---
title: "What an Irish website privacy policy must say"
description: "The information a privacy notice has to give visitors under the GDPR and the Data Protection Act 2018 in Ireland."
canonical: "https://fohrkast.com/guides/privacy-policy-requirements-ireland"
group: "Guides"
updated: "2026-06-28"
---
# What an Irish website privacy policy must say

A privacy policy is how you meet the GDPR transparency duty. It has to tell people, in plain language, who you are, what data you collect, why, on what lawful basis, who you share it with, and what rights they have.

## Transparency is an obligation, not a courtesy

Articles 13 and 14 of the GDPR require you to give specific information at the point you collect personal data. The Data Protection Act 2018 gives effect to the GDPR in Ireland. A privacy notice is the standard way to discharge this duty for a website.

## What the notice must contain

At a minimum, your privacy policy must include:

- Your identity and contact details
- The purposes and lawful basis for processing
- The categories of data collected
- Recipients or processors
- Any transfers outside the EEA and the safeguards for those transfers
- The retention period for the data
- The data subject rights, including access, rectification, erasure, and the right to complaint to the Data Protection Commission

## Plain language matters

The information has to be concise, transparent, intelligible, and in clear and plain language. A wall of legal text that no one can follow does not satisfy the transparency requirement.

## Keep it accurate as you change

Your notice should reflect the tools and processors you actually use. When you add analytics, a new payment provider, or an embedded service, the notice and your cookie disclosures need to keep pace. Fohrkast generates these from your answers and a free scan shows whether your site currently has them.

## Frequently asked questions

**Is a privacy policy legally required in Ireland?**  
If you collect personal data, the GDPR transparency duty applies, and a privacy notice is the standard way to meet it.

**Who do I complain to about data protection in Ireland?**  
The Data Protection Commission is the supervisory authority in Ireland.

## Citations and sources

- GDPR transparency: Regulation (EU) 2016/679, Articles 12 to 14
- Data Protection Act 2018 (Ireland): irishstatutebook.ie/eli/2018/act/7
- Supervisory authority: Data Protection Commission, dataprotection.ie

## About Fohrkast

Fohrkast is an automated scanner and cookie-consent widget that detects tracking scripts on your website and helps you publish an accurate privacy policy and accessibility statement. An automated scan is a readiness check, not a legal certification.

---

Source: https://fohrkast.com/guides/privacy-policy-requirements-ireland
This is automated readiness information, not legal advice or a guarantee of conformance. Last reviewed 2026-06-28.
