facebook-pixel

GDPR in Ireland: Your Privacy Rights Explained

L
Lunyb Security Team
··10 min read

Ireland sits at the heart of the European data protection landscape. Because so many of the world's largest technology companies — Google, Meta, TikTok, Apple, X and LinkedIn — have their EU headquarters in Dublin, the Irish Data Protection Commission (DPC) is effectively the lead regulator for hundreds of millions of Europeans under the General Data Protection Regulation (GDPR). If you live in Ireland, that means you have some of the strongest and most enforceable digital privacy rights in the world.

This guide explains, in plain English, exactly what your GDPR privacy rights are in Ireland, how the Data Protection Act 2018 fits in, how to exercise those rights, and what to do when a company mishandles your personal data.

What Is GDPR and How Does It Apply in Ireland?

The General Data Protection Regulation (GDPR) is an EU-wide law that took effect on 25 May 2018. It regulates how organisations collect, store, use and share personal data about individuals in the European Union. In Ireland, GDPR is implemented alongside the Data Protection Act 2018, which fills in national details such as the age of digital consent (16 in Ireland) and the powers of the Data Protection Commission.

GDPR applies to any organisation — whether based in Ireland, elsewhere in the EU, or overseas — that processes the personal data of people located in Ireland. That includes your bank, your employer, the HSE, your local GAA club, an American social network, and a small online shop in Cork.

Key Irish Regulators You Should Know

  • Data Protection Commission (DPC) — the national supervisory authority based in Dublin and Portarlington.
  • ComReg — regulates electronic communications and enforces the ePrivacy Regulations 2011 (cookies, marketing calls, SMS).
  • Circuit and High Courts — hear compensation claims for GDPR breaches.

What Counts as Personal Data Under Irish GDPR?

Personal data is any information that can identify a living individual, either on its own or when combined with other data. In Ireland, this is interpreted broadly by the DPC.

Examples include:

  • Your name, address, Eircode and phone number
  • Your PPS number and passport details
  • Email addresses and usernames
  • IP addresses, cookie IDs and device identifiers
  • Location data from your phone
  • Photos, CCTV footage and voice recordings
  • Bank account and payment card information

Some categories are treated as special category data and enjoy extra protection: health information, racial or ethnic origin, religious beliefs, trade union membership, sexual orientation, biometric data and genetic data.

Your Eight Core GDPR Rights in Ireland

GDPR gives every person in Ireland eight fundamental rights over their personal data. Any organisation processing your data — from Revenue to Ryanair — must respect these rights, usually within one calendar month of your request and free of charge.

1. The Right to Be Informed

Organisations must clearly tell you what data they collect, why, how long they keep it, and who they share it with. This is typically done through a privacy notice or privacy policy on a website.

2. The Right of Access (Subject Access Request)

You can ask any organisation for a copy of the personal data they hold about you. This is called a Subject Access Request (SAR). They must respond within one month and cannot charge a fee unless the request is manifestly excessive.

3. The Right to Rectification

If data about you is wrong or incomplete, you can require the organisation to correct it. This is particularly relevant for credit reports, medical records and employment files.

4. The Right to Erasure ("Right to Be Forgotten")

In certain circumstances you can ask an organisation to delete your personal data — for example, when the data is no longer needed, when you withdraw consent, or when it was collected unlawfully.

5. The Right to Restrict Processing

You can ask an organisation to pause its use of your data while a dispute is resolved, for example while you contest its accuracy.

6. The Right to Data Portability

You can request your data in a common, machine-readable format (such as CSV or JSON) and have it transferred to another provider. This is common when switching banks, energy providers or streaming services.

7. The Right to Object

You can object to processing based on legitimate interests, and you have an absolute right to object to direct marketing. Once you object to marketing, the organisation must stop immediately.

8. Rights Related to Automated Decision-Making and Profiling

You have the right not to be subject to purely automated decisions — including AI-driven ones — that produce legal or similarly significant effects, such as automated loan refusals or automated hiring decisions.

Quick Comparison: Your Rights at a Glance

RightWhen to Use ItResponse DeadlineCost
AccessYou want to see what a company knows about you1 monthFree
RectificationYour data is wrong or incomplete1 monthFree
ErasureData is no longer needed or was unlawfully collected1 monthFree
RestrictionYou are disputing accuracy or lawfulness1 monthFree
PortabilityYou are switching providers1 monthFree
ObjectYou do not want marketing or profilingImmediate for marketingFree
InformedAlways — should be proactiveAt point of collectionFree
Automated decisionsAn algorithm made a significant decision about you1 monthFree

How to Exercise Your GDPR Rights in Ireland

Enforcing your rights is easier than most people think. You do not need a solicitor to make a basic request.

  1. Identify the data controller. Check the organisation's privacy policy — usually linked in the website footer — for a Data Protection Officer (DPO) or privacy contact email.
  2. Put your request in writing. Email is best. State clearly which right you are exercising (e.g. "I am making a Subject Access Request under Article 15 GDPR").
  3. Verify your identity. The controller may reasonably ask you to prove who you are, but they cannot demand excessive documentation.
  4. Set a deadline. Remind them that GDPR requires a response within one calendar month. They can extend by a further two months only for complex requests.
  5. Keep records. Save every email, letter and response. You will need these if you complain to the DPC.

How to File a Complaint with the Irish Data Protection Commission

If a company ignores your request, gives an incomplete answer, or breaches your rights, you can complain to the Data Protection Commission free of charge.

  1. Go to dataprotection.ie and use the online complaints form, or write to the DPC at 21 Fitzwilliam Square South, Dublin 2, or Canal House, Station Road, Portarlington, Co. Laois.
  2. Attach copies of your original request and any responses.
  3. Describe clearly what went wrong and what outcome you are seeking.
  4. The DPC will acknowledge your complaint and may attempt an amicable resolution before formal investigation.
  5. If the DPC finds a breach, it can order corrective measures and impose administrative fines of up to €20 million or 4% of global annual turnover.

You can also claim compensation for material or non-material damage — including distress — through the Irish Circuit Court under Section 117 of the Data Protection Act 2018.

Cookies, Marketing and the ePrivacy Regulations

Alongside GDPR, Ireland enforces the ePrivacy Regulations (SI 336/2011). These are the rules behind cookie banners, marketing emails and unsolicited phone calls.

Cookies

Websites operating in Ireland must obtain your clear, opt-in consent before setting non-essential cookies. "Continuing to browse" is not valid consent. The DPC has repeatedly warned Irish businesses that pre-ticked boxes and cookie walls are unlawful.

Direct Marketing

Marketing emails and texts to individuals require prior opt-in consent, with a limited "soft opt-in" exception for existing customers being marketed similar products. Every message must include an easy unsubscribe link. Cold marketing calls to a number listed on the National Directory Database opt-out register are prohibited.

Protecting Your Own Privacy Beyond GDPR

GDPR gives you strong rights, but privacy is a shared responsibility. Here are practical steps Irish internet users can take today to reduce data exposure.

  • Use encrypted DNS (such as DNS-over-HTTPS in Firefox or on iOS) to prevent your ISP from logging every domain you visit.
  • Choose privacy-respecting browsers like Firefox, Brave or Safari with strict tracking prevention enabled.
  • Enable two-factor authentication on your email, bank and Revenue myAccount logins.
  • Review app permissions on your Android or iPhone every few months.
  • Use privacy-first tools when sharing links. If you share URLs on social media, a shortener like Lunyb lets you create clean, trackable short links without exposing your original URLs to aggressive third-party ad networks. You can read our honest Lunyb review or compare options in our 2026 URL shortener buyer's guide.
  • Delete accounts you no longer use. Every dormant account is a future breach waiting to happen.

Common GDPR Scenarios in Ireland

Employer Monitoring

Irish employers may monitor work email and internet use, but only with a clear, proportionate policy that has been communicated to staff. Covert monitoring is almost always unlawful.

CCTV at Home and in Business

Home CCTV that only records your own property is generally exempt from GDPR under the household exemption. Cameras that capture the public footpath or a neighbour's garden bring you into scope as a data controller, with obligations to post signage and delete footage promptly.

Health Data and the HSE

Your medical records are special category data. You can request a copy from your GP or hospital under Article 15, and the DPC has been particularly active in enforcing health data breaches following incidents like the 2021 HSE ransomware attack.

Schools and Children's Data

In Ireland, the digital age of consent is 16. Below that age, parental consent is required for information society services such as social media accounts. Schools must have a data protection policy and a designated DPO for public bodies.

Enforcement in Action: The DPC's Track Record

The Irish DPC has issued some of the largest GDPR fines in Europe, including €1.2 billion against Meta in 2023 for unlawful transfers of EU user data to the United States, €345 million against TikTok for children's data violations, and €390 million against Meta over the legal basis for behavioural advertising. These decisions matter for every user in Ireland because they set precedents that reshape how global platforms treat your data.

Frequently Asked Questions

Do I need a solicitor to make a GDPR complaint in Ireland?

No. The DPC's complaints process is free and designed to be accessible without legal representation. Most people successfully resolve issues through a simple email to the company followed by an online complaint form if needed. You may want a solicitor if you are pursuing compensation in the Circuit Court.

How long does a Subject Access Request take in Ireland?

Organisations must respond within one calendar month of receiving your request. They can extend by up to two additional months for complex or high-volume requests, but they must tell you within the first month and explain why. If the deadline is missed, you can complain to the DPC.

Can I claim compensation for a GDPR breach in Ireland?

Yes. Article 82 of GDPR and Section 117 of the Data Protection Act 2018 allow you to claim compensation for material damage (financial loss) and non-material damage (distress, anxiety, loss of control over your data) in the Circuit Court. Recent Irish and CJEU case law has clarified that mere upset alone may not be enough — you generally need to show actual, identifiable harm.

Does GDPR apply to companies outside the EU that I use?

Yes, if they offer goods or services to people in Ireland or monitor their behaviour. This is why US-based platforms like Google and Meta have to comply with your requests. Non-EU controllers must usually appoint an EU representative you can contact.

What is the difference between the DPC and ComReg for privacy issues?

The DPC handles personal data issues under GDPR — data breaches, subject access, unlawful profiling. ComReg handles electronic communications issues under the ePrivacy Regulations — nuisance calls, unsolicited SMS and some cookie complaints. For most everyday privacy problems, the DPC is the correct starting point.

Final Thoughts

Ireland's position as the European home of Big Tech gives residents an unusually powerful set of privacy tools. GDPR, the Data Protection Act 2018 and the ePrivacy Regulations combine to give you real, enforceable control over your personal data — but only if you use them. Learn your rights, exercise them confidently, and combine legal protections with sensible technical habits like encrypted DNS, strong passwords and privacy-respecting tools. Your data belongs to you; make sure the companies that hold it act like they know that.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles