facebook-pixel

GDPR in Ireland: Your Privacy Rights Explained

L
Lunyb Security Team
··10 min read

Ireland sits at the heart of European data protection. As the EU headquarters for many of the world's largest technology companies, the Irish Data Protection Commission (DPC) plays an outsized role in enforcing the General Data Protection Regulation (GDPR). Yet many Irish residents remain unsure about what rights they actually have, how to exercise them, or what happens when a company mishandles their personal information.

This guide breaks down GDPR in Ireland in plain English. You'll learn what the law covers, the eight core rights you hold as a data subject, how to file a complaint with the DPC, and practical steps to protect your privacy every day.

What Is GDPR and How Does It Apply in Ireland?

The General Data Protection Regulation (GDPR) is an EU-wide law that came into force on 25 May 2018. It governs how organisations collect, store, process, and share personal data belonging to individuals in the European Union. In Ireland, GDPR is supplemented by the Data Protection Act 2018, which tailors certain provisions to Irish national law.

Because Ireland hosts the European headquarters of companies like Meta, Google, Apple, LinkedIn, TikTok, and X (formerly Twitter), the Irish DPC acts as the "lead supervisory authority" for cross-border investigations involving these firms. That means decisions made in Dublin often ripple across all 27 EU member states.

Who Does GDPR Protect?

GDPR protects any identified or identifiable natural person located in the EU, regardless of nationality. If you live in Ireland — as a citizen, resident, student, or visitor — your personal data is covered whenever a business or public body processes it.

What Counts as Personal Data?

Personal data is any information that can identify you, directly or indirectly. Examples include:

  • Your name, address, and PPS number
  • Email addresses and phone numbers
  • IP addresses and device identifiers
  • Location data and browsing history
  • Photos, video, and voice recordings
  • Health, financial, and employment records
  • Biometric and genetic data (treated as "special category" data)

Your Eight Core GDPR Rights in Ireland

GDPR grants every data subject eight enforceable rights. Understanding each one is the first step to taking control of your digital life.

1. The Right to Be Informed

Organisations must tell you, in clear and plain language, why they're collecting your data, how they'll use it, how long they'll keep it, and who they'll share it with. This is typically delivered through a privacy notice on a website or at the point of collection.

2. The Right of Access

You can request a copy of all personal data an organisation holds about you. This is known as a Subject Access Request (SAR). The controller must respond within one month, free of charge in most cases.

3. The Right to Rectification

If your data is inaccurate or incomplete, you can ask for it to be corrected or updated. The organisation must act without undue delay.

4. The Right to Erasure ("Right to Be Forgotten")

You can request deletion of your data when it's no longer needed, when you withdraw consent, or when it has been processed unlawfully. There are exceptions — for example, when data is needed for legal claims or public interest tasks.

5. The Right to Restrict Processing

In certain circumstances, you can ask a controller to pause using your data while a dispute is resolved — for instance, while you contest its accuracy.

6. The Right to Data Portability

You can obtain your data in a structured, commonly used, machine-readable format and transfer it to another provider. This right applies to data you supplied and that is processed by automated means based on consent or contract.

7. The Right to Object

You can object to processing based on legitimate interests or public tasks, and you have an absolute right to object to direct marketing at any time.

8. Rights Related to Automated Decision-Making

You have the right not to be subject to solely automated decisions — including profiling — that produce legal or similarly significant effects, unless specific safeguards apply.

The Six Lawful Bases for Processing Data

Before an organisation can process your personal data, it must rely on one of six lawful bases defined in Article 6 of the GDPR. Knowing these helps you challenge processing that has no valid legal footing.

Lawful BasisWhen It AppliesExample
ConsentYou've given clear, freely-given permissionSigning up for a newsletter
ContractNeeded to fulfil a contract with youDelivering an online order
Legal ObligationRequired by Irish or EU lawRevenue tax reporting
Vital InterestsNecessary to protect someone's lifeEmergency medical treatment
Public TaskCarried out by a public authorityHSE health services
Legitimate InterestsBusiness need balanced against your rightsFraud prevention monitoring

How the Irish Data Protection Commission (DPC) Works

The DPC, headquartered in Dublin with an office in Portarlington, is Ireland's independent regulator for data protection. It has three main functions:

  1. Guidance: Publishing rules, blogs, and toolkits for individuals and organisations.
  2. Complaint handling: Investigating alleged breaches of GDPR raised by the public.
  3. Enforcement: Issuing reprimands, corrective orders, and administrative fines up to €20 million or 4% of global annual turnover — whichever is higher.

Landmark Irish Enforcement Decisions

The DPC has issued some of the largest GDPR fines in Europe, including a €1.2 billion penalty against Meta in 2023 for unlawful transfers of European user data to the United States, and a €345 million fine against TikTok the same year for children's privacy failures. These cases demonstrate that Irish enforcement carries real weight — even against tech giants.

How to File a GDPR Complaint in Ireland

If you believe an organisation has mishandled your data, you can complain directly to the DPC. The process is free and doesn't require a solicitor.

  1. Contact the organisation first. Most disputes are resolved faster by writing to the company's Data Protection Officer (DPO) and giving them a chance to respond within one month.
  2. Gather evidence. Keep copies of emails, screenshots, privacy notices, and any responses you've received.
  3. Submit your complaint to the DPC. Use the online form at dataprotection.ie, or write by post. Include your name, contact details, the organisation involved, and a clear description of the issue.
  4. Cooperate with the investigation. The DPC may ask for more information or attempt to mediate between you and the controller.
  5. Await the decision. Complex cases can take months or years. If you're unhappy with the outcome, you can appeal to the Irish Circuit Court.

Special Rules for Sensitive Data

GDPR treats certain categories of data as especially sensitive and grants them extra protection under Article 9. These include:

  • Racial or ethnic origin
  • Political opinions
  • Religious or philosophical beliefs
  • Trade union membership
  • Genetic and biometric data (used for identification)
  • Health data
  • Data about sex life or sexual orientation

Processing this data is generally prohibited unless you give explicit consent or one of a narrow set of exceptions applies — such as employment law obligations or public health necessity.

Children's Privacy Under Irish Law

The Data Protection Act 2018 sets Ireland's "digital age of consent" at 16. This means information society services (like social media platforms) must obtain parental consent to process personal data of children under 16. The DPC's Fundamentals for a Child-Oriented Approach to Data Processing sets out 14 principles that platforms must follow, including a "floor of protection" that treats all users as children by default unless age verification proves otherwise.

Cookies, Tracking, and the ePrivacy Regulations

In addition to GDPR, Ireland enforces the ePrivacy Regulations (S.I. No. 336 of 2011), which govern cookies, electronic marketing, and traffic data. Under these rules:

  • Websites must obtain your consent before setting non-essential cookies.
  • Cookie banners must offer genuine choice — no pre-ticked boxes or "accept only" buttons.
  • Direct marketing emails and SMS require prior opt-in, with a limited "soft opt-in" exception for existing customers.

Practical Steps to Protect Your Privacy Online

Knowing your rights is one thing — putting them into practice is another. Here are concrete actions Irish residents can take today.

Audit Your Digital Footprint

Search your name on Google, review which accounts you've signed up for, and use tools like Have I Been Pwned to check whether your email has appeared in any known data breach.

Review Privacy Settings

Every major platform — Facebook, Instagram, Google, LinkedIn — offers privacy dashboards. Turn off location history, ad personalisation, and third-party data sharing wherever possible.

Use Privacy-Respecting Tools

Consider switching to browsers like Brave or Firefox with strict tracking protection, encrypted DNS providers such as Cloudflare's 1.1.1.1 or Quad9, and privacy-focused search engines like DuckDuckGo or Ecosia.

Shorten and Share Links Safely

When sharing links, use a shortener that doesn't harvest excessive data or attach invasive tracking pixels. Services such as Lunyb offer clean, privacy-conscious URL shortening — a smart alternative for anyone conscious of how link data is logged. For a broader comparison, see our 2026 buyer's guide to URL shorteners and our detailed Rebrandly review.

Exercise Your Rights Regularly

Send annual Subject Access Requests to companies you no longer use, and follow up with deletion requests. Many organisations quietly retain data for years past its useful life.

What Businesses Operating in Ireland Must Do

If you run a business or website that collects data from Irish or EU users, GDPR compliance is not optional. Core obligations include:

  • Maintaining a Record of Processing Activities (ROPA)
  • Publishing a clear, accessible privacy notice
  • Appointing a Data Protection Officer (DPO) where required
  • Conducting Data Protection Impact Assessments (DPIAs) for high-risk processing
  • Notifying the DPC within 72 hours of a data breach that risks harm
  • Ensuring third-party processors sign data processing agreements
  • Implementing appropriate technical and organisational security measures

Cross-Border Data Transfers After Schrems II

The 2020 Schrems II ruling by the Court of Justice of the EU — a case brought by Austrian lawyer Max Schrems against the Irish DPC — invalidated the EU-US Privacy Shield. Today, transfers to countries outside the EEA require additional safeguards such as Standard Contractual Clauses (SCCs), transfer impact assessments, and, for US transfers, reliance on the EU-US Data Privacy Framework agreed in 2023.

Frequently Asked Questions

How long does an organisation have to respond to my Subject Access Request?

Under GDPR, controllers must respond within one calendar month of receiving your request. This can be extended by two further months for complex or numerous requests, but they must tell you about the extension within the first month.

Can I be charged a fee for making a GDPR request?

No. Access, rectification, erasure, and other rights requests are free of charge. A "reasonable fee" can only be charged if the request is manifestly unfounded, excessive, or repetitive — a high bar that rarely applies.

What penalties can the Irish DPC impose?

The DPC can issue reprimands, corrective orders, temporary or permanent processing bans, and administrative fines. Maximum fines reach €20 million or 4% of a company's global annual turnover, whichever is higher. Recent Irish decisions against Meta and TikTok have exceeded €1 billion and €345 million respectively.

Does GDPR apply to sole traders and small businesses in Ireland?

Yes. GDPR applies to any organisation — regardless of size — that processes personal data. Some obligations, such as maintaining a ROPA, are lighter for organisations with fewer than 250 employees, but the core rights and lawful basis requirements still apply.

What should I do if a company ignores my GDPR request?

Send one final written reminder giving them a clear deadline. If they still fail to respond within one month of your original request, you can lodge a complaint with the Data Protection Commission at dataprotection.ie. Keep records of every communication.

Conclusion

GDPR gives Irish residents some of the strongest privacy protections in the world — but those rights are only meaningful when you use them. Whether you're requesting a copy of your data, objecting to marketing, or filing a complaint with the DPC, every action reinforces a culture of accountability. Combine legal awareness with practical habits — privacy-respecting browsers, encrypted DNS, and mindful link sharing — and you'll be well positioned to protect your personal information in an increasingly data-driven world.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles