Authors
Authors
Article:
In our earlier article, “ICO guidance explained: the new data protection complaints regime from June 2026”, we outlined the new obligation introduced under section 103 of the Data (Use and Access) Act 2025 for all organisations to operate a data protection complaints process from 19 June 2026 where there has been any infringement of UK data protection law. Such processes are designed to address, for example, complaints about how personal data has been collected or used by an organisation, the way in which a Subject Access Request has been responded to or concerns following a data breach incident.
With that deadline fast approaching, organisations should now be carrying out final checks that their processes work in practice, and not just on paper.
Complaints can be made in various ways
The guidance from the data protection regulator, the Information Commissioner’s Office (ICO) makes clear that organisations must accept complaints however they are received, including through channels outside any formal complaints process.
In practice, this means complaints may be received by:
- email or online forms
- telephone or in person
- general enquiry inboxes
- post
- social media or other public platforms
Complaints picked up by customer facing teams, marketing teams or social media managers should be identified and promptly escalated to the relevant team or contact tasked with responding to data protection complaints. Organisations should also be careful to ensure that all social media accounts, email inboxes, and postal addresses are actively monitored. A good process will have clear signposting as to how data protection complaints can be raised with organisations to assist with this. Further, organisations should be careful not to respond to a complaint on social media and should instead request alternative contact information from the complainant as the ICO has highlighted that social media is not a secure form of communication.
30 days to acknowledge
The 30 day timeframe for acknowledging a complaint begins the day after it is received, regardless of the channel by which it was submitted.
The ICO advises that you do not need to acknowledge a complaint within 30 days if it is resolved before the 30-day deadline. However, it is advisable that organisations put in place automated acknowledgements in the form of a text or email to avoid the acknowledgment deadline being missed.
If complaints are made and/or acknowledged in person, clear written records should be kept, particularly where it may not be possible to follow up with an acknowledgement email or text message, in order to stay within the 30 day timeframe.
Identifying complaints early
Complaints may be raised in general or informal terms and may also be mixed with broader service complaints or data subject rights requests. Organisations should have a clear triage process to identify when a complaint engages data protection obligations and ensure it is handled accordingly.
This may mean that any complaint which mentions or references personal information, personal data, or data protection, should be escalated and assessed as to whether it is a data protection complaint and therefore needs to be dealt with under the organisation’s data protection complaints policy, acknowledged within the 30 day timeframe and responded to without undue delay (see below).
It is important that complaints are not dismissed simply because they include minor mention of data protection. If in doubt, those handling the complaints should be trained to contact the complainant and request further information to establish if the complaint can be classified as a data protection complaint.
Acting promptly, not just acknowledging
While complaints must be acknowledged within 30 days, the ICO expects organisations to investigate and respond without undue delay, starting when the complaint is received.
Organisations should have internal processes to enable:
- early triage (ideally within one working day of the complaint being received)
- diary tracking of acknowledgment deadlines
- escalation of urgent or high-risk complaints
Updating notices and communications
The ICO expects organisations to inform individuals of their right to complain, including in privacy notices and when responding to subject access requests.
Compliance requires reviewing not just complaints policies, but also privacy notices, template responses, for example, template data subject access request replies, and website content and customer communications to ensure that they all reference the right to complain.
Record-keeping
Organisations should keep records of complaints, how they are handled and their outcomes, and monitor trends or recurring issues. Complaint logs allow organisations to evidence compliance and identify potential systemic risks.
Putting the complaints process into practice
Compliance is less about introducing new systems and more about ensuring that existing processes capture and respond to complaints wherever they arise, including less obvious channels such as post and social media.
With the deadline approaching, organisations should ensure their processes are operational, documented and understood across the business, not just by legal or compliance teams. Training sessions for all employees are advisable, particularly as complaints can be made in person, and knowledge of the requirements will therefore be needed across organisations.
Print article