GDPR in Ireland: A Plain-English Guide for Small Businesses

A practical guide to data protection law in Ireland for small businesses: the GDPR and Data Protection Act 2018, the Data Protection Commission, individual rights, access requests, breach notification, penalties, and 2026-2027 changes.

Last updated: 2026-06-23

If you run a business in Ireland and handle personal data, you are governed by the GDPR and Ireland's Data Protection Act 2018 — and, like the rest of the EU, there is no small-business exemption. This guide explains what applies, who enforces it, and what is changing.

Disclaimer: This article is for informational purposes only and does not constitute legal advice. Privacy regulations are complex and change frequently. You should consult a qualified lawyer or data protection professional for guidance specific to your business. The information here is based on the GDPR (Regulation (EU) 2016/679) and the Data Protection Act 2018, as of the date below.

Two instruments work together: the General Data Protection Regulation (GDPR), directly applicable since 25 May 2018, and Ireland's Data Protection Act 2018, which gives it further effect and established the Data Protection Commission (DPC) as the supervisory authority. For the pan-EU detail, see our GDPR jurisdiction guide.

Does This Law Apply to Your Business?

Yes, if you process personal data of individuals — there is no revenue or headcount threshold. The obligations are the same whether you are a sole trader or a multinational; only the scale of what is "appropriate" changes. The GDPR follows the data subject, so a business outside Ireland that offers goods or services to, or monitors, people in Ireland is also covered.

What Rights Do Individuals Have?

The GDPR grants data subjects a broad set of rights:

RightGDPR ArticleKey detail
AccessArt. 15Copy of personal data plus processing details; respond within one month
RectificationArt. 16Correct inaccurate or incomplete data
ErasureArt. 17Delete data in specific circumstances ('right to be forgotten')
RestrictionArt. 18Pause processing during disputes
PortabilityArt. 20Receive data in a machine-readable format
ObjectArt. 21Object to processing; mandatory stop for direct marketing

A data subject access request (DSAR) must be answered without undue delay and within one month, extendable by up to two further months for complex requests (tell the person within the first month). Access is generally free.

What Your Business Must Do

  • Establish a lawful basis for every processing activity (consent, contract, legal obligation, vital interests, public task, or legitimate interests).
  • Be transparent with a clear privacy notice (see do I need a privacy policy?).
  • Respect individual rights — access, rectification, erasure, restriction, portability, objection.
  • Keep data secure with appropriate technical and organisational measures.
  • Minimise what you collect and keep (data inventory helps).
  • Be accountable — keep records of processing and sign data processing agreements with vendors.

Breach Notification

If you suffer a personal data breach likely to result in a risk to people's rights and freedoms, you must notify the DPC within 72 hours of becoming aware. Where the breach is likely to result in a high risk, you must also notify affected individuals without undue delay. Keep an internal record of all breaches.

Penalties

The GDPR's penalties run up to €20 million or 4% of total worldwide annual turnover, whichever is higher (a lower tier of €10 million or 2% applies to lesser infringements). The DPC is one of the EU's most active regulators because most major technology companies have their EU headquarters in Ireland — recent decisions include a €530 million fine against TikTok in May 2025. For a small business the realistic scale is far smaller, but the obligations are identical.

What's Changing (2026-2027)

  • EU "Digital Omnibus." The Commission has proposed amendments to the GDPR, but as of June 2026 those GDPR changes are still proposed, not law — only the separate AI Act track reached a provisional agreement in May 2026. Treat reported GDPR "rollbacks" as proposals until adopted. See the data governance news page.
  • GDPR Procedural Regulation (EU) 2025/2518 — adopted to harmonise cross-border enforcement; it applies from 2 April 2027 and mainly affects how complaints are handled.

References

Last reviewed: June 2026. EU data protection reform is in progress. Verify all statutory references against the current text of the law and consult qualified legal counsel before making compliance decisions for your business.