facebook-pixel

GDPR in Ireland: Your Privacy Rights Explained

L
Lunyb Security Team
··10 min read

Ireland sits at the heart of Europe's data protection landscape. As home to the European headquarters of Google, Meta, TikTok, Apple, and many other global tech firms, the Irish Data Protection Commission (DPC) has become one of the most influential regulators under the General Data Protection Regulation (GDPR). For everyday people living in Ireland, this legal framework grants powerful rights over how personal information is collected, stored, and shared.

This guide explains your GDPR privacy rights in Ireland in plain language, how to exercise them, and what to do when a company or public body gets it wrong.

What is GDPR and How Does It Apply in Ireland?

The General Data Protection Regulation (GDPR) is an EU-wide law that came into effect on 25 May 2018. It sets uniform rules for how personal data must be handled by organisations operating in or targeting the European Union. In Ireland, the GDPR is supplemented by the Data Protection Act 2018, which handles national-specific provisions such as children's consent age, law enforcement processing, and DPC enforcement powers.

The regulation applies to any organisation — Irish or foreign — that processes the personal data of people located in Ireland. This includes online shops, social media platforms, employers, hospitals, banks, schools, and even small local clubs that keep membership lists.

Who Enforces GDPR in Ireland?

The Data Protection Commission (DPC), headquartered in Dublin, is Ireland's independent supervisory authority. Because so many US tech giants have their European base in Ireland, the DPC acts as the "lead supervisory authority" for cross-border complaints against them under the GDPR's one-stop-shop mechanism.

What Counts as Personal Data?

Personal data is any information that can identify a living person, directly or indirectly. Under Irish and EU law this includes obvious details and many less obvious ones.

  • Name, address, phone number, and email address
  • PPS number, passport number, or driving licence
  • IP addresses, cookie identifiers, and device IDs
  • Location data from a smartphone
  • Photos, CCTV footage, and voice recordings
  • Health records, biometric data, and genetic information
  • Political opinions, religious beliefs, or trade union membership

The last category — known as special category data — receives extra protection and can normally only be processed with explicit consent or under narrow legal grounds.

Your Eight Core GDPR Rights in Ireland

Every person in Ireland has eight enforceable rights under the GDPR. These apply regardless of citizenship — a tourist, student, or worker on a stamp 1 permit has the same protection as an Irish national.

1. The Right to Be Informed

Organisations must tell you, in clear language, what data they collect, why, how long they keep it, who they share it with, and what your rights are. This is typically delivered through a privacy notice on a website or handed to you when you sign a contract.

2. The Right of Access

You can request a copy of all personal data an organisation holds about you. This is called a Subject Access Request (SAR). The organisation must respond within one month and free of charge in most cases.

3. The Right to Rectification

If your data is inaccurate or incomplete, you can require the controller to correct or complete it without undue delay.

4. The Right to Erasure ("Right to Be Forgotten")

You can ask for your data to be deleted when it is no longer necessary, when you withdraw consent, or when processing was unlawful. This right is not absolute — public interest, legal obligations, or freedom of expression can override it.

5. The Right to Restrict Processing

You can pause the use of your data while a dispute is being resolved, for example while you contest the accuracy of a credit record.

6. The Right to Data Portability

You can obtain your data in a structured, commonly used, machine-readable format (such as CSV or JSON) and have it transferred to another provider. This is particularly relevant for banking, streaming services, and social media.

7. The Right to Object

You can object to processing based on legitimate interests or public task, and — importantly — you have an absolute right to object to direct marketing at any time.

8. Rights Related to Automated Decision-Making

You have the right not to be subject to a decision based solely on automated processing — including profiling — that produces legal or similarly significant effects. Common examples include automatic loan refusals or algorithmic hiring decisions.

Legal Bases for Processing: When Can Companies Use Your Data?

Organisations must have one of six legal bases to process your data. Understanding these helps you know when you can push back.

Legal BasisTypical Use in IrelandCan You Withdraw?
ConsentMarketing emails, non-essential cookiesYes, at any time
ContractDelivering an online order, employmentNo, but you can end the contract
Legal obligationRevenue tax reporting, AML checks by banksNo
Vital interestsEmergency medical treatmentNo
Public taskHSE, local councils, An Garda SíochánaLimited
Legitimate interestsFraud prevention, basic analyticsYou can object

How to Make a Subject Access Request in Ireland

A Subject Access Request is the most commonly used GDPR right. Here is a step-by-step approach that works with any Irish or EU-based controller.

  1. Identify the controller. Find the organisation's data protection contact, usually listed in the privacy policy or with a Data Protection Officer (DPO) email.
  2. Put the request in writing. Email is fine. State clearly that you are making a request under Article 15 of the GDPR.
  3. Prove your identity. The controller may ask for reasonable verification, such as matching an account email.
  4. Be specific if you can. Narrowing the request (e.g. "call recordings from January to March 2025") speeds things up.
  5. Wait up to one month. The deadline can be extended by two additional months for complex requests, but the controller must tell you why.
  6. Escalate if ignored. If you receive no reply, or an inadequate one, complain to the DPC.

Sample SAR Wording

"Dear Data Protection Officer, I am writing to make a Subject Access Request under Article 15 of the GDPR. Please provide me with a copy of all personal data you hold about me, along with the information required by Article 15(1)(a)-(h). My account email is [address]. I look forward to your response within one month."

Cookies, Tracking, and ePrivacy in Ireland

Alongside the GDPR, the ePrivacy Regulations 2011 (S.I. No. 336/2011) govern cookies and electronic marketing in Ireland. Websites must obtain freely given, specific, informed consent before storing non-essential cookies on your device. The DPC has issued detailed guidance making clear that pre-ticked boxes, cookie walls, and "continued browsing = consent" are not lawful.

In practice this means every Irish-facing website should offer a genuine "Reject All" option that is as easy to click as "Accept All". If it does not, you have grounds to complain.

Protecting Your Data When Sharing Links

Whenever you click a link, information such as your IP address, browser type, and referrer can be logged by the destination and any redirect service in between. Choosing tools that minimise data collection matters. Privacy-conscious link shorteners such as Lunyb avoid heavy third-party trackers and give users transparent control over analytics — a small but meaningful step towards data minimisation as encouraged by GDPR Article 5. You can read an independent view in our honest review of Lunyb, or compare alternatives in our 2026 URL shortener buyer's guide.

Data Breaches: What Should Happen When Things Go Wrong

If an organisation suffers a personal data breach that is likely to result in a risk to your rights and freedoms, it must:

  • Notify the DPC within 72 hours of becoming aware of it.
  • Notify affected individuals without undue delay if the risk is high.
  • Document the breach internally, whether reportable or not.

Common breaches reported in Ireland include misdirected emails, ransomware attacks on healthcare providers, lost laptops, and unauthorised staff access to records. The DPC publishes an annual report showing thousands of breach notifications each year.

How to Complain to the Data Protection Commission

If a controller ignores you or handles your data unlawfully, you can lodge a complaint with the DPC. This is free of charge.

  1. Try to resolve the issue directly with the organisation first — the DPC expects this.
  2. Gather evidence: emails, screenshots, dates, and copies of any privacy notice.
  3. Submit a complaint via the DPC's online webform at dataprotection.ie, by email to info@dataprotection.ie, or by post to 21 Fitzwilliam Square South, Dublin 2, D02 RD28.
  4. The DPC will assess admissibility, may attempt amicable resolution, and can open a formal inquiry.
  5. Outcomes range from reprimands and compliance orders to administrative fines of up to €20 million or 4% of global turnover.

Can You Sue for Compensation?

Yes. Under Article 82 of the GDPR and Section 117 of the Data Protection Act 2018, you can bring a civil action in the Circuit Court for material or non-material damage — including distress — caused by a breach of your rights. Recent Irish case law (including Kaminski v Ballymaguire Foods) has confirmed that damages are available but must be evidenced.

Special Rules for Children in Ireland

Ireland set the digital age of consent at 16. Children under 16 cannot lawfully consent to online services relying on consent as their legal basis; a parent or guardian must consent on their behalf. The DPC's Fundamentals for a Child-Oriented Approach to Data Processing sets out 14 principles that platforms serving under-18s must follow, including a "floor of protection" for all users to avoid age-gating being used as a workaround.

International Data Transfers After Schrems II

Because Ireland hosts so many US-based platforms, transfers of personal data to the United States are a hot topic. Following the Schrems II ruling and the 2023 EU-US Data Privacy Framework, transfers to certified US companies are once again lawful — but the DPC continues to monitor safeguards closely. You have the right to know if your data leaves the EEA and what protections apply.

Practical Tips to Exercise Your Rights

  • Use a dedicated email address when signing up for services so you can track who shares your data.
  • Review privacy dashboards on Google, Meta, and Apple accounts at least once a year.
  • Reject non-essential cookies by default — it is your legal right.
  • Keep copies of any consent you give and any notices you receive.
  • If you receive unwanted marketing, reply once objecting under Article 21; further contact is then unlawful.

Frequently Asked Questions

Does GDPR apply to me if I live in Ireland but the company is based abroad?

Yes. The GDPR applies to any organisation offering goods or services to people in the EU or monitoring their behaviour, regardless of where the company is headquartered. You can complain to the Irish DPC, which will coordinate with other EU regulators if needed.

How long does a company have to respond to my data request?

One calendar month from receipt of your request. This can be extended by a further two months for complex or numerous requests, but the controller must notify you of the extension and the reason within the original month.

Can my employer read my work emails under GDPR?

Employers can monitor work communications only where it is necessary, proportionate, and transparent. They must inform staff in advance through a clear policy, minimise intrusion, and have a valid legal basis — usually legitimate interests. Blanket, covert monitoring is generally unlawful.

Is it free to make a Subject Access Request in Ireland?

Yes, in almost all cases. A controller can only charge a "reasonable fee" or refuse the request if it is manifestly unfounded or excessive, particularly if repetitive. The controller must justify any refusal or charge.

What happens if a company refuses to delete my data?

They must give you a reason in writing, referencing the GDPR ground they rely on (for example, a legal retention obligation). If you disagree, you can complain to the DPC and, ultimately, bring a case in the Circuit Court for compensation or a court order.

Conclusion

The GDPR gives people in Ireland some of the strongest privacy rights in the world, and the Data Protection Commission has the powers — and increasingly the willingness — to enforce them. Knowing your eight core rights, understanding the legal bases companies rely on, and being ready to make a Subject Access Request or file a complaint turns those rights from theory into practice. Data protection is not just paperwork; it is a fundamental part of daily life in a digital Ireland, and it belongs to you.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles