News & Insights

New Data Protection Complaints Procedures – Key Actions for Organisations

July 2026

  • Commercial & Technology

From 19 June 2026, new legal requirements governing how personal data protection complaints are handled came into force across the UK. The change forms part of reforms introduced under the Data (Use and Access) Act 2025 (DUAA) and applies to all organisations that process personal data, regardless of size or sector. Individuals must now have a clear, accessible route to raise data protection complaints, and those concerns must be handled in a structured and timely way.

What Businesses Must Do

It is important to have a documented complaints process that is easy for individuals to find and use and ensure they:

  • Provide a clear route to complaint: A defined complaints process that is easy for individuals to find and use is key, consider how best to present it – this could be via your website, a digital complaints form, or specific contact details for data protection complaints.
  • Acknowledged within 30 days: A formal acknowledgement is required in this timeframe – consider the most effective way to provide this to complainants, based on your business, for example: via automatic acknowledgement or more personalised communication.
  • Investigated complaints appropriately: DUAA 2025 requires organisations to take appropriate steps to investigate and respond to the complaint without undue delay, organisations should also consider if further information requests are required to assist in managing the complaint.
  • Clearly communicate the outcome: The response should explain the action taken, the outcome of the complaint and the organisation's position on its handling of the complainant's personal data. Where appropriate, a review process for disputed decisions may also be beneficial.

These steps are designed to ensure complaints are not only logged but actively resolved through a transparent and consistent process. Clear records should be maintained of complaints, investigations, decisions and any remedial action taken. This helps demonstrate accountability and good governance, identify recurring issues, and provides valuable opportunities to improve policies, procedures and customer outcomes.

Why This Matters for Business

A well-handled complaint can strengthen customer trust, reduce reputational risk and help minimise the likelihood of further regulatory scrutiny. The aim of the new requirements is not to create unnecessary administrative burden, but to encourage concerns to be identified and resolved at an earlier stage. Complaint data can also provide valuable insight into wider issues with data handling, particularly where recurring themes emerge around subject access requests.

Research highlighted by the Information Commissioner's Office (ICO) suggests that many organisations are still unaware of the new requirements or mistakenly believe they do not apply to them. Now that the changes are in force, it is important to review existing complaints procedures and ensure they align with the ICO guidance processes.

Practical Steps for Compliance

Organisations who are reviewing their processes due to the change should:

  • Design or Update the Complaint Handling Process: This could be embedded into existing complaints process or be standalone and focused on data protection matters. As part of this, organisations should review how customers can currently submit data protection complaints.
  • Set Ownership: Assign responsibility for investigation and responding to data protection complaints. Ensure staff know how to recognise and escalate complaints appropriately.
  • Update Privacy Documentation: Ensure privacy notices and other external facing documents explain process for raising data protection complaints.
  • Train Teams and Determine Internal Recording Processes: This may include setting up systems to track acknowledgement and response timelines and checking that response are clear, consistent, and legally compliant. Training teams on how to handle personal data, potential common complaint types and how they should be handled is also important.
  • Third Party Relationships: Organisations will often have relationships with third parties, such as data processing agreements and controller / controller arrangements, which may need review to ensure complaints handling responsibilities are accurately assigned.
Building Trust Through Better Handling

The new requirements are designed to strengthen trust by ensuring concerns about personal data are handled fairly, consistently and without unnecessary delay. An effective complaints process demonstrates a commitment to transparency and accountability, while also providing valuable insight into how data protection practices can be improved before issues escalate.

As the new framework becomes embedded, the Information Commissioner's Office (ICO) is encouraging organisations to make full use of its guidance and supporting materials when reviewing and refining their complaints procedures.