DPC Ireland: How to File a Privacy Complaint (2026 Guide)
If a company has mishandled your personal data, ignored a subject access request, or refused to delete your information, you have the right to complain to the Data Protection Commission (DPC) of Ireland. As the lead supervisory authority for many of the world's largest tech firms — including Meta, Google, TikTok, LinkedIn and Microsoft — the DPC handles some of the most consequential privacy cases in Europe. This guide walks you through exactly how to file a complaint, what happens next, and how to maximise your chances of a successful outcome.
What Is the Data Protection Commission (DPC)?
The Data Protection Commission is Ireland's independent regulator responsible for enforcing the General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018. Based in Dublin, the DPC investigates complaints, conducts audits, issues fines and provides guidance to both individuals and organisations on data protection matters.
Because so many multinational technology companies have their European headquarters in Ireland, the DPC often acts as the "lead supervisory authority" for cross-border cases affecting EU residents. This means a complaint filed in Dublin can result in enforcement action that ripples across the entire European Union.
Who Can File a Complaint?
Any individual (a "data subject") whose personal data has been processed unlawfully can file a complaint. You do not need to be an Irish resident — if the company you are complaining about is headquartered in Ireland, the DPC can accept complaints from anywhere in the EU/EEA and, in many cases, globally.
When Should You File a DPC Complaint?
You should consider filing a complaint with the DPC when a company has breached one of your rights under the GDPR. Common grounds include:
- Ignored subject access requests (SARs) — the company failed to provide your personal data within one month.
- Refusal to delete data — the controller ignored a valid "right to be forgotten" request.
- Unlawful marketing — you received emails, SMS or calls without valid consent.
- Data breaches — your data was leaked and the company failed to notify you appropriately.
- Excessive data collection — a service collects more information than necessary for its stated purpose.
- Unclear or misleading privacy policies — the controller cannot explain the legal basis for processing.
- International transfers — data was sent outside the EEA without adequate safeguards.
Try to Resolve Directly First
The DPC strongly encourages complainants to contact the organisation's Data Protection Officer (DPO) before escalating. Not only is this often faster, it also strengthens your case: showing that you attempted resolution and were ignored or refused makes DPC intervention more likely.
Step-by-Step: How to File a Complaint With DPC Ireland
Filing a complaint is free and can be done entirely online. Here is the full process:
- Gather your evidence. Collect emails, screenshots, dates, reference numbers and any correspondence with the organisation. The stronger your paper trail, the faster the DPC can act.
- Contact the organisation's DPO. Send a written request (email is fine) clearly stating what you want — access, deletion, correction, or an explanation. Give them the statutory one-month window to respond.
- Wait for a response — or the deadline to pass. If they refuse, respond inadequately, or ignore you entirely, you now have grounds to escalate.
- Visit the DPC website. Go to dataprotection.ie and navigate to the "Contact / Raise a Concern" section.
- Complete the online complaint form. You'll need to provide your name, contact details, the organisation you are complaining about, and a clear description of the issue.
- Attach supporting documents. Upload your evidence — the previous correspondence with the DPO is critical here.
- Submit and note your reference number. You'll receive an acknowledgement, usually within a few working days.
- Cooperate with the case handler. The DPC may ask for clarifications or additional evidence during the investigation.
Alternative Ways to Complain
If you can't or don't want to use the online form, you can also:
- Email: info@dataprotection.ie
- Post: Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
- Phone: +353 (0)761 104 800 for guidance (formal complaints must be in writing)
What Information You Need to Include
A well-prepared complaint dramatically speeds up the investigation. The DPC expects the following essentials:
| Category | Details Required |
|---|---|
| Your identity | Full name, postal address, email and phone number |
| The organisation | Legal name, address, website and DPO contact if known |
| Nature of the complaint | Clear summary of what happened and which GDPR right was breached |
| Timeline | Dates of key events, including when you first contacted the organisation |
| Evidence | Emails, screenshots, receipts, marketing messages, contracts |
| Prior contact | Copies of your SAR/erasure request and the organisation's response (or lack thereof) |
| Desired outcome | What you want the DPC to do — investigate, order deletion, impose a fine, etc. |
What Happens After You File?
The DPC's handling of complaints follows a broadly consistent workflow, though timelines vary significantly depending on complexity.
1. Acknowledgement and Triage
You'll typically receive an acknowledgement within 5–10 working days. A case officer reviews whether the DPC has jurisdiction and whether the complaint is well-founded.
2. Amicable Resolution Attempt
For many complaints, the DPC first tries to broker an amicable resolution — contacting the organisation on your behalf and giving them a chance to fix the issue. Around 70% of complaints are resolved at this stage.
3. Formal Investigation
If amicable resolution fails, the DPC can open a statutory inquiry. This involves compelling document production, interviewing staff, and producing a draft decision. Cross-border cases go through the EU "one-stop-shop" mechanism, involving other supervisory authorities.
4. Decision and Enforcement
Possible outcomes include a reprimand, a compliance order, a temporary or permanent ban on processing, and administrative fines up to €20 million or 4% of global annual turnover — whichever is higher.
How Long Does It Take?
| Complaint Type | Typical Timeline |
|---|---|
| Simple domestic issue (e.g. marketing) | 1–3 months |
| Subject access disputes | 3–6 months |
| Cross-border tech company inquiries | 1–3+ years |
| Data breach investigations | 6 months – 2 years |
Your Rights Under GDPR
Before filing, it's worth understanding exactly which rights you can enforce. The GDPR gives every EU resident eight core rights:
- Right to be informed — clear disclosure of how your data is used.
- Right of access — receive a copy of your personal data within one month.
- Right to rectification — correct inaccurate information.
- Right to erasure — have data deleted in certain circumstances.
- Right to restrict processing — pause processing while a dispute is resolved.
- Right to data portability — receive your data in a machine-readable format.
- Right to object — especially to direct marketing and profiling.
- Rights around automated decision-making — including profiling that produces legal effects.
Common Mistakes That Weaken Complaints
Case officers at the DPC see the same avoidable errors repeatedly. Steer clear of these to give your complaint the best chance:
- Skipping the DPO step. The DPC will often close a complaint if you haven't first given the controller a chance to respond.
- Vague descriptions. "They misused my data" isn't enough. Be specific: what data, when, how, and which right was breached?
- Missing evidence. Screenshots and full email headers matter. "They said…" without proof is difficult to act on.
- Filing against the wrong entity. The controller is who decides why and how data is processed — not always the customer-facing brand.
- Emotional language. Keep it factual. Regulators respond to evidence, not frustration.
- Waiting too long. Complaints made years after the incident are much harder to investigate.
Protecting Your Privacy Going Forward
Filing a complaint is a reactive step — but you can also reduce future exposure with better privacy hygiene. Use encrypted DNS resolvers, privacy-focused browsers such as Brave or Firefox with strict tracking protection, disposable email aliases for signups, and unique passwords stored in a reputable manager. When sharing links publicly — for example on social media or in support tickets — use a privacy-respecting URL shortener like Lunyb that doesn't harvest click data for advertising. For a wider comparison of link tools, see our 2026 buyer's guide to the best URL shorteners or our detailed honest review of Lunyb.
What If You Disagree With the DPC's Decision?
If you're unhappy with the outcome, you have several options:
- Appeal to the Circuit Court or High Court. Under Section 150 of the Data Protection Act 2018, you can appeal a DPC decision within 28 days.
- Judicial review. Challenge the process rather than the substance if you believe the DPC acted unlawfully.
- Claim compensation. Under Article 82 GDPR, you can sue the controller in the Irish courts for material or non-material damage.
- Contact the European Data Protection Board (EDPB). For cross-border cases, the EDPB can review the DPC's handling.
Frequently Asked Questions
Is there a fee to file a complaint with the DPC?
No. Filing a complaint with the Data Protection Commission is completely free. There are also no filing fees for appeals to the Circuit Court, although you may incur legal costs if you choose to be represented.
Can I file a complaint anonymously?
No — the DPC requires your identity so it can communicate with you and verify your standing as a data subject. However, your identity is treated confidentially and is not shared with the organisation without your consent, except where strictly necessary for the investigation.
How long do I have to file a complaint?
The GDPR does not set a strict deadline, but the DPC generally expects complaints to be filed within a reasonable time — typically within 12 months of the incident. Older complaints can still be accepted but may be harder to investigate due to lost records.
Can I complain about a company based outside Ireland?
Yes, if the company has an EU establishment in Ireland, or if it targets Irish/EU residents. For companies based in other EU countries, you can file with your local supervisory authority, which will coordinate with the relevant lead authority under the one-stop-shop mechanism.
Will the company know I filed the complaint?
In most cases, yes — the DPC will need to disclose your identity to properly investigate. If you have serious concerns about retaliation (for example, in an employment context), tell the case officer at the outset so they can consider protective measures.
Final Thoughts
The DPC is one of the most influential data protection regulators in the world, and its complaint process is designed to be accessible to ordinary individuals. Prepare your evidence carefully, follow the correct steps — starting with the organisation's DPO — and be patient with the timeline. Whether your issue is a stubborn marketing email or a systemic failure by a global tech giant, a well-documented complaint is one of the strongest tools you have to enforce your privacy rights under GDPR.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
ICO Fines 2026: Biggest Data Protection Penalties in the UK
The ICO issued record data protection penalties in 2026, with fines topping £6 million for ransomware failures and multi-million pound sanctions for marketing abuses. This guide examines the biggest UK fines of the year and the compliance lessons every organisation must learn.
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
Learn how to file a privacy complaint with Ireland's Data Protection Commission (DPC). This step-by-step guide covers evidence gathering, submission channels, timelines, and what happens after you complain under GDPR.
Data Protection Act 2018 Ireland: Complete Guide
A complete guide to Ireland's Data Protection Act 2018, covering its relationship with the GDPR, individual rights, business obligations, DPC enforcement powers, and penalties. Learn what your organisation needs to do to stay compliant.
Singapore PDPA vs GDPR: Key Differences for Businesses in 2026
Singapore's PDPA and the EU's GDPR both protect personal data but differ significantly in scope, consent standards, penalties, and rights. This guide compares the two frameworks side-by-side so businesses can build a compliance strategy that works across borders.