GDPR in Ireland and the Data Protection Act 2018
What the GDPR is, what Ireland’s Data Protection Act 2018 adds to it, and the rights the two give you — in plain English, with the access right in the detail it deserves.
Checked against the EUR-Lex text: 18 August 2026
On this page
1. How GDPR applies in Ireland
The General Data Protection Regulation — Regulation (EU) 2016/679 — is an EU regulation, which means it applies in Ireland directly: its text is the law, without needing to be rewritten into an Irish statute. It has applied since 25 May 2018 and covers any organisation processing the personal data of people in Ireland, wherever that organisation is based.
“GDPR” in Ireland therefore means the EU regulation itself — unlike in the UK, which since Brexit has run its own amended copy. If you are reading guidance online, check which one it describes; the differences now matter (section 5).
2. What the Data Protection Act 2018 adds
The Data Protection Act 2018 (No. 7 of 2018) is the Irish Act that gives the GDPR further effect and fills in the choices the Regulation leaves to member states. In practice it does four jobs:
- establishes the Data Protection Commission and its enforcement powers;
- sets Ireland-specific rules the GDPR permits, such as the age of digital consent (16 in Ireland);
- transposes the separate EU Law Enforcement Directive, so data processing by bodies like An Garda Síochána for policing purposes runs under Part 5 of the Act rather than the GDPR;
- provides the court route for compensation claims, which sits outside the DPC complaint process.
A confusing coincidence: the UK’s equivalent statute is also called the Data Protection Act 2018. They are different Acts of different parliaments. Guidance citing “the DPA 2018” without saying which country is describing one of them only.
3. The rights you can use
The GDPR gives you a set of rights over personal data that any organisation holds about you: to be informed about what is collected and why; to access it; to have it corrected or erased; to restrict or object to its use; and to data portability. None of them costs anything to exercise, and none needs a solicitor.
The one this site exists for is the right of access — Article 15 — because it is the gateway to the others: you cannot get data corrected or erased until you know what is held. Exercising it is called a subject access request.
4. Article 15: the right of access
Article 15 entitles you to confirmation of whether your personal data is being processed and, where it is, to access to the data and to supplementary information: the purposes of the processing, the categories of data, the recipients it has been or will be disclosed to (including in third countries, and the safeguards applied), the retention period or its criteria, the source of the data if not collected from you, and whether automated decision-making or profiling is involved. It also requires the organisation to tell you about your rights to rectification, erasure, restriction and objection, and your right to complain to a supervisory authority.
The organisation must provide a copy of the data undergoing processing. Where you make the request electronically, the response should come in a commonly used electronic form unless you ask otherwise. The right to a copy must not adversely affect the rights and freedoms of others — the basis on which other people’s data is redacted from what you receive.
An organisation must respond without undue delay and within one month of receiving your request. It may extend by up to two further months where requests are complex or numerous, but it must tell you within the first month that it is extending, and why.
There is normally no fee. A reasonable fee may only be charged where a request is manifestly unfounded or excessive, or where you ask for further copies of your data.
5. How Irish law differs from the UK's
The UK kept a copy of the GDPR at Brexit and has amended it since, most recently in 2026. Three differences are worth knowing if you deal with organisations on both sides of the border:
- Search scope. The UK text now limits a response to what a “reasonable and proportionate search” finds. The GDPR that applies in Ireland contains no such wording, and the Court of Justice of the EU has read the right of access broadly.
- Complaints. UK organisations owe a statutory internal complaints procedure before the regulator gets involved. In Ireland there is no equivalent duty — raising it with the organisation first is good practice, not a legal precondition, and the regulator is the DPC rather than the ICO.
- The texts are drifting. What is true of one regime is increasingly unsafe to assume of the other. Our UK GDPR page covers the UK side, including the current UK Article 15 text.
6. Putting it to use
Knowing the law is half of it; the other half is a request that lands in the right inbox with the right citation. How to make a subject access request in Ireland has the steps and a template, and our free letter generator writes the letter with the Irish citations in place.