GDPR in Ireland: Your Privacy Rights Explained
Ireland sits at the heart of Europe's data economy. With Dublin hosting the European headquarters of Google, Meta, TikTok, Apple, LinkedIn, and countless other tech giants, the country's Data Protection Commission (DPC) has become one of the most influential privacy regulators on the planet. For Irish residents, this creates a unique situation: the General Data Protection Regulation (GDPR) grants you some of the strongest privacy rights in the world, and the Irish DPC is often the first port of call for enforcement.
This guide explains exactly what your GDPR rights are in Ireland, how to exercise them, what businesses must do to comply, and how to file a complaint if your data is misused.
What Is GDPR and How Does It Apply in Ireland?
The General Data Protection Regulation (GDPR) is an EU-wide law that came into force on 25 May 2018. It governs how organisations collect, store, process, and share personal data belonging to individuals in the European Union and European Economic Area.
In Ireland, GDPR is implemented alongside the Data Protection Act 2018, which fills in national-level details such as the age of digital consent (set at 16 in Ireland) and the powers of the Data Protection Commission. Together, these two laws form the backbone of Irish privacy law.
Who Does GDPR Protect?
GDPR protects any identifiable living individual, known as a "data subject." If you live in Ireland, or if your personal data is processed by an organisation established in Ireland, you are covered—regardless of your nationality.
Who Must Comply?
GDPR applies to two types of organisations:
- Data controllers: the entities that decide why and how personal data is processed (for example, an online retailer collecting your address).
- Data processors: the entities that process data on behalf of controllers (for example, a cloud hosting provider).
The regulation applies to any organisation offering goods or services to people in the EU, even if the organisation itself is based outside the EU.
Your Eight Core GDPR Rights in Ireland
GDPR gives every Irish resident eight fundamental rights over their personal data. Understanding these rights is the first step to controlling your digital footprint.
1. The Right to Be Informed
Organisations must tell you clearly what data they collect, why they collect it, how long they keep it, and who they share it with. This is usually provided through a privacy notice or policy at the point of data collection.
2. The Right of Access
You can request a copy of all personal data an organisation holds about you. This is known as a Subject Access Request (SAR). The organisation must respond within one month, free of charge.
3. The Right to Rectification
If data held about you is inaccurate or incomplete, you can require the organisation to correct or update it.
4. The Right to Erasure ("Right to Be Forgotten")
You can ask organisations to delete your personal data when it is no longer needed, when you withdraw consent, or when it has been unlawfully processed. This right is not absolute—organisations can refuse if they have a legal obligation to retain the data.
5. The Right to Restrict Processing
You can ask an organisation to pause processing your data while a dispute is being resolved, such as when you contest the accuracy of the data.
6. The Right to Data Portability
You can obtain your data in a structured, commonly used, machine-readable format and transfer it to another service provider. This is particularly useful when switching banks, social networks, or cloud services.
7. The Right to Object
You have an absolute right to object to your data being used for direct marketing. You can also object to processing based on legitimate interests or public tasks.
8. Rights Related to Automated Decision-Making
You have the right not to be subject to a decision based solely on automated processing—including profiling—that produces legal or similarly significant effects, such as automated credit scoring or job application filtering.
Summary Table: Your GDPR Rights at a Glance
| Right | What It Lets You Do | Response Time |
|---|---|---|
| Right to be Informed | Know what data is collected and why | At collection |
| Right of Access | Request a copy of your data | 1 month |
| Right to Rectification | Correct inaccurate data | 1 month |
| Right to Erasure | Request deletion of your data | 1 month |
| Right to Restrict Processing | Pause processing during disputes | 1 month |
| Right to Data Portability | Receive and transfer your data | 1 month |
| Right to Object | Stop marketing or certain processing | Immediate for marketing |
| Automated Decision Rights | Human review of AI decisions | 1 month |
How to Exercise Your Rights: Step-by-Step
Exercising your GDPR rights is straightforward, but knowing the correct procedure improves your chances of a swift response.
- Identify the data controller. Check the organisation's privacy policy to find the correct contact—usually a Data Protection Officer (DPO) or a privacy team email address.
- Put your request in writing. While verbal requests are technically valid, written requests (email or post) create a clear record.
- Be specific. State which right you are exercising and, where possible, describe the data you want. For example: "I am making a Subject Access Request under Article 15 of the GDPR."
- Verify your identity. The organisation may reasonably ask for ID to confirm you are the data subject. Avoid sending more than is necessary.
- Track the deadline. Organisations must respond within one calendar month. Complex requests may be extended by two additional months, but they must inform you.
- Escalate if ignored. If the response is inadequate or absent, you can complain to the Data Protection Commission.
The Data Protection Commission (DPC): Ireland's Watchdog
The Data Protection Commission is Ireland's independent supervisory authority for GDPR. Based in Dublin with an office in Portarlington, the DPC handles complaints, investigates breaches, and enforces fines. Because so many multinational tech firms have their EU headquarters in Ireland, the DPC often acts as the "lead supervisory authority" for cross-border investigations under GDPR's one-stop-shop mechanism.
How to File a Complaint With the DPC
If you believe your rights have been breached, you can file a complaint directly with the DPC. The process is free.
- Try to resolve the issue with the organisation first (this is not mandatory but often faster).
- Gather evidence: copies of your original request, the response you received, dates, and any relevant correspondence.
- Submit a complaint through the DPC's online form at dataprotection.ie, by email to info@dataprotection.ie, or by post.
- The DPC will assess your complaint and may open an inquiry, mediate, or issue a formal decision.
Enforcement Powers and Notable Fines
The DPC can impose administrative fines of up to €20 million or 4% of a company's global annual turnover—whichever is higher. Over recent years, it has issued some of the largest GDPR fines in EU history, including record penalties against Meta and TikTok relating to data transfers, targeted advertising, and children's privacy.
What Businesses in Ireland Must Do to Comply
If you run a business in Ireland—whether a small e-commerce store or a SaaS platform—GDPR compliance is not optional. Non-compliance risks fines, reputational damage, and civil claims from affected individuals.
Key Compliance Obligations
- Lawful basis for processing: Identify a valid legal basis (consent, contract, legal obligation, vital interests, public task, or legitimate interests) for every data processing activity.
- Transparent privacy notices: Publish clear, plain-language privacy policies explaining data practices.
- Data minimisation: Only collect data that is strictly necessary for the stated purpose.
- Security measures: Implement appropriate technical and organisational safeguards—encryption, access controls, staff training.
- Breach notification: Report notifiable data breaches to the DPC within 72 hours of becoming aware.
- Records of processing activities: Maintain internal documentation of what data you process and why.
- Data Protection Impact Assessments (DPIAs): Conduct DPIAs for high-risk processing, such as large-scale profiling or biometric data.
- Appoint a DPO if required: Public authorities and organisations engaged in large-scale monitoring or processing of sensitive data must appoint a Data Protection Officer.
Special Considerations for Marketing and Links
Marketers frequently use tracking parameters, cookies, and shortened URLs. Under GDPR and the ePrivacy Regulations 2011 (Ireland's implementation of the ePrivacy Directive), you must obtain explicit consent before dropping non-essential cookies or sending electronic marketing to individuals. When using URL shorteners for campaign tracking, choose providers that respect privacy and offer transparent analytics. Tools like Lunyb allow you to shorten and track links without invasive user profiling—useful for staying on the right side of consent rules. For a broader comparison of privacy-respecting link tools, see our 2026 Buyer's Guide to URL Shorteners.
Common Privacy Scenarios in Ireland
CCTV in Workplaces and Homes
Employers using CCTV must inform staff, have a lawful basis, and limit recording to what is necessary. Homeowners with cameras that capture public footpaths or neighbours' property may also fall within GDPR scope and should minimise the area covered.
Employee Monitoring
Monitoring emails, internet usage, or location is only permitted with a clear lawful basis, proportionality, and transparent notice to staff. Covert monitoring is rarely lawful.
Children's Data
In Ireland, the digital age of consent is 16. Online services relying on consent must obtain parental authorisation for users under 16. The DPC's Fundamentals for a Child-Oriented Approach to Data Processing sets additional expectations for platforms serving children.
International Data Transfers
Following the Schrems II ruling, transferring personal data outside the EU requires safeguards such as Standard Contractual Clauses (SCCs) and, in many cases, supplementary measures to protect data from foreign surveillance.
Practical Tips to Protect Your Own Privacy
Beyond legal rights, there are practical steps every Irish resident can take to reduce data exposure:
- Use privacy-focused browsers such as Firefox or Brave, and enable tracking protection.
- Turn on encrypted DNS (DNS over HTTPS) to keep your browsing lookups private from your internet provider.
- Review app permissions on your phone regularly and revoke access that isn't essential.
- Use unique, strong passwords with a reputable password manager, and enable two-factor authentication.
- Be selective when clicking shortened links; if you're unsure where a link leads, use a link-preview tool or a shortener with built-in transparency such as Lunyb.
- Regularly audit which companies hold your data and submit erasure requests to services you no longer use.
How GDPR Interacts With Other Irish Laws
GDPR does not exist in isolation. It works alongside several Irish laws that shape privacy in practice:
- Data Protection Act 2018: Implements GDPR nationally and covers law enforcement processing under the Law Enforcement Directive.
- ePrivacy Regulations 2011: Cover cookies, direct marketing, and traffic data.
- Freedom of Information Act 2014: Governs access to personal data held by public bodies.
- Online Safety and Media Regulation Act 2022: Introduces additional obligations for online platforms regarding harmful content.
FAQ: GDPR and Privacy Rights in Ireland
How long does an organisation have to respond to my Subject Access Request?
Under GDPR, organisations must respond within one calendar month of receiving your request. For complex or numerous requests, they can extend this by a further two months, but they must inform you of the extension and the reasons within the original month.
Can I be charged for exercising my GDPR rights?
No. Exercising your rights is free in almost all cases. Organisations may only charge a "reasonable fee" if a request is manifestly unfounded, excessive, or if you request multiple copies of the same information.
What can I do if a company ignores my GDPR request?
You have two main options. You can lodge a complaint with the Data Protection Commission at dataprotection.ie, which is free. You also have the right to seek a judicial remedy through the Irish courts, including compensation for material or non-material damage such as distress.
Does GDPR apply to small businesses and sole traders in Ireland?
Yes. GDPR applies regardless of business size. However, some obligations, such as maintaining records of processing activities, are lighter for organisations with fewer than 250 employees—unless the processing is high-risk or involves special category data.
Are shortened URLs and click tracking allowed under GDPR?
Yes, but you must have a lawful basis and be transparent. If you use shortened URLs in marketing emails or on websites, tell users in your privacy notice that you track clicks, obtain consent where required by ePrivacy rules, and choose a shortening provider that handles data responsibly. Providers with clear privacy documentation—such as those reviewed in our URL shortener comparison and the detailed Rebrandly review—make compliance much easier.
Final Thoughts
GDPR gives Irish residents genuine, enforceable control over their personal data—and the Data Protection Commission has shown a growing willingness to use its powers against even the largest tech companies. Whether you're an individual protecting your digital life or a business building customer trust, understanding these rights is essential in 2026. Take a few minutes to audit the services you use, exercise your rights where needed, and choose tools and partners that treat your data with the respect the law demands.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Privacy Rights in Canada 2026: A Complete Guide for Individuals and Businesses
A complete 2026 guide to privacy rights in Canada, covering PIPEDA, the CPPA, Quebec's Law 25, and provincial protections. Learn how to exercise your rights, what businesses must do, and how to safeguard your personal data online.
GDPR After Brexit: What Changed for UK Businesses
GDPR after Brexit created two parallel regimes: the EU GDPR and the UK GDPR. This guide breaks down the key differences, new transfer rules like the IDTA, ICO enforcement trends, and what UK businesses must do in 2026 to stay compliant and protect adequacy status.
Singapore PDPA: Your Personal Data Protection Rights Explained
Singapore's PDPA gives you powerful rights over your personal data — from access and correction to consent withdrawal and breach notifications. This comprehensive guide explains each right, how to exercise it, and how the PDPA compares with global frameworks like GDPR.
Data Protection Act 2018 Ireland: The Complete Guide
Ireland's Data Protection Act 2018 works alongside the GDPR to protect personal data and create the Data Protection Commission. This complete guide covers scope, rights, obligations, enforcement, and practical compliance steps for Irish businesses.