GDPR in Ireland: Your Privacy Rights Explained
The General Data Protection Regulation (GDPR) has been in force across the European Union since May 2018, and in Ireland it is given further effect by the Data Protection Act 2018. Together, these laws give people living in Ireland some of the strongest privacy rights in the world. Yet many of us are still unsure what those rights actually mean, when they apply, or how to enforce them if a company mishandles our data.
This guide breaks down GDPR in Ireland in plain English, explains each of your privacy rights, and shows you the practical steps to take when something goes wrong. Whether you are a consumer, an employee, or a small business owner, understanding these rules is the first step to taking control of your personal information.
What Is GDPR and How Does It Apply in Ireland?
GDPR is an EU-wide regulation that governs how organisations collect, store, use, and share the personal data of individuals in the European Economic Area. Because it is a regulation rather than a directive, it applies directly in Ireland without needing to be transposed, although the Data Protection Act 2018 fills in national details such as the age of digital consent and the powers of the regulator.
In practical terms, GDPR applies to almost every organisation that processes personal data about people in Ireland, from multinational tech giants headquartered in Dublin to your local GP surgery, gym, or online retailer. It even applies to organisations based outside the EU if they target Irish residents with goods, services, or behavioural tracking.
Key Definitions You Should Know
- Personal data: Any information relating to an identified or identifiable living person, including name, email, IP address, location data, and online identifiers.
- Data controller: The organisation that decides why and how personal data is processed.
- Data processor: A third party that processes data on behalf of a controller, such as a cloud hosting provider.
- Data subject: You — the individual whose data is being processed.
- Special category data: Sensitive information such as health, race, religion, political opinions, sexual orientation, and biometric data, which receives extra protection.
The Role of the Data Protection Commission (DPC)
Ireland's independent supervisory authority for GDPR is the Data Protection Commission, based in Dublin and Portarlington. Because so many large US technology companies have their European headquarters in Ireland, the DPC has effectively become the lead regulator for much of Big Tech in Europe, handling complaints against Meta, Google, TikTok, X, LinkedIn, and Apple.
The DPC's responsibilities include:
- Investigating complaints from individuals about how their data has been handled.
- Auditing organisations and issuing fines for breaches of GDPR.
- Providing guidance to businesses on compliance.
- Cooperating with other EU supervisory authorities under the one-stop-shop mechanism.
- Approving codes of conduct and certification schemes.
Fines issued by the DPC can reach up to €20 million or 4% of a company's global annual turnover, whichever is higher. In recent years, the DPC has imposed record fines running into hundreds of millions of euro against major platforms, showing that GDPR enforcement in Ireland has real teeth.
Your Eight Core GDPR Rights in Ireland
GDPR grants every individual in Ireland eight enforceable rights over their personal data. Understanding each one puts you in a strong position to hold organisations accountable.
1. The Right to Be Informed
Organisations must tell you, in clear and plain language, what data they collect about you, why they collect it, how long they keep it, and who they share it with. This is usually delivered through a privacy notice on a website or a data protection statement handed to you when you sign up for a service.
2. The Right of Access
You can ask any organisation for a copy of the personal data they hold about you. This is known as a Subject Access Request (SAR). The organisation must respond within one month, free of charge in most cases, and provide the data in an accessible format.
3. The Right to Rectification
If any personal data held about you is inaccurate or incomplete, you can ask for it to be corrected or updated without undue delay.
4. The Right to Erasure ("Right to Be Forgotten")
In certain circumstances — such as when data is no longer necessary, you withdraw consent, or the processing is unlawful — you can request that your personal data be deleted. This right is not absolute; for example, it does not apply where an organisation has a legal obligation to keep records.
5. The Right to Restrict Processing
You can ask an organisation to pause the processing of your data in specific situations, such as while a dispute over accuracy is being resolved.
6. The Right to Data Portability
You can obtain your personal data in a structured, commonly used, machine-readable format and transfer it to another service provider — useful when switching banks, streaming services, or social platforms.
7. The Right to Object
You have an absolute right to object to your data being used for direct marketing. You can also object to processing based on legitimate interests or public interest tasks, though the organisation may continue if it can demonstrate compelling grounds.
8. Rights Related to Automated Decision-Making and Profiling
You have the right not to be subject to a decision based solely on automated processing — including profiling — that produces legal or similarly significant effects, unless specific exceptions apply.
Lawful Bases for Processing Personal Data
An organisation cannot process your personal data just because it wants to. Under GDPR, it must have one of six lawful bases:
| Lawful Basis | When It Applies | Example |
|---|---|---|
| Consent | You have given clear, specific, informed agreement | Signing up for a newsletter |
| Contract | Processing is necessary to fulfil a contract | Delivering an online order |
| Legal obligation | Required by Irish or EU law | Revenue tax reporting |
| Vital interests | Needed to protect someone's life | Emergency medical treatment |
| Public task | Carried out in the public interest | Census data collection by the CSO |
| Legitimate interests | Necessary for the organisation's interests, balanced against your rights | Fraud prevention on a banking app |
If you suspect a company is processing your data without any valid basis, that is a strong ground for a complaint to the DPC.
How to Make a Subject Access Request in Ireland
A Subject Access Request is often the most useful tool for exercising your rights. Here is a step-by-step process:
- Identify the controller. Find the correct contact — usually a Data Protection Officer (DPO) or privacy team — listed in the organisation's privacy notice.
- Write your request. State clearly that you are making a request under Article 15 GDPR. Include your full name and any account identifiers.
- Be specific if you can. Narrow requests (e.g., "all emails between me and your support team in 2024") are answered faster than open-ended ones.
- Send it by email or post. Keep a dated copy for your records.
- Wait up to one month. The controller may extend by two further months for complex requests, but must tell you within the first month.
- Review the response. Check that everything you would reasonably expect is included and that any redactions are properly justified.
Protecting Your Privacy Beyond GDPR
While GDPR gives you strong legal rights, day-to-day privacy also depends on the tools and habits you use online. A few practical steps go a long way:
- Use a private, tracker-blocking browser such as Brave or Firefox with strict settings.
- Enable encrypted DNS (DNS-over-HTTPS) on your devices to prevent your internet provider from logging every site you visit.
- Review app permissions on your phone regularly and revoke anything unnecessary.
- Use unique passwords stored in a reputable password manager, and enable two-factor authentication everywhere.
- Be careful with the links you share on social media — some shortening services quietly harvest analytics data on everyone who clicks. Privacy-focused alternatives like Lunyb let you shorten URLs without exposing your audience to invasive tracking, which is particularly relevant if you handle client or customer data under GDPR.
If you run a website or newsletter, choosing privacy-respecting tools reduces your own GDPR compliance burden. For a broader look at options, see our 2026 buyer's guide to URL shorteners and our honest review of Lunyb.
What to Do If Your Rights Are Breached
If an organisation refuses to respond to your request, provides an inadequate response, or you believe your data has been mishandled, you have clear escalation options:
- Complain to the organisation first. Contact their Data Protection Officer and give them a chance to fix the issue.
- Lodge a complaint with the DPC. You can do this free of charge through the DPC's online webform, by email to info@dataprotection.ie, or by post to their offices in Dublin or Portarlington.
- Seek a judicial remedy. You have the right to bring proceedings in the Irish Circuit Court or High Court, and to claim compensation for material or non-material damage caused by a GDPR breach.
- Contact a solicitor for group actions. Following the Digital Services Act and recent Irish case law, representative actions for privacy breaches are becoming more common.
Special Rules for Children in Ireland
The Data Protection Act 2018 sets the digital age of consent in Ireland at 16. This means children under 16 cannot legally consent to information society services (such as social media accounts) on their own — parental consent is required. The DPC has also published the Fundamentals for a Child-Oriented Approach to Data Processing, which sets 14 principles that organisations serving children must follow, including transparency, data minimisation, and default privacy settings set to "high."
Data Breaches: What Organisations Must Do
If an organisation suffers a personal data breach that is likely to result in a risk to your rights and freedoms, it must notify the DPC within 72 hours of becoming aware of it. Where the risk is high, it must also notify affected individuals directly and without undue delay. You are entitled to know:
- The nature of the breach and categories of data affected.
- The likely consequences.
- The measures being taken to address it.
- Contact details for further information.
If you receive a breach notification, change any affected passwords immediately, monitor your financial accounts, and consider placing a fraud alert with credit reference agencies.
Frequently Asked Questions
Does GDPR still apply in Ireland after Brexit?
Yes. Brexit affected the United Kingdom, not Ireland. Ireland remains a full member of the EU, so GDPR continues to apply directly. The Data Protection Commission remains Ireland's supervisory authority and is often the lead regulator for pan-European cases.
How much does it cost to make a Subject Access Request?
Subject Access Requests are free in almost all cases. An organisation can only charge a reasonable fee — or refuse to act — if a request is manifestly unfounded, excessive, or repetitive. Simply requesting your own data once a year does not meet that threshold.
Can I be compensated if my privacy rights are breached?
Yes. Under Article 82 GDPR and Section 117 of the Data Protection Act 2018, you can seek compensation in the Irish courts for both material damage (such as financial loss) and non-material damage (such as distress or loss of control over your data). Recent Court of Justice of the EU rulings have clarified that even non-financial harm can attract compensation, though you must be able to prove actual damage.
How long can a company keep my personal data?
GDPR requires data to be kept only for as long as necessary for the purpose it was collected. There is no fixed period — a supermarket loyalty scheme may keep purchase data for a few years, while employment records must often be kept for seven years for Revenue purposes. Organisations must publish their retention periods in their privacy notice.
What is the difference between GDPR and the ePrivacy Regulations in Ireland?
GDPR governs personal data in general, while the ePrivacy Regulations 2011 (SI 336/2011) cover electronic communications specifically — including cookies, direct marketing emails, and unsolicited phone calls. The two work together: if a website drops non-essential cookies without your consent, that is both an ePrivacy and a GDPR issue, and the DPC enforces both.
Final Thoughts
GDPR gives everyone in Ireland real, enforceable rights over their personal data — but those rights only work when people use them. By understanding the eight core rights, knowing how to make a Subject Access Request, and being ready to escalate to the Data Protection Commission when needed, you can hold organisations to a much higher standard. Combine that legal knowledge with sensible privacy tools and habits, and you will be firmly in control of your own digital footprint.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Data Protection Act 2018 Ireland: Complete Guide
Ireland's Data Protection Act 2018 gives effect to the GDPR under Irish law and empowers the Data Protection Commission to enforce it. This complete guide covers scope, individual rights, penalties, breach notification, and a step-by-step compliance roadmap for Irish organisations.
OAIC Complaints: How to Report a Privacy Breach in Australia
If an Australian organisation has mishandled your personal information, you have the right to complain to the OAIC. This step-by-step guide explains what qualifies as a privacy breach, how to gather evidence, and how the complaint process works from lodgement to determination.
Australian Data Breach Notification Scheme: Complete 2026 Guide
Australia's Notifiable Data Breaches scheme requires organisations to notify the OAIC and affected individuals when a breach is likely to cause serious harm. This guide covers obligations, timelines, penalties up to AUD $50 million, and how to build a compliant response plan.
UK Online Safety Act: What It Means for Your Privacy
The UK Online Safety Act reshapes how platforms moderate content, verify ages and handle private messages. Here's what it means for your privacy in 2026 — and the practical steps every UK user can take to protect their data.