facebook-pixel

DPC Ireland: How to File a Privacy Complaint (2026 Guide)

L
Lunyb Security Team
··9 min read

If an organisation has mishandled your personal data, you have the right to lodge a formal complaint with the Data Protection Commission (DPC) of Ireland. As the lead supervisory authority for many of the world's largest tech companies — including Meta, Google, TikTok, Apple and LinkedIn, all of which have EU headquarters in Dublin — the Irish DPC plays an outsized role in enforcing the General Data Protection Regulation (GDPR) across Europe.

This guide walks you through exactly how to file a privacy complaint with the DPC Ireland, what evidence you need, what happens after submission, and the realistic timelines you should expect. Whether you are an Irish resident or a European citizen whose data has been processed by a Dublin-based controller, this article will help you navigate the process confidently.

What Is the Data Protection Commission (DPC)?

The Data Protection Commission is the Republic of Ireland's independent authority responsible for upholding the fundamental right of individuals in the EU to have their personal data protected. Established in its current form by the Data Protection Act 2018, the DPC enforces both the GDPR and Ireland's national data protection law.

The DPC is headquartered at 21 Fitzwilliam Square South, Dublin 2, with an additional office in Portarlington, County Laois. It is led by three Commissioners for Data Protection following a structural reform in 2024. Because so many multinational tech firms base their EU operations in Ireland, the DPC often acts as the "lead supervisory authority" under the GDPR's one-stop-shop mechanism, handling cross-border cases on behalf of all EU data protection authorities.

What the DPC Can and Cannot Do

The DPC can investigate complaints, mediate disputes, issue reprimands, order organisations to change their practices, and impose administrative fines of up to €20 million or 4% of global annual turnover — whichever is higher. However, the DPC cannot award compensation to individuals; for monetary damages, you must bring a civil action in the Irish courts.

When Can You File a Complaint With the DPC?

You can lodge a complaint with the DPC Ireland when you believe that an organisation (a "data controller" or "data processor") has infringed your rights under data protection law. Common grounds include:

  • Refusal to respond to a Subject Access Request (SAR) within one month
  • Unlawful processing of your personal data without a valid legal basis
  • Failure to delete your data after a legitimate erasure request
  • Unsolicited marketing emails, texts, or calls without consent
  • A data breach that was not properly notified to you
  • Excessive CCTV surveillance by a neighbour, employer, or business
  • Inaccurate personal data that an organisation refuses to correct
  • Transfers of your data outside the EEA without adequate safeguards

Try to Resolve It Directly First

The DPC strongly encourages complainants to raise the issue directly with the organisation before escalating. Most companies have a Data Protection Officer (DPO) whose contact details should appear in the privacy policy. Give the organisation a reasonable deadline — typically 30 days — to respond. Keep every email, letter, and screenshot: this correspondence becomes crucial evidence later.

How to File a Privacy Complaint With the DPC Ireland: Step by Step

The DPC accepts complaints through three channels: an online webform, email, and postal mail. The online webform is the fastest and most reliable route. Here is the full process:

  1. Gather your evidence. Collect copies of your original request to the organisation, their reply (or proof of non-reply), the data in question, and any other supporting documents. Save everything as PDFs where possible.
  2. Identify the correct controller. Confirm the legal name and address of the organisation. For a multinational, this is usually the EU headquarters named in the privacy notice.
  3. Visit dataprotection.ie. Navigate to the "Contact / Raise a Concern" section and select the online complaint webform.
  4. Complete the webform. Provide your full name, address, email, a clear description of the complaint, the date the issue arose, and the outcome you are seeking (e.g. erasure, access, cessation of marketing).
  5. Upload supporting documents. Attach your evidence. The webform accepts common file types up to a reasonable size limit.
  6. Submit and keep the reference number. You will receive an automated acknowledgement with a case reference. Quote this in all future correspondence.

Alternative Submission Methods

If you prefer not to use the webform, you can email info@dataprotection.ie with the same information attached, or write to: Data Protection Commission, 21 Fitzwilliam Square South, Dublin 2, D02 RD28, Ireland. Postal complaints take longer to log but are equally valid.

What Information Must Your Complaint Include?

A well-structured complaint helps the DPC triage and investigate efficiently. Include every item below:

FieldDetails Required
Your identityFull name, postal address, email, phone number
Organisation complained aboutLegal name, registered address, website, DPO contact if known
Nature of complaintWhich GDPR right or principle you believe was breached
TimelineDates of the alleged breach and your contact with the organisation
EvidenceEmails, screenshots, letters, SAR responses, marketing material
Desired outcomeErasure, access, correction, cessation, investigation
DeclarationConfirmation the information is true to the best of your knowledge

What Happens After You Submit a Complaint?

Understanding the DPC's internal workflow helps set realistic expectations. The process typically unfolds in several phases:

1. Acknowledgement and Triage (1–4 weeks)

The DPC's Information and Assessment Unit confirms receipt and reviews whether your complaint falls within its remit. If not, you may be redirected — for example, employment-related grievances might go to the Workplace Relations Commission, and nuisance phone calls may fall under ComReg's jurisdiction.

2. Amicable Resolution (1–6 months)

Under Section 109(2) of the Data Protection Act 2018, the DPC must attempt to resolve the complaint amicably where possible. A case officer contacts the organisation, shares your complaint, and seeks a response. Many cases are closed at this stage with the organisation agreeing to erase data, provide access, or stop a particular practice.

3. Formal Inquiry (6 months to several years)

If amicable resolution fails, or if the breach is serious, the DPC may launch a formal statutory inquiry. This can include compelling the organisation to produce documents, conducting on-site audits, and drafting a decision. Cross-border inquiries involving other EU authorities take considerably longer due to the cooperation and consistency mechanisms under Article 60 GDPR.

4. Decision and Enforcement

The DPC issues a decision that may include a reprimand, a corrective order, a temporary or permanent ban on processing, or an administrative fine. Decisions can be appealed to the Irish Circuit Court or High Court within 28 days.

Typical Timelines: What to Expect

Realistic timelines vary dramatically depending on complexity:

  • Simple marketing complaint: 2–6 months
  • SAR non-compliance: 3–9 months
  • Domestic data breach: 6–18 months
  • Cross-border Big Tech inquiry: 2–5 years

The DPC publishes annual reports with statistics on resolution times. In recent years, the Commission has received over 10,000 complaints annually, with roughly two-thirds resolved within 12 months.

Your Rights During the Process

You have the right to be kept informed of progress, to receive a written decision, and — critically under Article 78 GDPR — to an effective judicial remedy if the DPC does not handle your complaint or inform you of progress within three months. This means you can seek judicial review in the Irish High Court if the DPC appears to be stalling.

Confidentiality and Anonymity

The organisation complained about will usually be told your identity, as it is often impossible to investigate a complaint without naming the data subject. If you have genuine concerns about retaliation (for instance, in employment contexts), raise this at submission and the DPC can consider protective measures.

Protecting Your Privacy Day to Day

Filing a complaint is a reactive measure. Proactively, you can minimise the personal data you expose online in the first place. Use privacy-respecting browsers, enable encrypted DNS, disable third-party cookies, and share links through tools that do not harvest excessive analytics. For example, when sharing URLs, choosing a privacy-conscious shortener like Lunyb reduces the amount of click-level data that ends up in third-party advertising ecosystems — a small but meaningful improvement over mainstream alternatives. If you want to compare options, our 2026 buyer's guide to URL shorteners breaks down the privacy practices of the leading platforms.

Common Mistakes That Weaken a Complaint

  1. Skipping the direct complaint stage. The DPC may defer your case until you have contacted the organisation.
  2. Vague descriptions. "They have my data" is not enough; specify which data, how it was collected, and which right was breached.
  3. No evidence. Allegations without screenshots, emails, or dates are hard to investigate.
  4. Wrong jurisdiction. If the controller has no establishment in Ireland and the processing is purely local to another member state, the authority there may be competent instead.
  5. Unrealistic remedies. The DPC cannot award damages or force a public apology.

Can Non-Irish Residents File With the DPC?

Yes. Any EU or EEA resident whose personal data is processed by a controller established in Ireland may lodge a complaint with the DPC directly, or lodge it with their local supervisory authority, which will transfer the case to Dublin under the one-stop-shop mechanism. Residents of the UK, post-Brexit, generally complain to the ICO about UK-focused processing but can still complain to the DPC about EU-focused processing by Irish-established controllers.

FAQ

Is there a fee to file a complaint with the DPC?

No. Lodging a complaint with the Data Protection Commission is completely free of charge, whether submitted online, by email, or by post.

How long do I have to file a complaint?

There is no strict statutory deadline, but the DPC encourages complaints to be filed as soon as reasonably possible after the alleged breach — ideally within 12 months. Older complaints can still be investigated but evidence may be harder to obtain.

Can I file a complaint anonymously?

Anonymous complaints are generally not investigated as individual cases, because the DPC needs to engage with you to gather evidence and communicate the outcome. However, you can submit anonymous information about systemic breaches, which may feed into broader own-volition inquiries.

What if I disagree with the DPC's final decision?

You have 28 days to appeal a legally binding DPC decision to the Irish Circuit Court (for most matters) or the High Court. You may also seek judicial review of procedural failings. Legal advice is strongly recommended at this stage.

Can I claim compensation through the DPC?

No. The DPC has no power to award monetary compensation. To claim damages for material or non-material loss arising from a GDPR breach, you must bring a civil action under Section 117 of the Data Protection Act 2018 in the Circuit Court or High Court.

Final Thoughts

Filing a complaint with the DPC Ireland is a powerful tool for enforcing your data protection rights, and the process is deliberately accessible to ordinary citizens without the need for a solicitor. The keys to success are preparation, evidence, and clarity: contact the organisation first, document everything, and submit a focused complaint through the online webform. While cross-border cases involving major tech platforms can take years, straightforward domestic complaints are often resolved within months — and even unsuccessful complaints contribute to the regulatory record that shapes future enforcement priorities.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles