GDPR in Ireland: Your Privacy Rights Explained
Ireland occupies a unique position in the European data protection landscape. As the European headquarters for many of the world's largest technology companies — including Meta, Google, Apple, TikTok, and Microsoft — the Irish Data Protection Commission (DPC) is effectively the lead regulator for hundreds of millions of people across the EU. If you live in Ireland, the General Data Protection Regulation (GDPR), together with the Irish Data Protection Act 2018, gives you some of the strongest privacy rights in the world.
But rights are only useful if you know how to exercise them. This guide breaks down exactly what GDPR means for people in Ireland, the eight rights you can rely on, how to make a complaint to the DPC, and practical steps to protect your personal data online.
What Is GDPR and How Does It Apply in Ireland?
The General Data Protection Regulation is an EU-wide law that governs how organisations collect, store, and use personal data. It came into force on 25 May 2018 and applies directly in every EU member state, including Ireland. Alongside GDPR, Ireland has its own Data Protection Act 2018, which fills in the gaps left by the regulation and establishes the Data Protection Commission as the national supervisory authority.
GDPR applies to any organisation — whether based in Ireland, the EU, or outside — that processes the personal data of people located in Ireland. This includes:
- Irish businesses of any size, from sole traders to multinationals
- Public bodies and government departments
- Charities, sports clubs, and community groups
- Foreign companies that offer goods or services to Irish residents
- Online platforms, apps, and websites that track Irish users
"Personal data" is defined broadly. It includes obvious things like your name, address, PPS number, and email, but also less obvious identifiers such as IP addresses, cookie IDs, location data, and even inferred data like your shopping preferences or political views.
Who Enforces GDPR in Ireland?
The Data Protection Commission (DPC), headquartered in Dublin, is Ireland's independent regulator. It has the power to investigate complaints, audit organisations, issue reprimands, order the deletion of data, and impose fines of up to €20 million or 4% of global annual turnover — whichever is higher. In recent years, the DPC has handed down some of the largest GDPR fines in Europe, including a €1.2 billion penalty against Meta in 2023 for unlawful data transfers.
Your Eight Core GDPR Rights in Ireland
GDPR grants every person in Ireland eight fundamental rights over their personal data. Understanding each one is the first step to taking control of your digital life.
1. The Right to Be Informed
Organisations must tell you, in clear and plain language, what data they collect about you, why they collect it, how long they keep it, who they share it with, and what legal basis they rely on. This is why every reputable website has a privacy notice — and why unclear or missing notices are a red flag.
2. The Right of Access (Subject Access Request)
You can ask any organisation to give you a copy of the personal data they hold about you. This is called a Subject Access Request (SAR). The organisation must respond within one month and, in most cases, provide the data free of charge.
3. The Right to Rectification
If any data an organisation holds about you is inaccurate or incomplete, you have the right to have it corrected without undue delay.
4. The Right to Erasure ("Right to Be Forgotten")
You can request the deletion of your personal data in specific circumstances — for example, if the data is no longer needed, if you withdraw consent, or if it was processed unlawfully. This right is not absolute; organisations may refuse if they have a legal obligation to keep the data (such as tax records) or a compelling legitimate interest.
5. The Right to Restrict Processing
You can ask an organisation to pause the processing of your data while a dispute is resolved — for instance, while they investigate whether your data is accurate.
6. The Right to Data Portability
You can request your data in a structured, commonly used, machine-readable format (like CSV or JSON) and transfer it to another service. This is especially relevant for banking, social media, and health apps.
7. The Right to Object
You can object to your data being processed for direct marketing (this must always be respected) or for purposes based on "legitimate interests" where you have a strong personal reason.
8. Rights Related to Automated Decision-Making
If a decision that significantly affects you — such as a loan application, insurance quote, or job screening — is made purely by an algorithm, you have the right to human review and to contest that decision.
Legal Bases: When Can Organisations Process Your Data?
Under GDPR, an organisation cannot simply collect data because it wants to. It must have one of six lawful bases for processing. Knowing these helps you challenge misuse.
| Legal Basis | When It Applies | Example |
|---|---|---|
| Consent | You've given clear, specific, freely given permission | Signing up for a newsletter |
| Contract | Processing is needed to fulfil a contract with you | Delivering an online order |
| Legal obligation | Required by Irish or EU law | Revenue reporting payroll data |
| Vital interests | To protect someone's life | Sharing medical info in an emergency |
| Public task | Carrying out an official public function | HSE processing patient records |
| Legitimate interests | Balanced against your rights and freedoms | Fraud prevention by a bank |
Consent, in particular, must be a genuine choice. Pre-ticked boxes, bundled consents, or "take it or leave it" cookie banners are not valid under GDPR, and the DPC has fined multiple companies for this exact issue.
How to Make a Subject Access Request in Ireland
A Subject Access Request is one of the most powerful tools you have. Here is a step-by-step process to submit one:
- Identify the data controller. This is the organisation that decides how your data is used — usually the company you interacted with.
- Find their contact point. Most privacy notices list a Data Protection Officer (DPO) email, often dpo@company.ie or a dedicated privacy portal.
- Write your request in plain language. You don't need a solicitor. State clearly: "Under Article 15 GDPR, I am requesting a copy of all personal data you hold about me."
- Prove your identity. The organisation may ask for reasonable verification, such as a photo ID or account confirmation.
- Wait up to one month. The response should be free unless your request is manifestly excessive or repetitive.
- Review the response carefully. If it is incomplete or missing, you can push back or escalate to the DPC.
How to Complain to the Data Protection Commission
If an organisation ignores your rights, mishandles your data, or refuses your request, you can lodge a complaint with the DPC. This is free of charge and does not require a lawyer.
Steps to File a DPC Complaint
- Try to resolve the issue directly with the organisation first. Keep copies of all correspondence.
- Visit dataprotection.ie and use the online complaint form, or write to the DPC's offices in Dublin or Portarlington.
- Include a clear timeline of events, copies of your original requests, and the organisation's responses.
- Explain what outcome you're seeking — for example, deletion of your data, correction, or a formal reprimand.
- The DPC will acknowledge receipt and assign a case handler. Investigations can take months, especially in cross-border cases.
Special Categories: Sensitive Data
GDPR gives extra protection to certain "special category" data. Organisations generally cannot process this without explicit consent or a specific legal exception. Special categories include:
- Racial or ethnic origin
- Political opinions
- Religious or philosophical beliefs
- Trade union membership
- Genetic and biometric data (such as fingerprints or facial recognition)
- Health data
- Data concerning sex life or sexual orientation
In Ireland, health data is particularly sensitive given the ongoing legacy of the HSE ransomware attack in 2021, which exposed the medical records of thousands of patients and prompted stricter enforcement across the healthcare sector.
Cookies, Tracking, and the ePrivacy Regulations
Alongside GDPR, Ireland enforces the European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011 — commonly called the ePrivacy Regulations. These rules govern cookies, tracking pixels, and marketing communications.
Under these rules, a website must:
- Get your prior consent before setting non-essential cookies
- Make it as easy to reject cookies as to accept them
- Not use "dark patterns" like pre-ticked boxes or confusing colour schemes
- Provide clear information about what each cookie does
The DPC published detailed cookie guidance in 2020 and has actively investigated non-compliant sites, including Irish media outlets and public sector websites.
Protecting Your Privacy in Practice
Knowing your rights is one thing — actively protecting your data is another. Here are practical measures you can take as an Irish resident to reduce your exposure.
Minimise the Data You Share
The best data breach is one that never happens because the data was never collected. Use disposable email addresses for one-off signups, avoid oversharing on social media, and question whether an app or service really needs access to your contacts, location, or camera.
Use Privacy-Respecting Tools
Choose browsers, search engines, and messaging apps that treat privacy as a default rather than a paid upgrade. Encrypted DNS resolvers, private search engines like DuckDuckGo, and end-to-end encrypted messengers like Signal all reduce the trail of data you leave behind.
Be Careful with Shortened Links
Link shorteners are useful, but many free services log detailed information about everyone who clicks — IP addresses, browser fingerprints, referrer data — and monetise that data. If you share links regularly, choose a shortener that publishes a clear privacy policy and doesn't sell click data. Lunyb, for instance, is designed with a privacy-first approach and gives you control over what analytics are collected. For a broader comparison of options, see our 2026 buyer's guide to URL shorteners or read our detailed Rebrandly review.
Regularly Audit Your Data Footprint
Once a year, take an hour to:
- Log into Google, Apple, and Microsoft privacy dashboards and delete old data
- Review app permissions on your phone
- Unsubscribe from mailing lists you no longer read
- Close dormant accounts using services like JustDeleteMe
- Check haveibeenpwned.com to see if your email has been in any breaches
GDPR Fines and Enforcement in Ireland: A Track Record
The DPC has become one of the most active regulators in the EU. Recent notable enforcement actions include:
- Meta (2023): €1.2 billion for unlawful transfers of EU user data to the United States
- TikTok (2023): €345 million for mishandling children's data
- Instagram (2022): €405 million for children's privacy failures
- WhatsApp (2021): €225 million for transparency violations
These cases show that GDPR is not a paper tiger — but they also underline why individuals need to actively use their rights, because regulators cannot catch every violation on their own.
Children's Data and Digital Age of Consent
Ireland set the digital age of consent at 16 under the Data Protection Act 2018. This means online services relying on consent as their legal basis need parental permission to process the data of anyone under 16. The DPC published the "Fundamentals for a Child-Oriented Approach to Data Processing" in 2021, setting expectations that apps and platforms must design their products with children's best interests in mind — a standard that has since influenced regulation across Europe.
Frequently Asked Questions
Can I make a GDPR request to a company outside the EU?
Yes. GDPR applies to any organisation that offers goods or services to people in Ireland or monitors their behaviour, regardless of where the company is based. If a US-based app has Irish users, it must comply with GDPR and respond to your requests. If it refuses, you can complain to the DPC.
How long does an organisation have to respond to my Subject Access Request?
One calendar month from the date they receive your request. This can be extended by a further two months for complex or numerous requests, but they must tell you within the first month and explain why.
Do I need to pay to make a GDPR request or DPC complaint?
No. Subject Access Requests and complaints to the Data Protection Commission are free. An organisation can only charge a "reasonable fee" if your request is manifestly unfounded or excessive — which is rare in practice.
What can I do if a small business ignores my GDPR request?
Small businesses have exactly the same obligations as large multinationals under GDPR. Send a written reminder referencing Article 15, give them a clear deadline, and if they still don't respond, file a complaint with the DPC. Many small businesses simply don't understand their obligations, so a firm but polite reminder often resolves the issue.
Does GDPR protect me from government surveillance?
GDPR primarily governs commercial and public-sector data processing, but it does apply to Irish government bodies. However, there are exemptions for national security, law enforcement, and intelligence services, which are governed by separate frameworks such as the Law Enforcement Directive. Additional oversight comes from the courts and independent bodies like the Designated Judge.
Final Thoughts
GDPR gives people in Ireland an exceptionally strong toolkit for controlling their personal data — but those rights only matter when they're actually used. Sending a Subject Access Request, objecting to marketing, or lodging a complaint with the DPC costs you nothing and forces organisations to take your privacy seriously. Combined with sensible digital habits and privacy-respecting tools, you can meaningfully reduce your exposure and reclaim control over your digital footprint.
Privacy is a long game. The more you exercise your rights, the more organisations learn to treat data responsibly — and the healthier the digital ecosystem becomes for everyone in Ireland.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Data Protection Act 2018 Ireland: Complete Guide for Businesses
Ireland's Data Protection Act 2018 gives effect to GDPR and adds Irish-specific rules on children's data, health data, and DPC powers. This complete guide explains the Act's scope, principles, individual rights, obligations, and penalties, with a practical compliance checklist for Irish businesses.
UK Data Protection Act vs GDPR Explained: A 2026 Compliance Guide
The UK Data Protection Act 2018 and the EU GDPR share the same DNA but differ in enforcement, fines, and international transfer rules. This 2026 guide breaks down the key differences and shows UK businesses how to stay compliant with both regimes.
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
Learn exactly how to file a privacy complaint with Ireland's Data Protection Commission (DPC). This step-by-step guide covers evidence, timelines, your rights, and what to expect after submission.
PIPEDA vs GDPR: Canadian Privacy Law Explained (2026 Guide)
PIPEDA and the GDPR both protect personal data, but they differ dramatically in consent rules, individual rights, breach timelines, and penalties. This guide compares the two frameworks side-by-side and shows Canadian businesses how to achieve dual compliance in 2026.