GetMySAR

GetMySAR Ireland

The Data Protection Commission: when and how to complain

When an Irish organisation ignores your subject access request, the DPC is the next step. What to do first, which of the three kinds of complaint yours is, exactly what the DPC asks you to send, and the three-month clock it puts on itself.

GetMySAR is an independent service. We are not the Data Protection Commission and not a law firm. Nothing here is legal advice. Complaining to the DPC is free and you can do it yourself.

1. What the Data Protection Commission is

The Data Protection Commission is Ireland’s supervisory authority for data protection — the body Article 77 of the GDPR gives you the right to complain to when an organisation mishandles your personal data. It is the Irish counterpart of the UK’s Information Commissioner’s Office, and a different body entirely from the Office of the Information Commissioner, which oversees freedom of information in Ireland. Confusing those two is the most common Irish mistake on this subject.

If it feels like your problem is everybody’s problem, it is. The DPC states that “the majority of the complaints and queries the Data Protection Commission (DPC) receives concern individuals seeking to exercise their ‘right of access’”. The single most-complained-about right in Ireland is the one this site is about.

Where the DPC is

Data Protection Commission
6 Pembroke Row
Dublin 2
D02 X963
Ireland

The DPC’s preferred route is its online form rather than post — see section 4.

Published by the DPC on its own site and checked 6 September 2026.

A second address is in circulation. An Garda Síochána’s data protection page gives the DPC as 21 Fitzwilliam Square South, Dublin 2, D02 RD28. The DPC’s own site gives the Pembroke Row address above. Both were live on 6 September 2026. Prefer the address the regulator publishes about itself.

2. Complain to the organisation first

Raise it with the organisation first — its data protection officer, if it has one, is the right address. If that gets you nowhere, Article 77 of the GDPR gives you the right to lodge a complaint with the Data Protection Commission, which supervises data protection law in Ireland.

This is not just good manners — it is what the DPC expects. It says that “generally, we will require you to have raised the matter directly with the organisation before raising a concern with this office”, and that you may proceed to the DPC if you are dissatisfied with the response “or if you have not received a response”.

So send one clear chaser to the organisation, in writing, before you go anywhere else. It also produces the document the DPC will ask you for.

3. Three kinds of access complaint — work out which is yours

The DPC divides access-request complaints into three, and asks for different evidence for each. Deciding which one you are making before you write is the difference between a complaint that moves and one that comes back asking for things.

In the DPC’s own words, the three are:

  • No response to an access request.
  • Incomplete response to an access request.
  • Exemptions to withhold data being applied incorrectly.

A response that arrived, but late and thin, is the second — not the first. A response that withheld things with a reason you doubt is the third. They are not interchangeable, and the evidence lists in the next section differ accordingly.

Before deciding, check the response against what the law required of it. The DPC says a controller must “provide information on action taken ‘without undue delay’” and in any event within one month, and that if it is not taking action it must tell you “the reasons for not taking action” and “the possibility of lodging a complaint with a supervisory authority and seeking a judicial remedy (through the courts)”. A refusal that does neither is a weaker refusal than it looks.

4. What the DPC asks you to send

You raise a concern through the DPC’s online form. It publishes the evidence it wants, and it is worth assembling before you start rather than halfway through.

If you got no response

  • A copy of the access request.
  • Any reminder letter you sent.
  • Any other relevant correspondence — for example, if the organisation asked for proof of identity, evidence that you provided it.
  • Signed authority from you, if a solicitor or representative made the contact.

If the response was incomplete

  • A copy of the access request.
  • A copy of any letter you sent “outlining the specific personal data that has not been provided”.
  • “Any evidence you have of the existence of the personal data concerned” — this is the one people miss, and it is why saying which document you know exists beats saying the response felt short.
  • Any other relevant correspondence, and signed authority.

If exemptions were applied wrongly

  • A copy of the access request.
  • A copy of any letter asking the organisation to explain the exemptions, together with any reply.
  • “Your views in writing as to why the exemptions being relied on by the data controller are not validly applied”.
  • Any other relevant correspondence, and signed authority.

Two of the three lists ask for a letter you may not have written yet — one naming the missing data, or one asking the organisation to justify an exemption. Writing it is not a delay; it is the step that turns a grievance into a complaint the DPC can act on.

5. What happens next, and how long it takes

The DPC gives itself a deadline, which is unusual and worth knowing: “when you raise a concern with us, we are obliged to provide you with an update or outcome report within three months”, and where the matter runs longer, “we will provide you with periodic updates”.

An update is not the same as a resolution — three months buys you a report on where it has got to, not necessarily your data. But it is a date you can hold them to, and most regulators do not offer one.

The DPC describes the stages a concern passes through as assessment, amicable resolution, complaint handling, inquiry or investigation, and adjudication or decision-making. Most access complaints end at amicable resolution — which in practice means the organisation produces the data once the regulator asks.

6. What the DPC can and cannot do for you

It supervises, it can require an organisation to act, and in the last resort it can fine. What it is not is your agent: it will not conduct the request for you, and a complaint is not a faster way to get the records than a well-made request in the first place.

Complaining is free, and Article 77 sits alongside — not instead of — your right to go to court. The DPC’s own guidance is careful to say a refusal notice should tell you about “seeking a judicial remedy” as well as about complaining, which is a reminder that the two routes are separate and you are not obliged to exhaust one before the other.

If your complaint is about a public body refusing records that are not your own personal data, that is freedom of information rather than data protection, and it belongs with the Office of the Information Commissioner instead.

How to make the request properly is the better use of an afternoon than a complaint about a bad one, and check what you got back helps you decide which of the three complaints in section 3 you are actually making.

Where this comes from

Everything quoted above is from the Data Protection Commission’s own published guidance, linked at the point it is used — its timescales page, its evidence requirements, its complaints-handling page and its access-request FAQ.

Sources checked 6 September 2026.