facebook-pixel

GDPR in Ireland: Your Privacy Rights Explained (2026 Guide)

L
Lunyb Security Team
··11 min read

Ireland sits at the heart of European data protection. With Dublin hosting the EU headquarters of Google, Meta, TikTok, Microsoft, LinkedIn, and Apple, the Irish Data Protection Commission (DPC) is one of the most influential privacy regulators in the world. For Irish residents, that means your personal data rights under the General Data Protection Regulation (GDPR) are not just theoretical — they are actively enforced on your doorstep.

This guide explains, in plain English, what GDPR means for people living in Ireland, the eight rights it gives you, how to use them, and what to do if a company ignores you. Whether you want to delete an old social media profile, stop receiving marketing emails, or find out what a business knows about you, the rules below are the tools you need.

What Is GDPR and How Does It Apply in Ireland?

The General Data Protection Regulation (GDPR) is an EU-wide law, in force since 25 May 2018, that governs how organisations collect, store, and use personal data about living individuals. In Ireland it is implemented alongside the Data Protection Act 2018, and enforced by the Data Protection Commission based in Dublin and Portarlington.

GDPR applies to any organisation — Irish or foreign — that processes the personal data of people in Ireland. That includes a local GAA club storing member phone numbers, a shop running a loyalty scheme, your employer, your bank, and global platforms like Instagram or Amazon. If they handle your data, they must follow the rules.

What Counts as "Personal Data"?

Personal data is any information that can identify a living person, directly or indirectly. In an Irish context this includes:

  • Your name, address, Eircode, and phone number
  • Your PPS number
  • Your email address and IP address
  • Photos, CCTV footage, and voice recordings
  • Bank account details and transaction history
  • Medical records held by your GP or HSE
  • Location data from your phone or car
  • Cookies and online identifiers used for tracking

Some categories receive extra protection, called "special category data" — including health information, racial or ethnic origin, religious beliefs, trade union membership, sexual orientation, and biometric data.

Your Eight GDPR Rights in Ireland

GDPR gives every person in Ireland eight enforceable rights over their personal data. You can exercise them with any organisation (the "data controller") that holds information about you, usually free of charge, and they must respond within one month.

RightWhat It Lets You DoTypical Use Case
1. Right to be informedKnow what data is collected and whyReading a privacy notice on a website
2. Right of accessGet a copy of your dataSubject Access Request to your bank
3. Right to rectificationCorrect inaccurate dataFixing a wrong address on insurance records
4. Right to erasureHave data deleted ("right to be forgotten")Closing an old online account
5. Right to restrict processingPause use of your dataWhile a dispute is being resolved
6. Right to data portabilityReceive data in a reusable formatMoving contacts between providers
7. Right to objectStop certain processing, especially marketingUnsubscribing from direct marketing
8. Rights around automated decisionsChallenge decisions made purely by algorithmCredit scoring or automated recruitment

1. The Right to Be Informed

Every organisation must tell you, in clear language, what personal data they collect, why, how long they keep it, who they share it with, and what your rights are. This is normally delivered through a privacy notice or privacy policy. In Ireland, the DPC expects these notices to be concise, transparent, and easily accessible — not buried in legal jargon.

2. The Right of Access (Subject Access Request)

You can ask any organisation for a copy of all personal data they hold about you. This is known as a Subject Access Request (SAR). You do not need to give a reason, and in almost all cases it must be provided free of charge within one calendar month.

What you can expect to receive:

  1. A copy of the personal data itself
  2. The purposes for which it is being processed
  3. The categories of data concerned
  4. Who it has been shared with, including transfers outside the EEA
  5. How long it will be kept
  6. The source of the data if it did not come from you

3. The Right to Rectification

If data about you is inaccurate or incomplete, you have the right to have it corrected. This is especially important for financial services, insurance quotes, and health records held by the HSE or private providers.

4. The Right to Erasure

Often called the "right to be forgotten", this lets you ask for your data to be deleted when, for example, it is no longer needed, you withdraw consent, or it was processed unlawfully. It is not absolute — a bank, Revenue, or employer may need to retain certain records for legal reasons (such as the seven-year retention required under Irish tax law).

5. The Right to Restrict Processing

You can ask an organisation to pause using your data while, for example, you dispute its accuracy. They can still store it, but cannot actively use it until the issue is resolved.

6. The Right to Data Portability

Where processing is based on consent or a contract and is carried out automatically, you can request your data in a structured, commonly used, machine-readable format (such as CSV or JSON) — and ask that it be sent directly to another provider where technically feasible.

7. The Right to Object

You have an absolute right to object to your data being used for direct marketing. For other purposes, such as processing based on "legitimate interests", you can object and the controller must stop unless they can show compelling grounds to continue.

8. Rights Related to Automated Decision-Making

If a decision that significantly affects you — such as a loan approval, insurance premium, or job application screening — is made solely by an automated system, you have the right to human intervention, to express your point of view, and to contest the decision.

How to Make a GDPR Request in Ireland

Exercising your rights is deliberately simple. There is no official form and no fee for the first request. Here is a practical step-by-step process that works for almost any organisation operating in Ireland.

  1. Identify the data controller. This is the organisation that decides how and why your data is used. Their contact details should be in the privacy policy.
  2. Find the Data Protection Officer (DPO). Public bodies and large processors must appoint one. The DPO's email is usually something like dpo@company.ie.
  3. Write a clear request. State your name, what right you are exercising (e.g. "I am making a Subject Access Request under Article 15 GDPR"), and provide enough detail to identify your records.
  4. Prove your identity. The controller may ask for reasonable ID to make sure they are not giving your data to someone else.
  5. Wait up to one month. They can extend by two further months for complex requests but must tell you why.
  6. Escalate if ignored. If you receive no response, an inadequate response, or a refusal you disagree with, complain to the DPC.

Sample Subject Access Request Email

"Dear Data Protection Officer, under Article 15 of the GDPR, I would like to request a copy of all personal data you hold about me, together with information on how it has been used, who it has been shared with, and how long it will be retained. My name is [Name], my date of birth is [DOB], and my account/customer reference is [number]. Please acknowledge receipt and respond within one month. Kind regards, [Name]."

The Irish Data Protection Commission (DPC)

The DPC is the national independent authority responsible for upholding data protection rights in Ireland. Because so many global tech companies have their EU base in Dublin, the DPC acts as the "lead supervisory authority" for cross-border complaints across the EU — which is why Irish decisions often make international headlines.

How to Complain to the DPC

If an organisation does not respond to your request or you believe your rights have been breached, you can lodge a free complaint with the DPC. You do not need a solicitor.

  • Online: via the complaint form on dataprotection.ie
  • By post: 21 Fitzwilliam Square South, Dublin 2, D02 RD28, or Canal House, Station Road, Portarlington, Co. Laois, R32 AP23
  • By email: info@dataprotection.ie

Include copies of your original request, the organisation's reply (or evidence of silence), and a short description of the issue. The DPC will usually attempt amicable resolution first before launching a formal investigation.

Potential Outcomes and Fines

The DPC can issue warnings, reprimands, enforcement notices, and administrative fines of up to €20 million or 4% of annual global turnover, whichever is higher. Recent years have seen record fines against Meta, TikTok, and WhatsApp Ireland running into hundreds of millions of euro — proof that Irish enforcement has real teeth.

Common GDPR Scenarios for Irish Residents

CCTV at Work or in Your Estate

Employers and management companies using CCTV must have a clear lawful basis, display signage, limit retention (usually 28 days), and let you request footage of yourself. Covert surveillance of staff is almost always unlawful.

Marketing Calls, Texts and Emails

Under GDPR and the ePrivacy Regulations 2011, Irish businesses need your consent before sending electronic marketing. You can withdraw consent at any time, and persistent nuisance marketing can be reported to the DPC and may be prosecuted.

Online Tracking and URL Shorteners

Every link you click can be logged, profiled, and sold. When you share links yourself — on social media, in newsletters, or over WhatsApp — the shortener you choose becomes a data controller too. Privacy-first tools such as Lunyb minimise the personal data collected on click-throughs, which matters if you want your own sharing habits to stay GDPR-friendly. For a wider comparison, see our 2026 buyer's guide to URL shorteners and our honest review of Lunyb.

Health Data and the HSE

You have the right to access your medical records held by GPs, hospitals, and the HSE. Special category data receives the strongest protection, and sharing between providers normally requires either your consent or a specific legal basis.

Children's Data

In Ireland, the digital age of consent is 16. Online services relying on consent to process a child's data must obtain parental authorisation below that age. The DPC's "Fundamentals for a Child-Oriented Approach to Data Processing" sets specific expectations for platforms likely to be accessed by minors.

Practical Tips to Protect Your Data Day-to-Day

  1. Read privacy notices before signing up — focus on retention periods and third-party sharing.
  2. Use unique, strong passwords and a reputable password manager.
  3. Enable two-factor authentication on banking, email, and Revenue myAccount.
  4. Reject non-essential cookies — Irish law requires an equally easy "Reject All" option.
  5. Audit app permissions on your phone every few months.
  6. Share privacy-respecting links rather than tracker-heavy ones when posting publicly.
  7. Keep records of GDPR requests you make — dates, recipients, and responses.

What GDPR Does Not Cover

GDPR is powerful but not unlimited. It does not apply to:

  • Personal or household activity (your own phone contacts, family photos)
  • Data about deceased persons (though separate Irish rules apply)
  • Anonymous data that cannot be linked back to you
  • Certain national security and law enforcement processing, which has its own regime

Journalistic, academic, artistic, and literary expression also benefit from specific exemptions under the Data Protection Act 2018 to balance privacy against freedom of expression.

FAQ: GDPR Privacy Rights in Ireland

How long does a company have to respond to my GDPR request in Ireland?

One calendar month from receipt. They can extend by up to two further months for complex or numerous requests, but they must inform you of the extension and the reasons within the first month.

Can I be charged for a Subject Access Request?

No, not for a first request. A "reasonable fee" is only permitted if a request is manifestly unfounded, excessive, or repetitive — and the organisation must be able to justify this. In practice, almost all SARs in Ireland are handled free of charge.

What happens if I complain to the Data Protection Commission?

The DPC will typically acknowledge your complaint, try to resolve it amicably with the organisation, and if unsuccessful may open a formal inquiry. Outcomes can include corrective orders, reprimands, or administrative fines. You can also seek compensation through the courts for damage caused by a breach.

Does GDPR apply to small Irish businesses and sole traders?

Yes. There is no small-business exemption. However, obligations are proportionate — a one-person consultancy will not need the same documentation as a bank. Keeping a simple record of processing activities, having a clear privacy notice, and responding promptly to data subject requests covers the essentials.

Can I ask Google or Facebook to delete my data from Ireland?

Yes. Because their European headquarters are in Dublin, Irish residents deal directly with the Irish entities of these platforms, and the DPC is the lead regulator. Each service has an online privacy dashboard where you can submit erasure, access, and objection requests, and you can escalate to the DPC if you are unhappy with the outcome.

Final Thoughts

GDPR gives people living in Ireland some of the strongest privacy rights in the world — and the DPC gives those rights real force. Understanding the eight rights, knowing how to send a short, confident email to a data controller, and being willing to escalate to the DPC when needed puts you in control of your digital footprint.

Privacy is not just about hiding; it is about choice. Every time you decide what to share, which services to trust, and which links to click or send, you are exercising rights that millions of people across Europe fought to secure. Use them.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles