GDPR in Ireland: Your Privacy Rights Explained
Ireland sits at the heart of the European data protection landscape. Because so many of the world's largest technology companies — Google, Meta, TikTok, Apple, X and LinkedIn — have their EU headquarters in Dublin, the Irish Data Protection Commission (DPC) is effectively the lead regulator for hundreds of millions of Europeans under the General Data Protection Regulation (GDPR). If you live in Ireland, that means you have some of the strongest and most enforceable digital privacy rights in the world.
This guide explains, in plain English, exactly what your GDPR privacy rights are in Ireland, how the Data Protection Act 2018 fits in, how to exercise those rights, and what to do when a company mishandles your personal data.
What Is GDPR and How Does It Apply in Ireland?
The General Data Protection Regulation (GDPR) is an EU-wide law that took effect on 25 May 2018. It regulates how organisations collect, store, use and share personal data about individuals in the European Union. In Ireland, GDPR is implemented alongside the Data Protection Act 2018, which fills in national details such as the age of digital consent (16 in Ireland) and the powers of the Data Protection Commission.
GDPR applies to any organisation — whether based in Ireland, elsewhere in the EU, or overseas — that processes the personal data of people located in Ireland. That includes your bank, your employer, the HSE, your local GAA club, an American social network, and a small online shop in Cork.
Key Irish Regulators You Should Know
- Data Protection Commission (DPC) — the national supervisory authority based in Dublin and Portarlington.
- ComReg — regulates electronic communications and enforces the ePrivacy Regulations 2011 (cookies, marketing calls, SMS).
- Circuit and High Courts — hear compensation claims for GDPR breaches.
What Counts as Personal Data Under Irish GDPR?
Personal data is any information that can identify a living individual, either on its own or when combined with other data. In Ireland, this is interpreted broadly by the DPC.
Examples include:
- Your name, address, Eircode and phone number
- Your PPS number and passport details
- Email addresses and usernames
- IP addresses, cookie IDs and device identifiers
- Location data from your phone
- Photos, CCTV footage and voice recordings
- Bank account and payment card information
Some categories are treated as special category data and enjoy extra protection: health information, racial or ethnic origin, religious beliefs, trade union membership, sexual orientation, biometric data and genetic data.
Your Eight Core GDPR Rights in Ireland
GDPR gives every person in Ireland eight fundamental rights over their personal data. Any organisation processing your data — from Revenue to Ryanair — must respect these rights, usually within one calendar month of your request and free of charge.
1. The Right to Be Informed
Organisations must clearly tell you what data they collect, why, how long they keep it, and who they share it with. This is typically done through a privacy notice or privacy policy on a website.
2. The Right of Access (Subject Access Request)
You can ask any organisation for a copy of the personal data they hold about you. This is called a Subject Access Request (SAR). They must respond within one month and cannot charge a fee unless the request is manifestly excessive.
3. The Right to Rectification
If data about you is wrong or incomplete, you can require the organisation to correct it. This is particularly relevant for credit reports, medical records and employment files.
4. The Right to Erasure ("Right to Be Forgotten")
In certain circumstances you can ask an organisation to delete your personal data — for example, when the data is no longer needed, when you withdraw consent, or when it was collected unlawfully.
5. The Right to Restrict Processing
You can ask an organisation to pause its use of your data while a dispute is resolved, for example while you contest its accuracy.
6. The Right to Data Portability
You can request your data in a common, machine-readable format (such as CSV or JSON) and have it transferred to another provider. This is common when switching banks, energy providers or streaming services.
7. The Right to Object
You can object to processing based on legitimate interests, and you have an absolute right to object to direct marketing. Once you object to marketing, the organisation must stop immediately.
8. Rights Related to Automated Decision-Making and Profiling
You have the right not to be subject to purely automated decisions — including AI-driven ones — that produce legal or similarly significant effects, such as automated loan refusals or automated hiring decisions.
Quick Comparison: Your Rights at a Glance
| Right | When to Use It | Response Deadline | Cost |
|---|---|---|---|
| Access | You want to see what a company knows about you | 1 month | Free |
| Rectification | Your data is wrong or incomplete | 1 month | Free |
| Erasure | Data is no longer needed or was unlawfully collected | 1 month | Free |
| Restriction | You are disputing accuracy or lawfulness | 1 month | Free |
| Portability | You are switching providers | 1 month | Free |
| Object | You do not want marketing or profiling | Immediate for marketing | Free |
| Informed | Always — should be proactive | At point of collection | Free |
| Automated decisions | An algorithm made a significant decision about you | 1 month | Free |
How to Exercise Your GDPR Rights in Ireland
Enforcing your rights is easier than most people think. You do not need a solicitor to make a basic request.
- Identify the data controller. Check the organisation's privacy policy — usually linked in the website footer — for a Data Protection Officer (DPO) or privacy contact email.
- Put your request in writing. Email is best. State clearly which right you are exercising (e.g. "I am making a Subject Access Request under Article 15 GDPR").
- Verify your identity. The controller may reasonably ask you to prove who you are, but they cannot demand excessive documentation.
- Set a deadline. Remind them that GDPR requires a response within one calendar month. They can extend by a further two months only for complex requests.
- Keep records. Save every email, letter and response. You will need these if you complain to the DPC.
How to File a Complaint with the Irish Data Protection Commission
If a company ignores your request, gives an incomplete answer, or breaches your rights, you can complain to the Data Protection Commission free of charge.
- Go to dataprotection.ie and use the online complaints form, or write to the DPC at 21 Fitzwilliam Square South, Dublin 2, or Canal House, Station Road, Portarlington, Co. Laois.
- Attach copies of your original request and any responses.
- Describe clearly what went wrong and what outcome you are seeking.
- The DPC will acknowledge your complaint and may attempt an amicable resolution before formal investigation.
- If the DPC finds a breach, it can order corrective measures and impose administrative fines of up to €20 million or 4% of global annual turnover.
You can also claim compensation for material or non-material damage — including distress — through the Irish Circuit Court under Section 117 of the Data Protection Act 2018.
Cookies, Marketing and the ePrivacy Regulations
Alongside GDPR, Ireland enforces the ePrivacy Regulations (SI 336/2011). These are the rules behind cookie banners, marketing emails and unsolicited phone calls.
Cookies
Websites operating in Ireland must obtain your clear, opt-in consent before setting non-essential cookies. "Continuing to browse" is not valid consent. The DPC has repeatedly warned Irish businesses that pre-ticked boxes and cookie walls are unlawful.
Direct Marketing
Marketing emails and texts to individuals require prior opt-in consent, with a limited "soft opt-in" exception for existing customers being marketed similar products. Every message must include an easy unsubscribe link. Cold marketing calls to a number listed on the National Directory Database opt-out register are prohibited.
Protecting Your Own Privacy Beyond GDPR
GDPR gives you strong rights, but privacy is a shared responsibility. Here are practical steps Irish internet users can take today to reduce data exposure.
- Use encrypted DNS (such as DNS-over-HTTPS in Firefox or on iOS) to prevent your ISP from logging every domain you visit.
- Choose privacy-respecting browsers like Firefox, Brave or Safari with strict tracking prevention enabled.
- Enable two-factor authentication on your email, bank and Revenue myAccount logins.
- Review app permissions on your Android or iPhone every few months.
- Use privacy-first tools when sharing links. If you share URLs on social media, a shortener like Lunyb lets you create clean, trackable short links without exposing your original URLs to aggressive third-party ad networks. You can read our honest Lunyb review or compare options in our 2026 URL shortener buyer's guide.
- Delete accounts you no longer use. Every dormant account is a future breach waiting to happen.
Common GDPR Scenarios in Ireland
Employer Monitoring
Irish employers may monitor work email and internet use, but only with a clear, proportionate policy that has been communicated to staff. Covert monitoring is almost always unlawful.
CCTV at Home and in Business
Home CCTV that only records your own property is generally exempt from GDPR under the household exemption. Cameras that capture the public footpath or a neighbour's garden bring you into scope as a data controller, with obligations to post signage and delete footage promptly.
Health Data and the HSE
Your medical records are special category data. You can request a copy from your GP or hospital under Article 15, and the DPC has been particularly active in enforcing health data breaches following incidents like the 2021 HSE ransomware attack.
Schools and Children's Data
In Ireland, the digital age of consent is 16. Below that age, parental consent is required for information society services such as social media accounts. Schools must have a data protection policy and a designated DPO for public bodies.
Enforcement in Action: The DPC's Track Record
The Irish DPC has issued some of the largest GDPR fines in Europe, including €1.2 billion against Meta in 2023 for unlawful transfers of EU user data to the United States, €345 million against TikTok for children's data violations, and €390 million against Meta over the legal basis for behavioural advertising. These decisions matter for every user in Ireland because they set precedents that reshape how global platforms treat your data.
Frequently Asked Questions
Do I need a solicitor to make a GDPR complaint in Ireland?
No. The DPC's complaints process is free and designed to be accessible without legal representation. Most people successfully resolve issues through a simple email to the company followed by an online complaint form if needed. You may want a solicitor if you are pursuing compensation in the Circuit Court.
How long does a Subject Access Request take in Ireland?
Organisations must respond within one calendar month of receiving your request. They can extend by up to two additional months for complex or high-volume requests, but they must tell you within the first month and explain why. If the deadline is missed, you can complain to the DPC.
Can I claim compensation for a GDPR breach in Ireland?
Yes. Article 82 of GDPR and Section 117 of the Data Protection Act 2018 allow you to claim compensation for material damage (financial loss) and non-material damage (distress, anxiety, loss of control over your data) in the Circuit Court. Recent Irish and CJEU case law has clarified that mere upset alone may not be enough — you generally need to show actual, identifiable harm.
Does GDPR apply to companies outside the EU that I use?
Yes, if they offer goods or services to people in Ireland or monitor their behaviour. This is why US-based platforms like Google and Meta have to comply with your requests. Non-EU controllers must usually appoint an EU representative you can contact.
What is the difference between the DPC and ComReg for privacy issues?
The DPC handles personal data issues under GDPR — data breaches, subject access, unlawful profiling. ComReg handles electronic communications issues under the ePrivacy Regulations — nuisance calls, unsolicited SMS and some cookie complaints. For most everyday privacy problems, the DPC is the correct starting point.
Final Thoughts
Ireland's position as the European home of Big Tech gives residents an unusually powerful set of privacy tools. GDPR, the Data Protection Act 2018 and the ePrivacy Regulations combine to give you real, enforceable control over your personal data — but only if you use them. Learn your rights, exercise them confidently, and combine legal protections with sensible technical habits like encrypted DNS, strong passwords and privacy-respecting tools. Your data belongs to you; make sure the companies that hold it act like they know that.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Data Protection Act 2018 Ireland: A Complete Guide for Businesses
Ireland's Data Protection Act 2018 sits alongside the GDPR to govern how personal data is handled. This complete guide covers scope, data subject rights, DPC enforcement powers, penalties up to €20 million, and a practical compliance checklist for Irish businesses.
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
A complete 2026 guide to filing a privacy complaint with the Data Protection Commission (DPC) in Ireland. Learn the process, timelines, evidence you need, and what outcomes to expect under the GDPR.
Bill C-27 Digital Charter: What You Need to Know in 2026
Bill C-27, Canada's Digital Charter Implementation Act, will replace PIPEDA with modern privacy rules, algorithmic transparency, and Canada's first federal AI law. Here's what businesses and individuals need to know about compliance, penalties, and preparation.
OAIC Complaints: How to Report a Privacy Breach in Australia
A step-by-step Australian guide to OAIC complaints: what counts as a privacy breach, how to complain to the organisation first, how to lodge with the regulator, and what outcomes to expect. Includes evidence tips, timelines, and answers to common questions.