GDPR in Ireland: Your Privacy Rights Explained (2026 Guide)
Ireland sits at the heart of Europe's data protection landscape. With the European headquarters of Meta, Google, TikTok, Apple, LinkedIn, and countless other tech giants based in Dublin, the Irish Data Protection Commission (DPC) has become one of the most influential privacy regulators in the world. If you live in Ireland, this means the General Data Protection Regulation (GDPR) gives you some of the strongest privacy rights on the planet — and a well-resourced authority to help enforce them.
This guide explains, in plain English, what GDPR means for people living in Ireland, the rights you have over your personal data, how to exercise them, and what to do when a company doesn't play by the rules.
What Is GDPR and How Does It Apply in Ireland?
The General Data Protection Regulation (GDPR) is an EU-wide law that came into force on 25 May 2018. It sets out how organisations must collect, store, and use the personal data of people in the EU. In Ireland, GDPR is implemented alongside the Data Protection Act 2018, which fills in national details and gives the Irish Data Protection Commission its enforcement powers.
GDPR applies to any organisation — regardless of where it is based — that processes the personal data of people located in Ireland or the wider EU. That means a US-based social network, an Indian e-commerce site, or a local Dublin shop all have to follow the same core rules when they collect your information.
What Counts as 'Personal Data'?
Personal data is any information that can identify a living person, directly or indirectly. Examples include:
- Your name, address, phone number, or email
- Your PPS number or passport details
- IP addresses, cookie identifiers, and device IDs
- Photos, CCTV footage, and voice recordings
- Location data from your phone
- Health, biometric, or genetic information (classed as 'special category' data with extra protections)
Your Eight Core Privacy Rights Under GDPR
GDPR grants every person in Ireland eight specific rights over their personal data. Understanding these is the first step to taking control of your digital life.
1. The Right to Be Informed
Organisations must tell you clearly what data they collect, why they collect it, how long they'll keep it, and who they share it with. This is usually done through a privacy notice or policy — the document most people scroll past before clicking 'Accept'.
2. The Right of Access (Subject Access Request)
You can ask any organisation to give you a copy of the personal data they hold about you. This is called a Subject Access Request (SAR). They must respond within one month, and in most cases it's free.
3. The Right to Rectification
If a company holds inaccurate or incomplete information about you, you can require them to fix it — again, within one month.
4. The Right to Erasure ('Right to Be Forgotten')
You can request that your personal data be deleted when it's no longer necessary, when you withdraw consent, or when it's been unlawfully processed. This right isn't absolute — an employer, for example, may need to keep tax records for years.
5. The Right to Restrict Processing
You can ask an organisation to pause using your data while a dispute is resolved — for example, while they verify whether the data is accurate.
6. The Right to Data Portability
You can request your data in a common, machine-readable format (like CSV or JSON) and have it transferred to another provider. This is especially useful when switching banks, streaming services, or social platforms.
7. The Right to Object
You can object to your data being used for direct marketing at any time, and the organisation must stop immediately. You can also object to processing based on 'legitimate interests' or public tasks.
8. Rights Related to Automated Decision-Making
If a fully automated system makes a significant decision about you — such as a loan refusal or a job screening — you have the right to human review and to challenge that decision.
The Role of the Irish Data Protection Commission (DPC)
The Data Protection Commission, based in Dublin and Portarlington, is Ireland's national supervisory authority for GDPR. Because so many multinational tech companies have their EU headquarters in Ireland, the DPC acts as 'lead supervisory authority' for those firms across the entire European Economic Area under the GDPR's One-Stop-Shop mechanism.
The DPC's responsibilities include:
- Handling complaints from individuals whose rights have been infringed
- Investigating data breaches and non-compliance
- Issuing binding decisions and fines (up to €20 million or 4% of global turnover, whichever is higher)
- Providing guidance to businesses and public bodies
- Cooperating with other EU data protection authorities
Recent enforcement highlights show the DPC's teeth: Meta has been fined over €1.2 billion for illegal data transfers, TikTok received a €345 million fine over children's data handling, and Instagram was penalised €405 million for how it processed teenage users' information.
Lawful Bases: Why Companies Can Process Your Data
Under GDPR, an organisation cannot process your data 'just because'. It must have one of six lawful bases:
| Lawful Basis | What It Means | Everyday Example |
|---|---|---|
| Consent | You freely agreed after being informed | Opting into a newsletter |
| Contract | Needed to fulfil an agreement with you | Your address for a delivery |
| Legal Obligation | Required by law | Revenue keeping tax records |
| Vital Interests | To protect someone's life | Hospital treating an unconscious patient |
| Public Task | Carrying out a function in the public interest | Local authority census work |
| Legitimate Interests | Reasonable business use that doesn't override your rights | Fraud prevention checks |
Consent, when used, must be a clear, affirmative action — pre-ticked boxes or buried terms don't count. You also have the right to withdraw consent as easily as you gave it.
How to Make a Subject Access Request in Ireland
A Subject Access Request (SAR) is the most powerful and commonly used GDPR right. Here's how to make one:
- Identify the controller. This is the organisation that decides how your data is used. Their contact details should be in their privacy policy.
- Write to them. Email is fine. State clearly: "I am making a subject access request under Article 15 of the GDPR."
- Specify what you want (optional). You can ask for everything, or narrow it down to a specific time period or type of data.
- Verify your identity. They may reasonably ask for ID to prevent someone impersonating you.
- Wait up to one month. Complex requests can be extended by two further months, but they must tell you why.
- Escalate if needed. If they refuse or ignore you, you can complain to the DPC.
What to Do About a Data Breach
A data breach is any incident where personal data is lost, stolen, exposed, or accessed without authorisation. Under GDPR, organisations must:
- Notify the DPC within 72 hours of becoming aware of a breach that risks people's rights
- Notify affected individuals directly if the breach is likely to result in a 'high risk' — for example, if passwords or financial information were exposed
If you receive a breach notification, act quickly:
- Change any affected passwords immediately, and don't reuse them elsewhere
- Enable two-factor authentication where possible
- Monitor your bank and credit card statements
- Be alert to phishing emails and calls pretending to be from the breached company
- Consider a fraud alert on your accounts
Protecting Your Privacy Day-to-Day
GDPR gives you legal rights, but proactive habits reduce how much personal data ends up out there in the first place. A few practical steps for people in Ireland:
Minimise the Data You Share
Every form, competition, and loyalty scheme collects data. Ask yourself: do they really need my date of birth, my Eircode, or my phone number? If a field isn't marked required, leave it blank.
Use Privacy-Respecting Tools
When sharing links — for example on social media, in newsletters, or with clients — consider a privacy-conscious link management platform. Services like Lunyb let you create short, branded links without harvesting excessive tracking data or bombarding recipients with third-party scripts. If you're evaluating options, our roundup of the best URL shorteners for 2026 compares privacy features across the major providers.
Manage Cookies Properly
Under Irish ePrivacy rules and DPC guidance, websites must give you a genuine choice about non-essential cookies. 'Reject All' should be as easy to click as 'Accept All'. If it isn't, that's a red flag — and something the DPC has taken action on.
Review App Permissions
Your smartphone is the single biggest source of personal data leaks. Regularly audit which apps have access to your location, microphone, contacts, and photos — and revoke anything that isn't essential.
Encrypt and Secure Your Network
Use encrypted DNS (like DNS-over-HTTPS in your browser), keep your home Wi-Fi password strong, and prefer HTTPS-enabled websites. Modern browsers such as Firefox and Brave offer built-in tracker blocking that meaningfully reduces the data advertisers can gather.
Special Considerations for Children's Data in Ireland
Ireland has set the 'digital age of consent' at 16 — one of the highest in the EU. This means children under 16 cannot legally consent to having their data processed by online services; a parent or guardian must consent on their behalf. The DPC has published a set of Fundamentals for a Child-Oriented Approach to Data Processing, which platforms serving Irish children are expected to follow, including default private profiles and minimal data collection.
How to Complain to the Data Protection Commission
If an organisation ignores your rights or mishandles your data, you can complain to the DPC — free of charge. The process:
- Try to resolve it directly first. Contact the organisation's Data Protection Officer (DPO) in writing.
- Gather evidence. Save emails, screenshots, and any responses (or lack of them).
- Submit a complaint via the DPC's online form at dataprotection.ie, or by post to their offices in Portarlington or Dublin.
- Cooperate with the investigation. The DPC may ask for more information as they assess your case.
- Await the outcome. The DPC can order the organisation to comply, impose fines, or refer the matter for further action.
You also retain the right to seek a judicial remedy through the Irish courts, including compensation for material or non-material damage caused by a GDPR infringement.
GDPR at Work: Employees' Rights in Ireland
Your GDPR rights apply in the workplace too. Employers can process employee data for legitimate purposes — payroll, health and safety, performance management — but they must be transparent and proportionate.
Key points for Irish workers:
- You can make a SAR to your employer or former employer for a copy of your HR file
- Workplace CCTV must be justified, signposted, and not used for covert monitoring except in exceptional circumstances
- Monitoring of email, internet use, or messaging platforms requires a clear policy and a lawful basis
- Biometric attendance systems (fingerprint clock-ins) generally require explicit consent and a data protection impact assessment
Frequently Asked Questions
Does GDPR still apply after Brexit if I deal with UK companies?
Yes. If you're in Ireland and a UK company processes your personal data, they must still comply with GDPR (and their own UK GDPR, which is broadly equivalent). Data transfers between Ireland and the UK are permitted under an EU adequacy decision, which is periodically reviewed.
How much can I claim if my data is misused?
GDPR allows compensation for both material damage (financial loss) and non-material damage (distress, anxiety, reputational harm). There's no fixed tariff — recent Irish and EU case law suggests non-material awards typically range from a few hundred to several thousand euro, depending on severity.
Can a company charge me for a Subject Access Request?
No, not in the vast majority of cases. SARs are free. A controller can only charge a 'reasonable fee' if the request is 'manifestly unfounded or excessive' — a high bar they must be able to justify.
How long can a company keep my data?
Only as long as necessary for the purpose it was collected. There's no single time limit — a receipt for tax purposes may be kept for six years, a job application for a year or so, and marketing consents typically need refreshing every couple of years. Companies must publish their retention periods in their privacy notice.
Do small businesses in Ireland have to comply with GDPR?
Yes. GDPR applies regardless of size — a sole trader in Galway is subject to the same core principles as Meta. However, obligations are proportionate: a small business handling limited, low-risk data isn't required to appoint a Data Protection Officer or keep the same level of documentation as a large enterprise.
Final Thoughts
GDPR gives people in Ireland a level of control over their personal data that would have seemed unimaginable a decade ago. The rights are real, the Data Protection Commission has both the authority and the willingness to enforce them, and the penalties for organisations that get it wrong are eye-watering.
The catch is that these rights only work if you use them. Read privacy notices before you click 'Accept', question why any organisation needs the data it asks for, and don't hesitate to submit a Subject Access Request or complain to the DPC when something feels wrong. Combined with sensible everyday habits — strong passwords, minimal data sharing, privacy-respecting tools — GDPR turns from a legal abstraction into a genuine shield for your digital life.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
GDPR in Ireland: Your Privacy Rights Explained
The General Data Protection Regulation gives people in Ireland powerful rights over their personal data. This guide explains what those rights are, how the Data Protection Commission enforces them, and the practical steps you can take to protect your privacy online.
Australia Privacy Act 2026: Your Rights Explained
The Australia Privacy Act 2026 gives Australians stronger rights over their personal information, including the right to erasure, a direct right to sue for serious privacy invasions, and enhanced protections for children. This guide explains what's changed, who's covered, and what individuals and businesses need to do now.
How Canadian Businesses Should Handle Data Privacy in 2026
Canadian businesses face a rapidly evolving privacy landscape in 2026, from PIPEDA and Quebec's Law 25 to the anticipated CPPA. This guide covers the laws that apply, common compliance mistakes, and a practical framework for building a defensible data privacy program.
Singapore PDPA vs GDPR: Key Differences Every Business Must Know
Singapore's PDPA and the EU's GDPR both protect personal data, but differ sharply in scope, consent, penalties, and breach rules. This guide compares the two laws side-by-side and shows Singapore businesses how to build a unified compliance strategy.