GDPR in Ireland: Your Privacy Rights Explained
Ireland occupies a unique position in the European data protection landscape. As the European headquarters for many of the world's largest technology companies — including Meta, Google, TikTok, LinkedIn, and Apple — the country's Data Protection Commission (DPC) acts as the lead supervisory authority for a huge portion of European personal data processing. That makes understanding your GDPR rights in Ireland especially important, whether you're an Irish resident, a business owner, or simply someone whose data flows through Dublin-based servers.
This guide breaks down the General Data Protection Regulation (GDPR) as it applies in Ireland, explains the eight core rights you hold as a data subject, and walks you through how to enforce them.
What Is GDPR and How Does It Apply in Ireland?
The General Data Protection Regulation (GDPR) is an EU-wide law that came into force on 25 May 2018. It governs how organisations collect, store, use, and share the personal data of individuals located in the European Union and European Economic Area.
In Ireland, the GDPR is given further effect by the Data Protection Act 2018, which handles national-level details such as the age of digital consent (set at 16 in Ireland), the powers of the DPC, and specific rules for law enforcement, journalism, and public sector processing.
Key points to understand about the Irish framework:
- Territorial scope: GDPR applies to any organisation processing the personal data of people in Ireland, even if the organisation is based outside the EU.
- Lead authority: The Data Protection Commission (DPC), headquartered in Dublin, is Ireland's supervisory authority and often the lead regulator for cross-border cases.
- Penalties: Fines can reach €20 million or 4% of global annual turnover, whichever is higher.
- Direct enforceability: You can rely on your GDPR rights directly against companies, without needing new legislation.
What Counts as Personal Data Under Irish GDPR?
Personal data is any information relating to an identified or identifiable living individual. That definition is deliberately broad and covers far more than most people expect.
Examples of personal data include:
- Your name, home address, and Eircode
- Email addresses, phone numbers, and PPS number
- IP addresses, cookie identifiers, and device IDs
- Location data from your phone or car
- CCTV footage where you can be identified
- Biometric data such as fingerprints or facial recognition templates
- Health records, prescriptions, and GP notes
Some categories receive extra protection under Article 9 and are called special category data. These include information about your health, race or ethnic origin, political opinions, religious beliefs, trade union membership, genetic and biometric data, and data about your sex life or sexual orientation. Processing this data generally requires explicit consent or a specific legal basis.
Your Eight Core GDPR Rights in Ireland
The GDPR gives every data subject in Ireland eight fundamental rights. Understanding them is the first step in taking control of your personal information.
1. The Right to Be Informed
Organisations must tell you clearly and transparently what data they collect about you, why they collect it, how long they keep it, who they share it with, and what your rights are. This is typically delivered through a privacy notice or privacy policy on a website.
2. The Right of Access
You have the right to request a copy of all personal data an organisation holds about you. This is known as a Subject Access Request (SAR). The organisation must respond within one month, free of charge in most cases.
3. The Right to Rectification
If an organisation holds inaccurate or incomplete data about you, you can ask them to correct or complete it. Banks, insurers, and healthcare providers must respond promptly.
4. The Right to Erasure ("Right to Be Forgotten")
You can request that your personal data be deleted when it is no longer necessary, when you withdraw consent, or when it has been processed unlawfully. There are exceptions — for example, where the data is needed for legal claims or public health reasons.
5. The Right to Restrict Processing
You can ask an organisation to pause processing your data while a dispute is resolved, for example when you contest the accuracy of the data.
6. The Right to Data Portability
Where processing is based on consent or a contract and carried out by automated means, you can receive your data in a structured, machine-readable format and transfer it to another service.
7. The Right to Object
You can object to processing based on legitimate interests, direct marketing, or research. For direct marketing, the objection is absolute — the organisation must stop immediately.
8. Rights Related to Automated Decision-Making
You have the right not to be subject to a decision based solely on automated processing — including profiling — where it produces legal or similarly significant effects. This is increasingly important as AI-driven credit scoring, insurance pricing, and hiring tools become common.
Comparing Your Rights: Quick Reference Table
| Right | Response Time | Cost | Key Limitation |
|---|---|---|---|
| Access (SAR) | 1 month (extendable to 3) | Free | Can be refused if manifestly unfounded |
| Rectification | 1 month | Free | Must be inaccurate or incomplete |
| Erasure | 1 month | Free | Not absolute; legal exemptions apply |
| Restriction | 1 month | Free | Only in defined circumstances |
| Portability | 1 month | Free | Automated processing only |
| Objection | 1 month | Free | Absolute for direct marketing |
| Automated decisions | Immediate on request | Free | Contract and legal exceptions |
How to Make a Subject Access Request in Ireland
A Subject Access Request is the most commonly used GDPR right. Here's how to submit one effectively:
- Identify the data controller. This is the organisation that decides why and how your data is processed — usually named in the privacy policy.
- Contact the Data Protection Officer (DPO). Large organisations must appoint one. Their email is typically dpo@company.ie or listed in the privacy notice.
- Write a clear request. State that you are making a request under Article 15 of the GDPR and specify what you want (e.g., all data, or just marketing preferences).
- Verify your identity. The organisation can ask for reasonable proof, such as a copy of photo ID.
- Wait up to one month. If the request is complex, they can extend by two more months but must tell you why.
- Review the response. Check for missing data, redactions, and whether third-party recipients are named.
A simple template: "Dear Data Protection Officer, under Article 15 of the GDPR I am requesting a copy of all personal data you hold about me, together with the information required by Article 15(1)(a)–(h). My details are [name, address, account number]. Please respond within one month."
The Role of the Data Protection Commission (DPC)
The Data Protection Commission is Ireland's independent regulator for data protection. Based in Dublin and Portarlington, it has three main functions:
- Handling complaints from individuals whose rights have been infringed.
- Investigating and fining organisations that breach the GDPR.
- Providing guidance to businesses, public bodies, and the general public.
Because so many multinational tech companies have their EU headquarters in Ireland, the DPC acts as the lead supervisory authority under the GDPR's one-stop-shop mechanism. It has issued some of the largest fines in EU history, including €1.2 billion against Meta in 2023 for unlawful data transfers to the United States and €345 million against TikTok for children's data violations.
How to Make a Complaint to the DPC
If an organisation ignores your rights or mishandles your data, you can lodge a complaint with the DPC free of charge. The process is straightforward:
- Contact the organisation first. The DPC generally expects you to raise the issue directly and give the controller a chance to resolve it.
- Gather evidence. Keep copies of emails, screenshots, and any response (or lack of response).
- Submit the complaint online. Use the DPC's webform at dataprotection.ie, by post, or by email to info@dataprotection.ie.
- Cooperate with the investigation. The DPC may ask for further information or attempt an amicable resolution.
- Await a decision. Outcomes can include a reprimand, corrective order, or administrative fine against the controller.
You also have the right to a judicial remedy in the Irish courts under section 117 of the Data Protection Act 2018, including compensation for material or non-material damage such as distress.
GDPR Rights and Everyday Online Life
Understanding your rights is only useful if you exercise them. Here are practical scenarios where Irish consumers routinely rely on GDPR:
Cookies and Website Tracking
Under the ePrivacy Regulations 2011 combined with GDPR, Irish websites must obtain your consent before dropping non-essential cookies. Consent must be freely given, specific, informed, and as easy to withdraw as to give. "Accept all" buttons without an equally prominent "Reject all" option are non-compliant, and the DPC has warned many Irish businesses about this.
Direct Marketing
Companies need your opt-in consent to send marketing emails or SMS in most cases. You can always unsubscribe, and your objection must be actioned immediately.
Link Sharing and Analytics
If you run a business, blog, or newsletter and share links, be aware that many link-tracking tools collect IP addresses and device data — which is personal data under GDPR. Choose services that publish transparent privacy policies and offer EU-based data handling. Privacy-focused link shorteners like Lunyb are designed with data minimisation in mind, which reduces your compliance burden as a controller. If you're evaluating options, our 2026 buyer's guide to URL shorteners compares the leading tools on privacy and features.
Employer Monitoring
Irish employers can monitor staff email and internet use only where there is a legitimate purpose, a clear policy, and proportionate measures. Employees retain full GDPR rights against their employer.
Special Considerations for Children's Data in Ireland
Ireland sets the digital age of consent at 16 — one of the highest in the EU. Below that age, a parent or guardian must consent to the processing of personal data by information society services (apps, social networks, online games).
The DPC's Fundamentals for a Child-Oriented Approach to Data Processing sets 14 principles, including a "best interests of the child" test, high-privacy defaults, and a prohibition on profiling children for marketing. Any organisation providing services to under-18s in Ireland should treat these fundamentals as mandatory in practice.
Data Breaches: What to Expect
If a company suffers a personal data breach that is likely to result in a risk to your rights and freedoms, they must notify the DPC within 72 hours. Where the risk is high — for example, leaked passwords, financial details, or health data — they must also notify you directly, without undue delay.
A proper breach notification to you should include:
- The nature of the breach and categories of data involved
- Likely consequences
- Measures taken to mitigate harm
- Contact details for the DPO or a point of contact
If you receive such a notice, change any affected passwords immediately, monitor bank statements, and consider registering with a credit reference agency to watch for identity fraud.
How Businesses in Ireland Can Stay Compliant
For Irish SMEs and sole traders, GDPR compliance doesn't have to be overwhelming. A practical starting checklist:
- Map the personal data you collect and where it is stored.
- Identify your lawful basis for each processing activity.
- Publish a clear, plain-English privacy notice.
- Put a data processing agreement in place with every vendor (cloud, email, analytics).
- Train staff to recognise data subject requests and breaches.
- Keep a Record of Processing Activities (ROPA) — required for most organisations.
- Review cookie banners and marketing consent flows annually.
Frequently Asked Questions
Does GDPR still apply in Ireland after Brexit?
Yes. Ireland remains a full EU member state, so GDPR applies directly. Brexit affected the United Kingdom, not Ireland. In fact, data transfers between Ireland and the UK now rely on a separate EU adequacy decision covering UK GDPR.
How long does an organisation have to respond to my Subject Access Request?
The default is one calendar month from the date they receive the request and verify your identity. They can extend by two additional months for complex or numerous requests, but they must inform you of the extension and the reasons within the first month.
Can I claim compensation for a GDPR breach in Ireland?
Yes. Under Article 82 of the GDPR and section 117 of the Data Protection Act 2018, you can claim compensation in the Circuit Court for both material damage (financial loss) and non-material damage (distress, anxiety, reputational harm) resulting from an infringement.
Is the Data Protection Commission free to use?
Yes. Making a complaint to the DPC is completely free, and you don't need a solicitor. However, court proceedings for compensation may involve legal costs.
What happens if I ignore a GDPR request as a small business?
Ignoring a valid request is itself a breach of the GDPR. The DPC can investigate, issue reprimands, and impose administrative fines even on small businesses. More commonly, small businesses receive corrective orders and guidance — but repeated non-compliance escalates quickly.
Final Thoughts
GDPR gives people in Ireland some of the strongest privacy protections in the world, and the Data Protection Commission has proven willing to enforce them against even the largest global platforms. Knowing your eight core rights — and how to exercise them — puts you in control of your personal information, whether you're dealing with a Dublin start-up, a Silicon Valley giant, or the local GP.
Take a moment to audit your own digital footprint: submit a Subject Access Request to a service you use often, review your marketing consents, and check the privacy policies of the tools you rely on daily. Small, regular actions are what turn GDPR from paperwork into genuine privacy.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Bill C-27 Digital Charter: What You Need to Know
Bill C-27, Canada's Digital Charter Implementation Act, introduces the CPPA, a new privacy tribunal, and AIDA to modernize privacy and regulate AI. Learn what it means for Canadian businesses and consumers, how it compares globally, and how to prepare.
ICO Fines 2026: Biggest Data Protection Penalties in the UK
The ICO issued record data protection penalties in 2026, with fines topping £6 million for ransomware failures and multi-million pound sanctions for marketing abuses. This guide examines the biggest UK fines of the year and the compliance lessons every organisation must learn.
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
Learn how to file a privacy complaint with Ireland's Data Protection Commission (DPC). This step-by-step guide covers evidence gathering, submission channels, timelines, and what happens after you complain under GDPR.
Data Protection Act 2018 Ireland: Complete Guide
A complete guide to Ireland's Data Protection Act 2018, covering its relationship with the GDPR, individual rights, business obligations, DPC enforcement powers, and penalties. Learn what your organisation needs to do to stay compliant.