Independent. MyID is not affiliated with the Department of Social Protection, MyGovID, or the Government of Ireland.

Your data rights

Published 2026-05-31Updated 2026-05-31By MyID Editorial

If your personal data is held by an Irish or EU organisation — a state department, a bank, an employer, a website — you have a set of rights under the General Data Protection Regulation (GDPR) and the Irish Data Protection Act 2018. These rights are real, enforceable, and free to exercise. This page is the overview; each sub-page covers a specific right with the steps and templates you need.

Your eight rights, in plain English

RightWhat it lets you do
Right of accessDemand a copy of all the personal data an organisation holds about you, plus information about how and why they process it. Free. They must respond within one month.
Right to rectificationRequire an organisation to correct inaccurate or incomplete personal data about you.
Right to erasure (the "right to be forgotten")Require deletion of your personal data in specific circumstances (e.g. you withdraw consent and there's no other lawful basis).
Right to restrict processingRequire an organisation to stop processing (but not necessarily delete) your data in certain circumstances.
Right to data portabilityReceive your data in a portable format and have it sent directly to another organisation.
Right to objectObject to processing based on legitimate interests, direct marketing, or processing for research/statistics.
Rights related to automated decision-makingRequire human review of decisions made about you by automated systems alone (including profiling), where the decision has significant effects.
Right to complain to the DPCIf an organisation breaches your rights or your data protection rights more generally, file a complaint with the Data Protection Commission.

What to use these rights for

Three common scenarios:

Sub-pages

If your data has been in a publicised breach

  1. The organisation should notify you directly. If they haven't, ask them (in writing) what happened, what data was affected, and what steps they're taking.
  2. Change passwords on the breached account and any account with the same password.
  3. Watch for follow-on phishing — breach victims are targeted with personalised social-engineering for months afterwards.
  4. If actual financial loss occurred, see first 24 hours.
  5. If you want to pursue accountability, file a complaint with the DPC.

What MyID cannot do

Related