The Information Commissioner’s Office (ICO) wants businesses to resolve data protection concerns “in-house” before approaching the regulator. The aim: quicker outcomes for individuals, less pressure on ICO resources, and stronger data subject trust.
What the new rules require
A “data protection complaint” arises when someone believes your business has breached data protection law in handling their personal data. The complainant could be a customer, client, third party or employee — anyone whose data you process. Importantly, the complaint must relate to the handling of personal data; a complaint purely about service quality does not qualify, even if it touches on data rights.
The obligation applies to every data controller, regardless of size. There are no exemptions.
In practice, you must:
- accept data protection complaints through any channel
- provide an accessible way to receive them
- acknowledge receipt within 30 days and
- respond without “undue delay”— investigate promptly, keep the individual updated, explain the outcome, and inform them of their right to escalate to the ICO
The ICO expects you to investigate properly: gather the facts, consult the right people internally, and check compliance with your own policies.
There is no need to reinvent the wheel — existing complaints systems can be adapted. Options include online or paper forms, a dedicated email address, a phone line, a portal, live chat with human escalation, or in-person channels. However, even if you publicise a preferred channel, you must still accept complaints received by any route.
Consider publishing a complaints procedure on your website covering: how to submit a complaint; what supporting information is needed; acceptable forms of ID and authority (for complaints made on someone else’s behalf); and expected timescales for acknowledgement, updates and outcomes.
You must also tell individuals about their right to complain—both to you and to the ICO—when collecting personal data and when responding to subject access requests. Update your privacy policy and any Subject Access Response template letters accordingly.
Internally, develop procedures for handling and resolving complaints—including those received informally. These policies need not be published, but staff must be trained on them. A structured approach builds accountability, strengthens trust, and reduces the risk of escalation to the ICO.
Your action list
Key steps to take now:
- Update your privacy policy (and SAR template letters) to inform data subjects of their right to complain, with clear guidance on how to do so.
- Create a formal data complaints policy setting out your process and assigned responsibilities.
- Put accessible mechanisms in place for receiving complaints—adapt existing systems where possible.
- Set up processes to acknowledge complaints within 30 days and provide timely updates.
- Train staff to recognise data protection complaints (as distinct from service complaints) and follow escalation procedures.
Need help? For support reviewing your data protection compliance or implementing these changes, contact our Commercial team by email or call 01293 558562.