facebook-pixel

GDPR in Ireland: Your Privacy Rights Explained

L
Lunyb Security Team
··12 min read

Ireland occupies a unique position in the European data protection landscape. As the European headquarters for Meta, Google, Microsoft, TikTok, Apple, LinkedIn, and dozens of other technology giants, the Irish Data Protection Commission (DPC) has become one of the most influential privacy regulators in the world. If you live in Ireland, this means you have some of the strongest data protection rights on the planet — and a well-funded regulator whose job is to enforce them.

This guide explains, in plain English, what the General Data Protection Regulation (GDPR) means for you as a resident of Ireland, what rights you can exercise today, how to make a complaint to the DPC, and what obligations businesses operating here must meet.

What Is GDPR and How Does It Apply in Ireland?

GDPR is an EU-wide regulation that governs how organisations collect, use, store, and share personal data about individuals in the European Economic Area. It became directly enforceable on 25 May 2018 and was supplemented in Ireland by the Data Protection Act 2018, which tailors the regulation to Irish law.

In practical terms, GDPR applies to almost every organisation you interact with — your bank, your GP, your employer, your child's school, the shop where you use a loyalty card, the app on your phone, and the social network where you scroll in the evenings. If the organisation processes information that can identify you, GDPR applies.

The Role of the Irish Data Protection Commission

The DPC, headquartered in Dublin and Portarlington, is Ireland's independent supervisory authority for data protection. Because so many multinational technology companies have their EU base in Ireland, the DPC acts as the lead regulator for cross-border investigations under the GDPR's "one-stop-shop" mechanism. In recent years it has issued record fines against Meta (€1.2 billion in 2023 for unlawful data transfers), TikTok, Instagram, and WhatsApp.

Your Eight Core Privacy Rights Under GDPR

GDPR gives you eight enforceable rights over your personal data. Every organisation processing your data must respond to a valid request within one calendar month, free of charge in most cases.

1. The Right to Be Informed

Organisations must clearly tell you what data they collect, why they collect it, how long they keep it, and who they share it with. This is usually delivered through a privacy notice or privacy policy on a website.

2. The Right of Access (Subject Access Request)

You can ask any organisation for a copy of the personal data they hold about you. This is one of the most powerful and most-used rights. The response must arrive within 30 days and include information about how the data is used, who it's shared with, and where it came from.

3. The Right to Rectification

If an organisation holds inaccurate or incomplete data about you, you can require them to correct it without undue delay.

4. The Right to Erasure ("Right to Be Forgotten")

You can ask for your data to be deleted where it is no longer needed for the purpose it was collected, where you withdraw consent, or where it has been processed unlawfully. This right is not absolute — for example, banks must keep certain records for anti-money laundering compliance.

5. The Right to Restrict Processing

You can require an organisation to pause processing your data, for example while a dispute about accuracy is being resolved.

6. The Right to Data Portability

Where you have provided data based on consent or a contract, you can ask for it in a structured, machine-readable format so you can move it to another provider.

7. The Right to Object

You have an absolute right to object to direct marketing at any time. You can also object to processing based on "legitimate interests" grounds, and the organisation must stop unless it can show compelling reasons to continue.

8. Rights Related to Automated Decision-Making and Profiling

You have the right not to be subject to decisions made solely by automated systems — including profiling — that have legal or similarly significant effects on you, such as automated credit refusals or algorithmic hiring decisions.

Comparison: Your GDPR Rights at a Glance

RightResponse TimeCostCommon Use Case
Access1 monthFreeGetting a copy of your medical or employment file
Rectification1 monthFreeFixing wrong address or misspelled name
Erasure1 monthFreeRemoving old social media data
Restriction1 monthFreePausing use of disputed data
Portability1 monthFreeMoving playlists between music services
ObjectImmediate for marketingFreeStopping unsolicited marketing emails
Automated decisions1 monthFreeChallenging an automated loan refusal
Be informedAt point of collectionFreeReading a privacy notice

How to Exercise Your Rights in Ireland

Making a data protection request is more straightforward than most people expect. You do not need a solicitor and you do not need to explain why you want the data.

  1. Identify the data controller. This is the organisation that decides how and why your data is processed. Their privacy notice will identify them.
  2. Locate the contact details. Most privacy notices list a data protection officer (DPO) or a dedicated privacy email address such as privacy@company.ie.
  3. Send a written request. Email is fine. State clearly which right you are exercising (for example, "I am making a subject access request under Article 15 GDPR").
  4. Provide identification. The organisation may reasonably ask for proof of identity to make sure they are not sending your data to somebody else.
  5. Wait up to one month. If the request is complex, they can extend by a further two months but must tell you within the first month.
  6. Escalate if needed. If you are unhappy with the response, complain to the DPC.

How to Make a Complaint to the Data Protection Commission

The DPC handles complaints free of charge. Before you complain, you should generally raise the issue with the organisation first and give them a chance to respond. If you are still unhappy, you can lodge a complaint through the DPC's online webform at dataprotection.ie, by email to info@dataprotection.ie, or by post to their Portarlington office.

What to Include in Your Complaint

  • Your full name and contact details
  • The name of the organisation you are complaining about
  • A clear description of what happened
  • Copies of any correspondence with the organisation
  • What outcome you are seeking (deletion, correction, compensation)

The DPC will acknowledge your complaint, attempt amicable resolution, and — if necessary — open a formal inquiry that can lead to fines of up to €20 million or 4% of global annual turnover, whichever is higher.

Special Categories of Data: Extra Protection

Certain types of personal data receive extra protection under Article 9 of GDPR because misuse could cause particular harm. These "special categories" include:

  • Racial or ethnic origin
  • Political opinions
  • Religious or philosophical beliefs
  • Trade union membership
  • Genetic and biometric data used to identify a person
  • Health data
  • Data concerning sex life or sexual orientation

Processing this data is generally prohibited unless a specific exception applies — such as your explicit consent, employment law obligations, or the provision of healthcare. In Ireland, additional safeguards apply through the Data Protection Act 2018, particularly around health research and children's data.

Children and the "Digital Age of Consent" in Ireland

Ireland set the digital age of consent at 16, which is at the higher end of the range permitted by GDPR. This means that online services relying on consent to process data — including most social networks — must obtain parental consent for users under 16.

The DPC's Fundamentals for a Child-Oriented Approach to Data Processing, published in 2021, sets out 14 principles that organisations must follow when processing children's data, including a "floor of protection" that means online services should treat all users as children unless they have taken robust steps to verify otherwise.

What Businesses in Ireland Must Do

If you run a business — even a sole trader or a small local shop with a customer email list — GDPR applies to you. The key obligations are:

Lawful Basis for Processing

You must identify a lawful basis (consent, contract, legal obligation, vital interests, public task, or legitimate interests) for every processing activity and document it.

Transparent Privacy Notices

Publish a clear, plain-English privacy notice explaining what data you collect and why. Vague or overly legalistic notices are themselves a compliance failure.

Data Security

Implement appropriate technical and organisational measures — encryption, access controls, staff training, backup and recovery plans. Even simple steps like using reputable link management platforms such as Lunyb to shorten and track marketing URLs, rather than pasting raw analytics-laden links into customer communications, can reduce inadvertent data exposure.

Breach Notification

Personal data breaches likely to result in a risk to individuals must be notified to the DPC within 72 hours of becoming aware of them. High-risk breaches must also be communicated to the affected individuals.

Data Protection Impact Assessments (DPIAs)

High-risk processing — such as large-scale profiling, systematic monitoring, or processing special category data at scale — requires a formal DPIA before it begins.

Records of Processing

Organisations with 250 or more employees, and smaller organisations conducting non-occasional processing, must maintain written records of their processing activities under Article 30.

Cookies, Tracking, and the ePrivacy Rules

Alongside GDPR, Ireland's ePrivacy Regulations (SI 336 of 2011) govern cookies and similar tracking technologies. The DPC's guidance is clear: non-essential cookies require prior, freely given, specific, informed, and unambiguous consent — the same standard as GDPR consent.

This means the "cookie wall" pop-ups that only offer an "Accept All" button are non-compliant. There must be a "Reject All" option that is as easy to use as "Accept All", and pre-ticked boxes are not valid consent. If you are building or auditing a website, tools that let you share campaign links without embedding third-party trackers — for example a privacy-focused shortener like Lunyb — can help simplify your consent management posture. For a broader look at options, see our 2026 buyer's guide to URL shorteners.

International Data Transfers After Schrems II

Personal data can flow freely within the EEA. Transfers outside — to the United States, the United Kingdom, or elsewhere — are subject to strict rules following the Court of Justice of the European Union's Schrems II judgment in 2020, which was itself an Irish case brought by privacy campaigner Max Schrems.

The 2023 EU–US Data Privacy Framework has restored a legal basis for transfers to certified US organisations, but transfers to other third countries still typically require Standard Contractual Clauses plus a transfer impact assessment. This area remains one of the most litigated in Irish and European privacy law.

Enforcement Trends: What the DPC Is Focused On

Recent DPC decisions and its published regulatory strategy point to several enforcement priorities:

  • Children's data — particularly on social media and gaming platforms
  • Targeted advertising and profiling — including behavioural advertising models
  • International data transfers — especially to jurisdictions without adequacy decisions
  • Transparency — clear information about how data is used
  • Security breaches — timely notification and appropriate safeguards

Businesses operating in Ireland — and particularly those with EU-wide operations — should treat these areas as high priority for compliance reviews.

Practical Steps to Protect Your Own Privacy

GDPR gives you the legal tools, but there are also practical steps every Irish resident can take to reduce their data exposure day to day:

  1. Review the privacy settings on every social media account at least once a year.
  2. Use a privacy-respecting browser and consider encrypted DNS services to reduce network-level tracking.
  3. Read privacy notices before signing up to new services — especially the sections on data sharing and retention.
  4. Send subject access requests to organisations you no longer use, then follow up with erasure requests.
  5. Turn off ad personalisation in your Google, Meta, and Microsoft accounts.
  6. Enable two-factor authentication on important accounts to reduce the risk of your data being stolen through account takeover.

Frequently Asked Questions

Do I have to pay to make a subject access request in Ireland?

No. Subject access requests and other GDPR rights requests are free of charge. An organisation can only charge a "reasonable fee" based on administrative costs where a request is manifestly unfounded or excessive, or for additional copies. In practice, fees are almost never charged for genuine first requests.

How long does the DPC take to resolve a complaint?

Simple complaints — for example unwanted marketing — are often resolved within a few months through amicable resolution. Complex cross-border inquiries against large multinationals can take several years due to the requirement to consult other European supervisory authorities under the one-stop-shop mechanism.

Can I claim compensation for a GDPR breach in Ireland?

Yes. Article 82 of GDPR and section 117 of the Data Protection Act 2018 give you the right to seek compensation for both material and non-material damage — including distress — caused by a GDPR infringement. Claims are made in the Circuit Court or, for larger amounts, the High Court.

Does GDPR apply to my personal use of data, like a home address book?

No. GDPR contains a "household exemption" that excludes purely personal or household activities — such as a private address book, a personal social media account used only for family and friends, or personal correspondence. It does apply as soon as processing has a professional or commercial element.

What is the difference between a data controller and a data processor?

A data controller decides why and how personal data is processed — for example, your employer or your bank. A data processor acts on behalf of the controller — for example, a cloud hosting provider or payroll bureau. Both have obligations under GDPR, but controllers bear the primary responsibility for compliance and are the ones you address rights requests to.

Conclusion

GDPR gives residents of Ireland one of the strongest sets of privacy rights anywhere in the world, backed by an increasingly assertive Data Protection Commission. Knowing your rights — and being willing to exercise them — is the single most effective way to hold organisations accountable for how they handle your personal information. Whether you are asking for a copy of your data, correcting an inaccurate record, or lodging a complaint with the DPC, the tools are there; they just need to be used.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles