facebook-pixel

GDPR in Ireland: Your Privacy Rights Explained (2026 Guide)

L
Lunyb Security Team
··11 min read

The General Data Protection Regulation (GDPR) gives people in Ireland some of the strongest privacy rights in the world. Whether you're signing up to an Irish retailer, using a social network based in Dublin, or clicking a link in a marketing email, the law sets strict rules about how your personal data can be collected, stored, and shared. This guide explains, in plain English, what those rights are, who enforces them, and how you can use them in everyday life.

What is GDPR and how does it apply in Ireland?

GDPR is an EU-wide regulation that came into force on 25 May 2018. In Ireland it is implemented alongside the Data Protection Act 2018, and it applies to any organisation — Irish, European, or international — that processes the personal data of people living in Ireland.

Because Dublin hosts the European headquarters of companies like Meta, Google, TikTok, Microsoft, LinkedIn, and Apple, Ireland's Data Protection Commission (DPC) plays a uniquely important role as the lead supervisory authority for much of the digital world. That means many of the biggest privacy decisions in Europe are actually made in Portarlington and Dublin.

Who does GDPR protect?

GDPR protects "data subjects" — any identifiable living person in the EU or EEA. In Ireland, this includes citizens, residents, tourists, workers, and students. Your rights apply regardless of nationality, as long as your personal data is being processed by an organisation subject to EU law.

What counts as personal data?

Personal data is any information that can identify you directly or indirectly. Examples include:

  • Your name, address, phone number, or email
  • Your PPS number, passport number, or Eircode
  • IP addresses, device IDs, and cookies
  • Photos, CCTV footage, or voice recordings
  • Location data from your phone
  • Purchase history, banking details, and loyalty card activity

Special category data — such as health information, religious beliefs, ethnicity, trade union membership, or sexual orientation — receives even stronger protection under Article 9 of GDPR.

Your eight core privacy rights under GDPR

GDPR gives you eight enforceable rights over your personal data. Any organisation processing your information in Ireland must respect these rights, usually within one month of your request.

1. The right to be informed

Organisations must tell you what data they collect, why they collect it, how long they keep it, and who they share it with. This is normally done through a privacy notice on their website or during signup.

2. The right of access

You can submit a Subject Access Request (SAR) and receive a copy of all personal data an organisation holds about you, free of charge, within one month.

3. The right to rectification

If your data is wrong or incomplete — for example, an incorrect address on your ESB bill or a misspelt name at your GP — you can require it to be corrected.

4. The right to erasure ("right to be forgotten")

You can ask for your data to be deleted when it is no longer needed, when you withdraw consent, or when it was processed unlawfully. This right is not absolute — a bank, for example, must retain some records for anti-money-laundering purposes.

5. The right to restrict processing

You can freeze the use of your data while a dispute is being resolved, without requiring full deletion.

6. The right to data portability

You can request your data in a common, machine-readable format (like CSV or JSON) and move it to another provider — useful when switching banks, mobile operators, or fitness apps.

7. The right to object

You can object to processing based on legitimate interests, and you have an absolute right to object to direct marketing at any time.

8. Rights related to automated decision-making

You have the right not to be subject to purely automated decisions that produce legal or similarly significant effects — such as automated credit scoring or profiling for insurance.

The lawful bases: why organisations can process your data

Under Article 6 of GDPR, an organisation must have a valid legal reason to process your personal data. There are six lawful bases, and they must choose one before collecting anything.

Lawful basisTypical Irish example
ConsentSigning up to a newsletter from an Irish retailer
ContractProviding your address to An Post for a delivery
Legal obligationRevenue collecting your PAYE information
Vital interestsSharing medical data in an A&E emergency
Public taskLocal councils processing housing applications
Legitimate interestsFraud prevention checks by AIB or Bank of Ireland

Consent must be freely given

Under GDPR, consent must be specific, informed, and unambiguous. Pre-ticked boxes are not valid. "Cookie walls" that force you to accept tracking to view content are generally considered non-compliant by the DPC and the European Data Protection Board.

The Data Protection Commission (DPC): Ireland's regulator

The DPC is Ireland's independent authority responsible for enforcing GDPR and the Data Protection Act 2018. Based in Dublin and Portarlington, it acts as the lead supervisory authority for many of the world's largest tech companies because their European headquarters are in Ireland.

What the DPC can do

  • Investigate complaints from individuals
  • Conduct audits and inquiries into organisations
  • Issue reprimands, warnings, and binding orders
  • Impose administrative fines of up to €20 million or 4% of global annual turnover
  • Refer cross-border decisions to the European Data Protection Board

Notable Irish GDPR enforcement

The DPC has issued some of the largest fines in EU history, including a €1.2 billion penalty against Meta in 2023 for unlawful data transfers to the United States, and multi-hundred-million-euro fines against WhatsApp, Instagram, and TikTok. These cases show that GDPR has real teeth — especially in Ireland.

How to make a GDPR complaint in Ireland

If you believe an organisation has mishandled your personal data, you have a clear route to complain. The process is free and does not require a solicitor.

  1. Contact the organisation first. Email their Data Protection Officer (DPO) or privacy team. Under GDPR they have one month to respond.
  2. Keep records. Save emails, screenshots, and reference numbers.
  3. Escalate to the DPC. If you're unhappy with the response — or receive none — file a complaint at dataprotection.ie using their online form.
  4. Cooperate with the investigation. The DPC may ask for further information or attempt amicable resolution.
  5. Appeal if needed. Decisions can be appealed to the Circuit Court or High Court in Ireland.

How long does a DPC complaint take?

Simple complaints can be resolved in a few months, while cross-border cases involving large tech companies may take years. The DPC publishes an annual report showing case volumes and outcomes.

Everyday privacy risks in Ireland (and how to reduce them)

Knowing your rights is only half the battle. Modern data-collection practices — from tracking pixels in emails to shortened links on social media — can quietly build a detailed profile of your online life. Here are practical steps to protect yourself.

Watch what you click

Shortened links are convenient but can hide the true destination. Before clicking a suspicious short link in a WhatsApp message or SMS (a common tactic in Irish "An Post" and Revenue scams), preview it or use a trustworthy shortener that discloses the destination. Privacy-focused tools such as Lunyb allow you to create short links without hidden third-party trackers, which is useful for businesses that want to respect GDPR by minimising unnecessary data collection. For a broader look at options, see our 2026 buyer's guide to URL shorteners.

Manage cookies properly

Under Ireland's ePrivacy Regulations 2011 (which sit alongside GDPR), non-essential cookies require your prior consent. If a website makes it easier to "Accept All" than to "Reject All", that is a red flag — and something the DPC has actively enforced against.

Use privacy-respecting tools

  • Choose browsers with strong tracker blocking (Firefox, Brave, Safari)
  • Enable encrypted DNS (DNS over HTTPS) in your browser or router
  • Use end-to-end encrypted messaging like Signal for sensitive conversations
  • Turn on two-factor authentication for banking and email

Limit what you share

Only provide the data an organisation actually needs. If a coffee-shop loyalty app asks for your date of birth and Eircode, ask why. GDPR's "data minimisation" principle means they should only collect what is strictly necessary.

GDPR rights at work in Ireland

Your GDPR rights don't stop at your employer's door. Irish employees have specific protections around workplace monitoring, HR files, and CCTV.

Access to your HR file

You can submit a Subject Access Request to your employer and receive copies of your contract, performance reviews, disciplinary records, and internal emails that identify you.

Workplace monitoring

Employers must be transparent about email monitoring, CCTV, and productivity tracking. Covert surveillance is almost never lawful in Ireland outside serious criminal investigations, and requires a Data Protection Impact Assessment (DPIA).

Working remotely

Since remote work became normalised, the DPC has published detailed guidance reminding employers that home-based monitoring tools must still meet GDPR's necessity and proportionality tests.

Children's privacy and the Digital Age of Consent

Ireland has set the "digital age of consent" at 16. This means that for information society services (like social media), children under 16 need parental consent before their personal data can be processed on the basis of consent.

The DPC's Fundamentals for a Child-Oriented Approach to Data Processing also require platforms to apply a "best interests of the child" test, use age-appropriate transparency, and disable profiling by default for minors.

Data breaches: what to expect if your data is exposed

If an organisation suffers a personal data breach that is likely to result in a risk to your rights and freedoms, they must notify the DPC within 72 hours. If the risk is high, they must also notify you directly.

What a breach notification should tell you

  • What data was affected (e.g., name, email, password hashes)
  • What the likely consequences are
  • What steps the organisation has taken
  • What you should do (e.g., change passwords, monitor accounts)

Your options after a breach

You can complain to the DPC, and under Article 82 of GDPR you may seek compensation through the Irish courts for material or non-material damage — including distress. Several class-action-style cases are progressing through the Irish legal system.

GDPR for small Irish businesses

GDPR isn't just about consumer rights — it also creates obligations for the SMEs, sole traders, and clubs that make up most of the Irish economy. Even a small yoga studio in Galway or a plumber in Cork processing customer contact details needs to comply.

Practical compliance steps

  1. Map the personal data you hold and why
  2. Publish a clear, plain-English privacy notice
  3. Identify a lawful basis for each processing activity
  4. Sign data processing agreements with suppliers (e.g., Mailchimp, Stripe)
  5. Have a documented breach response plan
  6. Train staff on the basics of data protection

Marketing teams in particular should be careful with link tracking and email analytics — using transparent, privacy-friendly tools helps meet GDPR's accountability principle without over-collecting data.

Frequently Asked Questions

Do I have to pay to make a Subject Access Request in Ireland?

No. Under GDPR, Subject Access Requests are free of charge. An organisation can only charge a "reasonable fee" if requests are manifestly unfounded, excessive, or repetitive — and even then, they must justify the charge.

How long does an organisation have to respond to my GDPR request?

Organisations must respond within one calendar month of receiving your request. This can be extended by a further two months for complex or numerous requests, but they must tell you within the first month and explain why.

Can I sue a company in Ireland for a GDPR breach?

Yes. Under Article 82 of GDPR and the Data Protection Act 2018, you can bring a civil action in the Circuit Court or High Court and seek compensation for material damage (financial loss) or non-material damage (distress and anxiety) caused by a data protection infringement.

Does GDPR apply to companies outside the EU that process Irish people's data?

Yes. GDPR has extraterritorial reach. Any company outside the EU that offers goods or services to people in Ireland, or monitors their behaviour, must comply — even if they have no physical presence in Europe.

What's the difference between GDPR and the Irish Data Protection Act 2018?

GDPR is an EU regulation that applies directly across all member states. The Data Protection Act 2018 is the Irish law that gives effect to GDPR in national law, sets the digital age of consent at 16, and establishes the powers and structure of the Data Protection Commission.

Final thoughts

GDPR gives people in Ireland genuine, enforceable control over their personal data — and the Data Protection Commission has shown it is willing to use its powers, even against the world's largest tech firms. Knowing your eight core rights, understanding how to make a complaint, and using privacy-respecting tools in your daily life are the most practical ways to benefit from the law. If you run a business, treating GDPR as an opportunity to build trust — rather than a box-ticking exercise — is one of the best long-term investments you can make.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles