facebook-pixel

GDPR in Ireland: Your Privacy Rights Explained

L
Lunyb Security Team
··11 min read

Ireland occupies a unique position in the European data protection landscape. As the European headquarters for many of the world's largest technology companies — including Meta, Google, TikTok, LinkedIn, and Apple — the country's Data Protection Commission (DPC) acts as the lead supervisory authority for a huge portion of European personal data processing. That makes understanding your GDPR rights in Ireland especially important, whether you're an Irish resident, a business owner, or simply someone whose data flows through Dublin-based servers.

This guide breaks down the General Data Protection Regulation (GDPR) as it applies in Ireland, explains the eight core rights you hold as a data subject, and walks you through how to enforce them.

What Is GDPR and How Does It Apply in Ireland?

The General Data Protection Regulation (GDPR) is an EU-wide law that came into force on 25 May 2018. It governs how organisations collect, store, use, and share the personal data of individuals located in the European Union and European Economic Area.

In Ireland, the GDPR is given further effect by the Data Protection Act 2018, which handles national-level details such as the age of digital consent (set at 16 in Ireland), the powers of the DPC, and specific rules for law enforcement, journalism, and public sector processing.

Key points to understand about the Irish framework:

  1. Territorial scope: GDPR applies to any organisation processing the personal data of people in Ireland, even if the organisation is based outside the EU.
  2. Lead authority: The Data Protection Commission (DPC), headquartered in Dublin, is Ireland's supervisory authority and often the lead regulator for cross-border cases.
  3. Penalties: Fines can reach €20 million or 4% of global annual turnover, whichever is higher.
  4. Direct enforceability: You can rely on your GDPR rights directly against companies, without needing new legislation.

What Counts as Personal Data Under Irish GDPR?

Personal data is any information relating to an identified or identifiable living individual. That definition is deliberately broad and covers far more than most people expect.

Examples of personal data include:

  • Your name, home address, and Eircode
  • Email addresses, phone numbers, and PPS number
  • IP addresses, cookie identifiers, and device IDs
  • Location data from your phone or car
  • CCTV footage where you can be identified
  • Biometric data such as fingerprints or facial recognition templates
  • Health records, prescriptions, and GP notes

Some categories receive extra protection under Article 9 and are called special category data. These include information about your health, race or ethnic origin, political opinions, religious beliefs, trade union membership, genetic and biometric data, and data about your sex life or sexual orientation. Processing this data generally requires explicit consent or a specific legal basis.

Your Eight Core GDPR Rights in Ireland

The GDPR gives every data subject in Ireland eight fundamental rights. Understanding them is the first step in taking control of your personal information.

1. The Right to Be Informed

Organisations must tell you clearly and transparently what data they collect about you, why they collect it, how long they keep it, who they share it with, and what your rights are. This is typically delivered through a privacy notice or privacy policy on a website.

2. The Right of Access

You have the right to request a copy of all personal data an organisation holds about you. This is known as a Subject Access Request (SAR). The organisation must respond within one month, free of charge in most cases.

3. The Right to Rectification

If an organisation holds inaccurate or incomplete data about you, you can ask them to correct or complete it. Banks, insurers, and healthcare providers must respond promptly.

4. The Right to Erasure ("Right to Be Forgotten")

You can request that your personal data be deleted when it is no longer necessary, when you withdraw consent, or when it has been processed unlawfully. There are exceptions — for example, where the data is needed for legal claims or public health reasons.

5. The Right to Restrict Processing

You can ask an organisation to pause processing your data while a dispute is resolved, for example when you contest the accuracy of the data.

6. The Right to Data Portability

Where processing is based on consent or a contract and carried out by automated means, you can receive your data in a structured, machine-readable format and transfer it to another service.

7. The Right to Object

You can object to processing based on legitimate interests, direct marketing, or research. For direct marketing, the objection is absolute — the organisation must stop immediately.

8. Rights Related to Automated Decision-Making

You have the right not to be subject to a decision based solely on automated processing — including profiling — where it produces legal or similarly significant effects. This is increasingly important as AI-driven credit scoring, insurance pricing, and hiring tools become common.

Comparing Your Rights: Quick Reference Table

RightResponse TimeCostKey Limitation
Access (SAR)1 month (extendable to 3)FreeCan be refused if manifestly unfounded
Rectification1 monthFreeMust be inaccurate or incomplete
Erasure1 monthFreeNot absolute; legal exemptions apply
Restriction1 monthFreeOnly in defined circumstances
Portability1 monthFreeAutomated processing only
Objection1 monthFreeAbsolute for direct marketing
Automated decisionsImmediate on requestFreeContract and legal exceptions

How to Make a Subject Access Request in Ireland

A Subject Access Request is the most commonly used GDPR right. Here's how to submit one effectively:

  1. Identify the data controller. This is the organisation that decides why and how your data is processed — usually named in the privacy policy.
  2. Contact the Data Protection Officer (DPO). Large organisations must appoint one. Their email is typically dpo@company.ie or listed in the privacy notice.
  3. Write a clear request. State that you are making a request under Article 15 of the GDPR and specify what you want (e.g., all data, or just marketing preferences).
  4. Verify your identity. The organisation can ask for reasonable proof, such as a copy of photo ID.
  5. Wait up to one month. If the request is complex, they can extend by two more months but must tell you why.
  6. Review the response. Check for missing data, redactions, and whether third-party recipients are named.

A simple template: "Dear Data Protection Officer, under Article 15 of the GDPR I am requesting a copy of all personal data you hold about me, together with the information required by Article 15(1)(a)–(h). My details are [name, address, account number]. Please respond within one month."

The Role of the Data Protection Commission (DPC)

The Data Protection Commission is Ireland's independent regulator for data protection. Based in Dublin and Portarlington, it has three main functions:

  • Handling complaints from individuals whose rights have been infringed.
  • Investigating and fining organisations that breach the GDPR.
  • Providing guidance to businesses, public bodies, and the general public.

Because so many multinational tech companies have their EU headquarters in Ireland, the DPC acts as the lead supervisory authority under the GDPR's one-stop-shop mechanism. It has issued some of the largest fines in EU history, including €1.2 billion against Meta in 2023 for unlawful data transfers to the United States and €345 million against TikTok for children's data violations.

How to Make a Complaint to the DPC

If an organisation ignores your rights or mishandles your data, you can lodge a complaint with the DPC free of charge. The process is straightforward:

  1. Contact the organisation first. The DPC generally expects you to raise the issue directly and give the controller a chance to resolve it.
  2. Gather evidence. Keep copies of emails, screenshots, and any response (or lack of response).
  3. Submit the complaint online. Use the DPC's webform at dataprotection.ie, by post, or by email to info@dataprotection.ie.
  4. Cooperate with the investigation. The DPC may ask for further information or attempt an amicable resolution.
  5. Await a decision. Outcomes can include a reprimand, corrective order, or administrative fine against the controller.

You also have the right to a judicial remedy in the Irish courts under section 117 of the Data Protection Act 2018, including compensation for material or non-material damage such as distress.

GDPR Rights and Everyday Online Life

Understanding your rights is only useful if you exercise them. Here are practical scenarios where Irish consumers routinely rely on GDPR:

Cookies and Website Tracking

Under the ePrivacy Regulations 2011 combined with GDPR, Irish websites must obtain your consent before dropping non-essential cookies. Consent must be freely given, specific, informed, and as easy to withdraw as to give. "Accept all" buttons without an equally prominent "Reject all" option are non-compliant, and the DPC has warned many Irish businesses about this.

Direct Marketing

Companies need your opt-in consent to send marketing emails or SMS in most cases. You can always unsubscribe, and your objection must be actioned immediately.

Link Sharing and Analytics

If you run a business, blog, or newsletter and share links, be aware that many link-tracking tools collect IP addresses and device data — which is personal data under GDPR. Choose services that publish transparent privacy policies and offer EU-based data handling. Privacy-focused link shorteners like Lunyb are designed with data minimisation in mind, which reduces your compliance burden as a controller. If you're evaluating options, our 2026 buyer's guide to URL shorteners compares the leading tools on privacy and features.

Employer Monitoring

Irish employers can monitor staff email and internet use only where there is a legitimate purpose, a clear policy, and proportionate measures. Employees retain full GDPR rights against their employer.

Special Considerations for Children's Data in Ireland

Ireland sets the digital age of consent at 16 — one of the highest in the EU. Below that age, a parent or guardian must consent to the processing of personal data by information society services (apps, social networks, online games).

The DPC's Fundamentals for a Child-Oriented Approach to Data Processing sets 14 principles, including a "best interests of the child" test, high-privacy defaults, and a prohibition on profiling children for marketing. Any organisation providing services to under-18s in Ireland should treat these fundamentals as mandatory in practice.

Data Breaches: What to Expect

If a company suffers a personal data breach that is likely to result in a risk to your rights and freedoms, they must notify the DPC within 72 hours. Where the risk is high — for example, leaked passwords, financial details, or health data — they must also notify you directly, without undue delay.

A proper breach notification to you should include:

  • The nature of the breach and categories of data involved
  • Likely consequences
  • Measures taken to mitigate harm
  • Contact details for the DPO or a point of contact

If you receive such a notice, change any affected passwords immediately, monitor bank statements, and consider registering with a credit reference agency to watch for identity fraud.

How Businesses in Ireland Can Stay Compliant

For Irish SMEs and sole traders, GDPR compliance doesn't have to be overwhelming. A practical starting checklist:

  1. Map the personal data you collect and where it is stored.
  2. Identify your lawful basis for each processing activity.
  3. Publish a clear, plain-English privacy notice.
  4. Put a data processing agreement in place with every vendor (cloud, email, analytics).
  5. Train staff to recognise data subject requests and breaches.
  6. Keep a Record of Processing Activities (ROPA) — required for most organisations.
  7. Review cookie banners and marketing consent flows annually.

Frequently Asked Questions

Does GDPR still apply in Ireland after Brexit?

Yes. Ireland remains a full EU member state, so GDPR applies directly. Brexit affected the United Kingdom, not Ireland. In fact, data transfers between Ireland and the UK now rely on a separate EU adequacy decision covering UK GDPR.

How long does an organisation have to respond to my Subject Access Request?

The default is one calendar month from the date they receive the request and verify your identity. They can extend by two additional months for complex or numerous requests, but they must inform you of the extension and the reasons within the first month.

Can I claim compensation for a GDPR breach in Ireland?

Yes. Under Article 82 of the GDPR and section 117 of the Data Protection Act 2018, you can claim compensation in the Circuit Court for both material damage (financial loss) and non-material damage (distress, anxiety, reputational harm) resulting from an infringement.

Is the Data Protection Commission free to use?

Yes. Making a complaint to the DPC is completely free, and you don't need a solicitor. However, court proceedings for compensation may involve legal costs.

What happens if I ignore a GDPR request as a small business?

Ignoring a valid request is itself a breach of the GDPR. The DPC can investigate, issue reprimands, and impose administrative fines even on small businesses. More commonly, small businesses receive corrective orders and guidance — but repeated non-compliance escalates quickly.

Final Thoughts

GDPR gives people in Ireland some of the strongest privacy protections in the world, and the Data Protection Commission has proven willing to enforce them against even the largest global platforms. Knowing your eight core rights — and how to exercise them — puts you in control of your personal information, whether you're dealing with a Dublin start-up, a Silicon Valley giant, or the local GP.

Take a moment to audit your own digital footprint: submit a Subject Access Request to a service you use often, review your marketing consents, and check the privacy policies of the tools you rely on daily. Small, regular actions are what turn GDPR from paperwork into genuine privacy.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles