

Simple complaints resolved through amicable means can close in 4-12 weeks. Formal inquiries typically take 6-18 months, and complex cross-border cases against major tech companies can take several years.

Is filing a DPC complaint free?

Yes, filing a complaint with the Data Protection Commission is completely free. You do not need a solicitor, though you may choose to consult one for complex cases or if you intend to pursue civil damages afterwards.

Can I file a complaint anonymously?

No. The DPC requires your name and contact details to investigate. Your identity may need to be shared with the organisation being investigated so it can respond to the specific facts. However, the DPC will not publish your name.

What if the company is based outside the EU?

If the organisation offers goods or services to people in the EU or monitors their behaviour, GDPR still applies and the DPC can investigate. For companies with no EU presence at all, enforcement is harder, but the DPC can still refer matters to international counterparts.

Should I complain to the DPC or go straight to court?

For most people, the DPC route is cheaper, easier, and lower risk. A DPC finding in your favour can also strengthen a later civil claim for compensation. Court action is usually reserved for cases where you've suffered significant, quantifiable harm.

Final Thoughts

Filing a complaint with Ireland's Data Protection Commission is one of the most powerful tools EU residents have to hold organisations accountable for how they handle personal data. The process is free, well-defined, and — when you go in with clear evidence and a calm timeline — genuinely effective. Combine formal complaints with everyday privacy hygiene: minimise what you share, prefer services that don't monetise your data, and keep your own records. Your rights only work if you use them.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles