facebook-pixel

GDPR in Ireland: Your Privacy Rights Explained (2026 Guide)

L
Lunyb Security Team
··10 min read

Ireland sits at the heart of European data protection. With most of the world's largest technology companies headquartered in Dublin, the Irish Data Protection Commission (DPC) has become one of the most influential regulators in Europe. If you live in Ireland — or your data is processed by an Irish-based company — the General Data Protection Regulation (GDPR) gives you a powerful set of enforceable rights. This guide explains exactly what those rights are, how to use them, and what to do when a company gets it wrong.

What Is GDPR and How Does It Apply in Ireland?

The General Data Protection Regulation (GDPR) is an EU-wide law that governs how organisations collect, store, and use personal data. In Ireland, it is implemented alongside the Data Protection Act 2018 and enforced by the Data Protection Commission (DPC), based in Dublin and Portarlington.

GDPR applies to any organisation — public or private — that processes the personal data of people in Ireland, regardless of where the organisation is based. That includes an Irish credit union storing member records, a US social network with Irish users, and a Dublin-based SaaS company selling to customers worldwide.

Why Ireland's Role Is Unique

Because companies like Meta, Google, TikTok, Microsoft, and Apple have their EU headquarters in Ireland, the DPC acts as the "lead supervisory authority" for most cross-border investigations under the GDPR's one-stop-shop mechanism. This means decisions made in Dublin often set precedent for the entire European Union.

The 8 Core GDPR Rights of Irish Residents

GDPR gives every person in Ireland eight fundamental rights over their personal data. Organisations must respond to most requests within one month, free of charge in the vast majority of cases.

1. The Right to Be Informed

You have the right to know what data is collected about you, why, how long it will be kept, and who it will be shared with. This is typically delivered through a privacy notice on a website or at the point of sign-up.

2. The Right of Access (Subject Access Request)

You can ask any organisation for a copy of the personal data they hold about you. This is known as a Subject Access Request (SAR). The organisation must reply within one month and cannot charge you unless the request is manifestly unfounded or excessive.

3. The Right to Rectification

If data held about you is inaccurate or incomplete, you can require the controller to correct or update it. This matters most for financial records, credit reports, and health data.

4. The Right to Erasure ("Right to Be Forgotten")

You can ask an organisation to delete your data when it is no longer needed, when you withdraw consent, or when it has been processed unlawfully. There are exceptions — for example, banks must retain transactional data under anti-money-laundering rules.

5. The Right to Restrict Processing

You can ask a controller to pause using your data while a dispute is resolved — for example, while accuracy is being verified.

6. The Right to Data Portability

You can obtain your data in a structured, machine-readable format (such as CSV or JSON) and transfer it to another provider. This applies to data you provided directly, processed by automated means, based on consent or a contract.

7. The Right to Object

You can object to processing based on legitimate interests or public interest, and you can absolutely object to direct marketing at any time — with no exceptions.

8. Rights Related to Automated Decision-Making

You have the right not to be subject to decisions made solely by automated means — including profiling — that produce legal or similarly significant effects, such as being refused credit or a job.

Lawful Bases for Processing Under GDPR

An organisation cannot simply collect your data because it wants to. It must identify one of six lawful bases before processing begins.

Lawful BasisTypical Example in Ireland
ConsentSigning up for a newsletter from an Irish retailer
ContractProviding your Eircode to Revolut to open an account
Legal obligationRevenue processing your PPS number for tax
Vital interestsHSE using medical data in an emergency
Public taskA local council processing housing applications
Legitimate interestsFraud prevention by an online bank

How to Submit a Subject Access Request in Ireland

A Subject Access Request is the most-used GDPR right. You do not need a solicitor, and you do not need to justify why you are asking.

  1. Identify the controller. Find the company's Data Protection Officer (DPO) or privacy contact — usually listed in the privacy policy.
  2. Put the request in writing. Email is fine. State clearly that you are making a Subject Access Request under Article 15 GDPR.
  3. Verify your identity. The controller may ask for proof of identity but cannot demand more than is reasonably necessary.
  4. Specify what you want. You can ask for everything, or narrow it down (e.g. "all call recordings from 2024").
  5. Wait up to one month. Complex requests may be extended by two further months, but the controller must tell you within the first month.
  6. Review and act. If the response is incomplete or missing, escalate internally or complain to the DPC.

Making a Complaint to the Data Protection Commission

If an organisation fails to respect your rights, you can lodge a complaint with the DPC free of charge. The DPC will assess the complaint, attempt amicable resolution, and — if necessary — open a formal inquiry.

What You Need to Include

  • Your name and contact details
  • The name of the organisation you are complaining about
  • A clear description of what happened and when
  • Copies of any correspondence with the organisation
  • The outcome you are seeking (e.g. deletion, correction, compensation)

Complaints can be submitted through the DPC's online webform at dataprotection.ie. There is no time limit in law, but the sooner you complain, the easier it is to investigate.

Cookies, Tracking, and ePrivacy in Ireland

GDPR works alongside the ePrivacy Regulations (S.I. 336 of 2011) in Ireland. Together, they require that websites obtain your freely given, specific, informed, and unambiguous consent before setting non-essential cookies or tracking scripts.

In practice, this means:

  • Pre-ticked boxes are not valid consent.
  • "Reject All" must be as easy to click as "Accept All".
  • You must be able to withdraw consent as easily as you gave it.
  • Cookie walls that force acceptance to access content are generally unlawful.

The DPC has fined several Irish and multinational operators for non-compliant cookie banners since 2020.

Data Breaches: What Companies Must Do

If your data is compromised in a breach, GDPR imposes strict duties on the controller.

  1. Notify the DPC within 72 hours of becoming aware of a breach that risks people's rights and freedoms.
  2. Notify affected individuals "without undue delay" if the breach is likely to result in a high risk — for example, exposure of financial details or health data.
  3. Document every breach, even ones not reported to the DPC, in an internal breach register.

If you receive a breach notification, take it seriously: change passwords, enable two-factor authentication, and monitor your accounts for unusual activity.

Penalties for GDPR Violations

The DPC can impose administrative fines up to €20 million or 4% of an organisation's global annual turnover, whichever is higher. Ireland has issued some of the largest GDPR fines in Europe.

YearCompanyFine (approx.)Reason
2023Meta (Facebook)€1.2 billionUnlawful EU–US data transfers
2023TikTok€345 millionChildren's data processing
2022Meta (Instagram)€405 millionChildren's account defaults
2021WhatsApp€225 millionTransparency failures

Practical Steps to Protect Your Privacy Rights

Understanding your rights is one thing — exercising them day-to-day is another. Here are practical steps every Irish resident can take to reduce data exposure.

1. Audit Your Digital Footprint

List the top 20 services you use — banks, social media, retailers, streaming — and check their privacy settings. Turn off unnecessary permissions, marketing consents, and ad personalisation.

2. Use Privacy-Respecting Tools

Choose a privacy-focused browser (such as Firefox or Brave), enable encrypted DNS resolvers, and use link-tracking-free tools when sharing URLs. A short-link service like Lunyb lets you share clean, trackable-by-you links without exposing recipients to third-party analytics beacons — useful for businesses that want to stay GDPR-compliant when sharing content. You can read our honest Lunyb review or compare options in our 2026 URL shortener buyer's guide.

3. Read Privacy Notices Before You Sign Up

Focus on three things: what data is collected, who it is shared with, and how long it is retained. Anything vague is a red flag.

4. Exercise Your Rights Regularly

Submit an occasional SAR to a company you interact with heavily. It's the fastest way to see what's really being stored — and to spot processing you didn't consent to.

5. Keep Records

Save copies of consents, opt-outs, and correspondence. If you need to complain to the DPC, evidence makes the process significantly faster.

GDPR for Small Businesses and Sole Traders in Ireland

If you run a business in Ireland — even as a sole trader — GDPR applies the moment you process personal data (customer names, emails, delivery addresses). Key obligations include:

  • Maintaining a Record of Processing Activities (ROPA)
  • Publishing a clear, accurate privacy notice
  • Using GDPR-compliant contracts with processors (e.g. Mailchimp, Stripe)
  • Reporting qualifying breaches to the DPC within 72 hours
  • Appointing a Data Protection Officer if you carry out large-scale monitoring or handle special category data

The DPC publishes free guidance specifically for SMEs, and there is no registration fee to operate under GDPR in Ireland.

Frequently Asked Questions

Is GDPR still in force in Ireland after Brexit?

Yes. Ireland remains an EU member state, so the EU GDPR continues to apply in full. Brexit only affected the UK, which now operates its own "UK GDPR" — a near-identical but separate regime.

How long does a company have to respond to my Subject Access Request?

One calendar month from the date the request is received. This can be extended by up to two further months for complex requests, but the controller must inform you of the extension within the first month.

Can I be charged for exercising my GDPR rights?

No, not in normal circumstances. Requests must be handled free of charge. A "reasonable fee" is only permitted where a request is manifestly unfounded, excessive, or repetitive — and the controller must be able to justify that decision.

What happens if I ignore a company's request to verify my identity?

The controller can refuse to act on the request if they cannot reasonably confirm you are the person the data relates to. However, they cannot demand excessive documentation — a passport scan is rarely necessary for a routine email SAR.

Can I claim compensation for a GDPR breach?

Yes. Under Article 82 GDPR and Section 117 of the Data Protection Act 2018, you can bring a civil action in the Irish Circuit Court or High Court for material or non-material damage — including distress — caused by an infringement.

Final Thoughts

GDPR is not a bureaucratic inconvenience — it is one of the strongest sets of privacy protections in the world, and in Ireland it is enforced by a regulator with genuine global reach. Knowing your eight rights, understanding how to submit a Subject Access Request, and keeping good records puts you in a strong position whenever an organisation mishandles your data. Combine that legal knowledge with sensible privacy hygiene, and you have real control over your digital life.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles