facebook-pixel

GDPR in Ireland: Your Privacy Rights Explained

L
Lunyb Security Team
··11 min read

Ireland sits at the heart of Europe's data protection landscape. As the European headquarters of Google, Meta, Microsoft, TikTok, LinkedIn, and dozens of other global tech companies, the country's Data Protection Commission (DPC) is one of the most influential regulators in the world. If you live, work, or run a business in Ireland, understanding your rights under the General Data Protection Regulation (GDPR) is essential.

This guide breaks down exactly what GDPR means in the Irish context, what rights you have as a data subject, how to enforce them, and what obligations businesses face. Whether you're a consumer wondering how to get your data deleted or a small business owner trying to stay compliant, this article has you covered.

What Is GDPR and How Does It Apply in Ireland?

The General Data Protection Regulation (GDPR) is an EU-wide law that came into effect on 25 May 2018. It governs how personal data of EU residents is collected, processed, stored, and shared. In Ireland, GDPR is supplemented by the Data Protection Act 2018, which implements and clarifies certain provisions at the national level.

Ireland's role is unique. Because so many multinational tech companies base their EU operations in Dublin, the Irish Data Protection Commission acts as the "lead supervisory authority" for cross-border complaints against those companies under the GDPR's one-stop-shop mechanism. This means a complaint filed in Berlin or Madrid about Meta or Google may end up being investigated in Dublin.

Who Does GDPR Protect?

GDPR protects any identifiable natural person (called a "data subject") whose personal data is processed by an organisation operating in or targeting the EU. Personal data is defined broadly and includes:

  • Name, address, phone number, and email
  • IP addresses and device identifiers
  • Location data
  • Biometric and health information
  • Political opinions, religious beliefs, and sexual orientation (special category data)
  • Financial information and PPS numbers

Your Eight Core Privacy Rights Under GDPR

GDPR gives every individual in Ireland eight enforceable rights over their personal data. These rights apply whether the organisation processing your data is a government body, a bank, a retailer, a hospital, or a social media platform.

1. The Right to Be Informed

Organisations must tell you, in clear and plain language, what data they collect, why they collect it, how long they keep it, and who they share it with. This is usually provided in a privacy notice or policy at the point of data collection.

2. The Right of Access

You can request a copy of all personal data an organisation holds about you. This is known as a Subject Access Request (SAR). The organisation must respond within one month and provide the information free of charge in most cases.

3. The Right to Rectification

If any data held about you is inaccurate or incomplete, you have the right to have it corrected. Organisations must act on rectification requests within a month.

4. The Right to Erasure (Right to Be Forgotten)

You can ask an organisation to delete your personal data in specific circumstances, such as when the data is no longer needed, when you withdraw consent, or when the data was processed unlawfully. There are exceptions, for example, for legal obligations or public interest.

5. The Right to Restrict Processing

You can ask an organisation to pause the processing of your data while a dispute is resolved, for example, while accuracy is being verified.

6. The Right to Data Portability

You can request your data in a structured, commonly used, machine-readable format (like CSV or JSON) and have it transferred to another provider. This applies to data you provided based on consent or a contract.

7. The Right to Object

You can object to processing based on legitimate interests, direct marketing, or scientific research. For direct marketing, the objection is absolute, the organisation must stop immediately.

8. Rights Related to Automated Decision-Making

You have the right not to be subject to a decision based solely on automated processing, including profiling, that produces legal or similarly significant effects on you. This applies to things like automated loan approvals or algorithmic recruitment tools.

How to Exercise Your GDPR Rights in Ireland

Enforcing your rights is often more straightforward than people expect. Here's a step-by-step process:

  1. Identify the controller. The data controller is the organisation that decides how and why your data is processed. Check their website's privacy policy for contact details, usually a Data Protection Officer (DPO) email.
  2. Send a written request. Email or post a clear request stating which right you are exercising. Include enough information to identify yourself, but do not send more than necessary.
  3. Wait one calendar month. The organisation must respond within 30 days. They may extend this by two months for complex requests, but must tell you why.
  4. Review the response. Check that the organisation provided what you asked for and explained any refusals.
  5. Escalate if unsatisfied. If you are not happy with the outcome, you can complain to the Data Protection Commission.

The Data Protection Commission (DPC): Ireland's Regulator

The Data Protection Commission, headquartered in Dublin with an office in Portarlington, is Ireland's independent authority responsible for upholding GDPR and the Data Protection Act 2018. It is led by three Commissioners as of 2023 and has grown significantly in staff and budget to handle its enormous cross-border caseload.

What the DPC Does

  • Investigates complaints from individuals
  • Conducts inquiries into potential breaches
  • Issues fines and enforcement notices
  • Provides guidance to businesses and the public
  • Cooperates with other EU data protection authorities

Notable DPC Enforcement Actions

Ireland's DPC has issued some of the largest GDPR fines in Europe, including:

CompanyYearFineReason
Meta (Facebook)2023€1.2 billionUnlawful transfers of EU data to the US
TikTok2023€345 millionChildren's privacy violations
Meta (Instagram)2022€405 millionChildren's data handling
WhatsApp2021€225 millionTransparency failures

How to File a Complaint with the DPC

If an organisation refuses to respect your rights, ignores your request, or mishandles your data, you can complain to the Data Protection Commission free of charge.

  1. Try to resolve it first. The DPC generally expects you to have contacted the organisation directly before complaining.
  2. Gather evidence. Save copies of your original request, any responses, and screenshots or documents that show the issue.
  3. Submit a complaint form. Visit dataprotection.ie and use the online complaint form, or send a letter to the DPC's Portarlington office.
  4. Await acknowledgement. The DPC will typically acknowledge your complaint within a few weeks and may attempt amicable resolution before formal investigation.
  5. Cooperate with the investigation. Provide any additional information the case handler requests.

You do not need a solicitor to complain, and there is no fee.

What GDPR Means for Irish Businesses

If you run a business in Ireland, whether a sole trader, SME, or multinational, GDPR imposes clear obligations. Non-compliance can result in fines of up to €20 million or 4% of global annual turnover, whichever is higher.

Core Business Obligations

  • Lawful basis for processing: You must have one of six lawful bases (consent, contract, legal obligation, vital interests, public task, or legitimate interests) before processing personal data.
  • Transparent privacy notices: Publish clear, accessible privacy policies on your website and any point of data collection.
  • Data minimisation: Only collect what you actually need.
  • Security measures: Implement appropriate technical and organisational security, including encryption, access controls, and staff training.
  • Breach notification: Notify the DPC within 72 hours of becoming aware of a personal data breach that poses a risk to individuals.
  • Data Protection Officer (DPO): Appoint a DPO if you are a public body or your core activities involve large-scale monitoring or processing of special category data.
  • Records of processing: Maintain a Record of Processing Activities (ROPA) if you have 250+ employees or engage in higher-risk processing.
  • Vendor management: Have Data Processing Agreements (DPAs) with any third parties that process data on your behalf.

Practical Tools for Compliance

Even small businesses handle a surprising amount of personal data, from newsletter subscriptions to customer analytics. Choosing privacy-respecting tools reduces your exposure. For example, when sharing links in marketing campaigns, using a GDPR-conscious link management service like Lunyb helps ensure that click tracking and analytics are handled transparently. You can read our honest review of Lunyb or compare it against alternatives in our 2026 buyer's guide to URL shorteners.

Special Considerations Under Irish Law

Children and Digital Consent

Under the Irish Data Protection Act 2018, the digital age of consent is 16. This means children under 16 cannot legally consent to the processing of their data by online services; parental consent is required. This is stricter than in some other EU states like Spain (14) or the UK (13).

PPS Numbers

Your Personal Public Service (PPS) number is highly sensitive. Only specific bodies listed in Schedule 5 of the Social Welfare Consolidation Act 2005 are entitled to request it. Private businesses generally cannot ask for your PPS number.

Employee Data

Employers must respect GDPR when handling staff records, CCTV, and workplace monitoring. Covert surveillance is almost always unlawful, and any monitoring must be proportionate and transparent.

Practical Steps to Protect Your Privacy in Ireland

Beyond exercising your legal rights, you can take everyday actions to reduce how much personal data ends up in circulation:

  1. Review privacy settings on social media, Google, and Apple accounts every few months.
  2. Use encrypted DNS resolvers like Cloudflare 1.1.1.1 or Quad9 to prevent ISP-level tracking of your browsing.
  3. Choose privacy-focused browsers such as Firefox or Brave, and install a reputable content blocker.
  4. Read privacy notices before accepting cookies, and reject non-essential tracking where possible.
  5. Use unique email aliases for signups so you can identify who leaks or sells your data.
  6. Enable two-factor authentication on all important accounts.
  7. Request deletion of dormant accounts you no longer use.

Common Myths About GDPR in Ireland

"GDPR only applies to big tech companies."

False. GDPR applies to any organisation processing personal data, from a one-person plumbing business keeping customer contacts to a hospital managing medical records.

"I need to give consent for everything."

Consent is only one of six lawful bases. Businesses often rely on contract or legitimate interests, so you may not see a consent banner for every use of your data.

"GDPR means my data can never be shared."

Not true. Data can be shared lawfully with processors, partners, or authorities if there's a valid basis, and appropriate safeguards are in place.

"Fines are only issued to giant corporations."

The DPC has fined small organisations, public bodies, and even individual data controllers. Any breach can trigger enforcement.

Frequently Asked Questions

How long does an organisation have to respond to a GDPR request in Ireland?

An organisation must respond to your request within one calendar month of receiving it. This can be extended by up to two additional months for complex or numerous requests, but they must inform you of the extension and the reason within the original month.

Can I sue a company directly under GDPR in Ireland?

Yes. Article 82 of the GDPR and Section 117 of the Irish Data Protection Act 2018 allow you to bring a civil claim for material or non-material damage, including distress. Recent Irish case law has confirmed that non-material damages are recoverable, though the amount is usually modest for minor breaches.

Does GDPR still apply to data transferred from Ireland to the UK after Brexit?

Yes, but the UK is treated as a third country. Transfers rely on the European Commission's adequacy decision for the UK (adopted in 2021 and subject to periodic review). If that adequacy status changes, businesses would need to use Standard Contractual Clauses or other safeguards.

Do I have to pay to make a Subject Access Request?

No. Subject Access Requests are free in almost all cases. An organisation can only charge a reasonable fee if the request is "manifestly unfounded or excessive", for example, if you repeatedly ask for the same data. In practice, fees are extremely rare.

What should I do if I discover my data has been breached?

First, contact the organisation to confirm what happened and what data was affected. Change any compromised passwords and monitor accounts for suspicious activity. If the organisation has not notified the DPC or the risk to you is high (financial fraud, identity theft), you can complain directly to the Data Protection Commission at dataprotection.ie.

Final Thoughts

GDPR gives people in Ireland some of the strongest privacy rights in the world, but those rights are only powerful if you use them. Whether you're requesting access to your data, asking for deletion, or complaining to the DPC, the process is designed to be accessible and free. For businesses, compliance is not just about avoiding fines, it's about building trust with customers in an era where privacy is a competitive advantage.

Take the time to understand your rights, choose tools and providers that respect them, and don't hesitate to push back when organisations fall short. The framework exists to protect you, and it works best when people actively use it.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles