facebook-pixel

GDPR in Ireland: Your Privacy Rights Explained (2026 Guide)

L
Lunyb Security Team
··10 min read

Ireland sits at the heart of European data protection enforcement. With most of the world's largest technology companies headquartered in Dublin, the Irish Data Protection Commission (DPC) is effectively the lead regulator for how your personal data is handled across the EU. That makes understanding your GDPR rights in Ireland particularly important — not just for Irish residents, but for anyone whose data flows through Irish-based platforms.

This guide explains what the General Data Protection Regulation means for you in practice, what rights you can exercise, and how to take action if a company fails to respect them.

What Is GDPR and How Does It Apply in Ireland?

The General Data Protection Regulation (GDPR) is an EU-wide law that came into force on 25 May 2018. In Ireland, it is implemented and extended through the Data Protection Act 2018, which fills in national details such as the age of digital consent (16 in Ireland) and the powers of the DPC.

GDPR applies whenever an organisation processes the personal data of people in the EU, regardless of where that organisation is based. "Personal data" is defined very broadly — it includes your name, email address, IP address, location data, device identifiers, photos, voice recordings, and even online behaviour patterns that could identify you.

Who Enforces GDPR in Ireland?

The Data Protection Commission (DPC), based in Dublin and Portarlington, is Ireland's independent supervisory authority. It investigates complaints, conducts audits, and issues binding decisions — including fines of up to €20 million or 4% of a company's global annual turnover, whichever is higher. Because so many multinational tech firms have their European headquarters in Ireland, the DPC often acts as the "lead supervisory authority" for cross-border cases affecting people across the EU.

Your Eight Core GDPR Rights

GDPR grants you eight specific rights over your personal data. Every organisation that processes your information must respect these rights and respond to requests within one month (extendable by two months for complex cases).

1. The Right to Be Informed

Organisations must tell you clearly what data they collect, why they collect it, how long they keep it, who they share it with, and the legal basis for processing. This is usually delivered through a privacy notice or privacy policy. If a policy is vague, impossible to find, or written in impenetrable legalese, that itself may be a GDPR breach.

2. The Right of Access (Subject Access Request)

You can ask any organisation for a copy of the personal data they hold about you. This is known as a Subject Access Request (SAR). The response must be free of charge in most cases and provided within 30 days. The data must be delivered in a readable format, together with information about how it is being used.

3. The Right to Rectification

If a company holds incorrect or incomplete information about you, you can require them to fix it. This applies to anything from a misspelled name to inaccurate credit scoring data or outdated employment records.

4. The Right to Erasure ("Right to Be Forgotten")

You can request deletion of your personal data when: it is no longer needed for the original purpose, you withdraw consent, you object to processing, or the data has been processed unlawfully. This right is not absolute — organisations can refuse if they have a legal obligation to retain the data (for example, tax or financial records).

5. The Right to Restrict Processing

Instead of full deletion, you can ask an organisation to "pause" the use of your data while a dispute is resolved — for instance, while they verify whether information is accurate or whether their legal basis for processing is valid.

6. The Right to Data Portability

You can request your data in a structured, commonly used, machine-readable format (such as JSON or CSV) and have it transferred to another service provider. This right applies to data you provided yourself and that is processed by automated means based on consent or a contract.

7. The Right to Object

You can object to processing based on legitimate interests, direct marketing, or scientific/historical research. For direct marketing, your objection is absolute — the organisation must stop immediately with no exceptions.

8. Rights Related to Automated Decision-Making

If a decision that significantly affects you is made purely by an algorithm — such as an automated loan refusal or an AI-driven job screening rejection — you have the right to request human review, express your point of view, and contest the decision.

Quick Reference: Your Rights at a Glance

RightWhat It MeansResponse Time
Be InformedReceive clear information about data useAt point of collection
AccessGet a copy of your data30 days
RectificationCorrect inaccurate data30 days
ErasureHave data deleted30 days
Restrict ProcessingPause use of your data30 days
Data PortabilityReceive data in reusable format30 days
ObjectStop certain processing activitiesImmediate for marketing
Automated DecisionsRequest human review30 days

Lawful Bases for Processing Your Data

Under GDPR, an organisation cannot simply decide to collect your data because it is useful to them. They must identify one of six lawful bases before processing begins:

  1. Consent — you freely gave specific, informed, unambiguous permission.
  2. Contract — processing is necessary to perform a contract with you (e.g. delivering a product you ordered).
  3. Legal obligation — the organisation must process your data to comply with a law.
  4. Vital interests — processing is needed to protect someone's life.
  5. Public task — processing is carried out in the public interest or official authority.
  6. Legitimate interests — the organisation has a genuine interest that is not overridden by your rights.

Marketing emails, website analytics, and tracking cookies almost always require your freely given consent. A pre-ticked box, a cookie banner with no "reject" option, or burying consent in a 40-page terms document does not meet GDPR's standard.

How to Make a Subject Access Request in Ireland

Submitting a SAR is one of the most practical ways to exercise your rights. Here is a step-by-step process:

  1. Identify the data controller. This is the organisation that decides how and why your data is processed. Check their privacy policy for a Data Protection Officer (DPO) contact.
  2. Write a clear request. State that you are making a Subject Access Request under Article 15 of GDPR. You do not need to use any specific template.
  3. Verify your identity. The controller may ask for ID to confirm you are who you say you are. This should be proportionate — a passport scan is usually excessive for low-risk data.
  4. Specify what you want. You can request everything, or narrow it to a specific time period or type of data (e.g. "all CCTV footage from 15 January").
  5. Wait up to 30 days. If the request is complex, the controller can extend by two months but must notify you.
  6. Review the response. Check whether all categories of data were provided, including recipients, retention periods, and the source of the data.

What to Do If an Organisation Does Not Comply

If a company ignores your request, provides an incomplete response, or refuses without a valid reason, you have options:

Step 1: Complain Directly

First, raise the issue in writing with the organisation's DPO or privacy team. Many disputes are resolved at this stage, especially where the failure was administrative.

Step 2: Lodge a Complaint with the DPC

If the response is still unsatisfactory, you can submit a formal complaint to the Data Protection Commission via dataprotection.ie. The complaint is free, and the DPC will investigate and attempt to resolve the matter. You will usually be asked to show that you tried to resolve it directly first.

Step 3: Seek Compensation

GDPR Article 82 gives you the right to seek compensation through the Irish courts for material or non-material damage — including distress — caused by a breach. This is a growing area of case law in Ireland.

Protecting Your Privacy Beyond Formal Rights

GDPR provides a powerful legal framework, but reducing the amount of data you expose in the first place is just as important. Practical measures include:

  • Using a privacy-focused browser such as Firefox or Brave, with tracker blocking enabled.
  • Switching to encrypted DNS services (such as DNS-over-HTTPS) to prevent your internet provider from logging every site you visit.
  • Reviewing cookie banners carefully and rejecting non-essential tracking.
  • Using disposable email addresses or aliases for sign-ups you don't fully trust.
  • Choosing link and sharing tools that minimise tracking. For example, a privacy-conscious URL shortener like Lunyb lets you share links without the heavy third-party analytics that many legacy shorteners embed. You can learn more in our honest Lunyb review or compare options in our 2026 buyer's guide.
  • Checking app permissions regularly on your phone and revoking anything that isn't essential.

Special Considerations for Children and Sensitive Data

Ireland sets the digital age of consent at 16. Below that age, parental consent is required for information society services relying on consent as their lawful basis. The DPC has published a "Fundamentals for a Child-Oriented Approach to Data Processing," which organisations serving children must follow.

So-called "special category data" — including racial or ethnic origin, political opinions, religious beliefs, trade union membership, genetic or biometric data, health information, and data about sexual orientation — enjoys stronger protection. Processing is prohibited unless one of the specific exceptions in Article 9 applies.

GDPR in the Workplace

Employers in Ireland are among the most frequent subjects of DPC complaints. If you work for an Irish employer, you have the right to know what data they hold about you, including:

  • Email monitoring logs
  • CCTV footage
  • Performance reviews and HR notes
  • Access card and location data
  • Communications sent via workplace platforms

Employers must be transparent about surveillance, carry out Data Protection Impact Assessments (DPIAs) for high-risk processing, and ensure monitoring is proportionate.

Recent Enforcement Trends in Ireland

The DPC has issued some of the largest GDPR fines in Europe, including multi-hundred-million-euro penalties against major social media and messaging platforms for issues ranging from unlawful cross-border data transfers to inadequate transparency and children's privacy failings. These decisions matter because they shape how companies worldwide design their products — if a feature cannot pass muster with the DPC, it typically has to change globally.

Frequently Asked Questions

Is GDPR still relevant after Brexit?

Absolutely. GDPR continues to apply in full across all EU member states, including Ireland. The UK has its own "UK GDPR" which is similar but increasingly diverging. If you are in Ireland, EU GDPR and the Irish Data Protection Act 2018 are the laws that protect you.

How long do I have to wait for a response to a Subject Access Request?

Organisations must respond within one calendar month of receiving your request. They can extend this by up to two further months for complex requests, but must notify you of the extension and the reasons within the original month.

Can I be charged for making a GDPR request?

In most cases, no. Requests must be handled free of charge. An organisation can only charge a "reasonable fee" if a request is manifestly unfounded or excessive — for example, repeated identical requests — and they must be able to justify that decision.

What happens after I complain to the DPC?

The DPC will acknowledge your complaint, assess whether it falls within their remit, and typically engage with the organisation on your behalf. Outcomes range from informal resolution to formal investigation, binding decisions, and administrative fines. You will be kept informed throughout the process.

Do small businesses in Ireland have to comply with GDPR?

Yes. GDPR applies regardless of organisation size. However, some obligations — such as appointing a Data Protection Officer or maintaining full records of processing activities — are only mandatory above certain thresholds or for specific types of processing. Small businesses still need a lawful basis, a privacy notice, appropriate security, and must honour your rights.

Final Thoughts

GDPR gives people in Ireland some of the strongest privacy rights in the world — but those rights only work if you use them. Reading privacy policies critically, challenging unnecessary data collection, submitting access requests when something feels off, and choosing privacy-respecting tools in your daily digital life all contribute to a healthier data ecosystem. The DPC is one of the most powerful privacy regulators on the planet, and it exists to work on your behalf. Don't hesitate to put it to work.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles