facebook-pixel

GDPR in Ireland: Your Privacy Rights Explained

L
Lunyb Security Team
··10 min read

Ireland occupies a unique position in the European data protection landscape. Because Dublin is the European headquarters for Meta, Google, TikTok, Apple, LinkedIn, and many other technology giants, the Irish Data Protection Commission (DPC) is effectively the lead supervisory authority for hundreds of millions of Europeans. That makes understanding your GDPR privacy rights in Ireland more than an academic exercise — it directly shapes how some of the world's largest companies handle your personal data.

This guide explains what the General Data Protection Regulation (GDPR) means for Irish residents, walks through each of your eight core rights, and shows you exactly how to enforce them if a company gets things wrong.

What Is GDPR and How Does It Apply in Ireland?

The General Data Protection Regulation is an EU-wide law that came into force on 25 May 2018. It governs how organisations collect, store, use, and share the personal data of people in the European Economic Area. In Ireland, GDPR is implemented and supplemented by the Data Protection Act 2018, which fills in national details such as the age of digital consent (16 in Ireland) and specific exemptions for journalism, research, and public bodies.

GDPR applies to any organisation — Irish or foreign — that processes the personal data of people located in Ireland. That includes multinational platforms based in Dublin's Silicon Docks, small local businesses running an email list, a GP surgery keeping patient files, and even a school storing student records.

Who Enforces GDPR in Ireland?

The Data Protection Commission (DPC), headquartered in Dublin with an office in Portarlington, is Ireland's independent regulator. Because so many US tech companies have their EU base in Ireland, the DPC has become one of the most influential privacy regulators in the world, issuing multi-billion-euro fines against companies including Meta, TikTok, and Instagram.

Your 8 Core GDPR Rights as an Irish Resident

GDPR grants every data subject in Ireland a set of enforceable rights. Understanding each one is the first step to reclaiming control of your personal information.

1. The Right to Be Informed

Before a company collects your data, it must tell you — clearly and in plain language — what it is collecting, why, how long it will keep it, and who it will share it with. This is usually delivered through a privacy notice or cookie banner. If a website's privacy policy is hidden, deliberately confusing, or missing entirely, that is already a GDPR breach.

2. The Right of Access (Subject Access Request)

You can ask any organisation to give you a copy of all personal data they hold about you. This is called a Subject Access Request (SAR). The organisation must respond within one calendar month, free of charge in most cases. This includes data such as account information, purchase history, location logs, and even internal notes about you.

3. The Right to Rectification

If your data is inaccurate or incomplete, you have the right to have it corrected. For example, if your bank has the wrong address or your employer has recorded incorrect qualifications, they must fix it without undue delay.

4. The Right to Erasure ("Right to Be Forgotten")

You can ask for your data to be deleted in specific circumstances — for instance, if it is no longer needed, if you withdraw consent, or if it was processed unlawfully. There are exceptions: an accountant cannot delete your tax records early, and a hospital cannot erase your medical history on demand.

5. The Right to Restrict Processing

Sometimes you may not want data deleted but do want it frozen. This right lets you tell a company to stop using your data while a dispute (for example, over accuracy) is resolved.

6. The Right to Data Portability

You can request your data in a common, machine-readable format (like CSV or JSON) and have it transferred to another provider. This is particularly relevant for banking, social media, and streaming services.

7. The Right to Object

You can object to processing based on legitimate interests or public interest — and you have an absolute right to object to direct marketing. If you tell an Irish company to stop emailing you promotional material, they must stop immediately.

8. Rights Related to Automated Decision-Making and Profiling

If a decision that significantly affects you (a loan refusal, an insurance quote, a job application filter) is made purely by an algorithm, you have the right to human review, to express your point of view, and to contest the decision.

GDPR Rights at a Glance

RightWhat It MeansResponse DeadlineTypical Use Case
Be InformedClear notice of how data is usedAt point of collectionReading a privacy policy
AccessGet a copy of your data1 monthRequesting your file from Meta
RectificationCorrect inaccurate data1 monthFixing a wrong address at a bank
ErasureDelete data no longer needed1 monthClosing an old account
Restrict ProcessingPause use of your data1 monthDisputed accuracy of records
Data PortabilityExport data in reusable format1 monthSwitching streaming services
ObjectStop certain processingImmediate for marketingUnsubscribing from ads
Automated DecisionsHuman review of AI decisionsCase by caseContesting a loan refusal

How to Exercise Your GDPR Rights in Ireland

Enforcing your privacy rights doesn't require a solicitor. Most requests can be made directly to the company holding your data in a few simple steps.

  1. Identify the data controller. This is the company or organisation that decides how your data is used. Their name and contact details should be in their privacy policy.
  2. Locate the Data Protection Officer (DPO). Large organisations must appoint a DPO. Email them directly — addresses like dpo@company.ie are common.
  3. Write a clear request. State your name, what right you are exercising (e.g. "I am making a Subject Access Request under Article 15 GDPR"), and any relevant account details.
  4. Verify your identity if asked. The controller can request reasonable ID to make sure they're not handing your data to an imposter.
  5. Wait up to one month. If the request is complex, they can extend by two further months but must tell you within the first month.
  6. Escalate if ignored. If they refuse, delay, or respond inadequately, you can complain to the DPC.

Filing a Complaint with the Data Protection Commission

Complaints to the DPC are free. You can submit them via the DPC's online webform at dataprotection.ie, by post to their Portarlington office, or by email. Include copies of your original request, the company's response (or lack thereof), and a short summary of the issue. The DPC will assess the complaint and may open a formal inquiry, mediate, or issue binding decisions and fines.

Notable GDPR Enforcement in Ireland

The DPC's decisions have reshaped how global companies handle European data. A few landmark cases illustrate the stakes:

  • Meta (2023): A record €1.2 billion fine for unlawful transfers of Facebook user data to the United States.
  • TikTok (2023): €345 million fine over how the platform handled the personal data of child users.
  • Instagram (2022): €405 million fine for exposing teenagers' contact details through business accounts.
  • WhatsApp (2021): €225 million fine for failing to explain how it processed user information.

These cases show that GDPR isn't a paper tiger — it has real financial consequences, even for the largest tech companies operating out of Dublin.

Everyday Steps to Protect Your Personal Data

Legal rights are powerful, but prevention is easier than cure. Reducing the amount of personal data you spread online is the single most effective privacy measure. Here are practical habits every Irish internet user should consider:

  1. Audit your accounts. Close old email addresses, dormant social profiles, and unused shopping accounts. Every account is a potential breach waiting to happen.
  2. Use strong, unique passwords. A reputable password manager makes this effortless.
  3. Enable two-factor authentication. Prefer app-based codes or hardware keys over SMS.
  4. Limit tracking. Use a privacy-focused browser, block third-party cookies, and consider encrypted DNS resolvers to reduce the trail of metadata you leave.
  5. Share links carefully. When you post URLs on social media or in messages, they can leak information about your accounts, referral IDs, or session tokens. Using a trustworthy link shortener like Lunyb lets you share clean, branded URLs without exposing the underlying tracking parameters. You can read more about the service in our honest Lunyb review.
  6. Read privacy notices before consenting. Reject non-essential cookies where possible.
  7. Check breach databases. Services like Have I Been Pwned tell you when your email appears in a leak.

Special Considerations Under the Irish Data Protection Act 2018

While GDPR sets the framework, the Data Protection Act 2018 tailors it to the Irish context. Key Irish-specific rules include:

  • Age of digital consent: Children under 16 in Ireland cannot consent to information society services on their own — parental consent is required.
  • Special categories of data: Additional rules apply to health, genetic, biometric, and religious data.
  • Public bodies: Government agencies face specific obligations around transparency and data sharing.
  • Journalism exemption: Journalistic activities in the public interest may be partially exempt from certain GDPR obligations, protecting press freedom.

GDPR for Small Irish Businesses

If you run a business in Ireland — from a Galway café with a loyalty scheme to a Cork-based SaaS startup — GDPR applies to you too. Even a simple newsletter constitutes personal data processing. Small business owners should:

  1. Publish a clear, plain-language privacy notice on their website.
  2. Document what data they collect and why (a basic Record of Processing Activities).
  3. Only collect data they genuinely need ("data minimisation").
  4. Have a process for handling access, correction, and deletion requests.
  5. Report serious data breaches to the DPC within 72 hours.

Marketing links are one area where small businesses often overlook privacy. If you share campaign URLs, using a shortener that respects privacy — and doesn't hoard unnecessary click data — helps demonstrate GDPR compliance. Our 2026 buyer's guide to URL shorteners and Rebrandly review compare the leading options on privacy and features.

Frequently Asked Questions

How long does a company have to respond to my GDPR request in Ireland?

The default deadline is one calendar month from the date the company receives your request. For particularly complex or numerous requests, they may extend by up to two additional months, but they must inform you of the extension — and the reason — within the original one-month window.

Can I be charged a fee for a Subject Access Request?

No. Subject Access Requests are free in the vast majority of cases. A controller may only charge a "reasonable fee" if the request is manifestly unfounded, excessive, or if you ask for additional copies of information already provided. In practice, this is rare.

What happens if a company ignores my GDPR request?

You can file a complaint with the Data Protection Commission. The DPC can investigate, order the company to comply, and issue administrative fines of up to €20 million or 4% of the company's global annual turnover — whichever is higher. You may also pursue compensation through the Irish courts for material or non-material damage.

Does GDPR apply to companies outside the EU that process my data?

Yes. GDPR has extraterritorial reach. Any organisation anywhere in the world that offers goods or services to people in Ireland, or monitors their behaviour, must comply. That includes US-based social networks, Asian e-commerce platforms, and cloud services worldwide.

Are cookies covered by GDPR in Ireland?

Cookies are covered by both GDPR and the ePrivacy Regulations (S.I. 336/2011). Non-essential cookies — including analytics and advertising cookies — require your prior, informed, and freely given consent. Cookie banners that pre-tick boxes, hide the reject option, or use "consent-or-pay" walls without alternatives are likely non-compliant, and the DPC has actively enforced against poor cookie practices.

Final Thoughts

GDPR has transformed the balance of power between individuals and the organisations that hold their data. For Irish residents, that shift is especially significant: the DPC sits at the centre of enforcement for many of the world's largest platforms. Knowing your eight core rights — and how to exercise them — puts real, enforceable tools in your hands. Combine that legal knowledge with everyday privacy habits like strong passwords, careful sharing, and privacy-respecting tools, and you can meaningfully reduce your digital footprint while making the most of the protections the law provides.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles