GDPR in Ireland: Your Privacy Rights Explained (2026 Guide)
The General Data Protection Regulation (GDPR) gives people in Ireland some of the strongest privacy rights in the world. Whether you're signing up to an Irish retailer, using a social network based in Dublin, or clicking a link in a marketing email, the law sets strict rules about how your personal data can be collected, stored, and shared. This guide explains, in plain English, what those rights are, who enforces them, and how you can use them in everyday life.
What is GDPR and how does it apply in Ireland?
GDPR is an EU-wide regulation that came into force on 25 May 2018. In Ireland it is implemented alongside the Data Protection Act 2018, and it applies to any organisation — Irish, European, or international — that processes the personal data of people living in Ireland.
Because Dublin hosts the European headquarters of companies like Meta, Google, TikTok, Microsoft, LinkedIn, and Apple, Ireland's Data Protection Commission (DPC) plays a uniquely important role as the lead supervisory authority for much of the digital world. That means many of the biggest privacy decisions in Europe are actually made in Portarlington and Dublin.
Who does GDPR protect?
GDPR protects "data subjects" — any identifiable living person in the EU or EEA. In Ireland, this includes citizens, residents, tourists, workers, and students. Your rights apply regardless of nationality, as long as your personal data is being processed by an organisation subject to EU law.
What counts as personal data?
Personal data is any information that can identify you directly or indirectly. Examples include:
- Your name, address, phone number, or email
- Your PPS number, passport number, or Eircode
- IP addresses, device IDs, and cookies
- Photos, CCTV footage, or voice recordings
- Location data from your phone
- Purchase history, banking details, and loyalty card activity
Special category data — such as health information, religious beliefs, ethnicity, trade union membership, or sexual orientation — receives even stronger protection under Article 9 of GDPR.
Your eight core privacy rights under GDPR
GDPR gives you eight enforceable rights over your personal data. Any organisation processing your information in Ireland must respect these rights, usually within one month of your request.
1. The right to be informed
Organisations must tell you what data they collect, why they collect it, how long they keep it, and who they share it with. This is normally done through a privacy notice on their website or during signup.
2. The right of access
You can submit a Subject Access Request (SAR) and receive a copy of all personal data an organisation holds about you, free of charge, within one month.
3. The right to rectification
If your data is wrong or incomplete — for example, an incorrect address on your ESB bill or a misspelt name at your GP — you can require it to be corrected.
4. The right to erasure ("right to be forgotten")
You can ask for your data to be deleted when it is no longer needed, when you withdraw consent, or when it was processed unlawfully. This right is not absolute — a bank, for example, must retain some records for anti-money-laundering purposes.
5. The right to restrict processing
You can freeze the use of your data while a dispute is being resolved, without requiring full deletion.
6. The right to data portability
You can request your data in a common, machine-readable format (like CSV or JSON) and move it to another provider — useful when switching banks, mobile operators, or fitness apps.
7. The right to object
You can object to processing based on legitimate interests, and you have an absolute right to object to direct marketing at any time.
8. Rights related to automated decision-making
You have the right not to be subject to purely automated decisions that produce legal or similarly significant effects — such as automated credit scoring or profiling for insurance.
The lawful bases: why organisations can process your data
Under Article 6 of GDPR, an organisation must have a valid legal reason to process your personal data. There are six lawful bases, and they must choose one before collecting anything.
| Lawful basis | Typical Irish example |
|---|---|
| Consent | Signing up to a newsletter from an Irish retailer |
| Contract | Providing your address to An Post for a delivery |
| Legal obligation | Revenue collecting your PAYE information |
| Vital interests | Sharing medical data in an A&E emergency |
| Public task | Local councils processing housing applications |
| Legitimate interests | Fraud prevention checks by AIB or Bank of Ireland |
Consent must be freely given
Under GDPR, consent must be specific, informed, and unambiguous. Pre-ticked boxes are not valid. "Cookie walls" that force you to accept tracking to view content are generally considered non-compliant by the DPC and the European Data Protection Board.
The Data Protection Commission (DPC): Ireland's regulator
The DPC is Ireland's independent authority responsible for enforcing GDPR and the Data Protection Act 2018. Based in Dublin and Portarlington, it acts as the lead supervisory authority for many of the world's largest tech companies because their European headquarters are in Ireland.
What the DPC can do
- Investigate complaints from individuals
- Conduct audits and inquiries into organisations
- Issue reprimands, warnings, and binding orders
- Impose administrative fines of up to €20 million or 4% of global annual turnover
- Refer cross-border decisions to the European Data Protection Board
Notable Irish GDPR enforcement
The DPC has issued some of the largest fines in EU history, including a €1.2 billion penalty against Meta in 2023 for unlawful data transfers to the United States, and multi-hundred-million-euro fines against WhatsApp, Instagram, and TikTok. These cases show that GDPR has real teeth — especially in Ireland.
How to make a GDPR complaint in Ireland
If you believe an organisation has mishandled your personal data, you have a clear route to complain. The process is free and does not require a solicitor.
- Contact the organisation first. Email their Data Protection Officer (DPO) or privacy team. Under GDPR they have one month to respond.
- Keep records. Save emails, screenshots, and reference numbers.
- Escalate to the DPC. If you're unhappy with the response — or receive none — file a complaint at dataprotection.ie using their online form.
- Cooperate with the investigation. The DPC may ask for further information or attempt amicable resolution.
- Appeal if needed. Decisions can be appealed to the Circuit Court or High Court in Ireland.
How long does a DPC complaint take?
Simple complaints can be resolved in a few months, while cross-border cases involving large tech companies may take years. The DPC publishes an annual report showing case volumes and outcomes.
Everyday privacy risks in Ireland (and how to reduce them)
Knowing your rights is only half the battle. Modern data-collection practices — from tracking pixels in emails to shortened links on social media — can quietly build a detailed profile of your online life. Here are practical steps to protect yourself.
Watch what you click
Shortened links are convenient but can hide the true destination. Before clicking a suspicious short link in a WhatsApp message or SMS (a common tactic in Irish "An Post" and Revenue scams), preview it or use a trustworthy shortener that discloses the destination. Privacy-focused tools such as Lunyb allow you to create short links without hidden third-party trackers, which is useful for businesses that want to respect GDPR by minimising unnecessary data collection. For a broader look at options, see our 2026 buyer's guide to URL shorteners.
Manage cookies properly
Under Ireland's ePrivacy Regulations 2011 (which sit alongside GDPR), non-essential cookies require your prior consent. If a website makes it easier to "Accept All" than to "Reject All", that is a red flag — and something the DPC has actively enforced against.
Use privacy-respecting tools
- Choose browsers with strong tracker blocking (Firefox, Brave, Safari)
- Enable encrypted DNS (DNS over HTTPS) in your browser or router
- Use end-to-end encrypted messaging like Signal for sensitive conversations
- Turn on two-factor authentication for banking and email
Limit what you share
Only provide the data an organisation actually needs. If a coffee-shop loyalty app asks for your date of birth and Eircode, ask why. GDPR's "data minimisation" principle means they should only collect what is strictly necessary.
GDPR rights at work in Ireland
Your GDPR rights don't stop at your employer's door. Irish employees have specific protections around workplace monitoring, HR files, and CCTV.
Access to your HR file
You can submit a Subject Access Request to your employer and receive copies of your contract, performance reviews, disciplinary records, and internal emails that identify you.
Workplace monitoring
Employers must be transparent about email monitoring, CCTV, and productivity tracking. Covert surveillance is almost never lawful in Ireland outside serious criminal investigations, and requires a Data Protection Impact Assessment (DPIA).
Working remotely
Since remote work became normalised, the DPC has published detailed guidance reminding employers that home-based monitoring tools must still meet GDPR's necessity and proportionality tests.
Children's privacy and the Digital Age of Consent
Ireland has set the "digital age of consent" at 16. This means that for information society services (like social media), children under 16 need parental consent before their personal data can be processed on the basis of consent.
The DPC's Fundamentals for a Child-Oriented Approach to Data Processing also require platforms to apply a "best interests of the child" test, use age-appropriate transparency, and disable profiling by default for minors.
Data breaches: what to expect if your data is exposed
If an organisation suffers a personal data breach that is likely to result in a risk to your rights and freedoms, they must notify the DPC within 72 hours. If the risk is high, they must also notify you directly.
What a breach notification should tell you
- What data was affected (e.g., name, email, password hashes)
- What the likely consequences are
- What steps the organisation has taken
- What you should do (e.g., change passwords, monitor accounts)
Your options after a breach
You can complain to the DPC, and under Article 82 of GDPR you may seek compensation through the Irish courts for material or non-material damage — including distress. Several class-action-style cases are progressing through the Irish legal system.
GDPR for small Irish businesses
GDPR isn't just about consumer rights — it also creates obligations for the SMEs, sole traders, and clubs that make up most of the Irish economy. Even a small yoga studio in Galway or a plumber in Cork processing customer contact details needs to comply.
Practical compliance steps
- Map the personal data you hold and why
- Publish a clear, plain-English privacy notice
- Identify a lawful basis for each processing activity
- Sign data processing agreements with suppliers (e.g., Mailchimp, Stripe)
- Have a documented breach response plan
- Train staff on the basics of data protection
Marketing teams in particular should be careful with link tracking and email analytics — using transparent, privacy-friendly tools helps meet GDPR's accountability principle without over-collecting data.
Frequently Asked Questions
Do I have to pay to make a Subject Access Request in Ireland?
No. Under GDPR, Subject Access Requests are free of charge. An organisation can only charge a "reasonable fee" if requests are manifestly unfounded, excessive, or repetitive — and even then, they must justify the charge.
How long does an organisation have to respond to my GDPR request?
Organisations must respond within one calendar month of receiving your request. This can be extended by a further two months for complex or numerous requests, but they must tell you within the first month and explain why.
Can I sue a company in Ireland for a GDPR breach?
Yes. Under Article 82 of GDPR and the Data Protection Act 2018, you can bring a civil action in the Circuit Court or High Court and seek compensation for material damage (financial loss) or non-material damage (distress and anxiety) caused by a data protection infringement.
Does GDPR apply to companies outside the EU that process Irish people's data?
Yes. GDPR has extraterritorial reach. Any company outside the EU that offers goods or services to people in Ireland, or monitors their behaviour, must comply — even if they have no physical presence in Europe.
What's the difference between GDPR and the Irish Data Protection Act 2018?
GDPR is an EU regulation that applies directly across all member states. The Data Protection Act 2018 is the Irish law that gives effect to GDPR in national law, sets the digital age of consent at 16, and establishes the powers and structure of the Data Protection Commission.
Final thoughts
GDPR gives people in Ireland genuine, enforceable control over their personal data — and the Data Protection Commission has shown it is willing to use its powers, even against the world's largest tech firms. Knowing your eight core rights, understanding how to make a complaint, and using privacy-respecting tools in your daily life are the most practical ways to benefit from the law. If you run a business, treating GDPR as an opportunity to build trust — rather than a box-ticking exercise — is one of the best long-term investments you can make.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
OAIC Complaints: How to Report a Privacy Breach in Australia
A step-by-step Australian guide to lodging a privacy complaint with the OAIC — including preparation, timelines, evidence, remedies and realistic outcomes. Learn exactly what to do when an organisation mishandles your personal information under the Privacy Act.
PIPEDA vs GDPR: Canadian Privacy Law Explained (2026 Guide)
PIPEDA and the GDPR both protect personal data, but they differ sharply on consent, individual rights, and penalties. This guide compares Canada's privacy law to Europe's GDPR and shows Canadian businesses exactly what compliance looks like in 2026.
Singapore PDPA: Your Personal Data Protection Rights Explained
Singapore's PDPA gives you clear rights over your personal data — from access and correction to data portability and breach notification. This guide explains each right, how to exercise it, and how to file a complaint with the PDPC in 2026.
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
A step-by-step guide to filing a privacy complaint with Ireland's Data Protection Commission (DPC), including what evidence to gather, how to submit, and what to expect at each stage. Learn timelines, appeal rights, and practical privacy tips for Irish residents.