facebook-pixel

GDPR in Ireland: Your Privacy Rights Explained (2026 Guide)

L
Lunyb Security Team
··11 min read

Ireland occupies a unique position in the European data protection landscape. As the European headquarters for Google, Meta, TikTok, Microsoft, LinkedIn, and countless other global technology companies, Dublin has become one of the most important regulatory capitals in the world. The Irish Data Protection Commission (DPC) is the lead supervisory authority for a huge share of the EU's digital economy, and the General Data Protection Regulation (GDPR) is enforced here with real teeth — Ireland has issued some of the largest privacy fines ever recorded.

But GDPR is not just about billion-euro headlines. It is a personal set of rights that every resident in Ireland can exercise, often for free and with minimal paperwork. This guide breaks down what GDPR actually means for you in Ireland, how to use your rights, and what to do when a company gets it wrong.

What Is GDPR and How Does It Apply in Ireland?

The General Data Protection Regulation (GDPR) is an EU-wide law that came into force on 25 May 2018. It governs how organisations collect, store, use, and share personal data about individuals in the European Union and European Economic Area. In Ireland, GDPR is supplemented by the Data Protection Act 2018, which fills in national details such as the age of digital consent (16 in Ireland) and rules for law enforcement processing.

GDPR applies to any organisation — Irish or foreign — that processes the personal data of people located in Ireland. That includes:

  • Irish businesses of any size, from sole traders to multinationals
  • Public bodies such as the HSE, Revenue, and local councils
  • Schools, universities, and charities
  • Foreign websites and apps that target Irish users or track them

"Personal data" is defined very broadly. It covers anything that can identify you: your name, email address, phone number, IP address, location data, photographs, CCTV footage, health records, purchase history, and even cookie identifiers.

The Role of the Irish Data Protection Commission (DPC)

The Data Protection Commission, based in Dublin and Portarlington, is Ireland's independent regulator for data protection. It has three main functions: handling complaints from individuals, investigating breaches, and enforcing GDPR against organisations that break the rules.

Because so many US tech giants have their EU headquarters in Ireland, the DPC acts as the "lead supervisory authority" for cross-border cases under GDPR's one-stop-shop mechanism. This means a complaint filed in Berlin or Madrid about Meta or TikTok is often ultimately handled by the DPC in Dublin.

Recent enforcement actions include:

  • A €1.2 billion fine against Meta in 2023 for unlawful transfers of European user data to the United States
  • A €345 million fine against TikTok in 2023 for how it processed children's data
  • Multiple nine-figure penalties against WhatsApp and Instagram for transparency failures

Your Eight Core Rights Under GDPR

GDPR gives every person in Ireland eight enforceable rights over their personal data. Organisations must generally respond to a request within one calendar month, free of charge.

1. The Right to Be Informed

You have the right to know what data is being collected about you, why, how long it will be kept, and who it will be shared with. This is why every legitimate website has a privacy notice.

2. The Right of Access (Subject Access Request)

You can ask any organisation to give you a copy of the personal data they hold about you. This is known as a Subject Access Request or SAR. The organisation has one month to respond and cannot charge you unless the request is "manifestly unfounded or excessive."

3. The Right to Rectification

If a company holds inaccurate or incomplete data about you, you can require them to correct it.

4. The Right to Erasure ("Right to Be Forgotten")

In many circumstances you can demand that your data be deleted — for example, when it is no longer needed for the original purpose, when you withdraw consent, or when it has been processed unlawfully.

5. The Right to Restrict Processing

You can require an organisation to stop actively using your data while a dispute (such as an accuracy challenge) is being resolved.

6. The Right to Data Portability

For data you provided yourself under consent or a contract, you can ask to receive it in a structured, commonly used, machine-readable format — and have it sent directly to another provider where technically feasible.

7. The Right to Object

You have an absolute right to object to your data being used for direct marketing. You can also object to processing based on "legitimate interests" or public tasks, though the organisation may push back with compelling grounds.

8. Rights Related to Automated Decision-Making

You have the right not to be subject to purely automated decisions — including profiling — that produce legal or similarly significant effects on you, such as an automated loan refusal or algorithmic hiring decision.

Legal Bases for Processing Your Data

An Irish organisation cannot process your personal data unless it can point to one of six lawful bases under Article 6 of GDPR. Understanding these helps you know when you can push back.

Legal BasisWhat It MeansTypical Example in Ireland
ConsentYou freely agreed after being clearly informedSigning up for a marketing newsletter
ContractProcessing needed to fulfil a contract with youAn Post processing your address to deliver a parcel
Legal ObligationRequired by Irish or EU lawRevenue processing your PPS number
Vital InterestsNecessary to protect someone's lifeAmbulance service sharing your medical data in an emergency
Public TaskRequired to perform an official public functionA local council issuing planning permission
Legitimate InterestsNecessary for a genuine business interest, balanced against your rightsFraud prevention checks by a bank

Special category data — including health information, religious beliefs, political opinions, sexual orientation, and biometrics — needs an additional condition under Article 9, usually explicit consent or a specific legal permission.

How to Make a Subject Access Request in Ireland

Making a Subject Access Request (SAR) is one of the most powerful tools GDPR gives you. Here is a step-by-step approach:

  1. Identify the data controller. This is the organisation that decides how and why your data is processed. Look on their website for a "Data Protection" or "Privacy" contact.
  2. Write your request in clear terms. You do not need to cite GDPR articles, but it helps. State that you are exercising your right of access under Article 15 GDPR.
  3. Be specific if possible. Narrowing the request (for example, "all emails between me and your support team in 2024") often gets a faster, more useful response.
  4. Prove your identity. The controller may ask for reasonable ID to make sure they are not disclosing your data to someone else.
  5. Wait one month. They must respond within 30 calendar days, extendable by two months for complex requests.
  6. Escalate if ignored. If you get no reply or an inadequate one, you can complain to the DPC.

Making a Complaint to the DPC

If an organisation refuses to respect your rights, mishandles your data, or suffers a breach that affects you, you can complain directly to the Data Protection Commission. Filing is free.

You can lodge a complaint through the DPC's online form at dataprotection.ie, by post to their offices in Portarlington or Dublin, or by email. Include:

  • Your name and contact details
  • The name of the organisation you are complaining about
  • A clear description of what happened and when
  • Copies of any correspondence, screenshots, or evidence
  • What outcome you would like

The DPC will typically try amicable resolution first. If that fails, they can open a formal investigation, issue reprimands, order corrective action, or impose administrative fines of up to €20 million or 4% of a company's global annual turnover — whichever is higher.

Data Breaches: What Organisations Must Do

A personal data breach is any incident that leads to accidental or unlawful destruction, loss, alteration, unauthorised disclosure of, or access to personal data. Examples include ransomware attacks, misdirected emails containing customer lists, lost unencrypted laptops, and unauthorised staff snooping.

Under GDPR, Irish organisations must:

  1. Notify the DPC within 72 hours of becoming aware of a breach, unless it is unlikely to result in a risk to individuals
  2. Notify affected individuals "without undue delay" if the breach is likely to result in a high risk to their rights and freedoms
  3. Document every breach internally, even those not reported

If you receive a breach notification, take it seriously. Change passwords, enable two-factor authentication, watch your bank statements, and consider registering with a credit-monitoring service.

GDPR, Cookies, and the ePrivacy Regulations

Cookie consent in Ireland is governed by both GDPR and the ePrivacy Regulations (S.I. 336 of 2011). In 2020 the DPC issued detailed cookie guidance that made clear:

  • Pre-ticked boxes are not valid consent
  • "Continued browsing" does not equal consent
  • Rejecting cookies must be as easy as accepting them
  • Strictly necessary cookies (like session or security cookies) do not need consent, but analytics and advertising cookies do

If a website you use in Ireland does not offer a clear "Reject All" button on its cookie banner, it is very likely breaching the rules.

Practical Steps to Protect Your Privacy in Ireland

Knowing your rights is only half the battle. Building good habits reduces how much personal data ends up in circulation in the first place.

  • Audit your accounts annually. Delete accounts on services you no longer use. Each dormant account is a future breach waiting to happen.
  • Use a password manager and enable two-factor authentication everywhere it is offered.
  • Switch to privacy-respecting tools where possible: encrypted DNS providers, privacy-focused browsers like Brave or Firefox, and search engines that do not build advertising profiles.
  • Be careful with the links you share. Long URLs often contain tracking parameters that leak information about you and the recipient. A privacy-conscious URL shortener like Lunyb can strip those parameters and give you clean, shareable links — you can read our honest review of Lunyb or see how it compares in our 2026 buyer's guide to URL shorteners.
  • Read privacy notices — at least the summary sections — before ticking consent boxes.
  • Exercise your right to object to marketing. Every legitimate email must have an unsubscribe link.

GDPR for Small Businesses and Sole Traders in Ireland

If you run a small business in Ireland, GDPR applies to you from the moment you collect a single customer email address. The good news is that compliance for a small operation is manageable if you approach it methodically:

  1. Map your data: what do you collect, why, where is it stored, and who has access?
  2. Identify your legal basis for each processing activity
  3. Publish a clear, plain-English privacy notice on your website
  4. Put a written contract in place with any processor (e.g. your email marketing tool, cloud storage provider, or accountant)
  5. Have a simple procedure to handle SARs and breaches
  6. Train anyone with access to customer data

The DPC publishes free guidance specifically aimed at SMEs, and there is no requirement for most small businesses to appoint a Data Protection Officer unless they carry out large-scale monitoring or process special category data as a core activity.

Frequently Asked Questions

How long does an Irish company have to respond to my data request?

One calendar month from the day they receive your request. They may extend by a further two months for particularly complex or numerous requests, but they must tell you about the extension within the original month and explain why.

Can I be charged for a Subject Access Request?

No, not in normal circumstances. Access is free. An organisation can only charge a "reasonable fee" if your request is manifestly unfounded, excessive, or repetitive — and they must justify that decision. They can also charge for additional copies beyond the first.

What is the age of digital consent in Ireland?

Under the Data Protection Act 2018, the age of digital consent in Ireland is 16. Below that age, an information society service (such as a social network) offered directly to a child needs consent from a parent or guardian to process the child's data on the basis of consent.

Does GDPR still apply after Brexit if my data goes to the UK?

Yes. Transfers of personal data from Ireland to the UK remain lawful because the European Commission has granted the UK an "adequacy decision." That means the UK is considered to offer an essentially equivalent level of protection. If that decision were ever withdrawn, additional safeguards such as Standard Contractual Clauses would be required.

What can the DPC actually do if I complain?

The DPC has a wide range of powers. It can investigate the organisation, issue reprimands, order it to comply with your rights, ban specific processing activities, suspend international data transfers, and impose administrative fines of up to €20 million or 4% of worldwide annual turnover, whichever is higher. In serious cases it can refer criminal offences to the DPP.

Conclusion

GDPR gives people in Ireland some of the strongest privacy rights in the world — but those rights only matter if you use them. Whether you are asking a retailer for a copy of your data, telling a marketer to stop emailing you, or complaining to the DPC about a breach, every request you make helps reinforce a culture where personal data is treated as something valuable rather than something to be harvested. Combine that with sensible everyday habits — clean links, strong passwords, privacy-respecting tools — and you can meaningfully reduce your digital footprint while still enjoying modern online services.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles