TBD

GDPR requests

GDPR request to a debt collector in Ireland

How a data subject access request can help uncover the records, source, recipients, and correction issues behind a disputed debt collection letter.

access request basis
Article 15
key question
source
who got the data
recipients

Check your dispute first

Answer a few questions to see your options before writing your complaint.

Check your options

A GDPR request is not a dirty trick. It is a consumer-rights tool. If a collector is processing your personal data, you can ask for access to that data and information about why it is being processed, where it came from, and who it was sent to.

The collector may hold account information, contact logs, letters, notes and call recordings. These records may help explain how it has handled your account.

TBD can turn that into a focused request rather than a vague data dump. The goal is to expose the evidence trail and spot data integrity issues the company needs to answer.

What to do next

  1. 1Send the access request to the organisation processing your data, such as the original provider and the collector where relevant.
  2. 2Ask specifically for the records connected to the alleged debt, not just 'everything'.
  3. 3After the response, check whether the amount, dates, address, account status, recipients, and source of data are accurate.
  4. 4If the response is missing, late, or shows wrong data, consider a rectification request or DPC complaint route.

What to request

Ask for account notes, billing records, final balance calculation, contract or order records, cancellation notes, complaint notes, call recordings or transcripts where held, letters, SMS logs, email logs, and internal status records about the collection account.

Also ask for purposes of processing, categories of personal data, recipients or categories of recipients, retention period, source of data where it was not collected from you, and meaningful information about automated decision-making or profiling if used.

What to check after the response

Look for mismatches: a credit treated as a debt, wrong cancellation date, missing complaint notes, wrong address, wrong eircode, unexplained fee increase, or a collector receiving data before the provider resolved the dispute.

If the records are inaccurate, a separate rectification request can ask the controller to correct the data and, where required, communicate correction or erasure to recipients.

Where TBD fits

TBD can prepare the DSAR, track the deadline, review the response for gaps, and convert the findings into the next complaint, rectification, ComReg, or DPC step.

Before you write

  • Name, address, account number, and collector reference
  • Copy of the demand letter
  • Dates of contact
  • The specific data categories requested
  • Any ID proof requested by the organisation
  • A calendar reminder for the response deadline

Questions people ask

Can a debt collector charge for a GDPR access request?

In most cases, the DPC says individuals cannot be required to pay a fee for an access request. Limited exceptions can apply where a request is manifestly unfounded or excessive.

Should I send the request to the collector or the original provider?

You may need to ask both. The provider may hold the original account history, while the collector may hold the information it received and its own contact records.

Does a GDPR request erase the debt?

No. It gives access to the data trail. Erasure or correction depends on the facts and legal basis for processing.

Related guides

Sources