facebook-pixel

GDPR in Ireland: Your Privacy Rights Explained

L
Lunyb Security Team
··9 min read

Since it came into force in May 2018, the General Data Protection Regulation (GDPR) has fundamentally reshaped how organisations collect, store, and use personal data across the European Union. In Ireland, GDPR is given further effect by the Data Protection Act 2018 and enforced by the Data Protection Commission (DPC) — the lead supervisory authority for many of the world's largest tech companies headquartered in Dublin.

Whether you're an Irish consumer wondering what a company can do with your email address, or a small business owner in Cork trying to stay compliant, understanding your GDPR privacy rights is essential. This guide breaks down everything you need to know about GDPR in Ireland, your legal rights, and how to exercise them.

What Is GDPR and Why Does It Matter in Ireland?

The GDPR is an EU-wide data protection law that governs how personal data of individuals in the European Economic Area (EEA) is processed. It applies to any organisation — regardless of where it is based — that offers goods or services to people in Ireland or monitors their behaviour.

Ireland holds a unique position in the GDPR landscape. Because companies like Meta, Google, TikTok, Apple, and Microsoft have their European headquarters in Dublin, the Irish DPC acts as the lead supervisory authority for cross-border data protection cases across the entire EU. This makes Irish enforcement decisions genuinely global in impact.

Key Definitions Every Irish Resident Should Know

  • Personal data: Any information relating to an identified or identifiable person — names, email addresses, PPS numbers, IP addresses, location data, and even online identifiers.
  • Data controller: The organisation that decides why and how personal data is processed (e.g., your bank, employer, or favourite online retailer).
  • Data processor: A third party that processes data on behalf of a controller (e.g., a cloud hosting provider).
  • Data subject: You — the individual whose personal data is being processed.

Your Eight Core GDPR Rights in Ireland

Under GDPR, individuals in Ireland have eight fundamental rights over their personal data. These rights are enforceable directly against any organisation that processes your information.

1. The Right to Be Informed

Organisations must tell you, in clear and plain language, what data they collect, why, how long they keep it, and who they share it with. This is usually delivered through a privacy notice or privacy policy on their website.

2. The Right of Access

You can request a copy of all personal data an organisation holds about you. This is known as a Subject Access Request (SAR). The organisation must respond within one month and, in most cases, provide the data free of charge.

3. The Right to Rectification

If any personal data held about you is inaccurate or incomplete, you have the right to have it corrected without undue delay.

4. The Right to Erasure ("Right to Be Forgotten")

You can ask an organisation to delete your personal data in specific circumstances — for example, when the data is no longer needed, when you withdraw consent, or when it has been processed unlawfully.

5. The Right to Restrict Processing

You can ask an organisation to pause processing your data while a dispute (such as questioning its accuracy) is resolved.

6. The Right to Data Portability

You can request your personal data in a structured, machine-readable format and transfer it to another service provider — useful when switching banks, energy suppliers, or social media platforms.

7. The Right to Object

You can object to processing based on legitimate interests, direct marketing, or scientific research. For direct marketing, the objection is absolute — organisations must stop immediately.

8. Rights Related to Automated Decision-Making

You have the right not to be subject to decisions based solely on automated processing — including profiling — that produce legal or similarly significant effects, such as automated loan refusals.

Comparison: GDPR Rights at a Glance

RightWhat It MeansResponse TimeCost
AccessGet a copy of your data1 monthFree (usually)
RectificationCorrect inaccurate data1 monthFree
ErasureDelete your data1 monthFree
RestrictionPause processing1 monthFree
PortabilityTransfer data to another provider1 monthFree
ObjectionStop specific processing1 monthFree
Automated decisionsHuman review of algorithms1 monthFree

The Role of the Irish Data Protection Commission (DPC)

The Data Protection Commission, based in Dublin, is Ireland's independent regulator responsible for upholding the rights of individuals under GDPR and the Data Protection Act 2018. It has broad powers to investigate complaints, conduct audits, and impose administrative fines of up to €20 million or 4% of global annual turnover, whichever is higher.

Recent High-Profile Irish DPC Fines

  • Meta (2023): €1.2 billion for unlawful data transfers to the US.
  • TikTok (2023): €345 million for children's data protection failings.
  • Instagram (2022): €405 million for mishandling teenagers' contact information.
  • WhatsApp (2021): €225 million for transparency failures.

These figures show that GDPR enforcement in Ireland is real, substantial, and increasingly consequential for global tech giants.

How to Make a Data Protection Complaint in Ireland

If you believe an organisation has mishandled your personal data, you can lodge a formal complaint with the DPC. Here's the step-by-step process:

  1. Contact the organisation directly first. Send a written request to their Data Protection Officer (DPO) or privacy contact and give them one month to respond.
  2. Gather your evidence. Save copies of emails, screenshots, privacy notices, and any responses (or lack of responses).
  3. Submit a complaint to the DPC. Use the online form at dataprotection.ie or write to the DPC's office in Portarlington or Dublin.
  4. Cooperate with the investigation. The DPC may ask for additional information or clarification.
  5. Await the decision. Investigations can take months or even years, but the DPC will keep you informed of significant developments.

GDPR for Small Businesses in Ireland

GDPR doesn't only affect big tech — every Irish business that processes personal data must comply, from the local bakery collecting customer emails for a loyalty scheme to a multinational software company. Small businesses often worry about the burden, but the core obligations are manageable if approached systematically.

Practical Compliance Checklist

  • Map the personal data you collect and why.
  • Identify your lawful basis for processing (consent, contract, legal obligation, vital interests, public task, or legitimate interests).
  • Publish a clear, accessible privacy notice on your website.
  • Implement appropriate technical and organisational security measures.
  • Have a documented process for handling data subject requests.
  • Report qualifying data breaches to the DPC within 72 hours.
  • Sign data processing agreements with third-party processors.
  • Train staff who handle personal data.

Common Pitfalls to Avoid

  • Relying on pre-ticked consent boxes (invalid under GDPR).
  • Using vague privacy notices full of legalese.
  • Retaining data "just in case" with no defined retention period.
  • Ignoring cookie consent rules under the ePrivacy Regulations.
  • Failing to vet cloud providers and marketing tools for GDPR compliance.

Protecting Your Privacy Online: Beyond GDPR

While GDPR gives you strong legal rights, real-world privacy protection also requires practical action. Legal rights are only useful if you also minimise the data trail you leave behind in the first place.

Everyday Steps to Reduce Your Data Footprint

  1. Use privacy-focused browsers like Firefox or Brave, and enable tracking protection.
  2. Configure encrypted DNS (DNS over HTTPS) to prevent your ISP from seeing every domain you visit.
  3. Review app permissions on your phone regularly and revoke anything unnecessary.
  4. Use unique, strong passwords managed through a reputable password manager.
  5. Enable two-factor authentication on all critical accounts.
  6. Be mindful of links you click and share. Malicious or tracking-heavy URLs are a common attack vector.

When sharing links — whether in marketing campaigns, on social media, or in personal messages — using a privacy-respecting URL shortener matters. Services like Lunyb allow you to shorten and manage links without excessive tracking or data harvesting. If you'd like an independent look, see our honest review of Lunyb or compare options in our 2026 buyer's guide to URL shorteners. For a competing product perspective, our Rebrandly review also covers pricing and features.

Cross-Border Data Transfers After Schrems II

One of the most complex areas of Irish GDPR practice involves data transfers outside the EEA. The Schrems II ruling by the Court of Justice of the European Union — a case brought by Austrian lawyer and Irish resident Max Schrems — invalidated the EU-US Privacy Shield in 2020, forcing organisations to reassess how they transfer data to the United States.

The EU-US Data Privacy Framework, adopted in July 2023, now provides a new legal basis for transfers to certified US organisations, but ongoing legal challenges mean businesses should still perform Transfer Impact Assessments (TIAs) and consider supplementary safeguards such as strong encryption.

Children's Data and the Digital Age of Consent in Ireland

Ireland has set the digital age of consent at 16. This means that children under 16 cannot lawfully consent to their personal data being processed by information society services (such as social media platforms) without parental authorisation. Organisations targeting or accessible to children must apply enhanced safeguards, transparency, and age-verification measures — an area of particular focus for recent DPC enforcement action.

Frequently Asked Questions

Is GDPR still in force in Ireland after Brexit?

Yes. GDPR remains fully in force in Ireland because Ireland is a member of the EU. Brexit only affected the UK, which now has its own "UK GDPR." Irish citizens and residents continue to benefit from the full protections of EU GDPR.

How long does an organisation have to respond to my Subject Access Request?

One calendar month from receipt. This can be extended by a further two months for complex or numerous requests, but the organisation must inform you of the extension within the first month.

Can I be charged for making a GDPR request?

In most cases, no. Access, rectification, erasure, and other rights requests are free of charge. However, organisations may charge a "reasonable fee" or refuse to act if a request is manifestly unfounded or excessive — particularly if it is repetitive.

What should I do if a company ignores my GDPR request?

First, follow up in writing and set a clear deadline. If you still receive no response, lodge a complaint with the Data Protection Commission at dataprotection.ie. Keep all evidence of your original request and any communications.

Does GDPR apply to sole traders and one-person businesses in Ireland?

Yes. GDPR applies regardless of business size. However, obligations are proportionate — a sole trader with a small customer email list has far fewer administrative burdens than a large enterprise. Focus on lawful basis, transparency, security, and honouring individuals' rights.

Final Thoughts

GDPR has given people in Ireland some of the strongest privacy rights in the world, backed by an active regulator with genuine enforcement teeth. Whether you're exercising your right of access, objecting to marketing, or building a compliant business, understanding these rights is the first step toward taking meaningful control of your personal data.

Combine your legal rights with sensible privacy hygiene — encrypted connections, careful link sharing, strong authentication, and minimal data disclosure — and you'll be well positioned to protect your privacy in an increasingly connected world.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles