facebook-pixel

GDPR in Ireland: Your Privacy Rights Explained

L
Lunyb Security Team
··10 min read

Ireland sits at the heart of European data protection. With the European headquarters of Google, Meta, Apple, Microsoft, TikTok, and LinkedIn all based in Dublin, the Irish Data Protection Commission (DPC) is one of the most influential regulators under the General Data Protection Regulation (GDPR). For Irish residents, this means your personal data is protected by one of the strongest privacy frameworks in the world — but understanding how to actually use those rights is another matter entirely.

This guide explains your GDPR privacy rights in Ireland, how the law is enforced locally through the Data Protection Act 2018, and how to make a complaint when a company misuses your information.

What Is GDPR and How Does It Apply in Ireland?

The General Data Protection Regulation (GDPR) is an EU-wide law that came into force on 25 May 2018. It governs how organisations collect, store, process, and share the personal data of individuals in the European Economic Area. In Ireland, GDPR is implemented alongside the Data Protection Act 2018, which fills in national-specific provisions such as the age of digital consent (set at 16 in Ireland) and the powers of the DPC.

GDPR applies to any organisation — Irish or foreign — that processes the personal data of people in Ireland. This includes everything from your local GAA club storing membership details, to multinational tech firms processing billions of data points daily from their Dublin offices.

Who Enforces GDPR in Ireland?

The Data Protection Commission (DPC), headquartered in Dublin and Portarlington, is the national supervisory authority. Because so many major tech companies have their EU base in Ireland, the DPC acts as the lead supervisory authority for cross-border cases across the entire EU under the "one-stop-shop" mechanism. It has issued some of the largest GDPR fines in history, including a €1.2 billion penalty against Meta in 2023.

Your Eight Core GDPR Rights in Ireland

GDPR grants every individual in Ireland eight fundamental rights over their personal data. Understanding each one is the first step to taking control of your digital life.

1. The Right to Be Informed

Organisations must tell you clearly what data they collect, why they collect it, how long they keep it, and who they share it with. This is typically delivered through a privacy notice or policy, which must be written in plain, accessible language.

2. The Right of Access

You can request a copy of all personal data an organisation holds about you. This is called a Subject Access Request (SAR). The organisation must respond within one month and generally cannot charge a fee.

3. The Right to Rectification

If data held about you is inaccurate or incomplete, you have the right to have it corrected. This is particularly relevant for financial records, credit files held by the Central Credit Register, and medical files held by the HSE.

4. The Right to Erasure ("Right to Be Forgotten")

You can ask an organisation to delete your personal data when it is no longer necessary, when you withdraw consent, or when it has been processed unlawfully. This right is not absolute — public interest, legal obligations, or freedom of expression may override it.

5. The Right to Restrict Processing

You can request that an organisation stops processing your data while a complaint or correction is being investigated. The data can still be stored, but it cannot be actively used.

6. The Right to Data Portability

You can ask for your personal data in a structured, machine-readable format (such as CSV or JSON) and transfer it to another service. This is useful when switching banks, mobile providers, or social media platforms.

7. The Right to Object

You can object to your data being used for direct marketing, profiling, or certain forms of automated decision-making. For marketing, the objection must be respected immediately and without exception.

8. Rights Related to Automated Decision-Making

You have the right not to be subject to a decision made solely by automated means — such as an algorithm denying you a loan or job interview — if it has a legal or similarly significant effect on you.

Comparison: GDPR Rights vs Pre-GDPR Irish Law

Before 2018, Ireland was governed by the Data Protection Acts 1988 and 2003. The protections were far weaker and enforcement was limited. The table below summarises the key differences.

AreaPre-GDPR (1988/2003 Acts)Current GDPR + Data Protection Act 2018
Maximum fine€100,000€20 million or 4% of global turnover
Response time for access requests40 days1 month (extendable by 2 months)
Access request feeUp to €6.35Free in most cases
Breach notificationNo mandatory requirementMandatory within 72 hours
Right to erasureNot explicitExplicit statutory right
Digital consent ageNot defined16 years
Data Protection OfficerNot requiredMandatory for many organisations

How to Make a Subject Access Request in Ireland

A Subject Access Request is the most powerful tool at your disposal. Here is the step-by-step process:

  1. Identify the data controller. This is the organisation that decides how your data is processed — for example, your bank, employer, or a social media platform.
  2. Find the correct contact. Most Irish organisations list a Data Protection Officer (DPO) or privacy email in their privacy policy.
  3. Submit your request in writing. Email is acceptable. Clearly state that you are making a request under Article 15 of the GDPR and specify what you want (all data, specific records, etc.).
  4. Verify your identity. The organisation may ask for proof of ID to prevent impersonation.
  5. Wait up to one month. If the request is complex, this can be extended by two further months, but they must tell you why.
  6. Review the response. If data is missing or incorrect, follow up or escalate to the DPC.

Filing a Complaint With the Data Protection Commission

If an organisation refuses to respond, provides an inadequate response, or you believe your data has been misused, you can lodge a complaint with the DPC. The process is free and does not require legal representation.

Steps to File a DPC Complaint

  1. Try to resolve the matter directly with the organisation first — the DPC usually expects this.
  2. Gather evidence: your original request, their response, screenshots, timestamps.
  3. Submit your complaint through the DPC's online webform at dataprotection.ie.
  4. The DPC will acknowledge your complaint and may act as mediator before launching a formal investigation.
  5. If a breach is confirmed, the DPC can issue reprimands, enforcement notices, or administrative fines.

Common GDPR Scenarios in Ireland

Workplace Monitoring

Irish employers can monitor employee emails and internet usage, but only with transparency, proportionality, and a legitimate interest. Covert surveillance is almost never lawful. Employees have the right to request copies of CCTV footage or recorded calls that feature them.

CCTV in Public and Private Spaces

Businesses using CCTV must display clear signage, limit retention (typically 28 days), and have a documented data protection impact assessment. Doorbell cameras pointing at public footpaths or neighbours' property have been a growing area of DPC complaints.

Direct Marketing and Cookies

Under the ePrivacy Regulations 2011 and GDPR, unsolicited marketing emails and SMS to individuals require prior opt-in consent. Websites must obtain genuine consent before setting non-essential cookies — pre-ticked boxes and "continue browsing to accept" banners are not valid.

Protecting Your Privacy Beyond GDPR

Legal rights are only one part of the equation. Practical privacy hygiene is just as important for Irish internet users in 2026.

  • Use encrypted DNS (such as DNS-over-HTTPS) in your browser to prevent your internet provider from logging every website you visit.
  • Choose privacy-respecting browsers like Firefox or Brave, and enable tracking protection.
  • Enable two-factor authentication on every important account, especially Revenue, banking, and email.
  • Be careful with link shorteners. Some free link shorteners log every click and sell traffic data. A privacy-first shortener like Lunyb provides analytics without reselling user information — a point we examined in our honest Lunyb review.
  • Review app permissions quarterly on your phone — many apps collect location data they never need.
  • Request erasure from services you no longer use rather than leaving dormant accounts open.

If you're a small business owner or marketer sharing links with Irish audiences, picking the right infrastructure matters. Our 2026 buyer's guide to URL shorteners compares providers on exactly these privacy criteria, and our Rebrandly review looks at a popular enterprise option.

Children and Digital Consent in Ireland

Ireland set the age of digital consent at 16 — the maximum allowed under GDPR. This means children under 16 cannot legally consent to the processing of their personal data by online services such as social media; parental consent is required instead. The DPC published the "Fundamentals for a Child-Oriented Approach to Data Processing" in 2021, which sets 14 specific principles for online services directed at or likely to be accessed by children.

Data Breaches: What to Do If You're Affected

Organisations must notify the DPC within 72 hours of becoming aware of a personal data breach that poses a risk to individuals. If the risk is high, they must also notify affected individuals directly.

If you're told your data has been breached:

  1. Change your password for the affected service and any other site where you reused it.
  2. Enable two-factor authentication.
  3. Monitor bank statements and credit reports via the Central Credit Register.
  4. Watch for phishing emails that reference leaked details to appear legitimate.
  5. Report identity theft to An Garda Síochána if you suspect fraud.

Frequently Asked Questions

Can I claim compensation under GDPR in Ireland?

Yes. Under Article 82 GDPR and Section 117 of the Data Protection Act 2018, you can bring a civil action in the Circuit Court for material damage (financial loss) or non-material damage (distress). Irish case law in this area is still developing, but awards for serious breaches have ranged from several hundred to several thousand euro.

How long should an Irish company keep my personal data?

GDPR requires that data is kept only as long as necessary for the purpose for which it was collected. Specific retention periods vary — employment records are typically kept for 7 years, financial records for 6 years under Revenue rules, and marketing data generally no longer than 2 years without renewed consent.

Does GDPR apply to personal use, such as my home address book?

No. The "household exemption" in Article 2 GDPR excludes purely personal or household activities. However, if you run a side business, blog with monetised content, or operate a CCTV camera pointing beyond your property, GDPR may apply.

What happens after Brexit — does UK data still fall under Irish GDPR?

The UK is now a third country under EU law, but it has an "adequacy decision" from the European Commission (reviewed in 2025), meaning data can continue to flow between Ireland and the UK largely as before. If adequacy were revoked, Irish organisations would need standard contractual clauses to transfer data.

Can I make a GDPR complaint anonymously?

The DPC generally requires your identity to investigate a complaint properly, but your details will not be shared with the organisation without your consent. For whistleblower-style disclosures about systemic breaches, the DPC accepts confidential tips and may open an own-volition inquiry.

Final Thoughts

GDPR gave Irish residents genuinely powerful tools to control their personal data — but those rights only matter if people use them. By understanding what you're entitled to, submitting access requests when needed, and choosing services that respect privacy by design, you shift the balance back in your favour. Ireland's position as Europe's tech hub makes the DPC one of the most watched regulators in the world, and every complaint filed helps shape how the biggest companies on the planet handle your information.

Protect your links with Lunyb

Create secure, trackable short links and QR codes in seconds.

Get Started Free

Related Articles