facebook-pixel

GDPR in Ireland: Your Privacy Rights Explained

L
Lunyb Security Team
··11 min read

Ireland occupies a unique position in the European data protection landscape. As the European headquarters for many of the world's largest technology companies — including Meta, Google, TikTok, Microsoft, and Apple — the Irish Data Protection Commission (DPC) is often the lead regulator for cross-border privacy cases affecting hundreds of millions of Europeans. If you live in Ireland, this means the General Data Protection Regulation (GDPR) gives you unusually direct access to one of the most influential privacy regulators on the continent.

This guide explains your privacy rights under GDPR as it applies in Ireland, how the Data Protection Act 2018 layers on top, how to exercise your rights, and what to do when a company mishandles your personal data.

What Is GDPR and How Does It Apply in Ireland?

The General Data Protection Regulation (GDPR) is an EU-wide law that came into force on 25 May 2018. It regulates how organisations collect, store, use, and share personal data about individuals in the European Economic Area. In Ireland, GDPR is supplemented by the Data Protection Act 2018, which fills in national-level details such as the age of digital consent (16 in Ireland) and the powers of the Data Protection Commission.

Together, these laws apply to almost every organisation that processes personal data about people in Ireland — from multinational tech firms and Irish banks to your local GP surgery, GAA club, or corner shop with a CCTV camera.

Key definitions you should know

  • Personal data: any information relating to an identified or identifiable person — name, email, IP address, location data, photos, and even opinions expressed about you.
  • Special category data: sensitive information such as health, ethnicity, religion, sexual orientation, biometric or genetic data. This has stricter protections.
  • Data controller: the organisation that decides why and how your data is processed.
  • Data processor: a third party that processes data on behalf of a controller (for example, a cloud hosting provider).
  • Data subject: you — the person the data is about.

Your Eight Core Privacy Rights Under GDPR

GDPR gives every person in Ireland eight enforceable rights over their personal data. Understanding these rights is the first step to protecting your privacy.

1. The right to be informed

Organisations must tell you, in plain language, what data they collect, why, how long they keep it, who they share it with, and what your rights are. This is usually done through a privacy notice or policy on their website.

2. The right of access

You can ask any organisation for a copy of the personal data they hold about you. This is called a Subject Access Request (SAR). The organisation must respond within one month, and in most cases they cannot charge you a fee.

3. The right to rectification

If your data is inaccurate or incomplete, you can ask for it to be corrected. This applies to obvious factual errors as well as outdated information.

4. The right to erasure ("right to be forgotten")

You can request the deletion of your data in certain circumstances — for example, when the data is no longer necessary, when you withdraw consent, or when it has been unlawfully processed. This right is not absolute; organisations can refuse if they have a legal obligation to keep the data (for instance, Revenue records).

5. The right to restrict processing

You can ask an organisation to pause using your data while a dispute or accuracy issue is resolved. They can still store it, but they cannot use it during the restriction.

6. The right to data portability

Where processing is based on consent or a contract and is carried out automatically, you can ask to receive your data in a common, machine-readable format (like CSV or JSON), or have it transferred directly to another provider.

7. The right to object

You can object to processing based on legitimate interests or public task, and you have an absolute right to object to direct marketing at any time.

8. Rights around automated decision-making and profiling

If a decision that significantly affects you (like a loan approval, insurance quote, or job screening) is made purely by an algorithm, you have the right to human review, to express your point of view, and to contest the decision.

The Role of the Irish Data Protection Commission (DPC)

The Data Protection Commission, based in Dublin and Portarlington, is Ireland's independent regulator for GDPR. It has three main jobs:

  1. Educating the public and businesses about data protection rights and obligations.
  2. Investigating complaints from individuals and potential breaches of the law.
  3. Enforcing the law through corrective powers, including warnings, orders, and fines of up to €20 million or 4% of a company's global annual turnover — whichever is higher.

Because so many tech giants have their EU headquarters in Dublin, the DPC acts as the lead supervisory authority under GDPR's "one-stop-shop" mechanism. It has issued some of the largest fines in EU history, including a €1.2 billion fine against Meta in 2023 over international data transfers.

How to Exercise Your GDPR Rights in Ireland

Exercising your rights is free and does not require a solicitor. Here is a practical step-by-step process.

Step 1: Identify the data controller

Find out which organisation controls your data. This is usually stated in their privacy policy, often at the bottom of their website.

Step 2: Locate their Data Protection Officer (DPO) or privacy contact

Larger organisations are required to appoint a DPO. Their contact details should be in the privacy notice. For smaller businesses, contact the general customer service address.

Step 3: Submit your request in writing

Send an email or letter clearly stating which right you are exercising (for example, "I am making a Subject Access Request under Article 15 of GDPR"). Include:

  • Your full name and any account details
  • Proof of identity if requested (a copy of ID)
  • A clear description of what you want
  • The date

Step 4: Wait up to one month

The organisation must respond within 30 calendar days. They can extend this by two months for complex requests, but must tell you why within the first month.

Step 5: Escalate if necessary

If they refuse, ignore you, or give an inadequate response, you can complain to the DPC at dataprotection.ie. Complaints are free.

GDPR Rights vs. Common Data Requests: A Quick Comparison

Your Right What You Can Ask For Response Time Common Refusal Reasons
Access (SAR) A copy of all personal data held about you 1 month Manifestly unfounded or excessive requests
Rectification Correction of inaccurate data 1 month Data is already accurate
Erasure Deletion of your data 1 month Legal obligation to retain (tax, medical records)
Portability Machine-readable copy of your data 1 month Data not held under consent or contract
Object to marketing Stop direct marketing immediately Immediate None — this is absolute

Special Considerations in Ireland

Digital age of consent

Under the Data Protection Act 2018, children under 16 in Ireland cannot legally consent to their data being processed by information society services (social media, apps, online games). Parental consent is required. This is stricter than the GDPR default of 13.

CCTV and workplace monitoring

CCTV cameras in Irish shops, workplaces, and public spaces must have clear signage, a documented lawful basis, and a retention policy. Employers who monitor emails, internet usage, or use biometric time-and-attendance systems must carry out a Data Protection Impact Assessment (DPIA) and inform staff transparently.

Direct marketing and ePrivacy

On top of GDPR, Ireland enforces the ePrivacy Regulations (S.I. 336 of 2011). These require prior opt-in consent for most electronic marketing (email, SMS) to individuals and strict rules on cookies. The DPC has been increasingly active in fining companies for non-compliant cookie banners.

Health data and PPS numbers

Your PPS number, medical records, and information held by the HSE are considered highly sensitive. Additional safeguards apply, and requests to access your medical records can also be made under the Freedom of Information Act 2014 where the body is a public authority.

Practical Steps to Protect Your Privacy Online

Knowing your rights is only half the battle. Reducing how much data you expose in the first place is equally important.

  1. Audit your accounts. Every six months, review which apps and services hold your data. Delete dormant accounts.
  2. Use privacy-focused browsers and search engines. Firefox, Brave, and DuckDuckGo reduce third-party tracking by default.
  3. Enable encrypted DNS. Services like Cloudflare 1.1.1.1 or NextDNS prevent your Internet provider from easily logging every domain you visit.
  4. Be cautious with link shorteners. Some free shorteners aggressively track clicks, IP addresses, and device fingerprints. Choose a provider with a transparent privacy policy — Lunyb, for example, minimises data collection and is a straightforward option reviewed in our honest Lunyb review.
  5. Review cookie banners properly. The "Reject All" option is legally required to be as easy to click as "Accept All" in Ireland. Use it.
  6. Turn off ad personalisation on Google, Meta, Microsoft, and Apple accounts.
  7. Use unique passwords and a password manager to reduce the damage of any single breach.

What Businesses in Ireland Must Do

If you run a business, sole trader operation, or even a community group in Ireland that handles personal data, GDPR applies to you. Key obligations include:

  • Maintaining a Record of Processing Activities if you have 250+ employees or handle sensitive/regular data.
  • Having a lawful basis for every processing activity (consent, contract, legal obligation, vital interests, public task, or legitimate interests).
  • Publishing a clear, accessible privacy notice.
  • Reporting personal data breaches to the DPC within 72 hours where there is a risk to individuals.
  • Carrying out Data Protection Impact Assessments (DPIAs) for high-risk processing.
  • Appointing a Data Protection Officer if you are a public body or engage in large-scale monitoring or processing of sensitive data.
  • Using tools and third-party providers that themselves comply with GDPR. For example, if you use link shorteners or analytics for marketing, ensure the provider processes data lawfully — the best URL shorteners buyer's guide covers privacy considerations, and the Rebrandly review examines a popular enterprise option.

Filing a Complaint With the DPC

If an organisation fails to respect your rights, you can file a formal complaint with the Data Protection Commission. Here is what to expect:

  1. Prepare your evidence. Gather emails, screenshots, dates, and copies of any request you made to the organisation.
  2. Submit online. Use the DPC's webform at dataprotection.ie or send a signed letter to their Portarlington or Dublin office.
  3. Amicable resolution. The DPC will often try to resolve the matter informally first, contacting the organisation on your behalf.
  4. Statutory inquiry. If informal resolution fails, the DPC may launch a formal investigation, which can result in binding decisions and fines.
  5. Appeal rights. Both you and the organisation can appeal decisions to the Circuit Court or High Court.

You can also seek compensation directly through the Irish courts for material or non-material damage caused by a GDPR breach, without going through the DPC first.

Frequently Asked Questions

How long does an Irish company have to respond to my Subject Access Request?

One calendar month from the date they receive your request. This can be extended by up to two additional months for complex or numerous requests, but they must notify you of the extension and the reason within the first month.

Can I be charged for a copy of my personal data?

No, the first copy must be provided free of charge. Organisations can only charge a reasonable fee based on administrative costs if a request is manifestly unfounded, excessive, or if you ask for additional copies.

Does GDPR apply to companies outside the EU that offer services in Ireland?

Yes. GDPR has extraterritorial reach. Any organisation that offers goods or services to people in Ireland, or monitors their behaviour, must comply with GDPR regardless of where the company is based. Non-EU companies must usually appoint an EU representative.

What is the digital age of consent in Ireland?

16 years old. Children under 16 in Ireland cannot legally consent to their personal data being processed by online services such as social media platforms; a parent or guardian must consent on their behalf.

Can I sue a company directly for a GDPR breach in Ireland?

Yes. Article 82 of GDPR and Section 117 of the Data Protection Act 2018 allow you to bring a civil action in the Irish courts for compensation, including for non-material damage such as distress. You can do this alongside or instead of a DPC complaint.

What happens if I lose my SAR response or the company refuses to reply?

Send one written reminder giving a reasonable deadline (typically 7–14 days). If they still fail to respond, file a complaint with the Data Protection Commission at dataprotection.ie. The DPC treats non-response as a serious breach of Article 12 of GDPR.

Conclusion

GDPR gives people in Ireland one of the strongest sets of privacy rights in the world, and the Data Protection Commission is one of the most influential regulators enforcing them. Whether you are a citizen wanting to control your digital footprint or a business owner wanting to stay compliant, understanding these rights and obligations is now a basic part of modern life.

Start with small steps: audit your accounts, exercise your right of access on one company this month, choose privacy-respecting tools where you can, and know that if something goes wrong, the DPC — and Irish courts — are on your side.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles