GDPR in Ireland: Your Privacy Rights Explained
The General Data Protection Regulation (GDPR) gives people in Ireland some of the strongest privacy rights in the world. Whether you're shopping online, using social media, or signing up for a newsletter, GDPR governs how organisations must handle your personal data. This guide explains your rights in plain English, how to exercise them, and what to do if a company gets it wrong.
What is GDPR and How Does It Apply in Ireland?
GDPR is a European Union regulation that came into force on 25 May 2018. In Ireland, it is supplemented by the Data Protection Act 2018 and enforced by the Data Protection Commission (DPC), headquartered in Dublin. Because many major tech companies (Google, Meta, TikTok, Microsoft) have their European headquarters in Ireland, the Irish DPC acts as the lead supervisory authority for cross-border data issues across the EU.
GDPR applies to any organisation — Irish, European, or international — that processes personal data of people located in Ireland. "Personal data" is any information that identifies you directly or indirectly: your name, email address, IP address, location, health records, browsing history, and even device identifiers.
Key Principles Every Organisation Must Follow
- Lawfulness, fairness, and transparency — you must be told what's happening with your data.
- Purpose limitation — data collected for one reason cannot be reused for another without a lawful basis.
- Data minimisation — only necessary data may be collected.
- Accuracy — data must be kept up to date.
- Storage limitation — data cannot be kept indefinitely.
- Integrity and confidentiality — data must be protected against loss or breach.
- Accountability — the organisation must be able to prove compliance.
Your Eight Core GDPR Rights in Ireland
GDPR grants you eight fundamental rights over your personal data. Every organisation processing your information — from your local GAA club to a multinational platform — must respect them.
| Right | What It Means | Typical Response Time |
|---|---|---|
| Right to be informed | Know who has your data and why | At point of collection |
| Right of access | Get a copy of the data held about you | 1 month |
| Right to rectification | Correct inaccurate data | 1 month |
| Right to erasure | Have your data deleted ("right to be forgotten") | 1 month |
| Right to restrict processing | Pause use of your data | 1 month |
| Right to data portability | Receive data in a machine-readable format | 1 month |
| Right to object | Stop processing (especially direct marketing) | Immediate for marketing |
| Rights around automated decisions | Human review of profiling-based decisions | Case by case |
1. The Right to Be Informed
Before an organisation collects your data, it must tell you clearly: who they are, what data they're collecting, why, how long they'll keep it, and who they'll share it with. This is usually done through a privacy notice or privacy policy. If a website's privacy notice is missing, hidden, or written in vague legalese, that is itself a GDPR issue.
2. The Right of Access (Subject Access Request)
You can ask any organisation for a copy of every piece of personal data they hold on you. This is called a Subject Access Request (SAR). It's free, and the organisation must respond within one month. You can request:
- Confirmation that they process your data.
- A copy of the data itself.
- Information on why they process it, who they share it with, and how long they keep it.
3. The Right to Rectification
If your data is wrong — an incorrect address, a misspelled name, an outdated phone number — you can require the organisation to fix it without delay.
4. The Right to Erasure
Also known as the "right to be forgotten," this lets you request deletion of your data when: it's no longer needed, you withdraw consent, you object to processing, or the data was processed unlawfully. Note that this right isn't absolute — organisations can refuse if they have a legal obligation to retain the data (for example, financial records under Revenue rules).
5. The Right to Restrict Processing
You can ask an organisation to "freeze" your data — keep it but stop using it — while a dispute is being resolved, such as when you've challenged its accuracy.
6. The Right to Data Portability
You can request your data in a structured, commonly used, machine-readable format (like CSV or JSON) and even have it transferred directly to another provider. This is particularly powerful for switching banks, health apps, or social platforms.
7. The Right to Object
You can object to processing based on legitimate interests, public interest, or direct marketing. For direct marketing, your objection is absolute — the organisation must stop immediately, no questions asked.
8. Rights Related to Automated Decision-Making
If a decision that significantly affects you (loan approval, insurance pricing, job screening) is made purely by algorithm, you have the right to human intervention, to express your view, and to contest the decision.
How to Make a GDPR Request in Ireland
Exercising your rights is simpler than most people think. Follow these steps:
- Identify the data controller. This is the company or organisation deciding how your data is used. Check their privacy policy for contact details.
- Write to their Data Protection Officer (DPO) or privacy contact. Email is fine — no special form is required.
- State clearly which right you're exercising. For example: "I am making a Subject Access Request under Article 15 of the GDPR."
- Provide proof of identity if requested (to prevent someone impersonating you).
- Keep records of your request and any responses.
- Wait one month for a reply. Complex requests may be extended by two more months, but the organisation must tell you.
Sample Wording for a Subject Access Request
"Dear Data Protection Officer,
Under Article 15 of the GDPR, I request a copy of all personal data you hold about me, together with information about the purposes of processing, categories of recipients, retention periods, and the source of the data. My details are [name, email, account reference]. Please respond within one month."
The Role of the Data Protection Commission
The Data Protection Commission (DPC) is Ireland's independent authority responsible for upholding GDPR. Its functions include:
- Handling complaints from individuals.
- Investigating potential breaches.
- Issuing fines — up to €20 million or 4% of global annual turnover, whichever is higher.
- Providing guidance to organisations and the public.
- Acting as lead supervisory authority for many of the world's largest tech firms.
Landmark Irish DPC decisions have resulted in some of the largest privacy fines in EU history, including multi-billion-euro penalties against Meta and hundreds of millions against TikTok and WhatsApp. This has cemented Dublin's role as the beating heart of European privacy enforcement.
How to File a Complaint with the DPC
- Try to resolve the issue directly with the organisation first.
- If unresolved, go to dataprotection.ie and complete the online complaint form.
- Provide copies of your correspondence and any evidence.
- The DPC will assess whether to investigate and keep you informed of progress.
There is no cost to file a complaint, and you do not need a solicitor.
Common Privacy Issues Faced by People in Ireland
Unwanted Marketing Emails and Texts
Under GDPR and the ePrivacy Regulations 2011, marketing messages require your explicit opt-in consent. Every message must include a free, easy way to unsubscribe. If you keep receiving messages after opting out, that's a clear breach.
Cookie Banners That Won't Take No for an Answer
The DPC has been vocal: cookie banners must offer a "reject all" option as prominently as "accept all." Pre-ticked boxes are not valid consent. If a website makes it easier to accept than reject, it may be violating GDPR.
Data Breaches
If your data is exposed in a breach, the organisation must notify the DPC within 72 hours and, in serious cases, notify you directly. You have the right to compensation for both material damage (financial loss) and non-material damage (distress).
Tracking via Shared Links and URLs
Many links you click contain tracking parameters that follow you across the web. Using a privacy-conscious URL shortener like Lunyb can help you share cleaner links without exposing recipients to unnecessary tracking. For a broader look at options, see our 2026 buyer's guide to URL shorteners.
Practical Steps to Protect Your Privacy in Ireland
Rights are only useful if you actively use them. Here are practical measures to take control of your data:
- Audit your accounts. Delete old accounts you no longer use — every dormant account is a potential breach vector.
- Review privacy settings on Google, Meta, Apple, and Microsoft accounts at least once a year.
- Use encrypted DNS (like Cloudflare 1.1.1.1 or Quad9) to prevent your Internet provider from seeing every domain you visit.
- Choose privacy-first browsers like Firefox or Brave, and enable tracker blocking.
- Turn off ad personalisation in your Google and Meta accounts.
- Use unique, strong passwords with a reputable password manager.
- Enable two-factor authentication on every important account.
- Read privacy policies before signing up — or at least skim for red flags like "we may share with third parties for marketing."
- Share short, clean links instead of raw URLs stuffed with tracking parameters. Tools like Lunyb and alternatives reviewed in our Rebrandly 2026 review can help.
GDPR at Work: Your Rights as an Employee
Your employer is a data controller too. They must have a lawful basis for processing your data, tell you what they collect (through an employee privacy notice), and respect your rights. This includes:
- Access to your HR file on request.
- Transparency about workplace monitoring (CCTV, email, keystroke tracking).
- Proportionate use of biometric data (fingerprint clock-ins require strong justification).
- Protection of health, trade union, and other special-category data.
Excessive monitoring or covert surveillance is a serious GDPR breach — and the DPC has issued significant fines to Irish employers who cross the line.
Children's Privacy Rights
Ireland's Data Protection Act sets the digital age of consent at 16. Below that age, parental consent is required for online services relying on consent as their lawful basis. The DPC's Fundamentals for a Child-Oriented Approach to Data Processing sets strict expectations: child-friendly language, high default privacy settings, and no profiling of children for marketing.
What Happens When Organisations Get It Wrong
GDPR fines in Ireland have made global headlines. Enforcement is real, and consequences are steep. Beyond fines, organisations face:
- Orders to stop processing.
- Mandatory changes to products and policies.
- Reputational damage.
- Civil claims for compensation from affected individuals.
Even small Irish businesses have been fined for issues like poor CCTV signage, lost USB sticks, or sending marketing without consent. The lesson: GDPR applies to everyone, not just tech giants.
Frequently Asked Questions
How long does an organisation have to respond to my GDPR request in Ireland?
One calendar month from the date they receive your request. This can be extended by a further two months if the request is complex, but they must notify you of the extension and the reason within the original month.
Can I be charged a fee for a Subject Access Request?
No. SARs are free. An organisation can only charge a "reasonable fee" for manifestly unfounded or excessive requests, or for additional copies of the same information — and it must justify the charge.
Do I need a solicitor to complain to the Data Protection Commission?
No. The DPC's complaint process is designed to be accessible to the public. You can submit a complaint yourself online at dataprotection.ie without any legal representation. Legal advice may help in complex cases or if you're pursuing compensation.
Does GDPR still apply after Brexit if I deal with UK companies?
Yes. If a UK organisation offers goods or services to people in Ireland, it must comply with EU GDPR. The UK also has its own "UK GDPR," which is very similar. Transfers of your data from Ireland to the UK are covered by an EU adequacy decision, meaning your rights travel with the data.
What compensation can I claim if my data is misused?
Under Article 82 GDPR and the Data Protection Act 2018, you can claim compensation for both material damage (financial loss) and non-material damage (distress, anxiety, reputational harm) through the Irish courts. Amounts vary widely — from a few hundred euros for minor distress to substantial sums for serious breaches.
Final Thoughts
GDPR gives people in Ireland an extraordinary level of control over their personal data — but only if they use it. Read privacy notices, exercise your rights, complain when things go wrong, and adopt everyday privacy habits like using strong passwords, encrypted DNS, and privacy-respecting tools. The Data Protection Commission is on your side, and so are technology providers that put user privacy first. Your data belongs to you — take it back.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
UK Data Protection Act vs GDPR Explained: Key Differences in 2026
Confused by the UK Data Protection Act vs GDPR? This guide explains how the UK GDPR and DPA 2018 work together, their key differences from the EU GDPR, and what UK businesses must do to stay compliant in 2026.
ICO Fines 2026: Biggest Data Protection Penalties in the UK
The ICO issued record-breaking data protection fines in 2026, targeting ransomware failures, unlawful profiling and PECR breaches. This guide breaks down the biggest UK penalties, why they happened, and how organisations can stay compliant.
Singapore PDPA vs GDPR: Key Differences Every Business Must Know
Singapore's PDPA and the EU's GDPR both protect personal data, but they differ sharply in scope, consent rules, breach timelines, and penalties. This guide breaks down the key differences and shows Singapore businesses how to build a dual-compliance strategy.
How Canadian Businesses Should Handle Data Privacy in 2026
A practical 2026 guide to how Canadian businesses should handle data privacy - covering PIPEDA, Quebec Law 25, breach reporting, cross-border transfers, and the security controls regulators expect. Includes a 30-60-90 day action plan and a comparison of Canada's major privacy regimes.