DPC Ireland: How to File a Privacy Complaint (2026 Guide)
If an organisation has mishandled your personal data, Ireland's Data Protection Commission (DPC) is the statutory body that can investigate on your behalf. Because Ireland hosts the European headquarters of many of the world's largest technology companies — including Meta, Google, TikTok, Microsoft, Apple and LinkedIn — the DPC is one of the most influential privacy regulators in the European Union. This guide explains exactly how to file a privacy complaint with the DPC, what to expect, and how to maximise your chances of a successful outcome.
What Is the Data Protection Commission (DPC)?
The Data Protection Commission is Ireland's independent authority responsible for enforcing the General Data Protection Regulation (GDPR) and the Data Protection Act 2018. It is the lead supervisory authority for most major U.S. tech companies operating in the EU, which gives it cross-border enforcement powers under the GDPR's "one-stop-shop" mechanism.
The DPC handles tens of thousands of queries and complaints every year, ranging from unlawful marketing emails to large-scale data breaches. Its remit covers any organisation — public or private — that processes personal data of individuals located in Ireland or, in cross-border cases, elsewhere in the EU.
What the DPC Can Do
- Investigate complaints against data controllers and processors
- Issue reprimands, warnings, orders, and corrective measures
- Impose administrative fines of up to €20 million or 4% of global annual turnover
- Order companies to stop processing or delete data
- Refer matters for criminal prosecution in limited circumstances
What the DPC Cannot Do
- Award financial compensation to individuals (that requires a civil court action)
- Overturn decisions made outside its data protection remit
- Act as a general consumer protection body
When You Can File a Complaint
You can lodge a complaint with the DPC if you believe your rights under the GDPR or the Data Protection Act 2018 have been infringed. Common grounds include:
- Access requests ignored: You submitted a Subject Access Request (SAR) and did not receive a response within one month (extendable by two further months for complex cases).
- Unlawful marketing: You received unsolicited emails, SMS, or phone calls without valid consent.
- Data breach: Your personal data was exposed, lost, or stolen and the controller failed to notify you where required.
- Excessive data collection: An organisation collected more data than necessary for its stated purpose.
- Refusal to erase data: A valid "right to be forgotten" request was ignored or refused without lawful basis.
- CCTV misuse: A neighbour or business has cameras capturing more than their own property.
- Workplace monitoring: An employer is monitoring staff without transparency or lawful basis.
- Cookie consent violations: A website drops tracking cookies before you consent.
Step 1: Try to Resolve It Directly First
The DPC strongly encourages — and in many cases requires — that you first attempt to resolve the matter directly with the organisation involved. This is both a practical and procedural requirement: the DPC will usually ask what steps you have taken before escalating.
How to Contact the Organisation
Every organisation that processes personal data must provide a contact point for data protection queries. For larger entities, this will be a Data Protection Officer (DPO), whose contact details are typically found in the company's privacy policy.
When writing to them:
- Clearly state which right you are exercising (e.g. access, erasure, objection)
- Provide enough information to identify yourself
- Give a reasonable deadline — one calendar month is the statutory limit
- Keep copies of all correspondence
What If They Don't Respond?
If the organisation fails to respond within one month, or if the response is unsatisfactory, you have a clear basis to escalate to the DPC. Keep every email, letter, and tracking receipt — these form part of your evidence.
Step 2: Gather Your Evidence
The strength of a DPC complaint largely depends on the quality of evidence you submit. Before filing, compile the following into a single folder or PDF:
- Your identity details: Full name, address, email, phone number
- The organisation's details: Company name, registered address, DPO contact
- Correspondence trail: All emails, letters, chat transcripts
- Dates and timeline: When the issue started, when you contacted them, when they responded (or failed to)
- Screenshots: Of problematic settings, marketing messages, cookie banners, or privacy notices
- Specific GDPR articles you believe were breached (optional but helpful)
- The outcome you want: Deletion, correction, cessation of processing, etc.
Step 3: Choose the Right Complaint Channel
The DPC offers several ways to submit a complaint. Choosing the right one speeds up handling.
| Channel | Best For | Typical Response Time |
|---|---|---|
| Webform at dataprotection.ie | Standard complaints with evidence | 2–6 weeks for initial acknowledgement |
| Email (info@dataprotection.ie) | Preliminary queries, additional documents | 2–4 weeks |
| Postal letter | Formal legal correspondence, no digital access | 4–8 weeks |
| Phone (01 765 0100) | General guidance only (not formal complaints) | Same day |
| Breach notification portal | Organisations reporting their own breaches | 72 hours (statutory) |
The Official Complaint Form
The webform is the preferred route for individuals. It walks you through structured questions, which reduces back-and-forth. You can upload supporting documents directly. The form is available in both English and Irish.
Step 4: What Happens After You File
Once your complaint is submitted, the DPC follows a defined process. Understanding each stage helps you set realistic expectations.
- Acknowledgement: You'll receive confirmation of receipt, usually within 10 working days, with a case reference number.
- Assessment: A case officer reviews whether the complaint falls within the DPC's remit and whether it is well-founded on its face.
- Amicable resolution: The DPC will usually attempt to resolve the matter informally by contacting the organisation. Many cases end here.
- Formal investigation: If amicable resolution fails, the DPC may open a statutory inquiry under Section 110 of the Data Protection Act 2018.
- Decision: The DPC issues a legally binding decision, which may include corrective measures and/or administrative fines.
- Appeal: Either party may appeal to the Circuit Court or High Court within 28 days.
Simple complaints can be resolved in a few months. Complex cross-border cases involving major tech platforms can take two to five years, partly because they must be coordinated with other EU supervisory authorities under the one-stop-shop mechanism.
Step 5: Cross-Border Complaints
If your complaint concerns a company whose EU headquarters is in Ireland (which is true of most major U.S. tech firms), the DPC acts as the "lead supervisory authority" for the entire EU. You do not have to file in Ireland yourself — you can file with your own national data protection authority, which will forward it to the DPC.
However, filing directly with the DPC can sometimes be faster, especially for English-language correspondence. Either route is legally valid under GDPR Article 77.
Protecting Yourself Before You Need to Complain
Prevention is always better than remediation. A few habits dramatically reduce the chances of your data ending up in the wrong hands:
- Use unique, strong passwords stored in a reputable password manager.
- Enable two-factor authentication on every account that supports it.
- Minimise the data you share — do not fill in optional form fields.
- Review privacy settings quarterly on social media and major platforms.
- Use privacy-respecting tools for everyday tasks. For example, when sharing links on social media or in email signatures, a privacy-focused URL shortener like Lunyb avoids the aggressive tracking cookies embedded by some alternatives. See our honest review of Lunyb for more detail, or compare the main providers in our 2026 buyer's guide.
- Check breach notification services like Have I Been Pwned regularly.
Common Mistakes That Weaken a Complaint
Case officers regularly see complaints undermined by avoidable errors. Avoid these:
- Skipping the direct contact stage — the DPC may send you back to try first.
- Vague allegations — "They have my data" is not enough; explain what, when, and how.
- Missing evidence — screenshots and copies of correspondence are essential.
- Expecting compensation — the DPC cannot award damages; that requires a separate civil action.
- Complaining about non-GDPR issues — defamation, consumer disputes, and employment matters generally fall outside the DPC's remit.
- Submitting duplicate complaints through multiple channels, which only slows processing.
Your Rights Alongside a DPC Complaint
Filing with the DPC is not your only option. Under GDPR Article 82, you also have the right to seek compensation through the Irish courts for material or non-material damage caused by a breach. These two routes can run in parallel; a DPC decision in your favour can strengthen a subsequent civil case.
You also retain the right to:
- Lodge a complaint with the data protection authority of your habitual residence in another EU state
- Seek a judicial remedy against the DPC itself if it fails to handle your complaint
- Receive information about the progress of your complaint within three months
Frequently Asked Questions
Is there a fee to file a complaint with the DPC?
No. Filing a complaint with the Data Protection Commission is completely free. The DPC is funded by the Irish State and does not charge individuals for investigating potential GDPR infringements. Legal representation is not required, although you may choose to engage a solicitor for complex matters.
How long do I have to file a complaint?
The GDPR does not set a strict statutory limitation period, but the DPC generally expects complaints to be filed within a reasonable time of the issue arising — typically within one year. Complaints about older matters may still be accepted if there is a good reason for the delay, but older evidence is harder to investigate.
Can I file a complaint anonymously?
No. The DPC requires your identity to investigate properly, as it needs to verify your relationship to the data in question and communicate with you about the outcome. However, the DPC will handle your information confidentially and will not share your identity with the organisation unless strictly necessary to progress the complaint.
What if the DPC decides not to investigate my complaint?
The DPC must give you reasons in writing if it decides not to pursue your complaint. You have the right to a judicial remedy under Article 78 GDPR, meaning you can challenge the DPC's decision in the Irish courts. You can also escalate to the European Data Protection Board in cross-border matters.
Will the organisation know I complained?
In most cases, yes. To investigate, the DPC must put the allegations to the organisation, and this will usually identify you — particularly where the complaint concerns your own data. If you fear retaliation (for example, in an employment context), you should raise this with the case officer at the outset so appropriate safeguards can be considered.
Can non-Irish residents file with the DPC?
Yes. If the organisation you are complaining about has its main EU establishment in Ireland, the DPC acts as the lead supervisory authority regardless of where you live in the EU. You can also file with your own national authority and ask them to forward the matter to the DPC under the one-stop-shop mechanism.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Data Protection Act 2018 Ireland: Complete Guide
The Data Protection Act 2018 gives effect to the GDPR in Ireland and sets out the obligations of controllers and processors. This complete guide explains the Act's scope, key definitions, data subject rights, enforcement by the DPC, and a practical compliance checklist for Irish organisations.
Bill C-27 Digital Charter: What Canadian Businesses Need to Know
Bill C-27, Canada's Digital Charter Implementation Act, overhauls private-sector privacy law and introduces the country's first federal AI legislation. Learn what the CPPA, PIDPTA, and AIDA mean for your business and how to prepare for compliance.
OAIC Complaints: How to Report a Privacy Breach in Australia
A complete Australian guide to lodging a privacy complaint with the OAIC. Learn the mandatory first steps, evidence to gather, timelines, conciliation outcomes, and when you can seek compensation under the Privacy Act 1988.
Singapore PDPA vs GDPR: Key Differences for Businesses in 2026
Singapore's PDPA and the EU's GDPR share common ground but differ sharply on consent, breach timelines, DPO rules, and penalties. This guide compares both laws side-by-side and offers practical compliance steps for businesses operating across jurisdictions.