DPC Ireland: How to File a Privacy Complaint (2026 Guide)
If your personal data has been mishandled by a company, public body, or online service, you have the right to lodge a complaint with the Data Protection Commission (DPC) in Ireland. As the country's independent supervisory authority for data protection, the DPC enforces the General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018. Because many of the world's largest tech firms have their European headquarters in Dublin, the DPC plays a central role in shaping privacy enforcement across the EU.
This guide walks you through exactly how to file a privacy complaint with the DPC Ireland, what evidence you'll need, how long it takes, and what outcomes to expect.
What Is the Data Protection Commission (DPC)?
The Data Protection Commission is Ireland's national independent authority responsible for upholding the fundamental right of individuals to have their personal data protected. Established under the Data Protection Act 2018, it enforces both the GDPR and Ireland's national data protection law.
The DPC's core responsibilities include:
- Investigating complaints from individuals about how their personal data is being handled
- Conducting inquiries into potential breaches of data protection law
- Issuing fines, reprimands, and corrective orders
- Providing guidance to organisations and the public
- Acting as the lead supervisory authority for many multinational tech companies headquartered in Ireland (including Meta, Google, TikTok, and LinkedIn)
When Should You File a Complaint With the DPC?
You can file a complaint with the DPC if you believe an organisation has breached your data protection rights under the GDPR or Irish law. Common grounds include:
- Ignored access requests: A company failed to respond to your Subject Access Request (SAR) within one month.
- Refused erasure: Your right to be forgotten was denied without valid legal reason.
- Unlawful processing: Your data was collected or used without a valid lawful basis.
- Marketing without consent: You received unsolicited emails, SMS, or calls after unsubscribing.
- Data breaches: An organisation exposed your data through a breach and failed to notify you appropriately.
- Excessive data collection: A service collected more personal information than necessary.
- CCTV misuse: Cameras recorded you in inappropriate contexts (e.g., a neighbour's camera pointed at your garden).
Try to Resolve It Directly First
The DPC strongly encourages complainants to contact the organisation directly before lodging a formal complaint. In most cases, you must show that you attempted to resolve the issue with the data controller and either received an unsatisfactory response or no response at all within one month.
Step-by-Step: How to File a Complaint With DPC Ireland
Step 1: Identify the Data Controller
The data controller is the organisation that decides how and why your data is processed. Check the company's privacy policy for the correct legal entity and contact details for their Data Protection Officer (DPO).
Step 2: Contact the Organisation Directly
Send a written request (email is fine, but keep a copy) explaining the issue. Reference the specific GDPR right you believe was violated, such as Article 15 (access), Article 17 (erasure), or Article 21 (objection). Give them 30 days to respond.
Step 3: Gather Your Evidence
Before contacting the DPC, compile the following:
- Copies of all correspondence with the organisation (emails, letters, chat logs)
- Screenshots of the issue (e.g., unsolicited messages, incorrect data displayed)
- Dates and timeline of events
- Your written request and the organisation's response (or proof of no response)
- Any relevant account information (usernames, reference numbers)
Step 4: Submit Your Complaint to the DPC
The DPC accepts complaints through several channels:
- Online webform: Available at dataprotection.ie under "Contact Us" — this is the fastest method.
- Email: info@dataprotection.ie
- Post: Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28
- Phone: +353 (0)761 104 800 (for guidance, not formal complaints)
Your complaint should include:
- Your full name and contact details
- The name and contact details of the organisation you are complaining about
- A clear description of the issue
- The specific data protection right you believe was breached
- Copies of supporting evidence
- The outcome you are seeking (e.g., data erasure, apology, compensation)
Step 5: Wait for Acknowledgement
The DPC typically acknowledges receipt within a few working days and assigns a case officer. You'll receive a reference number — keep this safe for all future correspondence.
What Happens After You File a Complaint?
The DPC follows a structured process outlined in Section 109 of the Data Protection Act 2018:
| Stage | What Happens | Typical Timeframe |
|---|---|---|
| 1. Acknowledgement | DPC confirms receipt and assigns case officer | 1-2 weeks |
| 2. Assessment | Case officer reviews whether the complaint falls within DPC's remit | 2-6 weeks |
| 3. Amicable Resolution | DPC attempts to mediate between you and the organisation | 1-3 months |
| 4. Formal Investigation | If no resolution, DPC may open a formal statutory inquiry | 6 months - 2+ years |
| 5. Decision | DPC issues findings, corrective measures, or fines | Varies |
Amicable Resolution
Most complaints are resolved at this stage. The DPC contacts the organisation, presents your complaint, and works toward a mutually acceptable outcome — such as deleting your data, correcting inaccuracies, or ceasing marketing contact.
Formal Statutory Inquiry
If amicable resolution fails or the issue is systemic, the DPC may launch a formal inquiry. These are more thorough and can result in binding decisions, corrective orders, or administrative fines of up to €20 million or 4% of global annual turnover — whichever is higher.
Cross-Border Complaints and the One-Stop-Shop
Because Ireland hosts the EU headquarters of many major tech platforms, the DPC often acts as the "lead supervisory authority" for cross-border complaints under the GDPR's one-stop-shop mechanism. If you're complaining about a service like Facebook, Instagram, WhatsApp, Google, or TikTok — regardless of where in the EU you live — your national data protection authority will likely forward the case to the DPC in Dublin.
You can file the complaint through your local supervisory authority (e.g., CNIL in France, ICO in the UK for non-GDPR matters, or the AEPD in Spain), and they will coordinate with the DPC.
Your Rights Under GDPR
Before filing a complaint, it helps to understand which specific right you're invoking. The GDPR grants you eight key rights:
- Right to be informed — Know how your data is being used
- Right of access — Request a copy of your personal data
- Right to rectification — Correct inaccurate data
- Right to erasure — Have your data deleted ("right to be forgotten")
- Right to restrict processing — Limit how your data is used
- Right to data portability — Move your data to another provider
- Right to object — Stop certain types of processing, including direct marketing
- Rights related to automated decision-making — Challenge purely automated decisions
Common Mistakes to Avoid When Filing
- Skipping the direct contact step: The DPC will usually redirect you back to the organisation if you haven't tried resolving it there first.
- Vague descriptions: Be specific. "They didn't reply to my email" is weaker than "On 3 March 2026, I sent a SAR under Article 15 GDPR to privacy@company.com; no response received within 30 days."
- Missing evidence: Screenshots, email headers, and timestamps strengthen your case significantly.
- Filing about non-personal issues: The DPC only handles personal data matters, not general consumer complaints (contact the CCPC for those).
- Unrealistic expectations: The DPC cannot award financial compensation — that requires a separate civil court claim under Section 117 of the Data Protection Act 2018.
Protecting Your Privacy Proactively
Filing complaints is reactive. The best defence is minimising how much personal data you expose in the first place. A few practical habits:
- Use privacy-focused browsers like Brave or Firefox with tracking protection enabled
- Enable encrypted DNS (DNS-over-HTTPS) in your browser or operating system
- Use disposable email addresses for sign-ups you don't fully trust
- Regularly review app permissions on your phone and revoke unused access
- When sharing links publicly, consider a privacy-respecting URL shortener like Lunyb that doesn't harvest click data for advertising purposes — see our honest Lunyb review for details
- Read privacy policies before creating accounts, especially the sections on data sharing and retention
If you manage links for marketing or business purposes, choosing tools that respect end-user privacy also reduces your own compliance risk. Our 2026 URL shortener comparison highlights which providers offer the strongest data protection guarantees.
Can You Appeal a DPC Decision?
Yes. If you disagree with the outcome of your complaint, you have two options:
- Judicial review: Challenge the DPC's decision in the Irish High Court within three months.
- Statutory appeal: For certain decisions (particularly formal inquiry outcomes), you can appeal to the Circuit Court within 28 days.
You can also pursue a separate civil action against the organisation itself under Section 117 of the Data Protection Act 2018 to claim compensation for material or non-material damage caused by the breach.
Frequently Asked Questions
Is there a fee to file a complaint with the DPC?
No. Filing a complaint with the Data Protection Commission is completely free. The DPC is funded by the Irish state and does not charge individuals for handling privacy complaints.
How long does the DPC take to resolve a complaint?
Simple complaints resolved through amicable resolution typically take 1-3 months. Formal statutory inquiries — especially those involving large tech companies — can take anywhere from six months to several years due to their complexity and cross-border nature.
Can I file a complaint anonymously?
No. The DPC requires your identity to investigate a complaint properly, as they need to verify your relationship to the personal data in question. However, your identity is not disclosed publicly, and the DPC handles complaints confidentially.
Can the DPC award me compensation?
No. The DPC can order organisations to change their practices, delete data, or pay administrative fines to the state — but it cannot award personal compensation. To claim damages, you must bring a separate civil action in the Circuit or High Court under Section 117 of the Data Protection Act 2018.
What if the company is based outside Ireland?
If the organisation has its main EU establishment in Ireland (as many tech giants do), the DPC will handle the case under the GDPR's one-stop-shop mechanism. If they're based in another EU country, file with that country's supervisory authority instead. For non-EU companies targeting Irish residents, the DPC still has jurisdiction.
Do I need a solicitor to file a complaint?
No. The complaint process is designed to be accessible without legal representation. However, for complex cases — particularly if you're seeking compensation through the courts — consulting a solicitor experienced in data protection law can be helpful.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Bill C-27 Digital Charter: What You Need to Know
Bill C-27, Canada's Digital Charter Implementation Act, introduces the CPPA, a new privacy tribunal, and AIDA to modernize privacy and regulate AI. Learn what it means for Canadian businesses and consumers, how it compares globally, and how to prepare.
ICO Fines 2026: Biggest Data Protection Penalties in the UK
The ICO issued record data protection penalties in 2026, with fines topping £6 million for ransomware failures and multi-million pound sanctions for marketing abuses. This guide examines the biggest UK fines of the year and the compliance lessons every organisation must learn.
Data Protection Act 2018 Ireland: Complete Guide
A complete guide to Ireland's Data Protection Act 2018, covering its relationship with the GDPR, individual rights, business obligations, DPC enforcement powers, and penalties. Learn what your organisation needs to do to stay compliant.
Singapore PDPA vs GDPR: Key Differences for Businesses in 2026
Singapore's PDPA and the EU's GDPR both protect personal data but differ significantly in scope, consent standards, penalties, and rights. This guide compares the two frameworks side-by-side so businesses can build a compliance strategy that works across borders.