facebook-pixel

DPC Ireland: How to File a Privacy Complaint (2026 Guide)

L
Lunyb Security Team
··9 min read

If an organisation has mishandled your personal data, ignored a subject access request, or refused to delete your information, you have the right to complain to the Data Protection Commission (DPC) of Ireland. As the lead supervisory authority for many of the world's biggest tech companies — including Meta, Google, TikTok, and Microsoft — the DPC handles some of the most consequential privacy cases in Europe.

This guide explains exactly how to file a privacy complaint with the DPC Ireland in 2026, what evidence you need, how long the process takes, and what outcomes you can realistically expect.

What Is the Data Protection Commission (DPC) Ireland?

The Data Protection Commission is Ireland's independent supervisory authority responsible for upholding the fundamental right of individuals to have their personal data protected. It enforces the General Data Protection Regulation (GDPR), the Irish Data Protection Act 2018, and the ePrivacy Regulations.

Because so many multinational tech companies have their EU headquarters in Dublin, the DPC also acts as the "lead supervisory authority" under the GDPR's one-stop-shop mechanism for cross-border complaints against those firms. That means a complaint you file in Dublin could set precedent affecting hundreds of millions of users across the EU.

What the DPC Can and Cannot Do

  • Can: Investigate complaints, issue reprimands, order data controllers to comply, impose administrative fines up to €20 million or 4% of global turnover, and refer matters to the Circuit Court.
  • Can: Mediate disputes between you and the organisation.
  • Cannot: Award you personal compensation — for that, you must go to court.
  • Cannot: Handle complaints about journalistic content, some law-enforcement processing, or matters clearly outside GDPR scope.

When Should You File a Complaint With the DPC?

You should consider filing a complaint when you believe an organisation has breached your data protection rights under the GDPR or Irish law. Common valid grounds include:

  1. Unlawful processing: An organisation is using your personal data without a valid legal basis.
  2. Ignored subject access request (SAR): You asked for a copy of your data and got no response within one month.
  3. Refusal to delete: You exercised your right to erasure and the controller refused without adequate justification.
  4. Data breach: Your data was exposed and the company failed to notify you appropriately.
  5. Unwanted marketing: A company continues to send you emails, texts or calls after you unsubscribed.
  6. Cookies and tracking: A website drops non-essential cookies without valid consent.
  7. Excessive CCTV or workplace surveillance: Monitoring that goes beyond what's necessary.

Try to Resolve It Directly First

The DPC strongly encourages you to contact the organisation's Data Protection Officer (DPO) before escalating. In many cases a firmly worded email citing the specific GDPR article being breached resolves the issue within weeks. Keep copies of everything — you'll need them if you do end up complaining formally.

How to File a Complaint With the DPC Ireland: Step-by-Step

The DPC accepts complaints by post, email, and through its online webform. The webform is the fastest and most reliable method in 2026.

Step 1: Gather Your Evidence

Before starting, collect:

  • The name and contact details of the organisation (the data controller).
  • Copies of all correspondence with the organisation and its DPO.
  • Screenshots, emails, letters, or recordings that demonstrate the breach.
  • Dates and a clear timeline of events.
  • Any reference numbers the company gave you.

Step 2: Attempt Resolution With the Controller

Send a written request to the organisation's DPO stating: (a) which right you are exercising, (b) the specific data or issue involved, and (c) that you expect a response within one calendar month as required by Article 12(3) GDPR. If they miss that deadline or refuse without justification, you have solid grounds to escalate.

Step 3: Complete the DPC Webform

Go to dataprotection.ie and navigate to "Contact us" → "Raise a Concern". You will be asked for:

  1. Your personal details (name, address, email, phone).
  2. Details of the organisation you're complaining about.
  3. A clear description of the issue.
  4. What GDPR right you believe has been breached.
  5. What steps you've already taken.
  6. What outcome you are seeking.
  7. Supporting documents (PDFs, screenshots, emails).

Step 4: Submit and Receive Acknowledgement

You'll receive an automatic acknowledgement, usually followed by a case reference number within 5–10 working days. Keep this number safe — you'll quote it in all future correspondence.

Step 5: Engage With the Case Handler

A DPC case officer may contact you for clarification or additional evidence. Respond promptly — delays on your side extend the overall timeline. The DPC will also contact the controller and typically ask them to respond within 21–28 days.

Complaint Channels Compared

ChannelBest ForResponse SpeedEvidence Handling
Online webformMost standard complaintsFastest (5–10 days ack.)Upload files directly
Email (info@dataprotection.ie)Follow-ups, simple queriesModerateAttach files, size limits apply
Postal mailPeople without digital access; sensitive originalsSlowestSend copies, not originals
Phone (+353 578 684 800)General guidance onlyImmediate for questionsNot accepted as formal complaint

What Happens After You File?

The DPC follows a structured process that can range from a few weeks (for simple mediation) to several years (for cross-border cases against major tech companies).

Phase 1: Assessment (0–8 weeks)

The DPC decides whether your complaint falls within its remit and whether it discloses a possible infringement. Complaints that are vexatious, out of scope, or duplicates may be closed at this stage.

Phase 2: Amicable Resolution (2–6 months)

The DPC will typically try to resolve the matter informally between you and the organisation. Many complaints — especially SAR delays and marketing issues — are settled here without formal investigation.

Phase 3: Statutory Inquiry (6 months to 3+ years)

If amicable resolution fails, or the issue is systemic, the Commissioners can open a formal inquiry under Section 110 of the Data Protection Act 2018. This can lead to reprimands, corrective orders, or significant fines.

Phase 4: Decision and Appeals

You will receive a written decision. Either party can appeal to the Circuit Court within 28 days. Cross-border cases go through the European Data Protection Board's cooperation and consistency mechanisms, which is why cases against companies like Meta or TikTok take years.

Tips to Strengthen Your Complaint

  • Be specific. Cite the exact GDPR article (e.g., Article 15 for access, Article 17 for erasure, Article 21 for objection).
  • Stick to facts. Emotional framing weakens your case. Present a clear timeline.
  • Quantify harm where possible. Financial loss, reputational damage, distress — describe concrete impact.
  • Attach evidence, don't just describe it. Screenshots with visible dates are gold.
  • State the remedy you want. Deletion, correction, cessation of processing, a formal reprimand, or referral for a fine.

Protecting Your Privacy Proactively

Filing complaints is a reactive tool. A better long-term strategy is minimising how much of your personal data ends up in the hands of third parties in the first place. Practical measures include:

  • Using encrypted DNS resolvers such as Cloudflare 1.1.1.1 or NextDNS to reduce ISP-level tracking.
  • Choosing privacy-respecting browsers like Firefox, Brave, or Safari with strict tracking protection enabled.
  • Using privacy-preserving link tools when sharing URLs publicly. Services like Lunyb shorten links without building advertising profiles on the people who click them — see our honest review of Lunyb for details.
  • Regularly exercising your rights: annual SARs, periodic erasure requests, and unsubscribing from mailing lists.
  • Reviewing app permissions on your phone every few months.

Common Mistakes to Avoid

  1. Skipping the DPO step. The DPC will often bounce your complaint back if you haven't given the controller a chance to respond first.
  2. Filing too early. Wait for the full one-month statutory response window before escalating a SAR complaint.
  3. Being vague. "They misused my data" is not enough. Say what data, what use, and why it's unlawful.
  4. Expecting compensation from the DPC. The regulator can order compliance and fine the company, but personal damages must be sought in court.
  5. Ignoring cross-border rules. If the company is based in another EU country, your local DPA may forward the case — you can also complain directly to your home country's authority.

DPC Ireland Contact Details

  • Website: www.dataprotection.ie
  • Email: info@dataprotection.ie
  • Phone: +353 578 684 800 / +353 761 104 800
  • Dublin office: 6 Pembroke Row, Dublin 2, D02 X963
  • Portarlington office: 21 Fitzwilliam Square South, Dublin 2

Frequently Asked Questions

How long does the DPC take to resolve a complaint?

Simple complaints resolved through amicable resolution typically take 3–6 months. Formal statutory inquiries can take 1–3 years, and complex cross-border cases involving large tech firms sometimes take 4–5 years due to the GDPR's cooperation mechanism with other EU regulators.

Does it cost anything to file a complaint with the DPC Ireland?

No. Filing a complaint with the Data Protection Commission is completely free. You do not need a solicitor, although you may choose to instruct one for complex matters or if you plan to seek compensation through the courts afterwards.

Can I complain to the DPC about a non-Irish company?

Yes, if the company has its EU main establishment in Ireland (as Meta, Google, TikTok, Microsoft, LinkedIn and many others do), the DPC is the lead supervisory authority. For companies based elsewhere in the EU, you can complain to the DPC and it will be transferred, or you can complain directly to your own country's data protection authority.

Can I get compensation through a DPC complaint?

No. The DPC can order a controller to comply, issue reprimands, and impose administrative fines that go to the Irish Exchequer — not to you. To recover compensation for material or non-material damage, you must bring a separate action in the Circuit Court under Section 117 of the Data Protection Act 2018.

What if I disagree with the DPC's decision?

You have the right to appeal a legally binding decision to the Circuit Court within 28 days of being notified. You can also complain to the Ombudsman about the DPC's handling of your case (as distinct from the substantive decision), or seek judicial review in the High Court for procedural errors.

Final Thoughts

The DPC Ireland complaints process is free, accessible, and increasingly effective — but it rewards preparation. Exhaust the direct route with the controller first, document everything, cite specific GDPR articles, and be patient. For everyday privacy hygiene, combine that reactive right to complain with proactive habits: minimise what you share, prefer privacy-first tools, and regularly audit who holds your data. Together, those two habits give you genuine control over your digital footprint in 2026 and beyond.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles