GDPR in Ireland: Your Privacy Rights Explained
Ireland sits at the heart of Europe's data protection landscape. As the European headquarters of Google, Meta, Microsoft, TikTok, LinkedIn, and dozens of other global tech companies, the country's Data Protection Commission (DPC) is one of the most influential regulators in the world. If you live, work, or run a business in Ireland, understanding your rights under the General Data Protection Regulation (GDPR) is essential.
This guide breaks down exactly what GDPR means in the Irish context, what rights you have as a data subject, how to enforce them, and what obligations businesses face. Whether you're a consumer wondering how to get your data deleted or a small business owner trying to stay compliant, this article has you covered.
What Is GDPR and How Does It Apply in Ireland?
The General Data Protection Regulation (GDPR) is an EU-wide law that came into effect on 25 May 2018. It governs how personal data of EU residents is collected, processed, stored, and shared. In Ireland, GDPR is supplemented by the Data Protection Act 2018, which implements and clarifies certain provisions at the national level.
Ireland's role is unique. Because so many multinational tech companies base their EU operations in Dublin, the Irish Data Protection Commission acts as the "lead supervisory authority" for cross-border complaints against those companies under the GDPR's one-stop-shop mechanism. This means a complaint filed in Berlin or Madrid about Meta or Google may end up being investigated in Dublin.
Who Does GDPR Protect?
GDPR protects any identifiable natural person (called a "data subject") whose personal data is processed by an organisation operating in or targeting the EU. Personal data is defined broadly and includes:
- Name, address, phone number, and email
- IP addresses and device identifiers
- Location data
- Biometric and health information
- Political opinions, religious beliefs, and sexual orientation (special category data)
- Financial information and PPS numbers
Your Eight Core Privacy Rights Under GDPR
GDPR gives every individual in Ireland eight enforceable rights over their personal data. These rights apply whether the organisation processing your data is a government body, a bank, a retailer, a hospital, or a social media platform.
1. The Right to Be Informed
Organisations must tell you, in clear and plain language, what data they collect, why they collect it, how long they keep it, and who they share it with. This is usually provided in a privacy notice or policy at the point of data collection.
2. The Right of Access
You can request a copy of all personal data an organisation holds about you. This is known as a Subject Access Request (SAR). The organisation must respond within one month and provide the information free of charge in most cases.
3. The Right to Rectification
If any data held about you is inaccurate or incomplete, you have the right to have it corrected. Organisations must act on rectification requests within a month.
4. The Right to Erasure (Right to Be Forgotten)
You can ask an organisation to delete your personal data in specific circumstances, such as when the data is no longer needed, when you withdraw consent, or when the data was processed unlawfully. There are exceptions, for example, for legal obligations or public interest.
5. The Right to Restrict Processing
You can ask an organisation to pause the processing of your data while a dispute is resolved, for example, while accuracy is being verified.
6. The Right to Data Portability
You can request your data in a structured, commonly used, machine-readable format (like CSV or JSON) and have it transferred to another provider. This applies to data you provided based on consent or a contract.
7. The Right to Object
You can object to processing based on legitimate interests, direct marketing, or scientific research. For direct marketing, the objection is absolute, the organisation must stop immediately.
8. Rights Related to Automated Decision-Making
You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects on you. This applies to things like automated loan approvals or algorithmic recruitment tools.
How to Exercise Your GDPR Rights in Ireland
Enforcing your rights is often more straightforward than people expect. Here's a step-by-step process:
- Identify the controller. The data controller is the organisation that decides how and why your data is processed. Check their website's privacy policy for contact details, usually a Data Protection Officer (DPO) email.
- Send a written request. Email or post a clear request stating which right you are exercising. Include enough information to identify yourself, but do not send more than necessary.
- Wait one calendar month. The organisation must respond within 30 days. They may extend this by two months for complex requests, but must tell you why.
- Review the response. Check that the organisation provided what you asked for and explained any refusals.
- Escalate if unsatisfied. If you are not happy with the outcome, you can complain to the Data Protection Commission.
The Data Protection Commission (DPC): Ireland's Regulator
The Data Protection Commission, headquartered in Dublin with an office in Portarlington, is Ireland's independent authority responsible for upholding GDPR and the Data Protection Act 2018. It is led by three Commissioners as of 2023 and has grown significantly in staff and budget to handle its enormous cross-border caseload.
What the DPC Does
- Investigates complaints from individuals
- Conducts inquiries into potential breaches
- Issues fines and enforcement notices
- Provides guidance to businesses and the public
- Cooperates with other EU data protection authorities
Notable DPC Enforcement Actions
Ireland's DPC has issued some of the largest GDPR fines in Europe, including:
| Company | Year | Fine | Reason |
|---|---|---|---|
| Meta (Facebook) | 2023 | €1.2 billion | Unlawful transfers of EU data to the US |
| TikTok | 2023 | €345 million | Children's privacy violations |
| Meta (Instagram) | 2022 | €405 million | Children's data handling |
| 2021 | €225 million | Transparency failures |
How to File a Complaint with the DPC
If an organisation refuses to respect your rights, ignores your request, or mishandles your data, you can complain to the Data Protection Commission free of charge.
- Try to resolve it first. The DPC generally expects you to have contacted the organisation directly before complaining.
- Gather evidence. Save copies of your original request, any responses, and screenshots or documents that show the issue.
- Submit a complaint form. Visit dataprotection.ie and use the online complaint form, or send a letter to the DPC's Portarlington office.
- Await acknowledgement. The DPC will typically acknowledge your complaint within a few weeks and may attempt amicable resolution before formal investigation.
- Cooperate with the investigation. Provide any additional information the case handler requests.
You do not need a solicitor to complain, and there is no fee.
What GDPR Means for Irish Businesses
If you run a business in Ireland, whether a sole trader, SME, or multinational, GDPR imposes clear obligations. Non-compliance can result in fines of up to €20 million or 4% of global annual turnover, whichever is higher.
Core Business Obligations
- Lawful basis for processing: You must have one of six lawful bases (consent, contract, legal obligation, vital interests, public task, or legitimate interests) before processing personal data.
- Transparent privacy notices: Publish clear, accessible privacy policies on your website and any point of data collection.
- Data minimisation: Only collect what you actually need.
- Security measures: Implement appropriate technical and organisational security, including encryption, access controls, and staff training.
- Breach notification: Notify the DPC within 72 hours of becoming aware of a personal data breach that poses a risk to individuals.
- Data Protection Officer (DPO): Appoint a DPO if you are a public body or your core activities involve large-scale monitoring or processing of special category data.
- Records of processing: Maintain a Record of Processing Activities (ROPA) if you have 250+ employees or engage in higher-risk processing.
- Vendor management: Have Data Processing Agreements (DPAs) with any third parties that process data on your behalf.
Practical Tools for Compliance
Even small businesses handle a surprising amount of personal data, from newsletter subscriptions to customer analytics. Choosing privacy-respecting tools reduces your exposure. For example, when sharing links in marketing campaigns, using a GDPR-conscious link management service like Lunyb helps ensure that click tracking and analytics are handled transparently. You can read our honest review of Lunyb or compare it against alternatives in our 2026 buyer's guide to URL shorteners.
Special Considerations Under Irish Law
Children and Digital Consent
Under the Irish Data Protection Act 2018, the digital age of consent is 16. This means children under 16 cannot legally consent to the processing of their data by online services; parental consent is required. This is stricter than in some other EU states like Spain (14) or the UK (13).
PPS Numbers
Your Personal Public Service (PPS) number is highly sensitive. Only specific bodies listed in Schedule 5 of the Social Welfare Consolidation Act 2005 are entitled to request it. Private businesses generally cannot ask for your PPS number.
Employee Data
Employers must respect GDPR when handling staff records, CCTV, and workplace monitoring. Covert surveillance is almost always unlawful, and any monitoring must be proportionate and transparent.
Practical Steps to Protect Your Privacy in Ireland
Beyond exercising your legal rights, you can take everyday actions to reduce how much personal data ends up in circulation:
- Review privacy settings on social media, Google, and Apple accounts every few months.
- Use encrypted DNS resolvers like Cloudflare 1.1.1.1 or Quad9 to prevent ISP-level tracking of your browsing.
- Choose privacy-focused browsers such as Firefox or Brave, and install a reputable content blocker.
- Read privacy notices before accepting cookies, and reject non-essential tracking where possible.
- Use unique email aliases for signups so you can identify who leaks or sells your data.
- Enable two-factor authentication on all important accounts.
- Request deletion of dormant accounts you no longer use.
Common Myths About GDPR in Ireland
"GDPR only applies to big tech companies."
False. GDPR applies to any organisation processing personal data, from a one-person plumbing business keeping customer contacts to a hospital managing medical records.
"I need to give consent for everything."
Consent is only one of six lawful bases. Businesses often rely on contract or legitimate interests, so you may not see a consent banner for every use of your data.
"GDPR means my data can never be shared."
Not true. Data can be shared lawfully with processors, partners, or authorities if there's a valid basis, and appropriate safeguards are in place.
"Fines are only issued to giant corporations."
The DPC has fined small organisations, public bodies, and even individual data controllers. Any breach can trigger enforcement.
Frequently Asked Questions
How long does an organisation have to respond to a GDPR request in Ireland?
An organisation must respond to your request within one calendar month of receiving it. This can be extended by up to two additional months for complex or numerous requests, but they must inform you of the extension and the reason within the original month.
Can I sue a company directly under GDPR in Ireland?
Yes. Article 82 of the GDPR and Section 117 of the Irish Data Protection Act 2018 allow you to bring a civil claim for material or non-material damage, including distress. Recent Irish case law has confirmed that non-material damages are recoverable, though the amount is usually modest for minor breaches.
Does GDPR still apply to data transferred from Ireland to the UK after Brexit?
Yes, but the UK is treated as a third country. Transfers rely on the European Commission's adequacy decision for the UK (adopted in 2021 and subject to periodic review). If that adequacy status changes, businesses would need to use Standard Contractual Clauses or other safeguards.
Do I have to pay to make a Subject Access Request?
No. Subject Access Requests are free in almost all cases. An organisation can only charge a reasonable fee if the request is "manifestly unfounded or excessive", for example, if you repeatedly ask for the same data. In practice, fees are extremely rare.
What should I do if I discover my data has been breached?
First, contact the organisation to confirm what happened and what data was affected. Change any compromised passwords and monitor accounts for suspicious activity. If the organisation has not notified the DPC or the risk to you is high (financial fraud, identity theft), you can complain directly to the Data Protection Commission at dataprotection.ie.
Final Thoughts
GDPR gives people in Ireland some of the strongest privacy rights in the world, but those rights are only powerful if you use them. Whether you're requesting access to your data, asking for deletion, or complaining to the DPC, the process is designed to be accessible and free. For businesses, compliance is not just about avoiding fines, it's about building trust with customers in an era where privacy is a competitive advantage.
Take the time to understand your rights, choose tools and providers that respect them, and don't hesitate to push back when organisations fall short. The framework exists to protect you, and it works best when people actively use it.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
UK Online Safety Act: What It Means for Your Privacy in 2026
The UK Online Safety Act reshapes how platforms handle your data, from mandatory age verification to potential scanning of encrypted messages. This 2026 guide explains what the Act actually requires, the privacy trade-offs involved and practical steps British users can take to stay in control of their personal information.
Australia Privacy Act 2026: Your Rights Explained
The Australia Privacy Act 2026 introduces sweeping reforms giving Australians powerful new rights over their personal data. Learn what's changed, your new protections, and what businesses must do to comply with penalties now reaching $50 million.
Singapore Online Safety Act 2026: Complete Guide for Users and Businesses
Singapore's Online Safety Act 2026 expands duties for platforms, empowers a new Online Safety Commission, and targets scams, deepfakes, and child safety. This complete guide explains who is in scope, what harms are covered, penalties, and practical compliance steps for businesses and users.
How Canadian Businesses Should Handle Data Privacy in 2026
A practical 2026 guide for Canadian businesses navigating PIPEDA, Quebec's Law 25, and provincial privacy laws. Learn how to map data, manage consent, secure systems, and respond to breaches — with clear steps and a comparison of key Canadian privacy laws.