facebook-pixel

GDPR in Ireland: Your Privacy Rights Explained

L
Lunyb Security Team
··11 min read

The General Data Protection Regulation (GDPR) gives people in Ireland some of the strongest privacy protections in the world. Whether you're a customer of an Irish business, a website user, or an employee, GDPR grants you enforceable rights over how your personal data is collected, used, and shared. This guide explains those rights in plain English, shows you how to exercise them, and explains what to do when a company doesn't comply.

What Is GDPR and How Does It Apply in Ireland?

The GDPR is a European Union regulation that came into force on 25 May 2018. It applies directly in every EU member state, including Ireland, where it is supplemented by the Irish Data Protection Act 2018. Together, these laws govern how personal data about people in Ireland is processed by companies, public bodies, and organisations.

Personal data is any information that can identify a living person, directly or indirectly. That includes obvious things like your name, PPS number, address, and email, but also less obvious data like your IP address, location data, browser cookies, and behavioural profiles built up by advertisers.

Ireland plays a particularly important role in GDPR enforcement because so many major tech companies — Google, Meta, TikTok, Microsoft, Apple, LinkedIn, X — have their European headquarters in Dublin. The Irish Data Protection Commission (DPC) is therefore the lead supervisory authority for many of the world's biggest platforms.

Who Must Comply With GDPR in Ireland?

GDPR applies to any organisation that processes the personal data of people in the EU, including:

  • Irish businesses of any size, from sole traders to multinationals
  • Public sector bodies, schools, hospitals, and local authorities
  • Non-EU companies offering goods or services to people in Ireland
  • Charities, sports clubs, and community groups holding member data
  • Employers handling staff records

Your Eight Core GDPR Rights

Under GDPR, every person in Ireland has eight fundamental data protection rights. Understanding each of them is the first step to taking control of your personal information.

1. The Right to Be Informed

Organisations must tell you, in clear and plain language, what personal data they collect, why they collect it, how long they keep it, and who they share it with. This is usually provided through a privacy notice or privacy policy on a website or app.

2. The Right of Access

You can request a copy of all personal data an organisation holds about you. This is known as a Subject Access Request (SAR). The organisation must respond within one month and, in most cases, provide the data free of charge.

3. The Right to Rectification

If any personal data held about you is inaccurate or incomplete, you can require it to be corrected without undue delay.

4. The Right to Erasure ("Right to Be Forgotten")

You can ask an organisation to delete your personal data where it is no longer needed, you withdraw consent, or the data has been unlawfully processed. There are exceptions — for example, where retention is required by Irish law (Revenue records, medical records, etc.).

5. The Right to Restrict Processing

You can require an organisation to stop actively using your data while a dispute (for example, about accuracy) is being resolved.

6. The Right to Data Portability

Where processing is based on consent or a contract and is carried out automatically, you can receive your data in a structured, commonly used, machine-readable format — and have it transferred to another provider.

7. The Right to Object

You can object to processing based on legitimate interests or public task, and you can object to direct marketing at any time. Objections to direct marketing must always be honoured.

8. Rights Related to Automated Decision-Making

You have the right not to be subject to a decision based solely on automated processing — including profiling — that produces legal or similarly significant effects, unless specific safeguards apply.

Summary of Rights and Deadlines

RightWhat You Can DoResponse DeadlineCost
AccessGet a copy of your data1 monthFree (usually)
RectificationCorrect inaccurate data1 monthFree
ErasureDelete your data1 monthFree
RestrictionPause processing1 monthFree
PortabilityReceive/transfer data1 monthFree
ObjectionStop certain processing1 monthFree
Marketing objectionStop direct marketingImmediatelyFree

How to Make a Subject Access Request in Ireland

A Subject Access Request is the most commonly used GDPR right. Here is how to make one effectively:

  1. Identify the data controller. This is the organisation deciding how your data is used — usually the company you interacted with.
  2. Find the correct contact. Look for a "Data Protection Officer" or "privacy@" email address in their privacy policy.
  3. Put your request in writing. Email is fine. State clearly that you are exercising your "right of access under Article 15 GDPR".
  4. Prove your identity. The organisation may reasonably request ID to prevent data being disclosed to the wrong person.
  5. Be specific if you can. Narrowing your request (for example, "emails between 2023 and 2024") often leads to a faster response.
  6. Track the deadline. They have one calendar month, extendable by two further months for complex requests (and only with notice to you).

Sample Wording You Can Use

"Dear Data Protection Officer, I am writing to make a Subject Access Request under Article 15 of the GDPR. Please provide me with a copy of all personal data you hold about me, along with the information required by Article 15(1)(a)–(h). My details are [name, address, account reference]. Please confirm receipt and the date by which I can expect a response."

The Role of the Data Protection Commission (DPC)

The Irish Data Protection Commission, headquartered in Dublin with an office in Portarlington, is the national independent authority responsible for upholding GDPR in Ireland. Its main functions are:

  • Handling complaints from members of the public
  • Investigating potential breaches of data protection law
  • Imposing fines and corrective measures on organisations
  • Providing guidance to businesses and public bodies
  • Acting as lead supervisory authority for cross-border cases involving large tech firms based in Ireland

The DPC has issued some of the largest GDPR fines in Europe, including multi-hundred-million-euro penalties against Meta, TikTok, and WhatsApp. This has real impact for Irish residents, whose complaints often drive these investigations.

How to Make a Complaint to the DPC

If an organisation refuses your request, ignores you, or you believe your data has been misused, you can complain to the DPC. The process is straightforward and free.

  1. Complain to the organisation first. Give them a chance to fix the issue. Keep a written record.
  2. Gather your evidence. Copies of emails, screenshots, and dates all help.
  3. Submit your complaint. Use the DPC's online form at dataprotection.ie or write to their Portarlington office.
  4. Cooperate with the investigation. The DPC may ask you or the organisation for further information.
  5. Receive a decision. The DPC can order the organisation to comply, impose fines, or dismiss the complaint. You have a right to appeal to the Circuit Court.

Special Categories of Data

Some types of personal data receive extra protection under Article 9 of GDPR. These "special category" data include:

  • Racial or ethnic origin
  • Political opinions
  • Religious or philosophical beliefs
  • Trade union membership
  • Genetic and biometric data (where used to identify a person)
  • Health data
  • Data about sex life or sexual orientation

Processing these requires explicit consent or another specific legal basis. Irish employers, healthcare providers, and insurers must be especially careful here.

Cookies, Tracking and ePrivacy in Ireland

GDPR works alongside the Irish ePrivacy Regulations (S.I. 336 of 2011). Together, they require most websites operating in Ireland to:

  • Obtain your consent before setting non-essential cookies
  • Make it as easy to refuse cookies as to accept them
  • Explain clearly what each cookie or tracker does
  • Allow you to change your mind at any time

The DPC has been active in enforcing cookie rules against Irish news sites, retailers, and government bodies. If a site drops advertising cookies before you click "Accept", that is likely a breach.

Practical Steps to Protect Your Privacy in Ireland

Knowing your rights is only half the battle — good day-to-day habits reduce how much data ends up in the wrong hands in the first place.

Minimise What You Share

Only provide the data an organisation genuinely needs. If a loyalty card form asks for your date of birth or PPS number, ask why. Under GDPR's data minimisation principle, they should only collect what is necessary.

Use Privacy-Respecting Tools

Choose browsers, search engines, and messaging apps that minimise tracking. Enable encrypted DNS (DNS over HTTPS) in your browser or router to prevent your internet provider from logging every website you visit. Keep operating systems and apps updated to close security gaps that could expose your data.

Be Careful with Shared Links

Long URLs often contain tracking parameters, session IDs, or affiliate codes that reveal your identity or referral source. When sharing links on social media, in emails, or across teams, consider a privacy-conscious link shortener such as Lunyb, which strips unnecessary tracking and gives you control over analytics. For a broader comparison of options, see our Best URL Shorteners Reviewed and Compared: 2026 Buyer's Guide and our honest review of Lunyb.

Review App Permissions Regularly

Once every few months, open your phone's privacy settings and revoke access to location, contacts, microphone, and camera for apps that don't genuinely need them.

Use Strong, Unique Passwords and Two-Factor Authentication

A password manager combined with two-factor authentication is the single most effective personal data-protection step most people can take.

What Happens When There's a Data Breach?

If an organisation suffers a data breach that risks your rights and freedoms, they must:

  • Report it to the DPC within 72 hours of becoming aware
  • Notify affected individuals directly if the risk is high
  • Document what happened and what they did to fix it

If you receive a breach notification, change any passwords involved, watch for phishing attempts, and consider requesting a copy of your credit report from an Irish credit reference agency if financial data was exposed.

Children's Data in Ireland

Ireland has set the digital age of consent at 16. This means online services relying on consent to process a child's data must obtain parental consent for anyone under 16. The DPC's "Fundamentals for a Child-Oriented Approach to Data Processing" sets out 14 principles that apply to any service likely to be accessed by children in Ireland.

Employer Data and Workplace Privacy

Employees in Ireland have the same GDPR rights as consumers. Common workplace issues include:

  • Access to your HR file, emails, and performance records via a SAR
  • Rules on CCTV monitoring — signage, purpose, and retention must be clear
  • Limits on monitoring employee email and internet use
  • Restrictions on sharing staff data with third parties without a lawful basis

Frequently Asked Questions

Can I be charged for making a Subject Access Request in Ireland?

No, in almost all cases the first copy of your data must be provided free of charge. An organisation can only charge a "reasonable fee" based on administrative costs if a request is manifestly unfounded, excessive, or if you ask for additional copies.

How long does an organisation have to respond to a GDPR request?

One calendar month from the date they receive your request. They may extend this by two further months for particularly complex or numerous requests, but they must tell you within the first month and explain why.

Does GDPR cover data held by public bodies like the HSE or Revenue?

Yes. Public sector organisations in Ireland are subject to GDPR and the Data Protection Act 2018, though some rights (like erasure) may be limited where the data is needed for a legal obligation or a task carried out in the public interest.

Can I claim compensation for a GDPR breach in Ireland?

Yes. Under Section 117 of the Data Protection Act 2018, you can bring a "data protection action" in the Irish Circuit Court or High Court for material or non-material damage, including distress, caused by a breach of your rights.

What if a company is based outside the EU but processes my data?

GDPR still applies if they offer goods or services to people in Ireland or monitor their behaviour. They should have an EU representative, and you can still complain to the Irish DPC.

Final Thoughts

GDPR gives people in Ireland real, enforceable control over their personal data — but rights only matter when they are used. Make a Subject Access Request when you're curious what a company knows about you. Object to direct marketing when it becomes intrusive. Complain to the DPC when things go wrong. Combined with sensible habits like minimising data sharing, using privacy-friendly tools, and being cautious about the links you click and share, you can dramatically reduce your digital footprint and keep your personal information where it belongs — with you.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles