GDPR in Ireland: Your Privacy Rights Explained
Ireland occupies a unique position in the European data protection landscape. As the European headquarters for Meta, Google, Microsoft, TikTok, Apple, LinkedIn, and dozens of other technology giants, the Irish Data Protection Commission (DPC) has become one of the most influential privacy regulators in the world. If you live in Ireland, this means you have some of the strongest data protection rights on the planet — and a well-funded regulator whose job is to enforce them.
This guide explains, in plain English, what the General Data Protection Regulation (GDPR) means for you as a resident of Ireland, what rights you can exercise today, how to make a complaint to the DPC, and what obligations businesses operating here must meet.
What Is GDPR and How Does It Apply in Ireland?
GDPR is an EU-wide regulation that governs how organisations collect, use, store, and share personal data about individuals in the European Economic Area. It became directly enforceable on 25 May 2018 and was supplemented in Ireland by the Data Protection Act 2018, which tailors the regulation to Irish law.
In practical terms, GDPR applies to almost every organisation you interact with — your bank, your GP, your employer, your child's school, the shop where you use a loyalty card, the app on your phone, and the social network where you scroll in the evenings. If the organisation processes information that can identify you, GDPR applies.
The Role of the Irish Data Protection Commission
The DPC, headquartered in Dublin and Portarlington, is Ireland's independent supervisory authority for data protection. Because so many multinational technology companies have their EU base in Ireland, the DPC acts as the lead regulator for cross-border investigations under the GDPR's "one-stop-shop" mechanism. In recent years it has issued record fines against Meta (€1.2 billion in 2023 for unlawful data transfers), TikTok, Instagram, and WhatsApp.
Your Eight Core Privacy Rights Under GDPR
GDPR gives you eight enforceable rights over your personal data. Every organisation processing your data must respond to a valid request within one calendar month, free of charge in most cases.
1. The Right to Be Informed
Organisations must clearly tell you what data they collect, why they collect it, how long they keep it, and who they share it with. This is usually delivered through a privacy notice or privacy policy on a website.
2. The Right of Access (Subject Access Request)
You can ask any organisation for a copy of the personal data they hold about you. This is one of the most powerful and most-used rights. The response must arrive within 30 days and include information about how the data is used, who it's shared with, and where it came from.
3. The Right to Rectification
If an organisation holds inaccurate or incomplete data about you, you can require them to correct it without undue delay.
4. The Right to Erasure ("Right to Be Forgotten")
You can ask for your data to be deleted where it is no longer needed for the purpose it was collected, where you withdraw consent, or where it has been processed unlawfully. This right is not absolute — for example, banks must keep certain records for anti-money laundering compliance.
5. The Right to Restrict Processing
You can require an organisation to pause processing your data, for example while a dispute about accuracy is being resolved.
6. The Right to Data Portability
Where you have provided data based on consent or a contract, you can ask for it in a structured, machine-readable format so you can move it to another provider.
7. The Right to Object
You have an absolute right to object to direct marketing at any time. You can also object to processing based on "legitimate interests" grounds, and the organisation must stop unless it can show compelling reasons to continue.
8. Rights Related to Automated Decision-Making and Profiling
You have the right not to be subject to decisions made solely by automated systems — including profiling — that have legal or similarly significant effects on you, such as automated credit refusals or algorithmic hiring decisions.
Comparison: Your GDPR Rights at a Glance
| Right | Response Time | Cost | Common Use Case |
|---|---|---|---|
| Access | 1 month | Free | Getting a copy of your medical or employment file |
| Rectification | 1 month | Free | Fixing wrong address or misspelled name |
| Erasure | 1 month | Free | Removing old social media data |
| Restriction | 1 month | Free | Pausing use of disputed data |
| Portability | 1 month | Free | Moving playlists between music services |
| Object | Immediate for marketing | Free | Stopping unsolicited marketing emails |
| Automated decisions | 1 month | Free | Challenging an automated loan refusal |
| Be informed | At point of collection | Free | Reading a privacy notice |
How to Exercise Your Rights in Ireland
Making a data protection request is more straightforward than most people expect. You do not need a solicitor and you do not need to explain why you want the data.
- Identify the data controller. This is the organisation that decides how and why your data is processed. Their privacy notice will identify them.
- Locate the contact details. Most privacy notices list a data protection officer (DPO) or a dedicated privacy email address such as privacy@company.ie.
- Send a written request. Email is fine. State clearly which right you are exercising (for example, "I am making a subject access request under Article 15 GDPR").
- Provide identification. The organisation may reasonably ask for proof of identity to make sure they are not sending your data to somebody else.
- Wait up to one month. If the request is complex, they can extend by a further two months but must tell you within the first month.
- Escalate if needed. If you are unhappy with the response, complain to the DPC.
How to Make a Complaint to the Data Protection Commission
The DPC handles complaints free of charge. Before you complain, you should generally raise the issue with the organisation first and give them a chance to respond. If you are still unhappy, you can lodge a complaint through the DPC's online webform at dataprotection.ie, by email to info@dataprotection.ie, or by post to their Portarlington office.
What to Include in Your Complaint
- Your full name and contact details
- The name of the organisation you are complaining about
- A clear description of what happened
- Copies of any correspondence with the organisation
- What outcome you are seeking (deletion, correction, compensation)
The DPC will acknowledge your complaint, attempt amicable resolution, and — if necessary — open a formal inquiry that can lead to fines of up to €20 million or 4% of global annual turnover, whichever is higher.
Special Categories of Data: Extra Protection
Certain types of personal data receive extra protection under Article 9 of GDPR because misuse could cause particular harm. These "special categories" include:
- Racial or ethnic origin
- Political opinions
- Religious or philosophical beliefs
- Trade union membership
- Genetic and biometric data used to identify a person
- Health data
- Data concerning sex life or sexual orientation
Processing this data is generally prohibited unless a specific exception applies — such as your explicit consent, employment law obligations, or the provision of healthcare. In Ireland, additional safeguards apply through the Data Protection Act 2018, particularly around health research and children's data.
Children and the "Digital Age of Consent" in Ireland
Ireland set the digital age of consent at 16, which is at the higher end of the range permitted by GDPR. This means that online services relying on consent to process data — including most social networks — must obtain parental consent for users under 16.
The DPC's Fundamentals for a Child-Oriented Approach to Data Processing, published in 2021, sets out 14 principles that organisations must follow when processing children's data, including a "floor of protection" that means online services should treat all users as children unless they have taken robust steps to verify otherwise.
What Businesses in Ireland Must Do
If you run a business — even a sole trader or a small local shop with a customer email list — GDPR applies to you. The key obligations are:
Lawful Basis for Processing
You must identify a lawful basis (consent, contract, legal obligation, vital interests, public task, or legitimate interests) for every processing activity and document it.
Transparent Privacy Notices
Publish a clear, plain-English privacy notice explaining what data you collect and why. Vague or overly legalistic notices are themselves a compliance failure.
Data Security
Implement appropriate technical and organisational measures — encryption, access controls, staff training, backup and recovery plans. Even simple steps like using reputable link management platforms such as Lunyb to shorten and track marketing URLs, rather than pasting raw analytics-laden links into customer communications, can reduce inadvertent data exposure.
Breach Notification
Personal data breaches likely to result in a risk to individuals must be notified to the DPC within 72 hours of becoming aware of them. High-risk breaches must also be communicated to the affected individuals.
Data Protection Impact Assessments (DPIAs)
High-risk processing — such as large-scale profiling, systematic monitoring, or processing special category data at scale — requires a formal DPIA before it begins.
Records of Processing
Organisations with 250 or more employees, and smaller organisations conducting non-occasional processing, must maintain written records of their processing activities under Article 30.
Cookies, Tracking, and the ePrivacy Rules
Alongside GDPR, Ireland's ePrivacy Regulations (SI 336 of 2011) govern cookies and similar tracking technologies. The DPC's guidance is clear: non-essential cookies require prior, freely given, specific, informed, and unambiguous consent — the same standard as GDPR consent.
This means the "cookie wall" pop-ups that only offer an "Accept All" button are non-compliant. There must be a "Reject All" option that is as easy to use as "Accept All", and pre-ticked boxes are not valid consent. If you are building or auditing a website, tools that let you share campaign links without embedding third-party trackers — for example a privacy-focused shortener like Lunyb — can help simplify your consent management posture. For a broader look at options, see our 2026 buyer's guide to URL shorteners.
International Data Transfers After Schrems II
Personal data can flow freely within the EEA. Transfers outside — to the United States, the United Kingdom, or elsewhere — are subject to strict rules following the Court of Justice of the European Union's Schrems II judgment in 2020, which was itself an Irish case brought by privacy campaigner Max Schrems.
The 2023 EU–US Data Privacy Framework has restored a legal basis for transfers to certified US organisations, but transfers to other third countries still typically require Standard Contractual Clauses plus a transfer impact assessment. This area remains one of the most litigated in Irish and European privacy law.
Enforcement Trends: What the DPC Is Focused On
Recent DPC decisions and its published regulatory strategy point to several enforcement priorities:
- Children's data — particularly on social media and gaming platforms
- Targeted advertising and profiling — including behavioural advertising models
- International data transfers — especially to jurisdictions without adequacy decisions
- Transparency — clear information about how data is used
- Security breaches — timely notification and appropriate safeguards
Businesses operating in Ireland — and particularly those with EU-wide operations — should treat these areas as high priority for compliance reviews.
Practical Steps to Protect Your Own Privacy
GDPR gives you the legal tools, but there are also practical steps every Irish resident can take to reduce their data exposure day to day:
- Review the privacy settings on every social media account at least once a year.
- Use a privacy-respecting browser and consider encrypted DNS services to reduce network-level tracking.
- Read privacy notices before signing up to new services — especially the sections on data sharing and retention.
- Send subject access requests to organisations you no longer use, then follow up with erasure requests.
- Turn off ad personalisation in your Google, Meta, and Microsoft accounts.
- Enable two-factor authentication on important accounts to reduce the risk of your data being stolen through account takeover.
Frequently Asked Questions
Do I have to pay to make a subject access request in Ireland?
No. Subject access requests and other GDPR rights requests are free of charge. An organisation can only charge a "reasonable fee" based on administrative costs where a request is manifestly unfounded or excessive, or for additional copies. In practice, fees are almost never charged for genuine first requests.
How long does the DPC take to resolve a complaint?
Simple complaints — for example unwanted marketing — are often resolved within a few months through amicable resolution. Complex cross-border inquiries against large multinationals can take several years due to the requirement to consult other European supervisory authorities under the one-stop-shop mechanism.
Can I claim compensation for a GDPR breach in Ireland?
Yes. Article 82 of GDPR and section 117 of the Data Protection Act 2018 give you the right to seek compensation for both material and non-material damage — including distress — caused by a GDPR infringement. Claims are made in the Circuit Court or, for larger amounts, the High Court.
Does GDPR apply to my personal use of data, like a home address book?
No. GDPR contains a "household exemption" that excludes purely personal or household activities — such as a private address book, a personal social media account used only for family and friends, or personal correspondence. It does apply as soon as processing has a professional or commercial element.
What is the difference between a data controller and a data processor?
A data controller decides why and how personal data is processed — for example, your employer or your bank. A data processor acts on behalf of the controller — for example, a cloud hosting provider or payroll bureau. Both have obligations under GDPR, but controllers bear the primary responsibility for compliance and are the ones you address rights requests to.
Conclusion
GDPR gives residents of Ireland one of the strongest sets of privacy rights anywhere in the world, backed by an increasingly assertive Data Protection Commission. Knowing your rights — and being willing to exercise them — is the single most effective way to hold organisations accountable for how they handle your personal information. Whether you are asking for a copy of your data, correcting an inaccurate record, or lodging a complaint with the DPC, the tools are there; they just need to be used.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Singapore Online Safety Act 2026: Complete Guide
Singapore's Online Safety Act 2026 consolidates and expands the country's online safety rules, covering platforms, marketers, and users alike. This complete guide explains who is in scope, what obligations apply, and how to stay compliant.
How Canadian Businesses Should Handle Data Privacy in 2026
Canadian businesses face a maturing privacy landscape shaped by PIPEDA, Quebec's Law 25, and provincial statutes. This guide covers compliance obligations, breach response, cross-border transfers, and building a sustainable privacy program in 2026.
ICO Fines 2026: Biggest Data Protection Penalties in the UK
The ICO issued record-breaking data protection penalties in 2026, with fines exceeding £12 million against UK organisations. This guide breaks down the biggest cases, common causes, and practical steps British businesses can take to stay compliant with UK GDPR.
ePrivacy Regulations Ireland: Latest Updates for 2026
A comprehensive 2026 guide to Ireland's ePrivacy Regulations, covering cookie consent, direct marketing rules, DPC enforcement trends, and practical compliance steps. Learn how S.I. 336/2011 interacts with the GDPR and what updates Irish businesses should prepare for.