facebook-pixel

DPC Ireland: How to File a Privacy Complaint (2026 Guide)

L
Lunyb Security Team
··9 min read

If a company has mishandled your personal data, ignored a subject access request, or refused to delete your information, you have the right to complain to the Data Protection Commission (DPC) of Ireland. As the lead supervisory authority for many of the world's largest tech firms — including Meta, Google, TikTok, LinkedIn and Microsoft — the DPC handles some of the most consequential privacy cases in Europe. This guide walks you through exactly how to file a complaint, what happens next, and how to maximise your chances of a successful outcome.

What Is the Data Protection Commission (DPC)?

The Data Protection Commission is Ireland's independent regulator responsible for enforcing the General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018. Based in Dublin, the DPC investigates complaints, conducts audits, issues fines and provides guidance to both individuals and organisations on data protection matters.

Because so many multinational technology companies have their European headquarters in Ireland, the DPC often acts as the "lead supervisory authority" for cross-border cases affecting EU residents. This means a complaint filed in Dublin can result in enforcement action that ripples across the entire European Union.

Who Can File a Complaint?

Any individual (a "data subject") whose personal data has been processed unlawfully can file a complaint. You do not need to be an Irish resident — if the company you are complaining about is headquartered in Ireland, the DPC can accept complaints from anywhere in the EU/EEA and, in many cases, globally.

When Should You File a DPC Complaint?

You should consider filing a complaint with the DPC when a company has breached one of your rights under the GDPR. Common grounds include:

  • Ignored subject access requests (SARs) — the company failed to provide your personal data within one month.
  • Refusal to delete data — the controller ignored a valid "right to be forgotten" request.
  • Unlawful marketing — you received emails, SMS or calls without valid consent.
  • Data breaches — your data was leaked and the company failed to notify you appropriately.
  • Excessive data collection — a service collects more information than necessary for its stated purpose.
  • Unclear or misleading privacy policies — the controller cannot explain the legal basis for processing.
  • International transfers — data was sent outside the EEA without adequate safeguards.

Try to Resolve Directly First

The DPC strongly encourages complainants to contact the organisation's Data Protection Officer (DPO) before escalating. Not only is this often faster, it also strengthens your case: showing that you attempted resolution and were ignored or refused makes DPC intervention more likely.

Step-by-Step: How to File a Complaint With DPC Ireland

Filing a complaint is free and can be done entirely online. Here is the full process:

  1. Gather your evidence. Collect emails, screenshots, dates, reference numbers and any correspondence with the organisation. The stronger your paper trail, the faster the DPC can act.
  2. Contact the organisation's DPO. Send a written request (email is fine) clearly stating what you want — access, deletion, correction, or an explanation. Give them the statutory one-month window to respond.
  3. Wait for a response — or the deadline to pass. If they refuse, respond inadequately, or ignore you entirely, you now have grounds to escalate.
  4. Visit the DPC website. Go to dataprotection.ie and navigate to the "Contact / Raise a Concern" section.
  5. Complete the online complaint form. You'll need to provide your name, contact details, the organisation you are complaining about, and a clear description of the issue.
  6. Attach supporting documents. Upload your evidence — the previous correspondence with the DPO is critical here.
  7. Submit and note your reference number. You'll receive an acknowledgement, usually within a few working days.
  8. Cooperate with the case handler. The DPC may ask for clarifications or additional evidence during the investigation.

Alternative Ways to Complain

If you can't or don't want to use the online form, you can also:

  • Email: info@dataprotection.ie
  • Post: Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland
  • Phone: +353 (0)761 104 800 for guidance (formal complaints must be in writing)

What Information You Need to Include

A well-prepared complaint dramatically speeds up the investigation. The DPC expects the following essentials:

CategoryDetails Required
Your identityFull name, postal address, email and phone number
The organisationLegal name, address, website and DPO contact if known
Nature of the complaintClear summary of what happened and which GDPR right was breached
TimelineDates of key events, including when you first contacted the organisation
EvidenceEmails, screenshots, receipts, marketing messages, contracts
Prior contactCopies of your SAR/erasure request and the organisation's response (or lack thereof)
Desired outcomeWhat you want the DPC to do — investigate, order deletion, impose a fine, etc.

What Happens After You File?

The DPC's handling of complaints follows a broadly consistent workflow, though timelines vary significantly depending on complexity.

1. Acknowledgement and Triage

You'll typically receive an acknowledgement within 5–10 working days. A case officer reviews whether the DPC has jurisdiction and whether the complaint is well-founded.

2. Amicable Resolution Attempt

For many complaints, the DPC first tries to broker an amicable resolution — contacting the organisation on your behalf and giving them a chance to fix the issue. Around 70% of complaints are resolved at this stage.

3. Formal Investigation

If amicable resolution fails, the DPC can open a statutory inquiry. This involves compelling document production, interviewing staff, and producing a draft decision. Cross-border cases go through the EU "one-stop-shop" mechanism, involving other supervisory authorities.

4. Decision and Enforcement

Possible outcomes include a reprimand, a compliance order, a temporary or permanent ban on processing, and administrative fines up to €20 million or 4% of global annual turnover — whichever is higher.

How Long Does It Take?

Complaint TypeTypical Timeline
Simple domestic issue (e.g. marketing)1–3 months
Subject access disputes3–6 months
Cross-border tech company inquiries1–3+ years
Data breach investigations6 months – 2 years

Your Rights Under GDPR

Before filing, it's worth understanding exactly which rights you can enforce. The GDPR gives every EU resident eight core rights:

  • Right to be informed — clear disclosure of how your data is used.
  • Right of access — receive a copy of your personal data within one month.
  • Right to rectification — correct inaccurate information.
  • Right to erasure — have data deleted in certain circumstances.
  • Right to restrict processing — pause processing while a dispute is resolved.
  • Right to data portability — receive your data in a machine-readable format.
  • Right to object — especially to direct marketing and profiling.
  • Rights around automated decision-making — including profiling that produces legal effects.

Common Mistakes That Weaken Complaints

Case officers at the DPC see the same avoidable errors repeatedly. Steer clear of these to give your complaint the best chance:

  1. Skipping the DPO step. The DPC will often close a complaint if you haven't first given the controller a chance to respond.
  2. Vague descriptions. "They misused my data" isn't enough. Be specific: what data, when, how, and which right was breached?
  3. Missing evidence. Screenshots and full email headers matter. "They said…" without proof is difficult to act on.
  4. Filing against the wrong entity. The controller is who decides why and how data is processed — not always the customer-facing brand.
  5. Emotional language. Keep it factual. Regulators respond to evidence, not frustration.
  6. Waiting too long. Complaints made years after the incident are much harder to investigate.

Protecting Your Privacy Going Forward

Filing a complaint is a reactive step — but you can also reduce future exposure with better privacy hygiene. Use encrypted DNS resolvers, privacy-focused browsers such as Brave or Firefox with strict tracking protection, disposable email aliases for signups, and unique passwords stored in a reputable manager. When sharing links publicly — for example on social media or in support tickets — use a privacy-respecting URL shortener like Lunyb that doesn't harvest click data for advertising. For a wider comparison of link tools, see our 2026 buyer's guide to the best URL shorteners or our detailed honest review of Lunyb.

What If You Disagree With the DPC's Decision?

If you're unhappy with the outcome, you have several options:

  • Appeal to the Circuit Court or High Court. Under Section 150 of the Data Protection Act 2018, you can appeal a DPC decision within 28 days.
  • Judicial review. Challenge the process rather than the substance if you believe the DPC acted unlawfully.
  • Claim compensation. Under Article 82 GDPR, you can sue the controller in the Irish courts for material or non-material damage.
  • Contact the European Data Protection Board (EDPB). For cross-border cases, the EDPB can review the DPC's handling.

Frequently Asked Questions

Is there a fee to file a complaint with the DPC?

No. Filing a complaint with the Data Protection Commission is completely free. There are also no filing fees for appeals to the Circuit Court, although you may incur legal costs if you choose to be represented.

Can I file a complaint anonymously?

No — the DPC requires your identity so it can communicate with you and verify your standing as a data subject. However, your identity is treated confidentially and is not shared with the organisation without your consent, except where strictly necessary for the investigation.

How long do I have to file a complaint?

The GDPR does not set a strict deadline, but the DPC generally expects complaints to be filed within a reasonable time — typically within 12 months of the incident. Older complaints can still be accepted but may be harder to investigate due to lost records.

Can I complain about a company based outside Ireland?

Yes, if the company has an EU establishment in Ireland, or if it targets Irish/EU residents. For companies based in other EU countries, you can file with your local supervisory authority, which will coordinate with the relevant lead authority under the one-stop-shop mechanism.

Will the company know I filed the complaint?

In most cases, yes — the DPC will need to disclose your identity to properly investigate. If you have serious concerns about retaliation (for example, in an employment context), tell the case officer at the outset so they can consider protective measures.

Final Thoughts

The DPC is one of the most influential data protection regulators in the world, and its complaint process is designed to be accessible to ordinary individuals. Prepare your evidence carefully, follow the correct steps — starting with the organisation's DPO — and be patient with the timeline. Whether your issue is a stubborn marketing email or a systemic failure by a global tech giant, a well-documented complaint is one of the strongest tools you have to enforce your privacy rights under GDPR.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles