facebook-pixel

GDPR in Ireland: Your Privacy Rights Explained

L
Lunyb Security Team
··11 min read

The General Data Protection Regulation (GDPR) is the cornerstone of privacy law in Ireland. Since it took effect in May 2018, alongside the Irish Data Protection Act 2018, it has given individuals unprecedented control over how their personal information is collected, stored, and used. If you live in Ireland—or interact with Irish businesses—you have specific, enforceable rights that companies must respect.

This guide breaks down what GDPR means for you in Ireland, the eight core rights it grants, how the Data Protection Commission (DPC) enforces the law, and the practical steps you can take to protect your personal data every day.

What Is GDPR and Why Does It Matter in Ireland?

GDPR is a European Union regulation that governs how personal data is processed by organisations operating in or serving individuals within the EU. In Ireland, it is applied alongside the Data Protection Act 2018, which fills in national details such as the age of digital consent (16) and the powers of the Data Protection Commission.

Ireland plays an outsized role in GDPR enforcement because many of the world's largest technology firms—Meta, Google, TikTok, Microsoft, LinkedIn, and X among them—have their European headquarters in Dublin. As a result, the Irish DPC is the lead supervisory authority for cross-border complaints involving these companies, making Irish privacy law relevant far beyond the country's borders.

Who GDPR Protects

GDPR protects any identifiable natural person in Ireland—known as a "data subject." This includes citizens, residents, tourists, and anyone whose data is processed by an Irish-based organisation. It does not protect companies or deceased persons.

Who GDPR Applies To

The regulation applies to:

  • Any organisation established in Ireland that processes personal data.
  • Non-EU organisations that offer goods or services to people in Ireland.
  • Organisations that monitor the behaviour of people in Ireland (for example, through website tracking).

The Eight Core Privacy Rights Under GDPR

GDPR grants every individual in Ireland eight fundamental rights over their personal data. Understanding each one is the first step to exercising control over your digital life.

RightWhat It MeansGDPR Article
Right to be InformedKnow what data is collected and whyArticles 13–14
Right of AccessRequest a copy of your dataArticle 15
Right to RectificationCorrect inaccurate dataArticle 16
Right to ErasureHave data deleted ("right to be forgotten")Article 17
Right to Restrict ProcessingLimit how data is usedArticle 18
Right to Data PortabilityReceive data in a portable formatArticle 20
Right to ObjectRefuse certain processing (e.g. marketing)Article 21
Rights Around Automated DecisionsNot be subject to solely automated decisionsArticle 22

1. The Right to Be Informed

Organisations must clearly tell you what personal data they collect, why they collect it, how long they keep it, and who they share it with. This is typically communicated through a privacy notice or policy on a website. If a company cannot explain in plain English what it does with your data, it is failing this obligation.

2. The Right of Access (Subject Access Request)

You can ask any organisation to give you a copy of the personal data it holds about you. This is called a Subject Access Request (SAR). In Ireland, organisations must respond within one calendar month and, in most cases, cannot charge a fee.

3. The Right to Rectification

If a company holds inaccurate or incomplete data about you, you have the right to have it corrected. This is particularly important for credit records, medical files, and employment data.

4. The Right to Erasure

Also known as the "right to be forgotten," this allows you to request that your data be deleted when it is no longer necessary, when you withdraw consent, or when it has been processed unlawfully. It is not absolute—organisations can refuse if they have legal grounds to retain data (for example, tax records).

5. The Right to Restrict Processing

You can ask an organisation to pause the processing of your data while a dispute is resolved, such as when you contest the accuracy of the information.

6. The Right to Data Portability

You can request your data in a structured, commonly used, machine-readable format (such as CSV or JSON) and transfer it to another service. This is common when switching banks, streaming platforms, or social media services.

7. The Right to Object

You can object to processing for direct marketing at any time, and the organisation must stop immediately. You can also object to processing based on "legitimate interests" or public tasks, though the organisation may be able to override the objection in some cases.

8. Rights Related to Automated Decision-Making

You have the right not to be subject to decisions made solely by automated means—such as algorithmic loan approvals or profiling—if those decisions have a significant effect on you. You can request human review.

The Role of the Irish Data Protection Commission (DPC)

The Data Protection Commission is the national independent authority responsible for upholding GDPR in Ireland. Based in Dublin and Portarlington, it investigates complaints, issues guidance, and imposes fines on organisations that break the law.

What the DPC Does

  • Receives and investigates complaints from individuals.
  • Conducts audits and inquiries into organisations.
  • Issues fines of up to €20 million or 4% of global annual turnover (whichever is higher).
  • Acts as lead supervisory authority for many multinational tech firms headquartered in Ireland.
  • Publishes guidance to help businesses and individuals understand the law.

Notable Enforcement Actions

The DPC has issued some of the largest GDPR fines to date, including a €1.2 billion penalty against Meta in 2023 for unlawful transfers of EU user data to the United States, and multi-hundred-million-euro fines against TikTok and WhatsApp for transparency and children's data violations. These cases show that Irish enforcement has real teeth—even against the world's largest platforms.

How to Make a GDPR Complaint in Ireland

If you believe an organisation has mishandled your personal data, you can take action in a structured, five-step process.

  1. Contact the organisation directly. Write to the company's Data Protection Officer (DPO) or privacy team. Clearly state what right you are exercising and what outcome you want.
  2. Wait for their response. They have one month to reply. Complex cases can be extended to three months with written justification.
  3. Gather evidence. Keep copies of all correspondence, screenshots, and any responses received.
  4. Submit a complaint to the DPC. If the organisation fails to respond or provides an unsatisfactory answer, you can file a complaint through the DPC's website at dataprotection.ie. There is no fee.
  5. Consider legal remedies. If you have suffered material or non-material damage, you may be entitled to compensation through the Irish courts under Section 117 of the Data Protection Act 2018.

Special Categories of Personal Data

Some data is considered particularly sensitive and receives extra protection under GDPR. Processing special category data is prohibited unless one of a limited number of conditions applies.

Special CategoryExamples
Health dataMedical records, prescriptions, fitness tracker data
Biometric dataFingerprints, facial recognition, iris scans
Genetic dataDNA test results
Racial or ethnic originEthnicity questionnaires
Political opinionsParty membership, voting preferences
Religious beliefsFaith-based memberships
Sexual orientationDating app preferences, identity data
Trade union membershipUnion enrolment records

Cookies, Tracking, and the ePrivacy Regulations

In Ireland, cookies and similar tracking technologies are governed by the ePrivacy Regulations 2011, which sit alongside GDPR. Websites must obtain your clear, informed consent before setting non-essential cookies—no more pre-ticked boxes or vague banners.

You should always be able to:

  • Reject all non-essential cookies as easily as you can accept them.
  • See a granular breakdown of cookie categories (analytics, advertising, functional).
  • Withdraw consent at any time.

The DPC has been active in enforcing cookie rules, warning both Irish businesses and international platforms about non-compliant banners.

Practical Steps to Protect Your Privacy in Ireland

Knowing your rights is one thing—using them is another. Here are practical measures every person in Ireland can take to safeguard their personal data.

Audit Your Digital Footprint

Search your name online, review which services hold your data, and delete accounts you no longer use. Tools like Google's "Results about you" and account dashboards on Meta, LinkedIn, and Microsoft make this easier than it used to be.

Use Privacy-Respecting Tools

Choose browsers, search engines, and services that minimise tracking. Encrypted messaging apps like Signal, privacy-focused browsers like Firefox and Brave, and encrypted DNS services all reduce the amount of data exposed to third parties.

Be Cautious with Shortened Links

URL shorteners are useful, but not all treat your data equally. When sharing links personally or professionally, choose a shortener that respects privacy, avoids intrusive tracking, and does not sell click data. Lunyb is one option built with privacy in mind, and you can compare alternatives in our 2026 URL shortener buyer's guide.

Read Privacy Notices Before Signing Up

Yes, they are long—but skim the sections on data sharing, retention, and international transfers. If a company transfers your data outside the EU/EEA, it should explain the safeguards it has in place.

Exercise Your Rights Regularly

Send a Subject Access Request to a company at least once a year. It is a simple email, and the responses often reveal how much data organisations hold that you had forgotten about.

GDPR for Small Businesses in Ireland

If you run a small business, sole trader operation, or community group in Ireland, GDPR applies to you the moment you process personal data—even a simple email newsletter list. Compliance need not be complicated.

Basic Compliance Checklist

  1. Map what personal data you collect and why.
  2. Identify your legal basis for processing (consent, contract, legitimate interest, etc.).
  3. Publish a clear, plain-English privacy notice.
  4. Secure data with encryption, access controls, and regular backups.
  5. Have a process for responding to Subject Access Requests within one month.
  6. Report qualifying data breaches to the DPC within 72 hours.
  7. Train staff on basic data protection principles.

What Happens If Your Data Is Breached?

Under GDPR, organisations must notify the DPC of a personal data breach within 72 hours of becoming aware of it if the breach is likely to result in a risk to your rights. If the risk is high, they must also notify you directly, without undue delay.

If you are informed of a breach, take these steps:

  1. Change passwords immediately, especially if reused across sites.
  2. Enable two-factor authentication on affected accounts.
  3. Monitor bank statements and credit reports for unusual activity.
  4. Consider a fraud alert with the Irish Credit Bureau if financial data was exposed.
  5. Document everything in case you decide to seek compensation.

Frequently Asked Questions

Do I have to pay to make a Subject Access Request in Ireland?

No. Subject Access Requests are free in almost all cases. An organisation can only charge a "reasonable fee" if a request is manifestly unfounded, excessive, or repetitive—and even then, it must justify the fee.

What is the age of digital consent in Ireland?

The Irish Data Protection Act 2018 sets the age of digital consent at 16. This means children under 16 cannot legally consent to information society services (such as social media accounts) on their own—parental consent is required.

Can I sue a company for a GDPR breach in Ireland?

Yes. Section 117 of the Data Protection Act 2018 allows individuals to bring civil claims for compensation in the Circuit Court or High Court if they have suffered damage—including non-material damage such as distress—as a result of a GDPR infringement.

How long does the DPC take to investigate a complaint?

Timelines vary. Simple complaints may be resolved in a few months, while complex cross-border investigations involving large platforms can take several years. The DPC publishes annual reports detailing typical case durations.

Does GDPR apply if I use a service based outside the EU?

Yes, if that service offers goods or services to people in Ireland or monitors their behaviour. Non-EU providers must comply with GDPR and, in many cases, appoint an EU representative. If they transfer your data outside the EEA, they must use approved safeguards such as Standard Contractual Clauses.

Final Thoughts

GDPR gives you meaningful, enforceable control over your personal data in Ireland. From the right to access your information to the right to be forgotten, the law puts you—not the organisation—at the centre of the conversation. The Data Protection Commission is one of the most active privacy regulators in Europe, and Irish courts increasingly recognise the value of privacy compensation.

The best privacy strategy combines knowledge with action: understand your rights, use tools that respect them, and exercise them regularly. Small habits—reviewing privacy notices, sending occasional Subject Access Requests, choosing services that minimise tracking—build up to a much stronger privacy posture over time.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles