facebook-pixel

GDPR in Ireland: Your Privacy Rights Explained

L
Lunyb Security Team
··11 min read

Ireland occupies a unique position in the European data protection landscape. As the European headquarters for many of the world's largest technology companies — including Meta, Google, Apple, TikTok, and Microsoft — the Irish Data Protection Commission (DPC) is effectively the lead regulator for hundreds of millions of people across the EU. If you live in Ireland, the General Data Protection Regulation (GDPR), together with the Irish Data Protection Act 2018, gives you some of the strongest privacy rights in the world.

But rights are only useful if you know how to exercise them. This guide breaks down exactly what GDPR means for people in Ireland, the eight rights you can rely on, how to make a complaint to the DPC, and practical steps to protect your personal data online.

What Is GDPR and How Does It Apply in Ireland?

The General Data Protection Regulation is an EU-wide law that governs how organisations collect, store, and use personal data. It came into force on 25 May 2018 and applies directly in every EU member state, including Ireland. Alongside GDPR, Ireland has its own Data Protection Act 2018, which fills in the gaps left by the regulation and establishes the Data Protection Commission as the national supervisory authority.

GDPR applies to any organisation — whether based in Ireland, the EU, or outside — that processes the personal data of people located in Ireland. This includes:

  • Irish businesses of any size, from sole traders to multinationals
  • Public bodies and government departments
  • Charities, sports clubs, and community groups
  • Foreign companies that offer goods or services to Irish residents
  • Online platforms, apps, and websites that track Irish users

"Personal data" is defined broadly. It includes obvious things like your name, address, PPS number, and email, but also less obvious identifiers such as IP addresses, cookie IDs, location data, and even inferred data like your shopping preferences or political views.

Who Enforces GDPR in Ireland?

The Data Protection Commission (DPC), headquartered in Dublin, is Ireland's independent regulator. It has the power to investigate complaints, audit organisations, issue reprimands, order the deletion of data, and impose fines of up to €20 million or 4% of global annual turnover — whichever is higher. In recent years, the DPC has handed down some of the largest GDPR fines in Europe, including a €1.2 billion penalty against Meta in 2023 for unlawful data transfers.

Your Eight Core GDPR Rights in Ireland

GDPR grants every person in Ireland eight fundamental rights over their personal data. Understanding each one is the first step to taking control of your digital life.

1. The Right to Be Informed

Organisations must tell you, in clear and plain language, what data they collect about you, why they collect it, how long they keep it, who they share it with, and what legal basis they rely on. This is why every reputable website has a privacy notice — and why unclear or missing notices are a red flag.

2. The Right of Access (Subject Access Request)

You can ask any organisation to give you a copy of the personal data they hold about you. This is called a Subject Access Request (SAR). The organisation must respond within one month and, in most cases, provide the data free of charge.

3. The Right to Rectification

If any data an organisation holds about you is inaccurate or incomplete, you have the right to have it corrected without undue delay.

4. The Right to Erasure ("Right to Be Forgotten")

You can request the deletion of your personal data in specific circumstances — for example, if the data is no longer needed, if you withdraw consent, or if it was processed unlawfully. This right is not absolute; organisations may refuse if they have a legal obligation to keep the data (such as tax records) or a compelling legitimate interest.

5. The Right to Restrict Processing

You can ask an organisation to pause the processing of your data while a dispute is resolved — for instance, while they investigate whether your data is accurate.

6. The Right to Data Portability

You can request your data in a structured, commonly used, machine-readable format (like CSV or JSON) and transfer it to another service. This is especially relevant for banking, social media, and health apps.

7. The Right to Object

You can object to your data being processed for direct marketing (this must always be respected) or for purposes based on "legitimate interests" where you have a strong personal reason.

8. Rights Related to Automated Decision-Making

If a decision that significantly affects you — such as a loan application, insurance quote, or job screening — is made purely by an algorithm, you have the right to human review and to contest that decision.

Legal Bases: When Can Organisations Process Your Data?

Under GDPR, an organisation cannot simply collect data because it wants to. It must have one of six lawful bases for processing. Knowing these helps you challenge misuse.

Legal BasisWhen It AppliesExample
ConsentYou've given clear, specific, freely given permissionSigning up for a newsletter
ContractProcessing is needed to fulfil a contract with youDelivering an online order
Legal obligationRequired by Irish or EU lawRevenue reporting payroll data
Vital interestsTo protect someone's lifeSharing medical info in an emergency
Public taskCarrying out an official public functionHSE processing patient records
Legitimate interestsBalanced against your rights and freedomsFraud prevention by a bank

Consent, in particular, must be a genuine choice. Pre-ticked boxes, bundled consents, or "take it or leave it" cookie banners are not valid under GDPR, and the DPC has fined multiple companies for this exact issue.

How to Make a Subject Access Request in Ireland

A Subject Access Request is one of the most powerful tools you have. Here is a step-by-step process to submit one:

  1. Identify the data controller. This is the organisation that decides how your data is used — usually the company you interacted with.
  2. Find their contact point. Most privacy notices list a Data Protection Officer (DPO) email, often dpo@company.ie or a dedicated privacy portal.
  3. Write your request in plain language. You don't need a solicitor. State clearly: "Under Article 15 GDPR, I am requesting a copy of all personal data you hold about me."
  4. Prove your identity. The organisation may ask for reasonable verification, such as a photo ID or account confirmation.
  5. Wait up to one month. The response should be free unless your request is manifestly excessive or repetitive.
  6. Review the response carefully. If it is incomplete or missing, you can push back or escalate to the DPC.

How to Complain to the Data Protection Commission

If an organisation ignores your rights, mishandles your data, or refuses your request, you can lodge a complaint with the DPC. This is free of charge and does not require a lawyer.

Steps to File a DPC Complaint

  1. Try to resolve the issue directly with the organisation first. Keep copies of all correspondence.
  2. Visit dataprotection.ie and use the online complaint form, or write to the DPC's offices in Dublin or Portarlington.
  3. Include a clear timeline of events, copies of your original requests, and the organisation's responses.
  4. Explain what outcome you're seeking — for example, deletion of your data, correction, or a formal reprimand.
  5. The DPC will acknowledge receipt and assign a case handler. Investigations can take months, especially in cross-border cases.

Special Categories: Sensitive Data

GDPR gives extra protection to certain "special category" data. Organisations generally cannot process this without explicit consent or a specific legal exception. Special categories include:

  • Racial or ethnic origin
  • Political opinions
  • Religious or philosophical beliefs
  • Trade union membership
  • Genetic and biometric data (such as fingerprints or facial recognition)
  • Health data
  • Data concerning sex life or sexual orientation

In Ireland, health data is particularly sensitive given the ongoing legacy of the HSE ransomware attack in 2021, which exposed the medical records of thousands of patients and prompted stricter enforcement across the healthcare sector.

Cookies, Tracking, and the ePrivacy Regulations

Alongside GDPR, Ireland enforces the European Communities (Electronic Communications Networks and Services) (Privacy and Electronic Communications) Regulations 2011 — commonly called the ePrivacy Regulations. These rules govern cookies, tracking pixels, and marketing communications.

Under these rules, a website must:

  • Get your prior consent before setting non-essential cookies
  • Make it as easy to reject cookies as to accept them
  • Not use "dark patterns" like pre-ticked boxes or confusing colour schemes
  • Provide clear information about what each cookie does

The DPC published detailed cookie guidance in 2020 and has actively investigated non-compliant sites, including Irish media outlets and public sector websites.

Protecting Your Privacy in Practice

Knowing your rights is one thing — actively protecting your data is another. Here are practical measures you can take as an Irish resident to reduce your exposure.

Minimise the Data You Share

The best data breach is one that never happens because the data was never collected. Use disposable email addresses for one-off signups, avoid oversharing on social media, and question whether an app or service really needs access to your contacts, location, or camera.

Use Privacy-Respecting Tools

Choose browsers, search engines, and messaging apps that treat privacy as a default rather than a paid upgrade. Encrypted DNS resolvers, private search engines like DuckDuckGo, and end-to-end encrypted messengers like Signal all reduce the trail of data you leave behind.

Be Careful with Shortened Links

Link shorteners are useful, but many free services log detailed information about everyone who clicks — IP addresses, browser fingerprints, referrer data — and monetise that data. If you share links regularly, choose a shortener that publishes a clear privacy policy and doesn't sell click data. Lunyb, for instance, is designed with a privacy-first approach and gives you control over what analytics are collected. For a broader comparison of options, see our 2026 buyer's guide to URL shorteners or read our detailed Rebrandly review.

Regularly Audit Your Data Footprint

Once a year, take an hour to:

  • Log into Google, Apple, and Microsoft privacy dashboards and delete old data
  • Review app permissions on your phone
  • Unsubscribe from mailing lists you no longer read
  • Close dormant accounts using services like JustDeleteMe
  • Check haveibeenpwned.com to see if your email has been in any breaches

GDPR Fines and Enforcement in Ireland: A Track Record

The DPC has become one of the most active regulators in the EU. Recent notable enforcement actions include:

  • Meta (2023): €1.2 billion for unlawful transfers of EU user data to the United States
  • TikTok (2023): €345 million for mishandling children's data
  • Instagram (2022): €405 million for children's privacy failures
  • WhatsApp (2021): €225 million for transparency violations

These cases show that GDPR is not a paper tiger — but they also underline why individuals need to actively use their rights, because regulators cannot catch every violation on their own.

Children's Data and Digital Age of Consent

Ireland set the digital age of consent at 16 under the Data Protection Act 2018. This means online services relying on consent as their legal basis need parental permission to process the data of anyone under 16. The DPC published the "Fundamentals for a Child-Oriented Approach to Data Processing" in 2021, setting expectations that apps and platforms must design their products with children's best interests in mind — a standard that has since influenced regulation across Europe.

Frequently Asked Questions

Can I make a GDPR request to a company outside the EU?

Yes. GDPR applies to any organisation that offers goods or services to people in Ireland or monitors their behaviour, regardless of where the company is based. If a US-based app has Irish users, it must comply with GDPR and respond to your requests. If it refuses, you can complain to the DPC.

How long does an organisation have to respond to my Subject Access Request?

One calendar month from the date they receive your request. This can be extended by a further two months for complex or numerous requests, but they must tell you within the first month and explain why.

Do I need to pay to make a GDPR request or DPC complaint?

No. Subject Access Requests and complaints to the Data Protection Commission are free. An organisation can only charge a "reasonable fee" if your request is manifestly unfounded or excessive — which is rare in practice.

What can I do if a small business ignores my GDPR request?

Small businesses have exactly the same obligations as large multinationals under GDPR. Send a written reminder referencing Article 15, give them a clear deadline, and if they still don't respond, file a complaint with the DPC. Many small businesses simply don't understand their obligations, so a firm but polite reminder often resolves the issue.

Does GDPR protect me from government surveillance?

GDPR primarily governs commercial and public-sector data processing, but it does apply to Irish government bodies. However, there are exemptions for national security, law enforcement, and intelligence services, which are governed by separate frameworks such as the Law Enforcement Directive. Additional oversight comes from the courts and independent bodies like the Designated Judge.

Final Thoughts

GDPR gives people in Ireland an exceptionally strong toolkit for controlling their personal data — but those rights only matter when they're actually used. Sending a Subject Access Request, objecting to marketing, or lodging a complaint with the DPC costs you nothing and forces organisations to take your privacy seriously. Combined with sensible digital habits and privacy-respecting tools, you can meaningfully reduce your exposure and reclaim control over your digital footprint.

Privacy is a long game. The more you exercise your rights, the more organisations learn to treat data responsibly — and the healthier the digital ecosystem becomes for everyone in Ireland.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles