GDPR in Ireland: Your Privacy Rights Explained
The General Data Protection Regulation (GDPR) is the cornerstone of privacy law in Ireland. Since it took effect in May 2018, alongside the Irish Data Protection Act 2018, it has given individuals unprecedented control over how their personal information is collected, stored, and used. If you live in Ireland—or interact with Irish businesses—you have specific, enforceable rights that companies must respect.
This guide breaks down what GDPR means for you in Ireland, the eight core rights it grants, how the Data Protection Commission (DPC) enforces the law, and the practical steps you can take to protect your personal data every day.
What Is GDPR and Why Does It Matter in Ireland?
GDPR is a European Union regulation that governs how personal data is processed by organisations operating in or serving individuals within the EU. In Ireland, it is applied alongside the Data Protection Act 2018, which fills in national details such as the age of digital consent (16) and the powers of the Data Protection Commission.
Ireland plays an outsized role in GDPR enforcement because many of the world's largest technology firms—Meta, Google, TikTok, Microsoft, LinkedIn, and X among them—have their European headquarters in Dublin. As a result, the Irish DPC is the lead supervisory authority for cross-border complaints involving these companies, making Irish privacy law relevant far beyond the country's borders.
Who GDPR Protects
GDPR protects any identifiable natural person in Ireland—known as a "data subject." This includes citizens, residents, tourists, and anyone whose data is processed by an Irish-based organisation. It does not protect companies or deceased persons.
Who GDPR Applies To
The regulation applies to:
- Any organisation established in Ireland that processes personal data.
- Non-EU organisations that offer goods or services to people in Ireland.
- Organisations that monitor the behaviour of people in Ireland (for example, through website tracking).
The Eight Core Privacy Rights Under GDPR
GDPR grants every individual in Ireland eight fundamental rights over their personal data. Understanding each one is the first step to exercising control over your digital life.
| Right | What It Means | GDPR Article |
|---|---|---|
| Right to be Informed | Know what data is collected and why | Articles 13–14 |
| Right of Access | Request a copy of your data | Article 15 |
| Right to Rectification | Correct inaccurate data | Article 16 |
| Right to Erasure | Have data deleted ("right to be forgotten") | Article 17 |
| Right to Restrict Processing | Limit how data is used | Article 18 |
| Right to Data Portability | Receive data in a portable format | Article 20 |
| Right to Object | Refuse certain processing (e.g. marketing) | Article 21 |
| Rights Around Automated Decisions | Not be subject to solely automated decisions | Article 22 |
1. The Right to Be Informed
Organisations must clearly tell you what personal data they collect, why they collect it, how long they keep it, and who they share it with. This is typically communicated through a privacy notice or policy on a website. If a company cannot explain in plain English what it does with your data, it is failing this obligation.
2. The Right of Access (Subject Access Request)
You can ask any organisation to give you a copy of the personal data it holds about you. This is called a Subject Access Request (SAR). In Ireland, organisations must respond within one calendar month and, in most cases, cannot charge a fee.
3. The Right to Rectification
If a company holds inaccurate or incomplete data about you, you have the right to have it corrected. This is particularly important for credit records, medical files, and employment data.
4. The Right to Erasure
Also known as the "right to be forgotten," this allows you to request that your data be deleted when it is no longer necessary, when you withdraw consent, or when it has been processed unlawfully. It is not absolute—organisations can refuse if they have legal grounds to retain data (for example, tax records).
5. The Right to Restrict Processing
You can ask an organisation to pause the processing of your data while a dispute is resolved, such as when you contest the accuracy of the information.
6. The Right to Data Portability
You can request your data in a structured, commonly used, machine-readable format (such as CSV or JSON) and transfer it to another service. This is common when switching banks, streaming platforms, or social media services.
7. The Right to Object
You can object to processing for direct marketing at any time, and the organisation must stop immediately. You can also object to processing based on "legitimate interests" or public tasks, though the organisation may be able to override the objection in some cases.
8. Rights Related to Automated Decision-Making
You have the right not to be subject to decisions made solely by automated means—such as algorithmic loan approvals or profiling—if those decisions have a significant effect on you. You can request human review.
The Role of the Irish Data Protection Commission (DPC)
The Data Protection Commission is the national independent authority responsible for upholding GDPR in Ireland. Based in Dublin and Portarlington, it investigates complaints, issues guidance, and imposes fines on organisations that break the law.
What the DPC Does
- Receives and investigates complaints from individuals.
- Conducts audits and inquiries into organisations.
- Issues fines of up to €20 million or 4% of global annual turnover (whichever is higher).
- Acts as lead supervisory authority for many multinational tech firms headquartered in Ireland.
- Publishes guidance to help businesses and individuals understand the law.
Notable Enforcement Actions
The DPC has issued some of the largest GDPR fines to date, including a €1.2 billion penalty against Meta in 2023 for unlawful transfers of EU user data to the United States, and multi-hundred-million-euro fines against TikTok and WhatsApp for transparency and children's data violations. These cases show that Irish enforcement has real teeth—even against the world's largest platforms.
How to Make a GDPR Complaint in Ireland
If you believe an organisation has mishandled your personal data, you can take action in a structured, five-step process.
- Contact the organisation directly. Write to the company's Data Protection Officer (DPO) or privacy team. Clearly state what right you are exercising and what outcome you want.
- Wait for their response. They have one month to reply. Complex cases can be extended to three months with written justification.
- Gather evidence. Keep copies of all correspondence, screenshots, and any responses received.
- Submit a complaint to the DPC. If the organisation fails to respond or provides an unsatisfactory answer, you can file a complaint through the DPC's website at dataprotection.ie. There is no fee.
- Consider legal remedies. If you have suffered material or non-material damage, you may be entitled to compensation through the Irish courts under Section 117 of the Data Protection Act 2018.
Special Categories of Personal Data
Some data is considered particularly sensitive and receives extra protection under GDPR. Processing special category data is prohibited unless one of a limited number of conditions applies.
| Special Category | Examples |
|---|---|
| Health data | Medical records, prescriptions, fitness tracker data |
| Biometric data | Fingerprints, facial recognition, iris scans |
| Genetic data | DNA test results |
| Racial or ethnic origin | Ethnicity questionnaires |
| Political opinions | Party membership, voting preferences |
| Religious beliefs | Faith-based memberships |
| Sexual orientation | Dating app preferences, identity data |
| Trade union membership | Union enrolment records |
Cookies, Tracking, and the ePrivacy Regulations
In Ireland, cookies and similar tracking technologies are governed by the ePrivacy Regulations 2011, which sit alongside GDPR. Websites must obtain your clear, informed consent before setting non-essential cookies—no more pre-ticked boxes or vague banners.
You should always be able to:
- Reject all non-essential cookies as easily as you can accept them.
- See a granular breakdown of cookie categories (analytics, advertising, functional).
- Withdraw consent at any time.
The DPC has been active in enforcing cookie rules, warning both Irish businesses and international platforms about non-compliant banners.
Practical Steps to Protect Your Privacy in Ireland
Knowing your rights is one thing—using them is another. Here are practical measures every person in Ireland can take to safeguard their personal data.
Audit Your Digital Footprint
Search your name online, review which services hold your data, and delete accounts you no longer use. Tools like Google's "Results about you" and account dashboards on Meta, LinkedIn, and Microsoft make this easier than it used to be.
Use Privacy-Respecting Tools
Choose browsers, search engines, and services that minimise tracking. Encrypted messaging apps like Signal, privacy-focused browsers like Firefox and Brave, and encrypted DNS services all reduce the amount of data exposed to third parties.
Be Cautious with Shortened Links
URL shorteners are useful, but not all treat your data equally. When sharing links personally or professionally, choose a shortener that respects privacy, avoids intrusive tracking, and does not sell click data. Lunyb is one option built with privacy in mind, and you can compare alternatives in our 2026 URL shortener buyer's guide.
Read Privacy Notices Before Signing Up
Yes, they are long—but skim the sections on data sharing, retention, and international transfers. If a company transfers your data outside the EU/EEA, it should explain the safeguards it has in place.
Exercise Your Rights Regularly
Send a Subject Access Request to a company at least once a year. It is a simple email, and the responses often reveal how much data organisations hold that you had forgotten about.
GDPR for Small Businesses in Ireland
If you run a small business, sole trader operation, or community group in Ireland, GDPR applies to you the moment you process personal data—even a simple email newsletter list. Compliance need not be complicated.
Basic Compliance Checklist
- Map what personal data you collect and why.
- Identify your legal basis for processing (consent, contract, legitimate interest, etc.).
- Publish a clear, plain-English privacy notice.
- Secure data with encryption, access controls, and regular backups.
- Have a process for responding to Subject Access Requests within one month.
- Report qualifying data breaches to the DPC within 72 hours.
- Train staff on basic data protection principles.
What Happens If Your Data Is Breached?
Under GDPR, organisations must notify the DPC of a personal data breach within 72 hours of becoming aware of it if the breach is likely to result in a risk to your rights. If the risk is high, they must also notify you directly, without undue delay.
If you are informed of a breach, take these steps:
- Change passwords immediately, especially if reused across sites.
- Enable two-factor authentication on affected accounts.
- Monitor bank statements and credit reports for unusual activity.
- Consider a fraud alert with the Irish Credit Bureau if financial data was exposed.
- Document everything in case you decide to seek compensation.
Frequently Asked Questions
Do I have to pay to make a Subject Access Request in Ireland?
No. Subject Access Requests are free in almost all cases. An organisation can only charge a "reasonable fee" if a request is manifestly unfounded, excessive, or repetitive—and even then, it must justify the fee.
What is the age of digital consent in Ireland?
The Irish Data Protection Act 2018 sets the age of digital consent at 16. This means children under 16 cannot legally consent to information society services (such as social media accounts) on their own—parental consent is required.
Can I sue a company for a GDPR breach in Ireland?
Yes. Section 117 of the Data Protection Act 2018 allows individuals to bring civil claims for compensation in the Circuit Court or High Court if they have suffered damage—including non-material damage such as distress—as a result of a GDPR infringement.
How long does the DPC take to investigate a complaint?
Timelines vary. Simple complaints may be resolved in a few months, while complex cross-border investigations involving large platforms can take several years. The DPC publishes annual reports detailing typical case durations.
Does GDPR apply if I use a service based outside the EU?
Yes, if that service offers goods or services to people in Ireland or monitors their behaviour. Non-EU providers must comply with GDPR and, in many cases, appoint an EU representative. If they transfer your data outside the EEA, they must use approved safeguards such as Standard Contractual Clauses.
Final Thoughts
GDPR gives you meaningful, enforceable control over your personal data in Ireland. From the right to access your information to the right to be forgotten, the law puts you—not the organisation—at the centre of the conversation. The Data Protection Commission is one of the most active privacy regulators in Europe, and Irish courts increasingly recognise the value of privacy compensation.
The best privacy strategy combines knowledge with action: understand your rights, use tools that respect them, and exercise them regularly. Small habits—reviewing privacy notices, sending occasional Subject Access Requests, choosing services that minimise tracking—build up to a much stronger privacy posture over time.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
GDPR in Ireland: Your Privacy Rights Explained
The General Data Protection Regulation gives people in Ireland powerful rights over their personal data. This guide explains what those rights are, how the Data Protection Commission enforces them, and the practical steps you can take to protect your privacy online.
Australia Privacy Act 2026: Your Rights Explained
The Australia Privacy Act 2026 gives Australians stronger rights over their personal information, including the right to erasure, a direct right to sue for serious privacy invasions, and enhanced protections for children. This guide explains what's changed, who's covered, and what individuals and businesses need to do now.
How Canadian Businesses Should Handle Data Privacy in 2026
Canadian businesses face a rapidly evolving privacy landscape in 2026, from PIPEDA and Quebec's Law 25 to the anticipated CPPA. This guide covers the laws that apply, common compliance mistakes, and a practical framework for building a defensible data privacy program.
Singapore PDPA vs GDPR: Key Differences Every Business Must Know
Singapore's PDPA and the EU's GDPR both protect personal data, but differ sharply in scope, consent, penalties, and breach rules. This guide compares the two laws side-by-side and shows Singapore businesses how to build a unified compliance strategy.