facebook-pixel

GDPR in Ireland: Your Privacy Rights Explained

L
Lunyb Security Team
··10 min read

Ireland sits at the heart of Europe's data protection landscape. As the European headquarters for many of the world's largest technology companies — including Meta, Google, TikTok, LinkedIn and Microsoft — the Irish Data Protection Commission (DPC) plays an outsized role in enforcing the General Data Protection Regulation (GDPR) across the EU. But GDPR isn't just about corporate fines. It's a comprehensive set of rights that every person in Ireland can use to control how their personal information is collected, stored and shared.

This guide explains, in plain English, what your privacy rights are under Irish GDPR law, how to exercise them, and what to do when a company doesn't comply.

What Is GDPR and How Does It Apply in Ireland?

The General Data Protection Regulation (GDPR) is an EU-wide law that came into force on 25 May 2018. It governs how organisations must collect, store, use and protect the personal data of people located in the European Union. In Ireland, GDPR is implemented alongside the Data Protection Act 2018, which provides the national legal framework and empowers the Data Protection Commission as the country's independent regulator.

GDPR applies to any organisation — whether based in Ireland, elsewhere in the EU, or outside the EU — that processes the personal data of people in Ireland. That includes small local businesses, hospitals, schools, government departments, and multinational tech giants headquartered in Dublin's docklands.

What Counts as "Personal Data"?

Personal data is any information that can identify you directly or indirectly. This includes obvious identifiers such as:

  • Your name, address, phone number, and email
  • Your PPS number and passport number
  • Your IP address, cookie identifiers and device IDs
  • Photographs and CCTV footage
  • Location data from your smartphone
  • Bank and payment details

GDPR also identifies special category data that gets extra protection: information about your health, race, ethnicity, religion, political opinions, trade union membership, sexual orientation, genetic data and biometric data.

Your Eight Core GDPR Rights in Ireland

GDPR gives you eight enforceable rights over your personal data. Every organisation processing your information must respect these, and the DPC can investigate complaints if they don't.

1. The Right to Be Informed

You have the right to know when your data is being collected, why, how long it will be kept, and who it will be shared with. This is normally communicated through a privacy notice or privacy policy on a website or in a paper form.

2. The Right of Access (Subject Access Request)

You can ask any organisation to provide a copy of the personal data it holds about you. This is called a Data Subject Access Request (DSAR). The organisation must respond within one calendar month, free of charge in most cases.

3. The Right to Rectification

If any personal data an organisation holds is inaccurate or incomplete, you can require them to correct it. This is particularly important for medical records, credit files, and employment records.

4. The Right to Erasure ("Right to Be Forgotten")

You can ask an organisation to delete your personal data in certain circumstances — for example, when the data is no longer needed, when you withdraw consent, or when it was processed unlawfully.

5. The Right to Restrict Processing

You can ask an organisation to temporarily stop processing your data while a dispute is being resolved — for example, while they investigate whether their records about you are accurate.

6. The Right to Data Portability

You can request your data in a structured, commonly used, machine-readable format (like CSV or JSON) so you can move it to another service provider. This applies mostly to data you have provided under consent or contract.

7. The Right to Object

You can object to your data being processed for direct marketing, profiling, or on the basis of a company's "legitimate interests". Objections to direct marketing must always be honoured.

8. Rights Around Automated Decision-Making

You have the right not to be subject to a decision based solely on automated processing — including profiling — that produces legal or similarly significant effects on you. Common examples include automated loan refusals or algorithmic hiring decisions.

The Role of the Irish Data Protection Commission (DPC)

The Data Protection Commission, based in Dublin and Portarlington, is Ireland's independent supervisory authority. Under GDPR's "one-stop-shop" mechanism, the DPC serves as the lead regulator for many of the biggest global tech firms because their EU headquarters are in Ireland.

The DPC has three main functions:

  1. Handling complaints from individuals who believe their rights have been breached.
  2. Investigating organisations for potential GDPR violations, either following a complaint or on its own initiative.
  3. Issuing guidance to businesses, public bodies and the public to promote compliance.

Since 2018, the DPC has issued some of the largest GDPR fines in Europe, including a €1.2 billion penalty against Meta in 2023 over EU–US data transfers, and multi-hundred-million euro fines against TikTok, Instagram and WhatsApp.

How to Exercise Your GDPR Rights: A Step-by-Step Guide

Exercising your rights is free and doesn't require a solicitor. Here's the process most Irish residents follow.

Step 1: Identify the Data Controller

The data controller is the organisation that decides why and how your data is processed. This is usually the company you interact with directly — the retailer, hospital, employer, or app provider.

Step 2: Send a Written Request

Contact the organisation's Data Protection Officer (DPO) or privacy team. Most Irish organisations list a dedicated email like dpo@company.ie or privacy@company.ie. Clearly state:

  • Which right you're exercising (e.g. access, erasure, rectification)
  • Enough information to identify yourself
  • The specific data or issue you're concerned about

Step 3: Wait for a Response

The organisation has one month to respond. In complex cases they can extend this by up to two additional months, but they must tell you and explain why.

Step 4: Escalate to the DPC If Necessary

If the organisation refuses, ignores you, or provides an inadequate response, you can lodge a complaint with the DPC through dataprotection.ie. The complaint form is free and available online.

GDPR Fines and Enforcement in Ireland

GDPR breaches can result in significant financial penalties. There are two tiers of fines:

TierMaximum FineTypical Violations
Lower tier€10 million or 2% of global annual turnover (whichever is higher)Failing to keep proper records, not notifying the DPC of a data breach, inadequate security
Upper tier€20 million or 4% of global annual turnover (whichever is higher)Breaching core data protection principles, ignoring individual rights, unlawful international transfers

The DPC has become one of the most active regulators in Europe. Recent notable Irish enforcement actions include:

  • Meta (Facebook) — €1.2 billion (2023): Unlawful transfer of EU user data to the United States.
  • TikTok — €345 million (2023): Violations relating to children's data.
  • Instagram — €405 million (2022): Public exposure of teenagers' contact details.
  • WhatsApp — €225 million (2021): Insufficient transparency about data sharing.

GDPR and Everyday Online Privacy in Ireland

Beyond the headlines, GDPR affects how ordinary people in Ireland experience the internet every day.

Cookies and Website Tracking

Under the ePrivacy Regulations (SI 336 of 2011) — enforced alongside GDPR — Irish websites must obtain your consent before setting non-essential cookies. This means the cookie banner must let you refuse tracking as easily as you can accept it. "Reject All" must be as prominent as "Accept All".

Marketing Emails and SMS

Companies cannot send you marketing communications without either your explicit consent or a valid "soft opt-in" (where you're an existing customer and were offered the chance to opt out at purchase). Every marketing message must include an easy unsubscribe option.

Link Sharing and URL Tracking

Many URL shorteners collect large volumes of behavioural and location data every time someone clicks a link. If you share links for business or personal reasons, choose a service that respects EU privacy law. Privacy-focused tools like Lunyb offer link shortening with minimal data collection and GDPR-compliant handling — see our honest Lunyb review and 2026 buyer's guide to URL shorteners for more comparisons.

Special Protections for Children in Ireland

Ireland has set the "digital age of consent" at 16 years old. This means online services (such as social media platforms) cannot rely on a child's own consent to process their data — they need verifiable parental consent instead.

The DPC has also published the Fundamentals for a Child-Oriented Approach to Data Processing, a set of 14 principles that require services likely to be accessed by children to apply the highest privacy settings by default and to explain data use in child-friendly language.

Data Breaches: What to Do if You're Affected

Under GDPR, organisations must notify the DPC of most personal data breaches within 72 hours of becoming aware of them. If the breach poses a high risk to your rights and freedoms — such as identity theft or financial loss — the organisation must also notify you directly, without undue delay.

If you receive a breach notification:

  1. Read carefully what data was affected.
  2. Change passwords immediately if login credentials were involved.
  3. Monitor bank statements and credit reports if financial data was exposed.
  4. Consider filing a complaint with the DPC if you're not satisfied with how the breach was handled.
  5. Keep evidence — you may be entitled to compensation for material or non-material damage.

Practical Tips to Protect Your Privacy Under Irish Law

GDPR gives you rights, but you can also take proactive steps to reduce how much of your data ends up in corporate databases in the first place:

  • Review privacy settings on every major service (Google, Meta, Apple, Microsoft) at least once a year.
  • Use encrypted DNS (like DNS-over-HTTPS) to prevent your internet provider from logging every domain you visit.
  • Choose privacy-respecting browsers such as Firefox or Brave, and use tracker-blocking extensions.
  • Read the cookie banner — clicking "Reject All" takes two seconds and cuts a huge amount of tracking.
  • Use aliased email addresses when signing up for newsletters or one-off services.
  • Be selective about apps — check what permissions each app requests, and revoke ones you don't need.

Frequently Asked Questions

Does GDPR still apply after Brexit if I'm dealing with a UK company?

Yes. If you're in Ireland, your data rights are still governed by EU GDPR regardless of where the company is based. UK companies that process the data of Irish residents must appoint an EU representative and comply with EU GDPR, in addition to the UK GDPR that governs their domestic operations.

How long does the DPC take to investigate a complaint?

Simple complaints are often resolved in a few months, but complex cross-border investigations involving multinational tech companies can take two to four years. The DPC provides updates during the process and publishes annual reports summarising outcomes.

Can I claim compensation for a GDPR breach?

Yes. Under Section 117 of the Data Protection Act 2018, you can bring a "data protection action" in the Circuit Court or High Court to claim compensation for material damage (financial loss) or non-material damage (distress, anxiety, reputational harm) caused by a GDPR infringement.

Do small Irish businesses have to comply with GDPR?

Yes. GDPR applies regardless of business size. However, some obligations — such as maintaining detailed records of processing activities or appointing a Data Protection Officer — are less onerous for organisations with fewer than 250 employees, provided their processing is occasional and low-risk.

What's the difference between a data controller and a data processor?

A controller decides why and how personal data is processed (e.g. your employer, your bank, an online retailer). A processor processes data on the controller's behalf (e.g. a cloud hosting company or payroll provider). Both have GDPR obligations, but you typically direct rights requests to the controller.

Conclusion

GDPR gives everyone in Ireland real, enforceable rights over their personal data — from asking a company what it knows about you, to demanding erasure, to lodging complaints with one of Europe's most influential regulators. Understanding these rights is the first step; using them regularly is what makes privacy meaningful.

As Ireland continues to host the European operations of the world's largest tech companies, the decisions made by the DPC in Dublin will shape digital privacy for hundreds of millions of Europeans. Whether you're an individual protecting your own data or a business handling customer information, staying informed about your obligations and entitlements under Irish and EU law is no longer optional — it's essential.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles