GDPR in Ireland: Your Privacy Rights Explained (2026 Guide)
Ireland sits at the heart of European data protection. Because so many of the world's biggest technology companies — Meta, Google, TikTok, Microsoft, LinkedIn, Apple, and X — have their European headquarters in Dublin, the Irish Data Protection Commission (DPC) has become one of the most influential privacy regulators on the planet. If you live in Ireland, that means the same body that fines Meta hundreds of millions of euro is also the one that protects your personal data when your local GP surgery, gym, or online retailer mishandles it.
This guide explains, in plain English, what the General Data Protection Regulation (GDPR) actually gives you as an Irish resident, how it works alongside the Irish Data Protection Act 2018, and exactly how to use your rights when something goes wrong.
What Is GDPR and How Does It Apply in Ireland?
The General Data Protection Regulation (GDPR) is an EU law that came into force on 25 May 2018. It sets out how organisations must collect, store, use, and share personal data about people in the European Economic Area. In Ireland, GDPR is directly applicable and is supplemented by the Data Protection Act 2018, which handles areas the EU left to national governments — such as the age of digital consent (16 in Ireland) and rules for law enforcement processing.
GDPR applies to almost every organisation that processes personal data about people in Ireland, whether that organisation is based in Cork, California, or Singapore. "Personal data" is defined very broadly: it covers your name, email, phone number, IP address, location data, photos, health records, and even online identifiers like cookies.
Who Enforces GDPR in Ireland?
The Data Protection Commission (DPC), headquartered in Dublin with an office in Portarlington, is Ireland's independent supervisory authority. The DPC handles complaints, carries out investigations, and issues fines of up to €20 million or 4% of a company's global annual turnover — whichever is higher.
Your Eight Core Privacy Rights Under GDPR
GDPR grants you eight specific rights over your personal data. Every organisation that holds information about you must be able to honour these rights, usually within one calendar month and free of charge.
- The right to be informed — Organisations must tell you clearly what data they collect, why, and how long they keep it (usually via a privacy notice).
- The right of access — You can request a copy of all personal data an organisation holds about you (a "subject access request" or SAR).
- The right to rectification — You can require inaccurate or incomplete data to be corrected.
- The right to erasure — Also called the "right to be forgotten," you can ask for your data to be deleted in certain circumstances.
- The right to restrict processing — You can ask an organisation to pause using your data while a dispute is resolved.
- The right to data portability — You can receive your data in a machine-readable format and move it to another provider.
- The right to object — You can object to direct marketing at any time, and to other processing on grounds relating to your particular situation.
- Rights related to automated decision-making and profiling — You have the right not to be subject to decisions made solely by algorithms that produce legal or similarly significant effects.
The Six Lawful Bases for Processing Your Data
An organisation cannot process your personal data just because it feels like it. Under Article 6 of the GDPR, it must rely on one of six lawful bases. Understanding these helps you push back when a company overreaches.
| Lawful Basis | When It Applies | Example in Ireland |
|---|---|---|
| Consent | You freely agree to a specific purpose | Signing up for a Tesco Clubcard newsletter |
| Contract | Needed to fulfil a contract with you | An Bord Gáis processing your address to bill you |
| Legal obligation | Required by Irish or EU law | Your employer sharing PAYE data with Revenue |
| Vital interests | To protect someone's life | A hospital accessing your records in an emergency |
| Public task | Carrying out an official function | The HSE processing vaccination records |
| Legitimate interests | Genuine business interest that doesn't override your rights | Fraud prevention by AIB or Bank of Ireland |
Special Category Data: Extra Protection
Some data is considered so sensitive that GDPR provides additional safeguards. This "special category data" includes information about your health, race or ethnicity, political opinions, religious beliefs, trade union membership, sexual orientation, genetic data, and biometric data used for identification.
To process special category data, an organisation needs both a lawful basis under Article 6 and a separate condition under Article 9. In practice, this means your GP, the HSE, or a Dublin gym using fingerprint entry must meet a higher standard before touching this information.
How to Make a Subject Access Request (SAR)
A subject access request is the single most powerful tool GDPR gives you. It forces an organisation to reveal exactly what it knows about you.
Step-by-Step: Filing a SAR in Ireland
- Identify the data controller. Check the company's privacy policy for a Data Protection Officer (DPO) or a dedicated privacy email address.
- Write your request. You can email, post a letter, or use an online form. State clearly: "I am making a subject access request under Article 15 of the GDPR."
- Verify your identity. The organisation can ask for reasonable proof, but cannot demand excessive documentation.
- Wait one month. They must respond within 30 calendar days, extendable by two months for complex requests (they must tell you if they extend).
- Review what you receive. You should get copies of the data, plus information on why they hold it, who they share it with, and how long they keep it.
- Escalate if needed. If they refuse, ignore you, or provide incomplete data, complain to the DPC.
How to File a Complaint With the Data Protection Commission
The DPC is free to use and does not require legal representation. Before complaining, you should generally try to resolve the issue directly with the organisation first.
What You'll Need
- Your contact details
- The name of the organisation you are complaining about
- A clear description of what happened and which of your rights you believe were breached
- Copies of any correspondence with the organisation
- Supporting evidence (screenshots, emails, letters)
You can submit complaints via the DPC's online webform at dataprotection.ie, by email to info@dataprotection.ie, or by post to their Portarlington office. There is no time limit as strict as some jurisdictions, but the DPC recommends complaining within a reasonable time of the incident.
Data Breaches: What Happens When Companies Get Hacked
Under GDPR, organisations must report most personal data breaches to the DPC within 72 hours of becoming aware of them. If a breach is likely to result in a high risk to your rights and freedoms — for example, exposure of financial data or health records — the organisation must also notify you directly without undue delay.
Ireland has seen several high-profile breaches. The 2021 HSE ransomware attack exposed data belonging to hundreds of thousands of patients. Meta has been fined multiple times by the DPC for breaches affecting Irish and EU users — including a record €1.2 billion fine in 2023 for unlawful data transfers to the United States.
What to Do If You're Affected by a Breach
- Change any passwords that may have been exposed, and enable two-factor authentication.
- Monitor bank accounts and credit reports (the Central Credit Register offers a free credit report).
- Be alert for phishing emails or phone calls referencing the breach.
- Keep records — you may be entitled to compensation for material or non-material damage.
Cookies, Tracking, and ePrivacy Rules
GDPR is not the only game in town. The ePrivacy Regulations 2011 (implementing the EU ePrivacy Directive) govern cookies and electronic marketing in Ireland. Together, they mean that:
- Websites must obtain your freely given, specific, informed and unambiguous consent before setting non-essential cookies.
- Pre-ticked boxes, "cookie walls," and "continue browsing = consent" are not valid under DPC guidance.
- Rejecting cookies must be as easy as accepting them.
- Direct marketing emails and SMS generally require prior opt-in consent.
If a website only offers you "Accept All" without an equally prominent "Reject All," it is very likely breaching Irish law. This is a common complaint category for the DPC.
Practical Privacy Tips for People Living in Ireland
Knowing your rights is one thing — reducing your exposure in the first place is another. A few practical habits go a long way.
- Use encrypted DNS (such as Cloudflare 1.1.1.1 or Quad9) to prevent your internet provider from seeing every domain you visit.
- Choose privacy-respecting browsers like Firefox or Brave, and install a reputable content blocker.
- Compartmentalise your identity — use email aliases (Apple Hide My Email, SimpleLogin, Firefox Relay) so a breach at one service doesn't cascade.
- Be cautious with shortened links. When you need to share links, use a reputable link shortener that respects privacy and gives you control over your data. Services like Lunyb let you create short links without harvesting excessive personal information — see our honest review of Lunyb and our 2026 buyer's guide for how it compares to alternatives.
- Review app permissions on your iPhone or Android at least twice a year.
- Exercise your rights. Every SAR or objection you send teaches organisations that Irish consumers take privacy seriously.
Children's Data and the Digital Age of Consent
Ireland set its digital age of consent at 16 under the Data Protection Act 2018. This means online services that rely on consent as their lawful basis cannot process the personal data of a child under 16 without parental authorisation. The DPC's Fundamentals for a Child-Oriented Approach to Data Processing sets out 14 principles that organisations must follow when their services are likely to be accessed by children, including a "floor of protection" that treats all users as children unless age verification is in place.
Cross-Border Complaints and the "One-Stop-Shop"
Because so many multinationals are based in Ireland, the DPC acts as "lead supervisory authority" for many cross-border cases under GDPR's one-stop-shop mechanism. If you complain about Meta, TikTok, or Google — even if you live in Germany or Spain — your case will often end up in Dublin. This system has been criticised for being slow, but recent years have seen the DPC issue landmark fines totalling billions of euro.
Frequently Asked Questions
How long does a company have to respond to my subject access request?
One calendar month from the day they receive your request and verify your identity. They can extend this by up to two additional months for complex or numerous requests, but they must inform you of the extension and the reasons within the original month.
Can I be charged a fee for making a data protection request?
No. Subject access requests and other GDPR requests are free. An organisation may only charge a reasonable fee (or refuse) if a request is "manifestly unfounded or excessive" — for example, if you make repetitive requests. The burden is on them to prove this.
What compensation can I get if my data protection rights are breached?
Article 82 of the GDPR gives you the right to compensation for both material damage (financial loss) and non-material damage (distress, anxiety, reputational harm). You must bring a claim in the Circuit Court or High Court in Ireland. The Court of Justice of the EU has confirmed that even non-material damage can be compensated, though you must show actual harm — a mere breach is not enough.
Does GDPR apply to my personal use of data, like a WhatsApp group?
No. GDPR contains a "household exemption" that excludes processing carried out by an individual in the course of a purely personal or household activity. Posting family photos on a private WhatsApp group is not caught. However, if you run a small business or community group, GDPR does apply to your processing.
What is the difference between a data controller and a data processor?
A data controller decides why and how personal data is processed — for example, your bank deciding to use your transaction history for fraud detection. A data processor processes data on behalf of a controller — for example, a cloud provider hosting the bank's servers. You direct your rights primarily at the controller, though processors also have some direct obligations under GDPR.
Final Thoughts
GDPR gives people in Ireland some of the strongest privacy rights in the world — but rights only matter when you use them. The DPC handles thousands of complaints each year, and simple actions like sending a subject access request, refusing non-essential cookies, or reporting a suspicious data practice all contribute to a healthier information ecosystem. Bookmark dataprotection.ie, keep this guide handy, and don't hesitate to push back when an organisation treats your data carelessly.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
PIPEDA vs GDPR: Canadian Privacy Law Explained (2026 Guide)
PIPEDA and GDPR both protect personal data, but they differ sharply in consent rules, individual rights, breach timelines, and penalties. This guide explains the key differences and shows Canadian businesses how to build a compliance program that satisfies both laws in 2026.
Singapore PDPA vs GDPR: Key Differences for Businesses in 2026
Singapore's PDPA and the EU's GDPR both protect personal data, but they differ significantly in consent, penalties, breach notification, and cross-border transfers. This guide breaks down the key differences so businesses can build a unified compliance strategy.
GDPR After Brexit: What Changed for UK Businesses and Data Protection
GDPR did not disappear after Brexit—it split into two parallel regimes. This guide explains how UK GDPR differs from EU GDPR, what adequacy decisions mean for data transfers, and the practical compliance steps every British business should take in 2026.
Data Protection Act 2018 Ireland: Complete Guide
Ireland's Data Protection Act 2018 gives effect to the GDPR under Irish law and empowers the Data Protection Commission to enforce it. This complete guide covers scope, individual rights, penalties, breach notification, and a step-by-step compliance roadmap for Irish organisations.