GDPR in Ireland: Your Privacy Rights Explained
The General Data Protection Regulation (GDPR) has fundamentally reshaped how organisations in Ireland collect, store, and use your personal information. Whether you're signing up for a loyalty card at Dunnes, applying for a job online, or scrolling social media, your data is constantly being processed — and the law gives you powerful rights to control it. This guide explains your GDPR privacy rights in Ireland in plain English, how to enforce them, and what to do if things go wrong.
What Is GDPR and Why Does It Matter in Ireland?
The GDPR is an EU-wide regulation that came into force on 25 May 2018. In Ireland, it is enforced alongside the Data Protection Act 2018 by the Data Protection Commission (DPC), based in Dublin. Because many of the world's largest technology companies — including Meta, Google, TikTok, Apple, and LinkedIn — have their European headquarters in Ireland, the Irish DPC plays an outsized role in enforcing GDPR across the entire EU.
In practical terms, GDPR gives every person in Ireland a set of enforceable rights over their personal data. Organisations that break the rules face fines of up to €20 million or 4% of annual global turnover, whichever is higher. The DPC has issued some of the largest GDPR fines on record, including a €1.2 billion penalty against Meta in 2023.
Who Does GDPR Protect?
GDPR protects any natural person located in the EU, regardless of nationality. If you live in Ireland — whether you're an Irish citizen, an EU national, or a non-EU resident — your personal data is protected whenever it is processed by an organisation operating in the EU or targeting EU users.
What Counts as Personal Data Under Irish GDPR?
Personal data is any information that can identify you, directly or indirectly. The definition is deliberately broad to keep pace with modern technology.
- Direct identifiers: your name, PPS number, Eircode, phone number, email address, photograph.
- Online identifiers: IP addresses, cookie IDs, device IDs, advertising identifiers.
- Location data: GPS coordinates, mobile network cell data, Wi-Fi based location.
- Behavioural data: browsing history, purchase records, app usage patterns.
- Special category data: health records, religious beliefs, sexual orientation, trade union membership, biometric and genetic data.
Special category data receives extra protection and generally requires your explicit consent before processing.
Your Eight Key Rights Under GDPR
GDPR grants eight fundamental data subject rights. Every organisation that processes your data must respect these rights, usually free of charge and within one month of your request.
1. The Right to Be Informed
Organisations must clearly tell you what data they collect, why they collect it, how long they keep it, and who they share it with. This is typically delivered through a privacy notice or policy at the point of data collection.
2. The Right of Access (Subject Access Request)
You can ask any organisation for a copy of the personal data they hold about you. This is called a Subject Access Request (SAR). The organisation has one calendar month to respond, free of charge.
3. The Right to Rectification
If data held about you is inaccurate or incomplete, you can request that it be corrected. For example, if your bank has your address wrong, you can insist it be fixed.
4. The Right to Erasure ("Right to Be Forgotten")
You can ask organisations to delete your personal data in certain circumstances — for instance, when the data is no longer necessary, when you withdraw consent, or when it was processed unlawfully.
5. The Right to Restrict Processing
You can require an organisation to pause processing your data while a dispute is resolved, without deleting the data outright.
6. The Right to Data Portability
You can obtain your personal data in a structured, commonly used, machine-readable format (such as CSV or JSON) and transfer it to another provider. This is especially useful when switching banks, telecom providers, or streaming services.
7. The Right to Object
You can object to processing based on legitimate interests or public tasks, and you have an absolute right to object to direct marketing at any time.
8. Rights Relating to Automated Decision-Making
You have the right not to be subject to decisions based solely on automated processing — including profiling — where those decisions produce legal or similarly significant effects (such as being refused credit or insurance).
Comparison: GDPR Rights vs. Pre-GDPR Irish Law
| Right | Before GDPR (DPA 1988/2003) | Under GDPR (2018+) |
|---|---|---|
| Access request fee | Up to €6.35 | Free |
| Response time | 40 days | 1 calendar month |
| Right to erasure | Limited | Explicit "right to be forgotten" |
| Data portability | Not available | Full right in machine-readable format |
| Breach notification | Not mandatory | Within 72 hours to DPC |
| Maximum fine | €100,000 | €20M or 4% global turnover |
How to Make a Subject Access Request in Ireland
A Subject Access Request is the most commonly exercised GDPR right. Follow these steps to make one effectively.
- Identify the data controller. This is the organisation that decides how your data is used — usually the company you have a relationship with.
- Find the right contact. Look for a Data Protection Officer (DPO) email or a privacy contact in the organisation's privacy policy.
- Write a clear request. State your name, confirm your identity, and specify what data you want. You can request everything, or narrow it to specific categories (e.g. CCTV footage, call recordings, emails).
- Set the deadline. Mention that under Article 15 GDPR, you expect a response within one calendar month.
- Keep records. Save copies of your request and any correspondence in case you need to escalate.
A simple template: "Under Article 15 of the GDPR, I am requesting a copy of all personal data you hold about me, including the purposes of processing, categories of data, recipients, and retention periods. My details are [name, DOB, account number]. Please respond within one month."
The Role of the Data Protection Commission (DPC)
The DPC is Ireland's independent supervisory authority for GDPR enforcement. Headquartered on Fitzwilliam Square in Dublin, with offices in Portarlington, it handles complaints, investigates breaches, and provides guidance to both individuals and organisations.
Because so many major tech companies have their EU headquarters in Ireland, the DPC acts as the "lead supervisory authority" for cross-border cases under the GDPR one-stop-shop mechanism. This has made it one of the most consequential regulators in Europe.
How to Lodge a Complaint With the DPC
- First, raise your concern directly with the organisation and give them a chance to respond.
- If unsatisfied, visit dataprotection.ie and use the online complaint form.
- Provide all correspondence, evidence, and a clear description of the issue.
- The DPC will acknowledge your complaint and may attempt an amicable resolution first.
- If the matter is serious, a formal statutory inquiry may be opened.
Complaints to the DPC are free, and you don't need a solicitor to make one.
Cookies, Tracking, and ePrivacy in Ireland
In addition to GDPR, Ireland implements the ePrivacy Directive through the ePrivacy Regulations 2011. These rules govern cookies, tracking pixels, and electronic marketing.
Under Irish guidance, websites must obtain your explicit opt-in consent before setting non-essential cookies. "Implied consent" (continuing to browse) is no longer acceptable. Cookie banners must:
- Offer a "Reject All" option as prominently as "Accept All".
- List third parties who will receive your data.
- Allow you to withdraw consent as easily as you gave it.
If a website makes it harder to reject cookies than to accept them, that may itself be a GDPR breach.
Protecting Your Privacy Day-to-Day
Knowing your rights is only half the battle. Taking practical steps to minimise the data you share online is equally important.
Everyday Privacy Habits
- Review app permissions on your phone monthly — revoke access to location, contacts, and microphone where unnecessary.
- Use a privacy-focused browser such as Firefox or Brave, with tracker blocking enabled.
- Switch to encrypted DNS (DNS over HTTPS) to prevent your internet provider from logging every site you visit.
- Enable two-factor authentication on email, banking, and Revenue.ie accounts.
- Be cautious with link sharing. Shortened links can hide trackers. If you need to share URLs, use a privacy-respecting shortener like Lunyb, which keeps analytics minimal and doesn't resell click data. See our honest review of Lunyb for a deeper look.
- Request deletion of old accounts you no longer use — dormant accounts are a common source of data breaches.
Choosing GDPR-Compliant Tools
When selecting services, favour providers that are transparent about data processing, host data in the EU, and offer clear exports and deletion. For link management, our 2026 buyer's guide to URL shorteners compares the privacy practices of leading providers, and our Rebrandly review breaks down one of the better-known commercial options.
Data Breaches: What to Do If You're Affected
Under GDPR, organisations must notify the DPC of personal data breaches within 72 hours. If the breach is likely to result in high risk to your rights and freedoms, they must also notify you directly without undue delay.
If you receive a breach notification:
- Change the password for the affected service immediately.
- Change the same password anywhere else you've reused it.
- Enable two-factor authentication.
- Monitor bank and credit card statements for unusual activity.
- Watch for phishing emails that reference the breach.
- Consider freezing your credit file with the Central Credit Register if financial data was exposed.
GDPR for Children in Ireland
Ireland has set the digital age of consent at 16, meaning children under 16 cannot give valid consent to information society services (such as social media accounts) without parental authorisation. The DPC's Fundamentals for a Child-Oriented Approach to Data Processing sets out 14 principles that organisations must follow when processing children's data, including a "best interests of the child" test and strict rules on profiling and advertising.
Enforcement Highlights in Ireland
The Irish DPC has issued several landmark decisions that illustrate how GDPR works in practice:
- Meta (2023): €1.2 billion fine for unlawful transfers of EU user data to the US.
- TikTok (2023): €345 million fine for breaches related to children's data settings.
- WhatsApp (2021): €225 million fine for transparency failures.
- Instagram (2022): €405 million fine over children's data exposure.
These cases show that GDPR has real teeth, and that the DPC is actively enforcing the law against even the largest global platforms.
Frequently Asked Questions
How long does an organisation have to respond to my GDPR request in Ireland?
One calendar month from the day they receive your request. In complex cases this can be extended by two further months, but they must tell you about the extension within the first month and explain why.
Can I be charged for making a Subject Access Request?
No. Subject Access Requests are free of charge. An organisation can only charge a "reasonable fee" if your request is manifestly unfounded or excessive — for example, repetitive requests — and they must justify any charge.
What happens if an Irish company ignores my GDPR request?
You can escalate the matter to the Data Protection Commission by submitting a complaint via dataprotection.ie. The DPC can investigate, order the organisation to comply, and impose administrative fines of up to €20 million or 4% of global turnover.
Does GDPR still apply after Brexit if a company is in Northern Ireland or the UK?
If a UK or Northern Ireland organisation offers goods or services to people in Ireland or monitors their behaviour, EU GDPR still applies to that processing. The UK also has its own near-identical regime (UK GDPR), so your rights are substantially equivalent in both jurisdictions.
Can I sue a company directly instead of complaining to the DPC?
Yes. Article 82 GDPR and Section 117 of the Data Protection Act 2018 give you the right to bring a civil action in the Circuit Court or High Court for material or non-material damage — including distress — caused by a GDPR breach. You can do this independently of, or in parallel with, a DPC complaint.
Conclusion
GDPR has given people in Ireland some of the strongest privacy rights in the world. From requesting a copy of your data to demanding its deletion, from objecting to marketing to complaining to the DPC, you have real tools to take control of your digital life. The key is knowing those rights exist — and being willing to use them. Combine that legal protection with sensible everyday privacy habits, and you can navigate the modern internet with far more confidence that your personal information stays yours.
Protect your links with Lunyb
Create secure, trackable short links and QR codes in seconds.
Get Started FreeRelated Articles
Singapore Online Safety Act 2026: Complete Guide for Businesses and Users
Singapore's Online Safety Act 2026 reshapes how online platforms, advertisers, and intermediaries handle harmful content. This complete guide covers scope, obligations, penalties, and practical compliance steps for businesses and users in Singapore.
How Canadian Businesses Should Handle Data Privacy in 2026
A practical 2026 guide to data privacy for Canadian businesses — covering PIPEDA, Quebec Law 25, consent, breach response, vendor management, and CPPA preparation. Learn exactly what to implement to stay compliant and build customer trust.
Privacy Rights in Canada 2026: A Complete Guide for Individuals and Businesses
Canadian privacy law has changed dramatically with Bill C-27, Quebec's Law 25, and expanded provincial rules. This 2026 guide explains your rights, business obligations, and practical steps to protect personal information in the digital age.
UK Data Protection Act vs GDPR Explained: Key Differences for 2026
The UK Data Protection Act 2018 and the GDPR often get confused, but they work together rather than compete. This guide explains how the DPA 2018, UK GDPR and EU GDPR interact, where the key differences lie, and what UK businesses must do to stay compliant in 2026.