facebook-pixel

DPC Ireland: How to File a Privacy Complaint (2026 Guide)

L
Lunyb Security Team
··10 min read

If an organisation has mishandled your personal data, you have the right under the GDPR and the Irish Data Protection Act 2018 to lodge a complaint with the Data Protection Commission (DPC). As Ireland's independent regulator — and the lead supervisory authority for many of the world's largest tech companies — the DPC has significant powers to investigate, order corrective action, and impose fines.

This guide walks you through exactly how to file a privacy complaint with the DPC Ireland, what evidence you need, how long investigations typically take, and what outcomes you can realistically expect.

What Is the Data Protection Commission (DPC)?

The Data Protection Commission is Ireland's national independent authority responsible for upholding the fundamental right of individuals in the EU to have their personal data protected. It enforces the General Data Protection Regulation (GDPR), the Data Protection Act 2018, and the ePrivacy Regulations.

Because many multinational technology companies — including Meta, Google, TikTok, Microsoft, and LinkedIn — have their European headquarters in Dublin, the DPC often acts as the "lead supervisory authority" for cross-border complaints under the GDPR's one-stop-shop mechanism. This means a complaint filed in Berlin or Madrid about Facebook may ultimately be investigated in Dublin.

What the DPC Can Do

  • Investigate complaints from individuals ("data subjects")
  • Issue reprimands, warnings, and compliance orders
  • Suspend or ban data processing activities
  • Impose administrative fines of up to €20 million or 4% of global annual turnover
  • Refer cases to the Circuit Court or High Court

What the DPC Cannot Do

  • Award financial compensation to you personally (you must sue in court for that)
  • Act as a legal adviser
  • Overturn decisions of other courts
  • Investigate complaints that fall outside data protection law (e.g. defamation, consumer disputes)

When Should You File a Complaint With the DPC?

You can complain to the DPC when you believe an organisation (a "data controller") has breached your rights under data protection law. Common grounds include:

  1. Unlawful processing — a company is using your data without a valid legal basis.
  2. Ignored subject access request (SAR) — you asked for a copy of your data and the organisation did not respond within one month.
  3. Refusal to erase — your "right to be forgotten" request was declined without valid justification.
  4. Data breach — your information was leaked, lost, or exposed.
  5. Unwanted marketing — you keep receiving emails, texts, or calls after unsubscribing.
  6. Excessive CCTV or workplace monitoring — surveillance that is disproportionate or lacks transparency.
  7. Inaccurate data — the organisation refuses to correct wrong information about you.

Try to Resolve It Directly First

The DPC strongly encourages you to raise the issue directly with the organisation before escalating. In practice, you should:

  1. Contact the organisation's Data Protection Officer (DPO) — their details must appear in the privacy notice.
  2. Put your complaint in writing (email is fine) and clearly state what you want them to do.
  3. Give them a reasonable deadline — usually one month, which mirrors the GDPR response window.
  4. Keep copies of all correspondence.

If the organisation ignores you, refuses, or gives an inadequate response, you can then escalate to the DPC with a strong paper trail.

How to File a Privacy Complaint With the DPC: Step by Step

The DPC accepts complaints through a dedicated online webform, by post, or by email. The online webform is the fastest and most reliable method.

Step 1: Gather Your Evidence

Before you start, collect:

  • Your full name, address, and contact details
  • The name and address of the organisation you are complaining about
  • A clear, chronological summary of what happened
  • Copies of emails, letters, screenshots, and any response (or lack of response) from the organisation
  • Any reference numbers, account IDs, or ticket numbers
  • The specific right or GDPR article you believe has been breached (optional but helpful)

Step 2: Access the DPC Complaint Form

Go to dataprotection.ie and navigate to "Contact Us" → "Raise a Concern" → "Lodge a Complaint". You will find an electronic complaint form that is structured to collect everything the DPC needs on first submission, reducing back-and-forth later.

Step 3: Complete the Form Clearly

Write in plain English. Stick to facts, dates, and documents. Avoid emotional language — investigators handle thousands of files a year and respond best to a clear timeline. A good complaint narrative follows this structure:

  1. Who — the organisation involved.
  2. What — what they did (or failed to do).
  3. When — dates of key events.
  4. How you tried to resolve it — direct contact, SAR, DPO correspondence.
  5. What outcome you want — erasure, correction, stopping marketing, a formal finding, etc.

Step 4: Attach Supporting Documents

Upload PDFs or screenshots of your evidence. The DPC can request originals later, but a complete initial submission accelerates triage significantly.

Step 5: Submit and Record Your Reference Number

Once submitted, you will receive an acknowledgment, typically within a few working days, including a case reference number. Keep this safe — you will use it in all future correspondence.

What Happens After You File?

The DPC's handling of complaints follows a structured, legally defined process. Here is what to expect at each stage.

Stage 1: Assessment and Triage (0–8 weeks)

A caseworker reviews your complaint to confirm it falls within the DPC's remit, that you tried to resolve it with the organisation, and that there is enough evidence to proceed. Some complaints are closed at this stage if they are out of scope or clearly unfounded.

Stage 2: Amicable Resolution

For many complaints, the DPC will attempt an "amicable resolution" — effectively mediation between you and the organisation. This often results in the organisation apologising, deleting data, honouring your SAR, or stopping the behaviour. Around a third of DPC complaints are resolved this way.

Stage 3: Formal Statutory Inquiry

If amicable resolution fails or the matter is serious, the DPC can open a statutory inquiry. This involves formal legal procedures, submissions from both sides, and ultimately a binding decision. Complex cross-border inquiries can take 18–36 months or longer.

Stage 4: Decision and Enforcement

Decisions can include reprimands, orders to bring processing into compliance, bans on specific activities, and administrative fines. You will receive a copy of the decision and may appeal to the Circuit Court within 28 days.

DPC Complaint Routes Compared

Route Best For Typical Timeline Formality
Direct to the organisation SARs, erasure, unsubscribe issues Up to 1 month Informal
DPC amicable resolution Unresolved individual complaints 2–6 months Mediated
DPC statutory inquiry Systemic breaches, large controllers 12–36+ months Formal legal
Circuit Court compensation claim Material or non-material damage 6–18 months Court proceedings

Common Mistakes to Avoid

1. Skipping the Direct Contact Stage

The DPC may bounce your complaint back if you have not first contacted the organisation. This is the single most common reason complaints stall at triage.

2. Submitting a Vague Narrative

"Facebook misused my data" is not actionable. "On 14 March I submitted a SAR to Meta Ireland via their privacy portal (ref #12345). I received no response within 30 days. On 20 April I sent a follow-up email to dpo@fb.com. I received an automated reply only." — that is actionable.

3. Expecting Compensation From the DPC

The DPC does not award damages. If you have suffered financial loss or significant distress, you need to pursue a separate claim in the Circuit Court under Section 117 of the Data Protection Act 2018.

4. Ignoring the One-Stop-Shop Rule

If your complaint concerns a multinational with its EU HQ in Ireland, your local national regulator (e.g. the CNIL in France) will usually transfer it to the DPC anyway. You can file directly with the DPC to save time.

5. Not Preserving Evidence

Screenshots get lost, inboxes get purged, and accounts get closed. Preserve everything the moment you suspect a breach.

Protecting Your Privacy Going Forward

Filing a complaint is a reactive measure. Reducing the amount of personal data you expose in the first place is a far more sustainable approach. A few practical habits:

  • Use masked email aliases for sign-ups so you can revoke them later.
  • Enable encrypted DNS (DNS-over-HTTPS) in your browser to prevent your ISP from logging every domain you visit.
  • Review app permissions on your phone every few months and revoke anything unused.
  • Avoid link trackers — many shortened links in marketing emails capture click, device, and location data. Using a privacy-respecting shortener like Lunyb for your own links means the people clicking them aren't profiled by third-party ad networks.
  • Read privacy notices before creating accounts — look specifically for the "legal basis" and "retention period" sections.

If you run a business or newsletter and share links regularly, choosing tooling that minimises data collection matters just as much for your audience as it does for you. Our 2026 buyer's guide to URL shorteners compares the main options on privacy, pricing, and features, and our honest review of Lunyb looks at how it stacks up for everyday use.

Can You Complain Anonymously?

No. The DPC cannot progress a formal complaint without knowing who you are, because they need to confirm that your rights as a specific data subject have been affected. However, you can submit general concerns or tip-offs about potentially unlawful processing anonymously — these may inform the DPC's own-volition inquiries but will not generate a case update for you.

What If You Are Not Happy With the DPC's Decision?

You have two main options:

  1. Appeal to the Circuit Court within 28 days of receiving the decision. The Circuit Court can affirm, vary, or annul the DPC's decision.
  2. Judicial review in the High Court if you believe the DPC acted unlawfully, unreasonably, or in breach of fair procedures. This is a higher bar and usually requires legal representation.

For cross-border decisions issued jointly by the European Data Protection Board (EDPB), additional appeal routes exist through the Court of Justice of the European Union.

Frequently Asked Questions

How much does it cost to file a complaint with the DPC?

Nothing. Filing a complaint with the Data Protection Commission is completely free, and you do not need a solicitor. Costs only arise if you choose to escalate to court for compensation or judicial review.

How long does the DPC take to resolve a complaint?

Simple complaints resolved through amicable resolution typically take 2–6 months. Formal statutory inquiries, especially cross-border cases involving major tech companies, can take 18 months to several years. The DPC publishes an annual report with current throughput statistics.

Can I file a complaint if I live outside Ireland?

Yes. If the organisation has its EU headquarters in Ireland, you can file directly with the DPC regardless of where you live in the EU/EEA. Alternatively, you can file with your national data protection authority, who will transfer the case to the DPC under the one-stop-shop mechanism.

Will the organisation know I made the complaint?

Yes. For the DPC to investigate and seek a response, it must share the substance of your complaint — including your identity — with the organisation. The DPC does not operate anonymised complaints at the formal stage.

Can I get compensation through the DPC?

No. The DPC can order corrective action and impose fines payable to the State, but it cannot award you personal compensation. If you have suffered material loss (e.g. identity fraud) or non-material damage (e.g. distress), you need to bring a separate civil claim in the Circuit Court under Section 117 of the Data Protection Act 2018. A favourable DPC decision strengthens such a claim significantly.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles