facebook-pixel

DPC Ireland: How to File a Privacy Complaint (2026 Guide)

L
Lunyb Security Team
··9 min read

If an organisation has mishandled your personal data, you have the right under the General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018 to lodge a complaint with the Data Protection Commission (DPC). As the lead supervisory authority for many of the world's largest technology companies — including Meta, Google, TikTok, and LinkedIn, all of which have their European headquarters in Dublin — the DPC plays an outsized role in global privacy enforcement.

This guide walks you through exactly how to file a privacy complaint with the DPC Ireland, what information you need to prepare, how long the process takes, and what outcomes you can realistically expect.

What Is the Data Protection Commission (DPC)?

The Data Protection Commission is Ireland's independent national regulator responsible for upholding the fundamental right of individuals to have their personal data protected. Established in its current form by the Data Protection Act 2018, the DPC enforces GDPR, the Law Enforcement Directive, and the ePrivacy Regulations across Ireland.

The DPC is led by three Commissioners for Data Protection and is headquartered at 21 Fitzwilliam Square South, Dublin 2, with a second office in Portarlington, County Laois. Because so many multinational tech companies have their EU base in Ireland, the DPC is often the lead supervisory authority for cross-border complaints under GDPR's one-stop-shop mechanism.

What the DPC Can Do

  • Investigate complaints from individuals ("data subjects")
  • Issue binding decisions and corrective orders
  • Impose administrative fines of up to €20 million or 4% of global annual turnover
  • Order organisations to stop processing data, erase it, or change their practices
  • Refer matters to the European Data Protection Board (EDPB) for cross-border disputes

When Should You File a Complaint with the DPC?

You can file a complaint with the DPC if you believe an organisation based in Ireland — or one whose EU lead regulator is the DPC — has breached your data protection rights. Common grounds for complaint include:

  1. Ignored subject access request: You asked for a copy of your data and the company failed to respond within one month.
  2. Refused erasure request: The organisation declined to delete your data without a valid legal basis.
  3. Unlawful marketing: You received unsolicited emails, SMS, or calls without consent.
  4. Data breach notification failures: Your data was exposed and you were not informed.
  5. Excessive data collection: A service demands more information than it needs to deliver its product.
  6. Cookies and tracking: A website set tracking cookies without proper consent.
  7. Inaccurate data: The organisation refused to correct wrong information about you.

Try to Resolve It Directly First

The DPC strongly encourages — and in most cases requires — you to contact the organisation directly before lodging a formal complaint. Most companies have a Data Protection Officer (DPO) whose contact details should be in their privacy policy. Give the organisation a reasonable chance to respond (typically 30 days) and keep written records of every exchange.

Step-by-Step: How to File a Complaint with the DPC Ireland

Step 1: Gather Your Evidence

Before you contact the DPC, assemble a clear file containing:

  • The full name and address of the organisation
  • A chronological account of what happened and when
  • Copies of any emails, letters, or screenshots relevant to your complaint
  • Any responses (or non-responses) you received from the organisation
  • Reference numbers, account IDs, or case IDs
  • A clear statement of the outcome you are seeking

Step 2: Choose Your Submission Method

The DPC offers several ways to submit a complaint. The most efficient is the online webform via dataprotection.ie, but you can also post, email, or (in limited cases) phone.

MethodWhereBest For
Online webformdataprotection.ie/en/contact/make-complaintMost complaints — fastest acknowledgement
Emailinfo@dataprotection.ieAttaching large evidence files
Post21 Fitzwilliam Square South, Dublin 2, D02 RD28If you prefer hard-copy records
Phone+353 578 684 800General queries, not formal complaints

Step 3: Complete the Complaint Form

The webform asks you to provide:

  1. Your personal details (the DPC does not accept anonymous complaints)
  2. Details of the organisation you are complaining about
  3. The nature of the alleged infringement
  4. Dates and a chronological narrative
  5. Evidence of your attempts to resolve the matter directly
  6. Any supporting documents (PDFs, screenshots, emails)
  7. The outcome you are seeking (e.g. erasure, compensation referral, enforcement action)

Step 4: Submit and Wait for Acknowledgement

The DPC typically acknowledges receipt within 10 working days. You will be assigned a case reference number — keep this safe, as you will need it for all future correspondence.

Step 5: Engage with the Assessment Process

A case officer will review your complaint and may contact you for additional information. They may also attempt "amicable resolution" — effectively mediating between you and the organisation. If that fails, the DPC can escalate to a formal statutory inquiry.

What Happens After You File?

The DPC's complaint-handling process has several possible paths. Understanding them helps you set realistic expectations.

Amicable Resolution

In many cases, the DPC will try to broker a direct resolution between you and the organisation. This is quicker and less formal — the organisation might agree to delete your data, correct it, or change its practices. If both parties accept, the matter is closed.

Formal Investigation

If amicable resolution is not possible or appropriate (particularly for systemic breaches), the DPC can open a statutory inquiry under section 110 of the Data Protection Act 2018. These inquiries can take months or years, especially in cross-border cases involving multinationals.

Possible Outcomes

  • Reprimand: A formal warning placed on the organisation's record
  • Compliance order: The organisation is ordered to change specific practices
  • Processing ban: Temporary or permanent prohibition on certain data uses
  • Administrative fine: Up to €20 million or 4% of global turnover
  • No infringement found: The DPC closes the case without action

How Long Does a DPC Complaint Take?

Timelines vary enormously based on complexity. Here is a realistic breakdown:

Complaint TypeTypical Timeframe
Simple access request dispute (Irish company)3–6 months
Marketing or cookie complaint6–12 months
Breach involving sensitive data9–18 months
Cross-border inquiry (Big Tech)2–5+ years

If three months pass with no substantive update, GDPR Article 78 gives you the right to seek a judicial remedy in the Irish Circuit Court or High Court against the DPC's inaction.

Cross-Border Complaints and the One-Stop-Shop

Because Ireland hosts the European headquarters of many major platforms, complaints against these companies — even if you live in another EU country — often end up with the DPC as the "lead supervisory authority". You can still file your complaint with your local national regulator (for example, the CNIL in France or the BfDI in Germany), and they will transfer it to the DPC under GDPR's one-stop-shop mechanism.

This system has drawn criticism for creating bottlenecks and inconsistent enforcement, but reforms announced by the European Commission in 2024 aim to speed up cross-border cooperation and dispute resolution between regulators.

Protecting Your Privacy Day-to-Day

Filing a complaint is a reactive step. The better long-term strategy is to minimise how much personal data you expose in the first place. A few practical habits:

  • Use encrypted DNS resolvers (such as Cloudflare 1.1.1.1 or Quad9) to prevent your network provider from logging every site you visit
  • Switch to a privacy-focused browser like Firefox or Brave with strict tracking protection enabled
  • Use disposable email aliases for one-off signups
  • Review and revoke app permissions on your phone every few months
  • Use a privacy-respecting URL shortener like Lunyb instead of trackers-heavy alternatives when sharing links, so that recipients are not profiled by third parties the moment they click. For a wider comparison, see our 2026 buyer's guide to URL shorteners.

If you are evaluating link-sharing tools specifically for GDPR-sensitive contexts, our honest review of Lunyb and our Rebrandly 2026 review both cover the data-handling practices worth checking before you integrate any shortener into a workflow that touches personal data.

Common Mistakes to Avoid

1. Not Contacting the Organisation First

The DPC may bounce your complaint back if you have not given the organisation a fair chance to respond. Always exhaust direct channels first and document every step.

2. Submitting Vague Complaints

"Facebook misused my data" is not actionable. The DPC needs specifics: which account, which processing activity, which right was violated, and when.

3. Missing Deadlines

While there is no strict statute of limitations on GDPR complaints, filing promptly — ideally within 12 months of becoming aware of the issue — significantly strengthens your case.

4. Expecting Personal Compensation

The DPC does not award financial compensation to complainants. If you want damages, you must bring a separate civil action in the Irish courts under section 117 of the Data Protection Act 2018.

5. Giving Up After Delays

Follow up every 90 days, in writing, with your case reference. Persistent complainants get faster progress.

Your Rights Alongside the Complaints Process

Filing a complaint does not prevent you from exercising other legal rights in parallel. Under GDPR you can:

  • Lodge a complaint in your own Member State's regulator (Article 77)
  • Seek an effective judicial remedy against the organisation (Article 79)
  • Seek a judicial remedy against the DPC itself for inaction or an unsatisfactory outcome (Article 78)
  • Claim compensation for material or non-material damage (Article 82)
  • Mandate a non-profit organisation (such as NOYB or Digital Rights Ireland) to lodge the complaint on your behalf (Article 80)

FAQ

Is there a fee to file a complaint with the DPC Ireland?

No. Lodging a complaint with the Data Protection Commission is completely free of charge, as required by GDPR Article 57(3). You do not need a solicitor, although you may choose to use one for complex cases.

Can I file a complaint anonymously?

No. The DPC requires your name and contact details so that it can process the complaint, correspond with you, and verify your standing as a data subject. However, the DPC will not disclose your identity to the organisation without your consent where it is not strictly necessary.

What if I live outside Ireland but want to complain about an Irish-based company?

You can either file directly with the DPC or lodge the complaint with your local national supervisory authority, which will transfer it to the DPC under the one-stop-shop mechanism. Filing directly is usually faster.

Can I get compensation through a DPC complaint?

No, the DPC cannot award compensation. If you want financial damages, you must bring a civil claim in the Irish Circuit Court or High Court under section 117 of the Data Protection Act 2018. A successful DPC finding, however, can strengthen a subsequent civil claim.

What happens if the DPC rules against me?

You have the right under GDPR Article 78 to appeal the decision in the Irish courts within 28 days of being notified. You may also ask the DPC to review the matter if new evidence emerges.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles