GDPR in Ireland: Your Privacy Rights Explained
The General Data Protection Regulation (GDPR) gives people in Ireland some of the strongest privacy protections in the world. Whether you're signing up for a loyalty card in Dunnes, using a banking app, or browsing a news site, organisations that collect your personal data must follow strict rules. This guide explains your GDPR rights in Ireland in plain English, how to exercise them, and what to do when a company gets it wrong.
What Is GDPR and How Does It Apply in Ireland?
GDPR is an EU-wide regulation that came into force on 25 May 2018. It governs how organisations collect, store, use, and share personal data about individuals in the European Economic Area. In Ireland, GDPR is implemented alongside the Data Protection Act 2018, and enforcement is handled by the Data Protection Commission (DPC), headquartered in Dublin.
Because so many multinational tech companies — including Meta, Google, TikTok, LinkedIn, and Apple — have their European headquarters in Ireland, the DPC is one of the busiest and most influential privacy regulators in Europe. That means Irish residents often have a front-row seat to landmark GDPR enforcement actions.
Who Does GDPR Protect?
GDPR protects any identifiable living individual in Ireland (and across the EU). It applies whenever an organisation processes your personal data, regardless of whether the organisation itself is based in Ireland, the wider EU, or overseas. If a US-based app is offered to Irish users, it must comply with GDPR.
What Counts as Personal Data?
Personal data is any information that can identify you directly or indirectly. This includes obvious items like your name, address, PPS number, and email, but also less obvious data such as IP addresses, device identifiers, location history, cookie IDs, photos, and even opinions expressed about you. Special categories — health data, religious beliefs, sexual orientation, biometrics — get extra protection.
Your Eight Core GDPR Rights in Ireland
GDPR gives you eight fundamental rights over your personal data. Every organisation processing your data must respect these rights and respond to your requests, usually within one month and free of charge.
| Right | What It Means | Common Use Case |
|---|---|---|
| Right to be Informed | Organisations must tell you what data they collect and why | Privacy notices at sign-up |
| Right of Access | Get a copy of the personal data held about you | Subject Access Request (SAR) |
| Right to Rectification | Correct inaccurate or incomplete data | Fixing wrong address at your bank |
| Right to Erasure | "Right to be forgotten" — deletion of your data | Closing an old social media account |
| Right to Restrict Processing | Pause how your data is used | Dispute over data accuracy |
| Right to Data Portability | Receive your data in a reusable format | Switching between service providers |
| Right to Object | Stop specific processing, especially marketing | Opting out of direct marketing |
| Rights Around Automated Decisions | Human review of decisions made by algorithms | Credit scoring or job screening |
1. The Right to Be Informed
Before an organisation collects your data, it must clearly tell you who they are, what data they want, why they need it, how long they'll keep it, and who they'll share it with. This is why you see privacy notices and cookie banners on Irish websites. If a privacy policy is vague, misleading, or hidden behind ten clicks, that's a potential GDPR breach.
2. The Right of Access (Subject Access Requests)
You can ask any organisation to send you a copy of all personal data they hold about you. This is called a Subject Access Request (SAR). You don't need to give a reason. The organisation has one month to respond, and it must be free unless your request is manifestly excessive.
3. The Right to Rectification
If a company holds inaccurate information about you — a misspelled name, out-of-date address, or incorrect financial details — you can demand they correct it. This is particularly important for credit reference agencies, insurance providers, and healthcare records in Ireland.
4. The Right to Erasure
Also known as the "right to be forgotten," this lets you request deletion of your data in certain circumstances: when the data is no longer needed, when you withdraw consent, when you object to processing, or when the data has been processed unlawfully. There are exceptions — organisations can refuse if they have a legal obligation to retain records (for example, Revenue tax records).
5. The Right to Restrict Processing
You can ask an organisation to stop actively using your data without deleting it. This is useful when you're contesting the accuracy of your data or objecting to its use — the organisation must "freeze" processing until the issue is resolved.
6. The Right to Data Portability
Where processing is based on consent or a contract and carried out automatically, you can request your data in a structured, commonly used, machine-readable format (like CSV or JSON). You can then transfer it to another service. This right underpins competition between banks (open banking), streaming services, and social platforms.
7. The Right to Object
You have an absolute right to object to your data being used for direct marketing — no ifs, no buts. You can also object to processing based on "legitimate interests" or public tasks, though organisations may be able to justify continuing in narrow cases.
8. Rights Related to Automated Decision-Making
If a fully automated system makes a significant decision about you — approving a loan, filtering a job application, setting insurance premiums — you have the right to human review, to express your point of view, and to contest the decision.
How to Make a Subject Access Request in Ireland
A Subject Access Request is the most commonly used GDPR right. Here's how to submit one effectively:
- Identify the data controller. Look at the organisation's privacy policy to find the correct contact — usually a Data Protection Officer (DPO) or a dedicated privacy email address.
- Write your request clearly. State that you're making a request under Article 15 of the GDPR. Include your full name, any account details, and the timeframe you're interested in.
- Verify your identity. The organisation may ask for proof of identity — this is legitimate, but they shouldn't demand excessive documentation.
- Wait up to one month. Responses must be provided within 30 days. Complex requests can be extended by two additional months, but the organisation must notify you.
- Review the response. Check whether the data provided seems complete. If categories are missing (for example, no marketing profiles or no cookie data), you can push back.
Templates are available on the Data Protection Commission website at dataprotection.ie, and many are free to use.
The Role of the Data Protection Commission (DPC)
The DPC is Ireland's independent supervisory authority for GDPR. Based on Fitzwilliam Square in Dublin, it handles complaints, investigates breaches, issues fines, and provides guidance to both individuals and organisations.
How to File a Complaint With the DPC
If an organisation refuses your request, ignores you, or you believe your data has been misused, you can complain to the DPC. The process is:
- Contact the organisation first and give them a chance to respond — the DPC generally expects this step.
- If unsatisfied, submit a complaint through the DPC's online portal, by post, or by email to info@dataprotection.ie.
- Include copies of correspondence, dates, and a clear explanation of what went wrong.
- The DPC will assess the complaint and may attempt to resolve it amicably before opening a formal inquiry.
Enforcement and Fines
The DPC has issued some of the largest GDPR fines in Europe, including multi-hundred-million-euro penalties against major tech platforms. Fines can reach up to €20 million or 4% of global annual turnover, whichever is higher.
Common GDPR Issues Irish Consumers Face
Understanding your rights is one thing — recognising when they're being violated is another. Here are frequent issues Irish residents encounter:
- Unwanted marketing: Continued emails or SMS after you've unsubscribed. This also breaches the ePrivacy Regulations 2011.
- Cookie walls: Websites forcing you to accept all cookies to access content. The DPC has ruled that consent must be freely given.
- Data breaches: When organisations lose or expose your data. They must notify the DPC within 72 hours and notify you if there's a high risk to your rights.
- Excessive data collection: Apps requesting permissions or information they don't genuinely need.
- Opaque profiling: Being targeted with ads, prices, or content based on behavioural profiles you never knowingly agreed to.
Practical Steps to Protect Your Privacy in Ireland
GDPR gives you legal rights, but proactive habits keep your data footprint small in the first place. Consider these steps:
- Read privacy notices selectively. Focus on the "what we share" and "how long we keep it" sections.
- Use encrypted DNS services like Cloudflare's 1.1.1.1 or NextDNS to reduce network-level tracking.
- Choose privacy-respecting browsers such as Firefox or Brave, with tracker blocking enabled.
- Review app permissions on iOS and Android monthly — revoke access to location, contacts, and microphone where not essential.
- Use link tools that don't harvest data. When sharing links, a privacy-conscious shortener like Lunyb keeps your click data minimal rather than building marketing profiles. You can read more in this honest review of Lunyb or compare options in the 2026 buyer's guide to URL shorteners.
- Enable two-factor authentication on your email and banking accounts to reduce breach impact.
GDPR for Small Businesses and Sole Traders in Ireland
If you run a business in Ireland — even a one-person consultancy — GDPR applies to you the moment you process personal data about clients, staff, or newsletter subscribers. Key obligations include maintaining a record of processing activities, having a lawful basis for each type of processing, publishing a clear privacy notice, and reporting eligible data breaches to the DPC within 72 hours.
Small businesses often assume GDPR is only for tech giants — that's a costly mistake. The DPC regularly investigates SMEs, particularly around marketing consent and CCTV use. Investing a few hours in proper documentation protects you from complaints and fines.
Frequently Asked Questions
Is GDPR still enforced in Ireland after Brexit?
Yes. Ireland remains a full member of the EU, so GDPR applies without change. Brexit affected the UK, which now operates under its own "UK GDPR," but for anyone living in Ireland the EU GDPR continues in force through the Data Protection Act 2018.
How long does an organisation have to respond to my Subject Access Request?
Organisations must respond within one calendar month of receiving your request. They can extend this by two further months for complex or numerous requests, but they must tell you within the first month and explain the reason for the delay.
Can I be charged a fee to access my personal data?
Generally no. Subject Access Requests are free. An organisation can only charge a "reasonable fee" or refuse a request if it is manifestly unfounded or excessive — for example, if you submit repeated identical requests. The burden is on the organisation to justify any refusal.
What happens if a company ignores my GDPR request?
First, follow up in writing and reference the one-month deadline under Article 12 of the GDPR. If you still get no response, you can lodge a complaint with the Data Protection Commission at dataprotection.ie. The DPC can compel the organisation to comply and, in serious cases, impose administrative fines.
Do I have GDPR rights against foreign websites that don't have an office in Ireland?
Yes, if they offer goods or services to people in the EU or monitor their behaviour. GDPR has extraterritorial reach. Non-EU organisations must appoint an EU representative you can contact. In practice, enforcement against overseas companies with no EU presence can be slower, but your rights still exist in law.
Final Thoughts
GDPR gives Irish residents genuine, enforceable power over their personal data — but rights only matter when you use them. Whether that means sending a Subject Access Request to a former employer, unsubscribing from an aggressive marketing list, or filing a complaint with the DPC when something goes wrong, exercising your rights signals to organisations that privacy is not optional. Combine legal awareness with sensible digital habits, and you'll navigate the modern data economy on your own terms.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
DPC Ireland: How to File a Privacy Complaint (2026 Guide)
Learn how to file a privacy complaint with Ireland's Data Protection Commission (DPC). This step-by-step guide covers evidence gathering, submission channels, timelines, and what happens after you complain under GDPR.
Data Protection Act 2018 Ireland: Complete Guide
A complete guide to Ireland's Data Protection Act 2018, covering its relationship with the GDPR, individual rights, business obligations, DPC enforcement powers, and penalties. Learn what your organisation needs to do to stay compliant.
Singapore PDPA vs GDPR: Key Differences for Businesses in 2026
Singapore's PDPA and the EU's GDPR both protect personal data but differ significantly in scope, consent standards, penalties, and rights. This guide compares the two frameworks side-by-side so businesses can build a compliance strategy that works across borders.
PIPEDA vs GDPR: Canadian Privacy Law Explained (2026 Guide)
PIPEDA and the GDPR both protect personal data, but they differ sharply on consent, individual rights, and enforcement. This guide compares both laws side by side and offers a practical compliance checklist for Canadian businesses in 2026.