Data Protection Complaints – Action needed for every data controller

29th July 2026

Much of the attention around the Data (Use and Access) Act 2025 (DUAA) has focused on technical changes that appeal to data protection geeks (like me and my colleagues?) such as the scope of a reasonable and proportionate search, how controllers can use automated decision-making and a broad lawful basis of legitimate interests for scientific research. However, one of the most immediate practical changes for all organisations is the introduction of a formal requirement to have a process for handling data protection complaints. This affects every organisation that processes personal data.

The new provisions, inserted into the Data Protection Act 2018, give individuals a statutory right to raise a data protection complaint directly with an organisation before escalating the matter to the ICO. Organisations must provide a way for complaints to be made, must acknowledge them within 30 days, investigate them without undue delay and communicate the outcome to the complainant.

For many businesses, the first task will be updating their privacy policy. Individuals should be told that they have the right to make a data protection complaint and given clear information about how to do so. This is also a good opportunity to review whether existing contact details and internal processes remain fit for purpose.
The second step is putting in place a documented complaints procedure. While the legislation does not prescribe a particular format, a written policy will help ensure complaints are handled consistently and that appropriate records are maintained. The policy should cover how complaints are received, who investigates them, escalation routes and expected timescales.

If a data subject complains to the ICO without first exhausting the data controller’s complaints process, we would expect them to be rebuffed and directed to the organisation’s complaints procedure. If there is no complaints process, this will immediately stand out to the ICO!

Perhaps the biggest challenge is staff awareness. A data protection complaint does not need to mention the GDPR or use legal language. An individual simply expressing dissatisfaction with how their personal data has been handled may be making a complaint. Front-line teams including those dealing with social media accounts or other unorthodox communication channels need training to recognise complaints, understand when they should be escalated and know where these complaints fit within the organisation’s wider compliance framework.

For organisations that have not yet reviewed their processes, now is a good time to update privacy policies, implement a complaints procedure (that ideally dovetails with any existing complaints procedure) and ensure staff know what a data protection complaint looks like before one lands in their inbox.