GetMySAR

GetMySAR Ireland

The Data Protection Commission: when and how to complain

Ireland’s data protection regulator makes organisations answer ignored subject access requests — free, and without a solicitor. What the DPC is, when to go to it, and how to put a complaint in that sticks.

1. What the Data Protection Commission is

The Data Protection Commission — the DPC, still widely searched for as the “Data Protection Commissioner”, its pre-2018 name — is Ireland’s independent data protection authority. It supervises compliance with the GDPR and the Data Protection Act 2018, handles complaints from individuals, and can investigate, order an organisation to comply and impose fines.

Because so many technology companies have their European headquarters in Ireland, the DPC is also the lead European regulator for several of the world’s largest data controllers. For you, the practical point is simpler: it is the body that makes an Irish organisation answer an ignored subject access request, at no cost to you.

2. Before you complain

Raise it with the organisation first — its data protection officer, if it has one, is the right address. If that gets you nowhere, Article 77 of the GDPR gives you the right to lodge a complaint with the Data Protection Commission, which supervises data protection law in Ireland.

Two things strengthen your position and shorten the process: a copy of your original request with the date it was sent, and one follow-up to the organisation after the month passed, in writing, saying the deadline has been missed and that you will complain to the DPC if there is no response. Organisations that ignore a request often answer that letter.

Not sent the request yet, or unsure it was valid? Start here — a clear request now beats a weak complaint later.

3. When a complaint is the right move

  • No response one month after a valid request — the clearest case. An organisation must respond without undue delay and within one month of receiving your request. It may extend by up to two further months where requests are complex or numerous, but it must tell you within the first month that it is extending, and why.
  • A late extension — the organisation invoked extra time after the first month had already passed, or gave no reason.
  • An incomplete response — records you know exist are missing, or the supplementary information Article 15 requires was never addressed.
  • A fee demand for a first copy of your data, or disproportionate identity requirements that function as a refusal.
  • A blanket refusal without naming a legal basis for it.

4. How to complain

Complaints go to the DPC directly at dataprotection.ie — look for raising a concern on its site, which takes you through its web form. Include your original request, proof of when it was sent, the follow-up, and any response you did get. There is no charge, and you do not need a solicitor.

Article 77 of the GDPR is the right you are exercising: everyone has the right to lodge a complaint with a supervisory authority where they consider the processing of their personal data infringes the Regulation.

5. What the DPC can and cannot do for you

It can require the organisation to comply with your request, order broader corrective measures and, in serious cases, fine. Most SAR complaints resolve well short of that — an organisation that ignored you tends to find the request once the regulator forwards it.

It cannot award you compensation. A claim for damage caused by an infringement is a court matter under the Data Protection Act 2018, separate from the complaint — worth knowing before you frame what you want out of the process.