facebook-pixel

GDPR in Ireland: Your Privacy Rights Explained (2026 Guide)

L
Lunyb Security Team
··10 min read

Ireland sits at the heart of European data protection. With most major US tech companies—Meta, Google, TikTok, Apple, Microsoft, LinkedIn—headquartered in Dublin, the Irish Data Protection Commission (DPC) is effectively the lead supervisory authority for a huge chunk of the internet under the General Data Protection Regulation (GDPR). That gives Irish residents unusually direct access to enforcement, but it also means understanding your rights is more important here than almost anywhere else in Europe.

This guide explains, in plain English, what GDPR means for you as an Irish resident in 2026: the rights you can exercise, how to use them, what the DPC actually does, and the practical steps to take when a company mishandles your personal data.

What is GDPR and how does it apply in Ireland?

The General Data Protection Regulation (GDPR) is an EU-wide law that governs how organisations collect, store, and use personal data about individuals in the European Economic Area. In Ireland, GDPR is given effect through the Data Protection Act 2018, which fills in national details such as the age of digital consent (16 in Ireland) and the powers of the Data Protection Commission.

GDPR applies to any organisation—whether based in Ireland, elsewhere in the EU, or overseas—that processes the personal data of people in Ireland. That includes your bank, your GP, your employer, your local sports club, and international platforms like Facebook or Amazon. Personal data means anything that can identify you: your name, email, IP address, location, biometric identifiers, and even online cookies that build a profile of your behaviour.

Why Ireland matters more than most member states

Because so many multinational tech firms have their EU headquarters in Dublin, the DPC acts as the "one-stop shop" regulator for their EU-wide operations. Recent years have seen record fines issued from Dublin—hundreds of millions of euros against Meta, TikTok, and others—for breaches ranging from unlawful advertising practices to inadequate child safety measures. For Irish residents, this means complaints filed with the DPC can trigger investigations affecting hundreds of millions of Europeans.

Your eight core GDPR rights as an Irish resident

GDPR gives you eight specific, legally enforceable rights over your personal data. Every organisation that holds data about you must respect these, and generally must respond to requests within one calendar month, free of charge.

  1. The right to be informed — Organisations must tell you clearly what data they collect, why, how long they keep it, and who they share it with. This is typically delivered via a privacy notice.
  2. The right of access — You can request a copy of all personal data an organisation holds about you (a "Subject Access Request" or SAR).
  3. The right to rectification — You can require inaccurate or incomplete data about you to be corrected.
  4. The right to erasure — Also called the "right to be forgotten," you can ask for your data to be deleted in certain circumstances.
  5. The right to restrict processing — You can ask an organisation to pause using your data while a dispute is resolved.
  6. The right to data portability — You can request your data in a machine-readable format so you can move it to another provider.
  7. The right to object — You can object to processing for direct marketing, profiling, or when the legal basis is "legitimate interests."
  8. Rights related to automated decision-making — You have the right not to be subject to purely automated decisions—including AI-driven profiling—that produce legal or similarly significant effects.

How to exercise your rights: a step-by-step process

Enforcing your GDPR rights in Ireland is designed to be accessible. You don't need a solicitor, and you don't need to pay anything in most cases.

  1. Identify the data controller. This is the organisation that decides how and why your data is processed. Their contact details—and often a Data Protection Officer (DPO)—should be listed in their privacy policy.
  2. Send a written request. Email is fine. Clearly state which right you are exercising (for example, "I am making a Subject Access Request under Article 15 of the GDPR").
  3. Verify your identity. The organisation can ask for reasonable proof that you are who you say you are, but they cannot demand excessive documentation.
  4. Wait up to one month. They must respond within 30 calendar days. For complex requests, they can extend this by two further months but must tell you why.
  5. Escalate if unhappy. If they refuse, ignore you, or provide an inadequate response, you can complain to the Data Protection Commission.

Sample Subject Access Request template

Keep it simple:

"Dear [Company], Under Article 15 of the General Data Protection Regulation, I am requesting a copy of all personal data you hold about me, including the purposes of processing, categories of data, recipients, retention periods, and the source of any data not collected directly from me. My identifying details are: [name, email, account number]. Please respond within one calendar month. Yours sincerely, [Name]."

The role of the Data Protection Commission (DPC)

The Data Protection Commission, based in Dublin and Portarlington, is Ireland's independent regulator for GDPR. Its role is to uphold your rights, investigate complaints, and enforce compliance—including through significant fines.

The DPC has several key functions:

  • Handling complaints from individuals
  • Investigating data breaches (which controllers must report within 72 hours)
  • Conducting audits and inquiries
  • Issuing guidance and codes of conduct
  • Cooperating with other EU regulators through the European Data Protection Board
  • Imposing administrative fines of up to €20 million or 4% of global annual turnover, whichever is higher

How to file a complaint with the DPC

Complaints can be lodged directly through the DPC's website at dataprotection.ie. You should generally try to resolve the issue with the organisation first, but this is not always required—particularly if you believe an ongoing breach is causing harm. Include copies of your original request, the response (or lack of one), and any supporting evidence.

Common GDPR issues faced by Irish consumers

Certain complaints appear again and again in DPC reports. Knowing them helps you recognise when your rights are being breached.

IssueWhat it looks likeRight affected
Unsolicited marketingEmails, texts, or calls after you unsubscribedRight to object
CCTV misuseEmployer or neighbour cameras capturing you without noticeRight to be informed
Ignored SARsCompany fails to respond in 30 daysRight of access
Cookie wallsSites forcing consent to non-essential cookiesRight to be informed / consent
Data breachesYour details leaked in a hack you weren't told aboutRight to be informed
Excessive data collectionApp demanding contacts, location, camera for no reasonData minimisation principle

GDPR at work: your rights as an employee in Ireland

Your employer processes a large volume of personal data about you—payroll, PPS numbers, sick leave records, performance reviews, CCTV footage, and increasingly, monitoring data from laptops and email systems. GDPR applies fully to this relationship.

Key points for Irish employees:

  • Your employer must provide a clear employee privacy notice explaining what they collect and why.
  • Workplace monitoring (email, keystroke logging, GPS on company vehicles) must be proportionate, transparent, and typically supported by a Data Protection Impact Assessment.
  • You can submit a SAR to your employer—including for emails that mention you, HR files, and performance notes.
  • Consent is generally not a valid legal basis for employee data processing because of the power imbalance; employers must rely on contract, legal obligation, or legitimate interests.

Protecting your privacy proactively

GDPR gives you strong reactive rights, but the best privacy strategy is also proactive. A few habits reduce how much data you expose in the first place.

Minimise the data you share

Only give organisations what they truly need. If a loyalty card form asks for your date of birth and marital status, ask why—and consider leaving optional fields blank.

Use privacy-respecting tools

Browsers like Firefox and Brave block trackers by default. Encrypted DNS providers (such as Cloudflare's 1.1.1.1 or NextDNS) prevent your internet provider from logging every domain you visit. Password managers reduce the damage of any single breach.

Be careful with links you share

Long URLs often contain tracking parameters that leak information about where you came from, what campaign you clicked, or even your identifier on another platform. When sharing links publicly or in messages, using a shortener that strips these parameters and offers analytics without invasive third-party tracking helps limit exposure. Services like Lunyb provide a straightforward way to create clean short links—see our honest review of Lunyb or the broader 2026 buyer's guide to URL shorteners for a comparison of options, including Rebrandly.

Review app permissions

Both iOS and Android let you audit which apps have access to your location, microphone, camera, contacts, and photos. A quarterly review is a healthy habit.

What happens after Brexit and with international transfers?

Ireland remains firmly within the EU GDPR regime. Data transfers to the UK are covered by an adequacy decision, meaning UK-based services can process Irish data lawfully—for now, subject to periodic review by the European Commission.

Transfers to the United States are governed by the EU-US Data Privacy Framework, which replaced the invalidated Privacy Shield. US companies that self-certify under the Framework can lawfully receive Irish data, though the arrangement remains subject to legal challenge. For transfers to other countries without an adequacy decision, organisations must use Standard Contractual Clauses and conduct a transfer impact assessment.

Penalties and enforcement in 2026

The DPC has become one of Europe's most active GDPR enforcers by fine value. Recent years have seen:

  • Multi-hundred-million-euro fines against Meta for unlawful data transfers and advertising practices
  • Significant penalties against TikTok relating to children's data
  • Enforcement action against LinkedIn for behavioural advertising
  • Continuing scrutiny of AI training data and large language models

Individuals also have the right to claim compensation—both material (financial loss) and non-material (distress)—through the Irish courts when a GDPR breach causes them harm.

Frequently asked questions

How long does an organisation have to respond to a Subject Access Request in Ireland?

One calendar month from the date the request is received. This can be extended by up to two additional months for complex or numerous requests, but the organisation must notify you of the extension and the reason within the original month.

Can I be charged a fee for accessing my personal data?

No. Subject Access Requests are free of charge. An organisation can only charge a "reasonable fee" if a request is clearly excessive or repetitive, and even then they must justify the charge. If they demand payment for a first, reasonable request, complain to the DPC.

What is the difference between the DPC and a court?

The Data Protection Commission investigates complaints and can issue enforcement notices and fines against organisations. It cannot award you compensation. To claim damages for distress or financial loss caused by a GDPR breach, you need to bring a civil case in the Circuit Court or High Court, though a DPC finding often strengthens such a claim.

Does GDPR cover deceased people?

No. GDPR only protects living individuals. However, Ireland's Data Protection Act 2018 and other laws such as duty of confidentiality can still restrict how information about deceased people is handled, particularly in healthcare contexts.

What is the age of digital consent in Ireland?

16. Children under 16 cannot legally consent to information society services (such as social media) processing their data based on consent alone—parental authorisation is required. This is stricter than the GDPR default of 13 and applies to platforms offering services to Irish minors.

Can I make a GDPR request by phone or must it be in writing?

You can technically make a request by any means, including phone, but writing is strongly recommended. A written request (email is fine) creates a clear timestamp, evidence of what you asked for, and a paper trail that is essential if you later need to escalate to the DPC.

Final thoughts

GDPR gives Irish residents some of the strongest data protection rights in the world, backed by an active regulator with global reach. The law only works, however, when people actually use it. Sending a Subject Access Request, objecting to unwanted marketing, or filing a complaint with the DPC costs nothing and takes minutes—yet each action reinforces a culture of accountability that benefits everyone. Combine those reactive rights with proactive habits like minimising the data you share, using privacy-respecting tools, and cleaning up the links you distribute, and you'll have meaningful control over your digital footprint in 2026 and beyond.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles