The legal framework
Protection rests on the Data Protection Act 2019, closely modelled on the GDPR and enforced by the Office of the Data Protection Commissioner. The ODPC has been notably active, issuing penalty notices including against digital lenders that misused borrowers' phone contacts. These statutes follow the familiar pattern: lawful basis, purpose limitation, security, and rights of access, correction and objection.
Key points
| Rights | Access, correction, objection, and erasure under the more recent statutes |
|---|---|
| Registration | Data controllers must often register with the regulator |
| Breach notification | Required under most of these Acts |
| Cross-border transfers | Permitted subject to adequacy or safeguards |
| Regulator | Office of the Data Protection Commissioner |
| Sectoral rules | Telecommunications and financial regulators impose additional confidentiality duties |
| Penalty notices | Capped by reference to turnover, and actively issued |
| Digital lending | A major enforcement focus, with penalties against lending apps |
| Data protection officers | Required for certain categories of organisation |
In practice
- Write to the organisation first, citing the relevant statutory right; keep proof of the date.
- Set out clearly what you want: a copy of your data, deletion, or an end to marketing.
- If there is no adequate reply within the statutory period, complain to the regulator — it is free.
- For dating, health and fertility apps, ask specifically about third-party sharing and overseas transfers.
- Complain online to the Office of the Data Protection Commissioner: it is free and responsive.
- For lending app harassment, cite the data protection breach as well as the conduct.
Cost and coverage
Complaints to the regulator are free.
Recent changes
Digital lending applications that harvest contact lists have become the most common subject of enforcement across the region, alongside unsolicited marketing.
Where to go
- Office of the Data Protection Commissioner — complaints and guidance.
- Telecommunications regulator for mobile and SMS abuse.
- Consumer protection body for related commercial disputes.
Worth knowing
Where a foreign platform is involved, the GDPR often applies in parallel if the company operates in Europe. Complaining in both places at once is legitimate and frequently faster. Digital lending apps that contact a borrower's phone contacts have been penalised repeatedly. That practice is a data protection breach, not merely aggressive collection.
Official sources and links
- eCitizen — official government services portal
