facebook-pixel

GDPR in Ireland: Your Privacy Rights Explained (2026 Guide)

L
Lunyb Security Team
··10 min read

The General Data Protection Regulation (GDPR) gives people in Ireland some of the strongest privacy rights in the world. Whether you're shopping online, using social media, or interacting with an Irish public body, GDPR governs how your personal data is collected, stored, and used. This guide explains exactly what those rights are, how to enforce them, and what to do when a company or organisation gets it wrong.

What Is GDPR and How Does It Apply in Ireland?

GDPR is a European Union regulation that came into force on 25 May 2018 and sets a unified standard for how personal data must be processed across all EU member states. In Ireland, it is implemented and supplemented by the Data Protection Act 2018, which appointed the Data Protection Commission (DPC) as the national supervisory authority.

Because many of the world's largest tech companies — Meta, Google, TikTok, Apple, Microsoft, LinkedIn — have their European headquarters in Dublin, the Irish DPC acts as the lead regulator for cross-border data protection cases across the EU. That makes Ireland a uniquely important jurisdiction for global privacy enforcement.

Who Does GDPR Protect?

GDPR protects any identified or identifiable natural person (a "data subject") whose personal data is processed by an organisation. You don't need to be an Irish citizen — if you're physically in Ireland or your data is being processed by an Irish-established organisation, you're covered.

What Counts as Personal Data?

Personal data is any information relating to an identifiable individual. This includes:

  • Names, addresses, and phone numbers
  • Email addresses and usernames
  • IP addresses and device identifiers
  • Location data and browsing history
  • Photographs and CCTV footage
  • Health, financial, and employment records
  • Biometric and genetic data (special category)

Your Eight Core GDPR Rights in Ireland

GDPR grants every person in Ireland eight enforceable rights over their personal data. Understanding them is the first step to protecting your privacy.

1. The Right to Be Informed

Organisations must tell you clearly what data they collect, why, how long they'll keep it, and who they share it with. This is usually provided in a privacy notice or policy at the point of data collection.

2. The Right of Access (Subject Access Request)

You can ask any organisation to give you a copy of the personal data they hold about you. This is called a Subject Access Request (SAR). They must respond within one month, free of charge in most cases.

3. The Right to Rectification

If an organisation holds inaccurate or incomplete data about you, you can require them to correct or complete it — again, within one month.

4. The Right to Erasure ("Right to Be Forgotten")

You can request that your personal data be deleted where it is no longer necessary, where you withdraw consent, or where it was processed unlawfully. This isn't absolute — legal, tax, or public-interest grounds can override it.

5. The Right to Restrict Processing

You can ask an organisation to pause processing your data while a dispute (for example about accuracy or lawfulness) is resolved.

6. The Right to Data Portability

You can request your data in a structured, commonly used, machine-readable format (like CSV or JSON) and have it transferred to another provider — useful when switching banks, mobile operators, or social platforms.

7. The Right to Object

You can object to processing based on legitimate interests, direct marketing, or scientific/statistical research. For direct marketing, the objection is absolute — the organisation must stop immediately.

8. Rights Related to Automated Decision-Making

You have the right not to be subject to a decision based solely on automated processing — including profiling — that produces legal or similarly significant effects, such as automated credit scoring or job screening.

Comparing Your GDPR Rights at a Glance

Right What You Can Do Response Time Cost
AccessGet a copy of your data1 monthFree (usually)
RectificationCorrect inaccurate data1 monthFree
ErasureDelete your data1 monthFree
RestrictionPause processing1 monthFree
PortabilityExport data in machine-readable form1 monthFree
ObjectionStop specific processing1 monthFree
Automated decisionsHuman review of AI decisions1 monthFree
Be informedGet a privacy noticeAt collectionFree

How to Make a Subject Access Request in Ireland

A Subject Access Request is the most commonly used GDPR right. Here's the process step by step:

  1. Identify the data controller. Find out which specific organisation holds your data (check their privacy policy for a Data Protection Officer's contact details).
  2. Write your request. You can email, post, or use an online form. Be clear that you are making a request under Article 15 of the GDPR.
  3. Provide identification. The organisation can request reasonable proof of identity to prevent disclosure to the wrong person.
  4. Specify the data you want. You can request all data or narrow it to a specific timeframe, system, or category to speed things up.
  5. Wait up to one month. Complex or high-volume requests can be extended by a further two months, but the organisation must tell you within the first month.
  6. Review the response. Check the data for accuracy and completeness. If something is missing, follow up in writing.

Sample Subject Access Request Wording

"Dear [Data Protection Officer], under Article 15 of the General Data Protection Regulation, I request a copy of all personal data you hold about me, along with information about the purposes of processing, categories of data, recipients, retention periods, and the source of the data if not collected from me directly. My details are: [name, address, account/customer number]. Please respond within one month."

The Role of the Data Protection Commission (DPC)

The Data Protection Commission is Ireland's independent regulator, based in Dublin and Portarlington. It has three main functions:

  • Handling complaints from individuals whose rights have been breached
  • Investigating and fining organisations that fail to comply
  • Providing guidance to businesses, public bodies, and the public

The DPC has levied some of the largest GDPR fines in EU history, including a €1.2 billion fine against Meta in 2023 for unlawful data transfers, and hundreds of millions against TikTok, WhatsApp, and Instagram. Individuals in Ireland benefit directly from this enforcement capacity.

How to File a Complaint with the DPC

  1. Try to resolve the issue with the organisation first — the DPC generally expects this.
  2. If unresolved, submit a complaint through the DPC's online portal at dataprotection.ie.
  3. Include a description of the issue, the organisation's response, and any supporting documents (emails, screenshots).
  4. The DPC will assess admissibility and open an inquiry if warranted.
  5. Outcomes can include enforcement notices, corrective orders, or administrative fines up to €20 million or 4% of global annual turnover, whichever is higher.

Special Categories of Data and Extra Protections

Some personal data is considered particularly sensitive under Article 9 of the GDPR and receives extra protection. Processing is prohibited unless a specific legal basis applies.

  • Racial or ethnic origin
  • Political opinions
  • Religious or philosophical beliefs
  • Trade union membership
  • Genetic and biometric data (when used for identification)
  • Health data
  • Data concerning sex life or sexual orientation

In Ireland, health data held by the HSE, GPs, and private clinics falls under both GDPR and the Health Research Regulations. Employers must also be especially careful with employee health and sickness records.

Children's Data: The Irish Digital Age of Consent

Ireland set the digital age of consent at 16 years, meaning children under 16 cannot legally consent to their data being processed by online services — parental consent is required. This affects sign-ups to social media, gaming platforms, and many educational apps. The DPC's Fundamentals for a Child-Oriented Approach to Data Processing sets out 14 specific principles service providers must follow when children are likely users.

Everyday Practical Privacy Tips for Irish Users

Knowing your rights is one thing; reducing the amount of personal data you expose in the first place is even better. Some practical habits:

  1. Read privacy notices before signing up. Focus on retention periods and third-party sharing.
  2. Use strong, unique passwords and enable two-factor authentication where available.
  3. Limit link tracking. When sharing URLs on social media or in messages, use a privacy-focused shortener like Lunyb, which lets you share clean, controlled links without exposing referral parameters. You can read our honest review of Lunyb to see how it compares.
  4. Review app permissions on your phone quarterly. Revoke anything you no longer use.
  5. Opt out of marketing lists — under GDPR, your objection is absolute and immediate.
  6. Use encrypted messaging (Signal, iMessage, WhatsApp) rather than SMS for sensitive conversations.
  7. Enable encrypted DNS (DNS-over-HTTPS) in your browser to reduce network-level snooping.

If you run a business or side-project and share links with customers, choosing tools that respect data minimisation matters. Our 2026 buyer's guide to URL shorteners and our Rebrandly review both cover how different providers handle logs, click data, and EU data residency.

What Happens When an Organisation Breaches GDPR?

A personal data breach is any security incident leading to accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access to personal data. Under GDPR:

  • Controllers must notify the DPC within 72 hours of becoming aware of a breach where there's a risk to individuals.
  • If the risk is high, they must also notify affected individuals directly, without undue delay.
  • You can seek compensation for material or non-material damage (including distress) through the Circuit Court or High Court in Ireland.

Recent Enforcement Highlights

Ireland's DPC has been at the centre of landmark cases: the Schrems II ruling reshaped EU–US data transfers, and multi-hundred-million euro fines against major platforms have set precedents for behavioural advertising, children's data, and cross-border transfers. These decisions directly strengthen the rights of Irish residents.

GDPR at Work: Your Rights as an Employee

Your employer is a data controller. That means they must have a lawful basis for processing your data, provide a privacy notice, and respect your rights. Key points for Irish employees:

  • CCTV monitoring must be proportionate, signposted, and justified.
  • Email and internet monitoring requires clear policies and, in most cases, prior notice.
  • Biometric clock-in systems need explicit consent and a Data Protection Impact Assessment.
  • You can make a Subject Access Request to your employer — including for HR files, disciplinary records, and manager emails referencing you.

Frequently Asked Questions

How long does an organisation have to respond to my GDPR request in Ireland?

One calendar month from receipt of a valid request. This can be extended by two further months for complex or numerous requests, but the organisation must inform you of the extension (and the reason) within the initial month.

Can I be charged for a Subject Access Request?

No, not in most cases. Requests are free. An organisation can only charge a "reasonable fee" if the request is manifestly unfounded, excessive, or if you're asking for additional copies of the same data.

What can I do if a company ignores my GDPR request?

First, send a follow-up in writing giving them a firm deadline. If they still don't respond, you can lodge a complaint with the Data Protection Commission at dataprotection.ie. You can also pursue civil action for compensation if you've suffered damage or distress.

Does GDPR apply to small businesses and sole traders in Ireland?

Yes. GDPR applies to any organisation processing personal data, regardless of size. However, obligations are proportionate — a sole trader with a customer mailing list has far fewer administrative requirements than a multinational, but the core principles (lawfulness, transparency, security) still apply.

Can I request deletion of my data from Google or Meta?

Yes. Both companies provide dedicated forms for erasure requests, delisting from search results, and account deletion. If they refuse or ignore your request, you can complain to the Irish DPC, which is their lead EU regulator. Note that erasure isn't absolute — legal retention obligations or freedom of expression can sometimes override it.

Conclusion

GDPR gives you real, enforceable power over your personal data in Ireland — from finding out what's held about you to demanding its deletion. The Data Protection Commission provides a free and effective route to challenge organisations that fail to comply, and the fines it has issued show these rights have teeth. Combine this legal framework with practical privacy habits — strong passwords, minimal data sharing, and privacy-conscious tools — and you'll be well positioned to control your digital footprint in Ireland well into 2026 and beyond.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles