How to Make a GDPR Complaint to Ireland's Data Protection Commission (2026)

Ireland's data protection watchdog, the Data Protection Commission (DPC), enforces the GDPR against every organisation established in the State, from a corner shop with a CCTV camera to Meta and TikTok, whose European headquarters sit within walking distance of the DPC's Dublin offices. If an organisation has misused your personal data, ignored your access request, refused to delete your information, or keeps sending you marketing texts you never agreed to, you can complain to the DPC free of charge.
This guide explains how a GDPR complaint in Ireland works in practice: what the DPC expects you to do before complaining, how to use its online webform, what the Commission can and cannot do for you, how long the process takes, and how to pursue compensation through the courts if you have suffered damage.
Information last verified on 20 July 2026. This page is general legal information for the Republic of Ireland, not legal advice.
What is the Data Protection Commission?
The Data Protection Commission is Ireland's independent supervisory authority for data protection, established under the Data Protection Act 2018, the law that gives effect to the GDPR in Ireland. It is led by three Commissioners: Dr Des Hogan, Chairperson and Commissioner for Data Protection since February 2024, Dale Sunderland, also appointed in February 2024, and Niamh Sweeney, the third sitting Commissioner.
The DPC's offices are at 6 Pembroke Row, Dublin 2, D02 X963. Because so many global technology companies have their EU main establishment in Dublin, the DPC is one of the most consequential privacy regulators in Europe. For the wider legal framework, see our overview of Ireland's data privacy laws, and browse the rest of our Ireland law guides.
Before you complain: raise it with the organisation first
The DPC expects that you will generally have raised the matter directly with the organisation before bringing a concern to its office. In practice, that means writing to the organisation, or to its data protection officer if it has one, setting out what went wrong and what you want done about it.
Keep copies of everything: your original request, the organisation's replies, and any deadlines it missed. The DPC will typically ask for evidence of that exchange when it assesses your complaint, and a complaint that arrives with a clear paper trail moves faster.
If the organisation puts things right at this stage, you have your remedy without a regulator ever being involved. If it ignores you or refuses, that correspondence becomes the backbone of your complaint.
How do I make a GDPR complaint to the DPC?
The primary route is the DPC's online webform at forms.dataprotection.ie/contact. The form covers the full range of complaint types, including access to personal data, correction, deletion, search engine delisting, restriction of processing, data portability, objection, unlawful access or disclosure of personal data, and direct electronic marketing.

You can also write to the DPC by post at 6 Pembroke Row, Dublin 2, D02 X963, or contact it by telephone. The webform should still be your first choice, because it routes your complaint into the correct queue from day one.
One practical warning comes from the DPC itself. The webform asks complainants to exercise caution when using artificial intelligence tools to draft or prepare complaints, warning that such tools "can produce inaccurate, incomplete, or misleading information". You remain responsible for what you submit, so describe what happened in your own words, in date order, and attach your evidence.
What should I include?
Set out who the organisation is, what personal data is involved, what the organisation did or failed to do, and when. Attach the correspondence showing you raised it with the organisation first, along with anything that evidences the problem itself, such as the marketing messages you received or the access request that went unanswered.
What can the DPC investigate?
| Complaint type | Legal framework |
|---|---|
| Misuse of personal data, ignored rights requests, data breaches | GDPR, applied by the Data Protection Act 2018 |
| Spam texts, emails and marketing calls | ePrivacy Regulations 2011 (S.I. No. 336/2011), Regulation 13 |
| Data processing for the prevention, investigation, detection or prosecution of criminal offences | Law Enforcement Directive, Part 5 of the Data Protection Act 2018 |
| Legacy matters from before 25 May 2018 | Data Protection Acts 1988 and 2003 |
The ePrivacy strand matters more than most people realise. Unsolicited marketing by text, email or automated call generally requires your consent, and the DPC prosecutes marketing offences under Regulation 13 of S.I. 336/2011. The webform has a dedicated category for direct electronic marketing complaints.
Neighbour CCTV disputes are another common complaint. Where a domestic camera captures footage beyond the operator's own property, the GDPR's household exemption falls away and the DPC can deal with a complaint, although it encourages you to speak to the neighbour first. For how data protection law applies to cameras and call recording generally, see Ireland's recording laws.
What happens after you complain?
The DPC first assesses whether your complaint is within its remit and may ask you for further evidence. From there, the law points it firmly towards settlement: under the Data Protection Act 2018, the DPC is mandated to facilitate or arrange an amicable resolution of the matter where there is a reasonable likelihood of one being achieved.
Amicable resolution is voluntary, but it is often the fastest way to get what you actually want, such as your data corrected, deleted, or finally handed over. Many complaints end here.
If the matter cannot be resolved amicably, the DPC can reject or dismiss the complaint, provide advice, serve an enforcement notice on the organisation, or take other appropriate action. A full statutory inquiry under Part 6 of the 2018 Act is reserved for matters of an extremely serious nature or those indicating a systemic failing.
Where a formal decision issues, the DPC's corrective powers are substantial: warnings and reprimands, compliance orders, orders to rectify or erase data, bans on processing, and administrative fines of up to €20,000,000 or 4% of the organisation's total worldwide annual turnover.
How long does a DPC complaint take?
The one firm commitment the DPC makes is this: it is obliged to give you an update or an outcome report within three months of your complaint. Where the matter goes on for longer, it must provide you with periodic updates.

There is no statutory deadline for a final decision, and complex cases, especially cross-border ones, can run much longer. Complaints resolved amicably are often the quickest to close.
Complaints about Big Tech: the one-stop-shop
If your complaint concerns a company whose EU main establishment is in Ireland, such as Meta or TikTok, the GDPR's one-stop-shop mechanism applies. You can lodge the complaint with any EU supervisory authority, and it will be routed to the DPC as lead supervisory authority. Other concerned authorities can object to the DPC's draft decision, and disputes go to the European Data Protection Board (EDPB) for a binding determination under Article 65 GDPR.
That is exactly how the largest GDPR fine in history came about. In May 2023, the DPC fined Meta Platforms Ireland €1.2 billion for transferring Facebook users' data to the United States in breach of Article 46(1) GDPR, adopting its final decision on foot of an EDPB Article 65 determination after objections from other European authorities. The decision also ordered Meta to suspend the transfers within five months.
In May 2025, the DPC fined TikTok €530 million over transfers of European users' data to China: €485 million for the transfer infringement and €45 million for transparency failures, with an order to bring its processing into compliance within six months.
The practical point for complainants is simple. A GDPR complaint about a Dublin-headquartered platform ends up with the Irish DPC no matter where in the EU it is filed, so you lose nothing by filing it with the DPC directly.
Can the DPC award me compensation?
No. The DPC's corrective powers run against the organisation, and any fine is paid to the Exchequer, not to you. If you want compensation for the harm a data breach or GDPR infringement caused you, the route is a data protection action under section 117 of the Data Protection Act 2018.
A section 117 action is deemed to be an action founded on tort. It can be brought in the Circuit Court, which has jurisdiction concurrently with the High Court, and the court can grant an injunction or a declaration, or award compensation. Damage expressly includes material and non-material damage, so distress-type harm can be compensated, although a Circuit Court award is capped at that court's general tort limit.
Not-for-profit bodies can also bring representative actions on behalf of data subjects under Article 80(1) GDPR, but section 117(7) requires the body to have been mandated by the data subject to do so. A section 117 claim does not require you to complain to the DPC first: the complaint and the court action are separate tracks. If you are considering a court claim, talk to a solicitor.
How do I make a subject access request?
A subject access request (SAR) under Article 15 GDPR lets you find out what personal data an organisation holds about you and obtain a copy of it. You can make one in writing or verbally, though the DPC encourages written requests; its own template opens with the line "I wish to make an access request under Article 15 of the General Data Protection Regulation (GDPR)". The organisation may ask you for evidence of your identity.

Access is free of charge. A reasonable fee can be charged only in very limited circumstances where a request is manifestly unfounded or excessive, and it is for the organisation to prove that.
The organisation must respond within one month, extendable by two further months for complex or numerous requests provided it tells you within the first month, under Article 12(3) GDPR. You are entitled to confirmation that your data is being processed, a copy of the data, the purposes of the processing, the categories of data, the recipients, the retention periods, and details of any automated decision-making.
If your request is refused or ignored, chase the organisation once more in writing, then raise a concern with the DPC. An unanswered access request is one of the most common complaints the webform is built for.
Frequently asked questions
This page is general legal information for the Republic of Ireland and is not legal advice. Data protection complaints turn on their specific facts, and time limits apply to court claims. For complaints about your personal data, contact the Data Protection Commission; if you are considering a compensation claim under section 117, consult a solicitor.
Frequently Asked Questions
How do I make a GDPR complaint in Ireland?
Raise the issue with the organisation first and keep the correspondence, then complain to the Data Protection Commission through its webform at forms.dataprotection.ie/contact. The service is free, and the DPC must give you an update or an outcome report within three months.
Is it free to complain to the Data Protection Commission?
Yes. There is no fee for complaining to the DPC, and making a subject access request to an organisation is also free except in very limited cases where a request is manifestly unfounded or excessive.
Do I have to contact the organisation before complaining to the DPC?
In general, yes. The DPC expects you to have raised the matter directly with the organisation, or its data protection officer, before bringing a concern to its office, and it will ask for evidence of that exchange.
How long does a DPC complaint take?
The DPC is obliged to provide an update or an outcome report within three months, and periodic updates after that if the matter continues. There is no statutory deadline for a final decision, and serious cross-border cases can take considerably longer.
Can I get compensation for a GDPR breach in Ireland?
Not from the DPC, which cannot award compensation to complainants. You would need to bring a data protection action under section 117 of the Data Protection Act 2018 in the Circuit Court or High Court, and compensation can cover both material and non-material damage.
Can I complain to the DPC about companies like Meta or TikTok?
Yes. The DPC acts as lead supervisory authority for many platforms with their EU main establishment in Ireland, and complaints lodged anywhere in the EU about them are routed to it. Its decisions include the €1.2 billion Meta fine in 2023 and the €530 million TikTok fine in 2025.
What is a subject access request and how long does it take?
It is your right under Article 15 GDPR to get confirmation that an organisation is processing your personal data and to receive a copy of it. It is free, and the organisation must respond within one month, extendable by two further months for complex or numerous requests.
Updates
The DPC announced a €530 million fine against TikTok over transfers of European user data to China, with an order to bring its processing into compliance within six months.
Sources and References
- DPC: Complaints handling, investigations and enforcement for individuals(dataprotection.ie).gov
- DPC contact and complaint webform(dataprotection.ie).gov
- DPC: Right of access (making an access request)(dataprotection.ie).gov
- Data Protection Act 2018, section 117: compensation through the courts(irishstatutebook.ie).gov
- DPC announces conclusion of inquiry into Meta Ireland, €1.2 billion fine (May 2023)(dataprotection.ie).gov
- S.I. No. 336/2011: ePrivacy Regulations (electronic marketing and cookies)(irishstatutebook.ie).gov