GDPR in Ireland: Your Privacy Rights Explained
Ireland sits at the heart of European data protection. With most major tech giants — Meta, Google, TikTok, Apple, Microsoft — running their European headquarters from Dublin, the Irish Data Protection Commission (DPC) is effectively the lead regulator for how billions of people's data is handled across the EU. That makes understanding your GDPR rights in Ireland especially important, whether you're a consumer, a small business owner, or an employee wondering what your employer can and can't do with your data.
This guide breaks down the General Data Protection Regulation (GDPR) as it applies in Ireland, explains each of your privacy rights in plain English, and shows you how to actually exercise them.
What Is GDPR and How Does It Apply in Ireland?
The General Data Protection Regulation (GDPR) is an EU-wide law that came into force on 25 May 2018. It governs how organisations collect, use, store, and share personal data about individuals located in the EU. In Ireland, GDPR is implemented alongside the Data Protection Act 2018, which fills in national-level details such as the powers of the DPC and specific rules for children, employees, and law enforcement.
Personal data under GDPR is broadly defined. It includes obvious things like your name, address, PPS number, and email — but also IP addresses, cookies, location data, photographs, and even opinions expressed about you. If a piece of information can identify you directly or indirectly, GDPR applies.
Who Enforces GDPR in Ireland?
The Data Protection Commission (DPC), based in Dublin and Portarlington, is Ireland's independent supervisory authority. Because so many multinationals have their EU base in Ireland, the DPC operates as the "lead supervisory authority" for cross-border cases under the GDPR's one-stop-shop mechanism. Recent multi-hundred-million-euro fines against Meta, TikTok, and Instagram were all issued by the Irish DPC.
Your Eight Core Privacy Rights Under GDPR
GDPR gives every person in Ireland eight enforceable rights over their personal data. Organisations must respond to requests generally within one month, free of charge, and in a clear format.
1. The Right to Be Informed
Any organisation collecting your data must tell you — up front and in plain language — who they are, what data they're collecting, why, how long they'll keep it, and who they'll share it with. This is why you see privacy notices and cookie banners on websites. If a company hides this or buries it in legalese, they're breaking the law.
2. The Right of Access (Subject Access Request)
You can ask any organisation for a copy of the personal data they hold about you. This is called a Subject Access Request (SAR). They must respond within one month, provide the data in a readable format, and explain how they're using it. Common examples include requesting your file from an employer, medical records from a GP, or your full activity history from a social network.
3. The Right to Rectification
If data an organisation holds about you is inaccurate or incomplete, you can require them to correct it without undue delay. This applies to everything from a misspelled name on a bank account to an incorrect job title on a professional platform.
4. The Right to Erasure ("Right to Be Forgotten")
You can ask an organisation to delete your data when it's no longer needed, when you withdraw consent, or when it's being processed unlawfully. There are exceptions — for example, banks must keep certain records for anti-money-laundering purposes, and journalists can rely on freedom of expression exemptions.
5. The Right to Restrict Processing
You can require an organisation to pause processing your data while a dispute is resolved — for example, while they investigate whether the data is accurate, or while you object to their use of it.
6. The Right to Data Portability
You can ask for your data in a structured, commonly used, machine-readable format (usually CSV or JSON) so you can move it to another service. This is common when switching banks, streaming services, or fitness apps.
7. The Right to Object
You can object to your data being used for direct marketing at any time — and the organisation must stop immediately, no questions asked. You can also object to processing based on "legitimate interests" or public tasks, though the organisation may push back if they have compelling reasons.
8. Rights Related to Automated Decision-Making
You have the right not to be subject to purely automated decisions — including profiling — that have significant effects on you (like being refused a loan or a job by an algorithm). You can demand human review.
Legal Bases: When Can Organisations Actually Use Your Data?
Organisations can't just process your data because they feel like it. They need one of six legal bases under Article 6 of GDPR.
| Legal Basis | When It's Used | Example in Ireland |
|---|---|---|
| Consent | You've clearly agreed | Signing up to a marketing newsletter |
| Contract | Needed to deliver a service you asked for | An Post using your address to deliver a parcel |
| Legal obligation | Required by law | Revenue collecting your PPS number |
| Vital interests | Life-or-death situations | A hospital sharing your blood type in an emergency |
| Public task | Official function | The HSE running vaccination programmes |
| Legitimate interests | Reasonable business use, balanced against your rights | A shop keeping CCTV for security |
For sensitive data — health, ethnicity, religion, sexual orientation, biometrics — organisations need an even stronger justification under Article 9.
How to Make a Data Protection Complaint in Ireland
If you believe an organisation has mishandled your data, ignored a request, or failed to protect your information, you can complain directly to the Data Protection Commission. The DPC handles thousands of complaints each year from Irish residents.
- Contact the organisation first. Write to their Data Protection Officer (DPO) or privacy team. Explain the issue clearly and state which right you're relying on. Keep a copy of everything.
- Give them one month to respond. This is the statutory deadline for most GDPR requests.
- Gather evidence. Save emails, screenshots, letters, and dates. The DPC will ask for these.
- Submit a complaint to the DPC. Use the online form at dataprotection.ie, or write to their office in Portarlington. There is no fee.
- Cooperate with the investigation. The DPC may mediate, investigate formally, or issue binding decisions and fines.
- Escalate if needed. You can appeal DPC decisions to the Circuit Court, or seek compensation through the courts for material or non-material damage.
Special Rules for Employees and Children in Ireland
Workplace Data
Employers in Ireland must have a clear legal basis to monitor staff. Blanket surveillance of emails, keystrokes, or location without notice is generally unlawful. Employees have full access rights, meaning you can request everything HR holds about you — including performance notes, disciplinary records, and internal messages that reference you.
Children's Data
Ireland set the digital age of consent at 16 under the Data Protection Act 2018. This means online services offering things like social media accounts to under-16s must obtain verifiable parental consent. The DPC's "Fundamentals for a Child-Oriented Approach to Data Processing" sets out 14 principles that platforms must follow when their services are likely to be used by children.
Practical Steps to Protect Your Privacy Online
Knowing your rights is only half the battle. Reducing how much personal data you expose in the first place makes those rights easier to exercise.
- Audit your account permissions. Regularly check which apps have access to your Google, Apple, and Facebook accounts. Revoke anything you don't actively use.
- Use encrypted DNS and private browsers. Browsers like Firefox and Brave block trackers by default. Encrypted DNS services stop your internet provider from logging every site you visit.
- Minimise link tracking. Many shortened links harvest analytics such as IP address, device, and location. If you share links regularly, use a privacy-respecting shortener like Lunyb, which lets you share short URLs without building detailed profiles of the people who click them. You can read more in our honest Lunyb review or compare options in the 2026 URL shortener buyer's guide.
- Enable two-factor authentication. A data breach at one service becomes much less dangerous if your account can't be logged into with just a password.
- Read the privacy notice before signing up. Look specifically for how long they keep data and whether they share it with third parties for advertising.
- Exercise your rights annually. Send a Subject Access Request to a service you've used for years. You'll be surprised what's in there.
What Happens When Organisations Break GDPR?
GDPR fines can reach €20 million or 4% of a company's global annual turnover, whichever is higher. The Irish DPC has issued some of the largest fines in EU history, including €1.2 billion against Meta in 2023 for illegal EU-US data transfers, €345 million against TikTok for children's data violations, and €405 million against Instagram.
Beyond fines, organisations face reputational damage, compensation claims from affected individuals, and orders to stop the offending processing entirely — which can shut down entire products.
GDPR After Brexit: What Changes for Ireland?
Ireland remains fully within the EU GDPR framework. The UK now has its own "UK GDPR," which is largely similar but diverging over time. For Irish residents, this mainly matters when data flows to UK-based companies. The European Commission has granted the UK an "adequacy decision," meaning data can flow freely — but this is reviewed periodically and could change.
Frequently Asked Questions
How long does an organisation have to respond to my Subject Access Request in Ireland?
One calendar month from the date they receive your request. They can extend this by a further two months for complex or numerous requests, but they must tell you within the first month and explain why.
Can I be charged for making a data protection request?
No. GDPR requests are free of charge. The only exception is if a request is "manifestly unfounded or excessive" — for example, someone submitting identical requests weekly. In that case, an organisation can charge a reasonable admin fee or refuse.
What's the difference between the DPC and the Ombudsman?
The Data Protection Commission specifically handles data protection and privacy matters. The Office of the Ombudsman deals with broader complaints about how public bodies treat citizens. If your complaint is about personal data, go to the DPC.
Does GDPR apply to small businesses and sole traders in Ireland?
Yes. GDPR applies to any organisation processing personal data, regardless of size. However, some requirements (like appointing a Data Protection Officer or keeping formal records of processing) are scaled to the size and risk of the business. A sole trader running a mailing list still needs consent, but doesn't need a full DPO.
Can I claim compensation if my data is misused?
Yes. Under Article 82 of GDPR and Section 117 of the Data Protection Act 2018, you can bring a civil claim in the Circuit Court or High Court for material damage (financial loss) or non-material damage (distress). Irish courts have increasingly awarded compensation for data breaches, though amounts tend to be modest unless significant harm can be shown.
Final Thoughts
GDPR gives people in Ireland some of the strongest privacy rights in the world — but those rights only matter if you use them. Send a Subject Access Request. Object to marketing. Delete accounts you no longer use. Read the privacy notice. Every action you take pushes organisations toward better practices, and every complaint the DPC receives sharpens enforcement across the entire EU.
Privacy isn't just a legal formality; it's control over your own story. In a country that hosts more tech giants per capita than almost anywhere on earth, exercising that control has never been more important.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Australia Privacy Act 2026: Your Rights Explained
The Australia Privacy Act 2026 introduces the biggest overhaul of Australian privacy law in decades. This guide explains your new rights, the obligations on businesses, penalties for breaches, and practical steps to protect your personal information.
ICO Fines 2026: Biggest Data Protection Penalties in the UK
The Information Commissioner's Office continues to impose record penalties in 2026, targeting breaches of UK GDPR, PECR and the Data Protection Act. This guide breaks down the biggest ICO fines of the year, the reasons behind them, and the compliance lessons every UK organisation should take on board.
Data Protection Act 2018 Ireland: The Complete Guide for Businesses
A complete guide to Ireland's Data Protection Act 2018: how it implements the GDPR, key principles, data subject rights, DPC enforcement powers, and penalties. Learn what your business needs to do to stay compliant.
Singapore PDPA: Your Personal Data Protection Rights Explained
Singapore's PDPA gives residents strong rights over how organisations handle their personal data. This guide explains your access, correction, and consent rights, and shows how to file complaints with the PDPC.