facebook-pixel

GDPR in Ireland: Your Privacy Rights Explained

L
Lunyb Security Team
··11 min read

Ireland occupies a unique position in the European data protection landscape. As the European headquarters for many of the world's largest technology companies — including Meta, Google, Apple, TikTok, and Microsoft — the Irish Data Protection Commission (DPC) acts as the lead supervisory authority for a vast portion of the EU's digital population. If you live in Ireland, the General Data Protection Regulation (GDPR) gives you some of the strongest privacy rights in the world, and the Data Protection Act 2018 fine-tunes how those rules apply locally.

This guide explains what GDPR means in the Irish context, what rights you actually have, how to exercise them, and where to turn when something goes wrong.

What Is GDPR and How Does It Apply in Ireland?

The General Data Protection Regulation (GDPR) is an EU-wide law, effective since 25 May 2018, that governs how personal data of individuals in the European Economic Area must be collected, stored, processed, and shared. In Ireland, GDPR is directly applicable and is supplemented by the Data Protection Act 2018, which sets out national-level provisions such as the digital age of consent (16 in Ireland) and the powers of the DPC.

GDPR applies to any organisation — whether based in Ireland, the EU, or overseas — that processes the personal data of people in Ireland. It covers everything from a small local café collecting emails for a loyalty scheme to global platforms tracking user behaviour across billions of devices.

Who Enforces GDPR in Ireland?

The Data Protection Commission (DPC), headquartered in Dublin, is Ireland's independent regulator. Because so many multinational tech companies have their EU base in Ireland, the DPC frequently acts as the "lead supervisory authority" for cross-border cases under the GDPR's one-stop-shop mechanism. It has the power to investigate complaints, issue reprimands, order corrective action, and impose fines of up to €20 million or 4% of global annual turnover — whichever is higher.

Your Core Privacy Rights Under GDPR

GDPR gives every person in Ireland eight enforceable rights over their personal data. These rights apply whenever an organisation processes information that can identify you — a name, email, IP address, phone number, location, health record, or even a cookie identifier.

1. The Right to Be Informed

Organisations must tell you, in clear and plain language, what data they collect, why, how long they keep it, who they share it with, and what legal basis they rely on. This is usually delivered through a privacy notice or policy displayed at the point of data collection.

2. The Right of Access

You can ask any organisation for a copy of the personal data it holds about you. This is called a Subject Access Request (SAR). The organisation must respond within one month, free of charge in most cases.

3. The Right to Rectification

If data held about you is inaccurate or incomplete, you can require the controller to correct it without undue delay.

4. The Right to Erasure ("Right to Be Forgotten")

You can ask an organisation to delete your data when it is no longer needed, when you withdraw consent, when the processing is unlawful, or when you object and there is no overriding legitimate interest.

5. The Right to Restrict Processing

You can require an organisation to pause processing your data — for instance, while a dispute over accuracy is resolved.

6. The Right to Data Portability

For data you provided based on consent or a contract, you can receive it in a structured, machine-readable format and have it transferred to another provider.

7. The Right to Object

You can object to processing based on legitimate interests or public tasks, and you have an absolute right to object to direct marketing at any time.

8. Rights Related to Automated Decision-Making and Profiling

You have the right not to be subject to a decision based solely on automated processing — including profiling — that produces legal or similarly significant effects, with limited exceptions.

Quick Reference: GDPR Rights at a Glance

RightWhat It Lets You DoResponse Deadline
Be InformedKnow what data is collected and whyAt point of collection
AccessGet a copy of your data1 month
RectificationCorrect inaccurate data1 month
ErasureHave your data deleted1 month
RestrictionPause processing1 month
PortabilityReceive/move your data1 month
ObjectStop certain processingWithout undue delay
Automated DecisionsRequire human reviewWithout undue delay

The Legal Bases for Processing Personal Data

An organisation cannot process your data just because it wants to. Under Article 6 of GDPR, it must rely on one of six legal bases. Understanding these helps you assess whether a request is legitimate.

  1. Consent — you have given clear, freely-given, specific, and informed permission.
  2. Contract — processing is necessary to fulfil an agreement with you.
  3. Legal obligation — required by Irish or EU law (e.g. Revenue records).
  4. Vital interests — needed to protect someone's life.
  5. Public task — carried out in the public interest by a public authority.
  6. Legitimate interests — necessary for the controller's or a third party's interests, balanced against your rights.

Special categories of data — including health, ethnicity, political opinions, sexual orientation, biometric and genetic data — require an additional condition under Article 9 and are treated with heightened protection.

How to Make a Subject Access Request in Ireland

A Subject Access Request (SAR) is the most commonly used GDPR right. Here's a step-by-step process for making one effectively.

  1. Identify the data controller. This is the organisation that decides how and why your data is processed — often listed in their privacy policy.
  2. Find the correct contact channel. Many organisations have a dedicated privacy email (e.g. dpo@company.ie) or an online SAR form.
  3. Write a clear request. State that you are making a request under Article 15 GDPR, describe the data or timeframe you want, and provide enough detail for them to identify you.
  4. Verify your identity. The organisation may request proof — but should not demand excessive documentation.
  5. Wait up to one month. If the request is complex, the controller may extend this by two months but must tell you within the first month.
  6. Review the response. Check the data provided, the retention periods, and the third parties listed as recipients.

If the response is inadequate, ignored, or refused without a valid reason, you can complain to the DPC.

Filing a Complaint with the Data Protection Commission

If you believe your rights have been breached — for instance, a company won't delete your data, ignores your access request, or has suffered a data breach affecting you — you can lodge a complaint directly with the DPC. There is no fee, and you do not need a solicitor.

What You'll Need

  • Your contact details
  • The name of the organisation involved
  • A clear description of what happened and when
  • Copies of relevant correspondence (emails, screenshots, letters)
  • Evidence you first raised the issue with the organisation (recommended but not always required)

Complaints can be submitted via the DPC's online webform, by email, or by post to their offices in Dublin or Portarlington. The DPC will assess the complaint, may attempt amicable resolution, and can escalate to formal investigation.

Data Breaches: Your Right to Be Notified

If an organisation suffers a personal data breach that is likely to result in a high risk to your rights and freedoms, it must notify you without undue delay. It must also report the breach to the DPC within 72 hours of becoming aware of it.

Common examples include:

  • Hacked customer databases exposing passwords or payment details
  • Lost or stolen unencrypted laptops containing personal records
  • Emails sent to the wrong recipient revealing sensitive information
  • Ransomware attacks encrypting personal data

If you receive a breach notification, take practical steps: change affected passwords, monitor your bank accounts, and consider a credit freeze if financial data was exposed.

Practical Privacy Habits for People Living in Ireland

Knowing your rights is only half the picture. Day-to-day habits shape how much data you expose in the first place. Here are practical steps that complement your GDPR protections.

Minimise the Data You Share

Before filling in a form, ask whether every field is necessary. GDPR's principle of data minimisation means organisations should only collect what is strictly needed — but many still request more than they should.

Review App and Cookie Permissions

Ireland's ePrivacy Regulations require websites to obtain consent for non-essential cookies. Reject non-essential trackers where possible, and periodically audit the permissions granted to mobile apps.

Use Privacy-Respecting Tools

Choose services that treat your data as an asset to protect rather than a product to sell. For example, when sharing links online — in emails, social posts, or marketing campaigns — a privacy-conscious link management tool like Lunyb avoids the invasive third-party tracking common to older shortening services. For a broader comparison of options, see our 2026 buyer's guide to URL shorteners.

Watch for Phishing Playing on GDPR

Scammers sometimes send fake "data breach" or "account verification" emails referencing GDPR. Always check the sender address and go directly to the official website rather than clicking embedded links.

GDPR and Children in Ireland

Under the Irish Data Protection Act 2018, the digital age of consent is 16. This means that for information society services (such as social networks) offered directly to a child, consent must come from a parent or guardian if the child is under 16.

The DPC has also published the "Fundamentals for a Child-Oriented Approach to Data Processing," a framework that requires organisations to design services with children's best interests in mind, including strong default privacy settings and clear, age-appropriate language.

Cross-Border Data Transfers

GDPR restricts the transfer of personal data outside the EEA unless the destination country provides an adequate level of protection or specific safeguards are in place. Following the Schrems II ruling — a case originating from Ireland — transfers to the United States have been under intense scrutiny. The EU-US Data Privacy Framework, adopted in 2023, currently provides a lawful pathway, but organisations still need to conduct transfer impact assessments and rely on Standard Contractual Clauses where appropriate.

Employer Data Processing: What Workers Should Know

Employees in Ireland enjoy the same GDPR rights as consumers, plus specific protections in the workplace context.

  • Monitoring must be proportionate. Employers should conduct a Data Protection Impact Assessment before implementing CCTV, email monitoring, or productivity tracking.
  • Transparency is required. Staff must be informed in advance about what data is collected and why.
  • Sensitive data has extra protection. Health information, trade union membership, and biometric access controls require an Article 9 condition.
  • SARs still apply. Employees can request access to HR files, performance records, and even relevant internal emails about them.

Penalties and Notable Irish Enforcement Cases

The DPC has issued some of the largest GDPR fines in Europe. High-profile cases have targeted Meta, TikTok, and WhatsApp, with penalties running into hundreds of millions of euros. These decisions signal that even the largest platforms are not exempt from meaningful accountability — and that Irish residents' complaints can lead to concrete outcomes.

Frequently Asked Questions

How long does an organisation have to respond to my GDPR request in Ireland?

Generally one month from receipt of the request. This can be extended by up to two additional months for complex or numerous requests, but the organisation must inform you of the extension within the initial month.

Can I make a GDPR complaint anonymously in Ireland?

No. The DPC needs your identity to investigate and follow up with you. However, your identity is not automatically shared with the organisation you are complaining about unless disclosure is necessary for the investigation, and the DPC will discuss this with you first.

Does GDPR apply to my personal social media use?

Purely personal or household activity — like sharing photos with friends and family — is exempt. But if you run a business page, publish content publicly at scale, or process others' data in a professional capacity, GDPR obligations do apply.

What is the difference between a data controller and a data processor?

A controller decides why and how personal data is processed. A processor handles data on behalf of a controller (for example, a cloud hosting provider). You direct most GDPR rights requests at the controller, though both share compliance responsibilities.

Can I sue a company directly for a GDPR breach in Ireland?

Yes. In addition to complaining to the DPC, you can pursue a civil claim in the Irish courts for material or non-material damage, including distress, caused by a GDPR infringement. Recent Irish case law has clarified that claims must meet a threshold of genuine, demonstrable harm.

Final Thoughts

GDPR in Ireland is more than a regulatory framework — it is a set of practical tools you can use to take back control of your personal information. Whether you are asking an app to delete your account, questioning an employer's monitoring policy, or filing a complaint with the DPC, the law is designed to work in your favour. Combine that legal protection with sensible digital habits and privacy-respecting tools, and you have a strong foundation for protecting your data in an increasingly connected world.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles