Privacy Policy Generator Ireland
GDPR under the Data Protection Act 2018, the ePrivacy Regulations 2011, and the DPC as lead authority for much of big tech.
An Irish privacy policy follows GDPR structure but has to be specific about three Irish facts: the DPC as regulator, the digital age of consent at sixteen, and where your main establishment sits for one-stop-shop purposes.
Ireland matters out of proportion to its size because so many multinationals have their EU main establishment there, making the Data Protection Commission the lead supervisory authority under the one-stop-shop. Its decisions set the tone for the whole bloc, and its cookie guidance is among the most detailed published by any authority.
Domestically, GDPR is applied through the Data Protection Act 2018, and cookies are governed by the ePrivacy Regulations 2011 (S.I. 336/2011), which the DPC enforces separately. Its cookie sweep found the usual failures - pre-set non-necessary cookies, implied consent from continued browsing, and reject options that were harder to reach than accept.
Ireland also set the digital age of consent at sixteen, which is at the upper end of the EU range and matters for any consent-based service used by teenagers.
What a privacy policy in Ireland has to cover
Controller identity and, where relevant, confirmation that Ireland is your EU main establishment
The DPC named as supervisory authority with its complaint route
The digital age of consent at sixteen and how parental consent is verified
Transfer mechanisms per destination, with the assessment position for US recipients
Retention periods reflecting Irish statutory limitation periods
How Ireland actually moves personal data
EU-wide processing run from Dublin
If your main establishment is Irish, the DPC is your lead authority for cross-border processing - which changes who you notify, who you correspond with, and who you name.
Cookie consent under S.I. 336/2011
The DPC treats a six-month consent lifetime as a reasonable ceiling and expects a reject control on the first layer of the banner.
Transfers to the United States
Post-Schrems II, Irish-established exporters carry the transfer assessment burden that produced the landmark decisions. The Data Privacy Framework covers certified importers only.
Health research and special categories
The Health Research Regulations impose consent and safeguard requirements beyond GDPR for health research conducted in Ireland.
Under-sixteens
With the digital age of consent at sixteen, consent-based services need verifiable parental consent for a wider age band than in most member states.
Third parties the draft will ask you about
Stripe · Realex/Global Payments · An Post · AWS eu-west-1 (Dublin) · Microsoft 365 · Google Workspace · Mailchimp · Salesforce
The rules that apply
GDPR + Data Protection Act 2018
The Irish implementation, including the digital age of consent set at sixteen and restrictions specific to health and research processing.
ePrivacy Regulations 2011 (S.I. 336/2011)
Regulation 5 requires consent before storing or accessing information on a device, enforced by the DPC with its own guidance and sweeps.
The Data Protection Commission
Lead supervisory authority for organisations with an Irish main establishment, and the named complaint route for Irish residents.
Consumer Rights Act 2022
A consolidated Irish consumer regime covering goods, services and digital content, including the fourteen-day withdrawal right and remedies hierarchy.
Online Safety and Media Regulation Act 2022
Coimisiún na Meán oversight for video-sharing and designated online services, layered on top of the Digital Services Act.
What the generated privacy policy contains
Identity and contact details of the controller
Your legal entity, trading name, registered address and a working contact route - plus a representative or DPO where one is required.
Categories of personal data and their sources
What you collect directly, what you observe automatically, and what you receive from third parties such as payment providers or ad platforms.
Purposes and lawful basis, purpose by purpose
A table that pairs each processing purpose with its lawful basis rather than listing all six bases and hoping one fits.
Recipients and sub-processors
The categories of recipient, and for the ones that matter to users - payment, hosting, analytics, support - the named provider.
International transfers and their safeguards
Where data leaves its home jurisdiction, and the mechanism relied on: adequacy, standard contractual clauses, the UK addendum or IDTA.
Retention periods per data category
Concrete periods or the criteria used to set them, which is what regulators ask for first when a complaint lands.
Rights and how to exercise them
Access, rectification, erasure, portability, objection and restriction, with the actual route to make a request and the deadline you work to.
Complaints and supervisory authority
The regulator a user can escalate to, named, with a link - not a generic "your local authority".
Irish compliance essentials
Establish your lead authority position
Document where cross-border processing decisions are taken, because it determines who supervises you.
Configure the banner to DPC guidance
Reject on the first layer, no pre-checked boxes, consent lifetime around six months.
Set the age gate to sixteen
And build a verifiable parental consent route for anyone below it where you rely on consent.
Document transfer assessments
The Irish exporter cases remain the reference point for what an assessment has to engage with.
Where this usually goes wrong
Assuming the DPC is your lead authority without an Irish establishment
The one-stop-shop follows the main establishment, meaning the place where decisions about processing are actually taken - not where a subsidiary is registered.
Cookies set before the banner is answered
The DPC sweep report singled this out, along with banners that treated continued browsing as consent.
Digital age of consent set to thirteen
Ireland uses sixteen. Services that gate at thirteen are non-compliant for Irish teenagers.
Confusing the DPC with the ICO
They are separate regulators under separate statutes. An Irish policy that names the ICO is describing a different legal system.
Frequently asked questions
Is the DPC my regulator if I sell into Ireland?
Only if you have an Irish main establishment. Otherwise Irish residents can complain to the DPC, but your lead authority is wherever your EU main establishment sits - and if you have none, every authority can act.
What is the digital age of consent in Ireland?
Sixteen. Below that, a consent-based information society service needs consent from a parent or guardian.
Do Irish cookie rules differ from GDPR?
They come from a different instrument - the ePrivacy Regulations 2011 - but use the GDPR consent standard. The DPC enforces them directly and has published detailed guidance on banner design.
Is a privacy policy legally required?
If you process personal data, in almost every market yes. GDPR and UK GDPR require the disclosure at the point of collection, CCPA/CPRA requires a notice at collection plus an annually reviewed policy, and app stores and payment processors require a public policy URL before they will list or onboard you.
Can I copy another company’s privacy policy?
It is both a copyright problem and a compliance problem. A copied policy describes someone else’s data flows, processors and retention periods, so it is inaccurate the moment you publish it - and an inaccurate transparency notice is itself a breach of GDPR Article 13.
How often does a privacy policy need updating?
Whenever your processing changes - a new analytics tool, a new payment provider, a new market - and as a backstop, review it annually. CPRA makes the twelve-month review explicit.
Does PolicifyAI give legal advice?
No. PolicifyAI is a technology provider, not a law firm. The output is a structured, jurisdiction-aware draft that a qualified adviser should review before you rely on it.
Privacy Policy Generator Ireland
Answer a short questionnaire and get a draft written for Ireland. Free to start, no card required.
Generate your privacy policyOther documents for Ireland
Each one is written for the same context, not a generic template.
The same document, by country
Go deeper
PolicifyAI is a technology provider, not a law firm, and this page is not legal advice. Generated documents are a structured starting point that a qualified adviser should review before you publish or rely on them.