Hand touching and signing a tablet.

DATA PROTECTION LAW

Data protection update: are you ready for data complaints?

The Data (Use and Access) Act 2025 (DUAA) introduces an important new compliance duty for businesses. From 19 June 2026, all organisations must have a clear and accessible process for handling data protection complaints.

The Information Commissioner’s Office (ICO) wants businesses to resolve data protection concerns “in-house” before approaching the regulator. The aim: quicker outcomes for individuals, less pressure on ICO resources, and stronger data subject trust.

What the new rules require

A “data protection complaint” arises when someone believes your business has breached data protection law in handling their personal data. The complainant could be a customer, client, third party or employee — anyone whose data you process. Importantly, the complaint must relate to the handling of personal data; a complaint purely about service quality does not qualify, even if it touches on data rights.

The obligation applies to every data controller, regardless of size. There are no exemptions.

In practice, you must:

  • accept data protection complaints through any channel
  • provide an accessible way to receive them
  • acknowledge receipt within 30 days and
  • respond without “undue delay”— investigate promptly, keep the individual updated, explain the outcome, and inform them of their right to escalate to the ICO

The ICO expects you to investigate properly: gather the facts, consult the right people internally, and check compliance with your own policies.

There is no need to reinvent the wheel — existing complaints systems can be adapted. Options include online or paper forms, a dedicated email address, a phone line, a portal, live chat with human escalation, or in-person channels. However, even if you publicise a preferred channel, you must still accept complaints received by any route.

Consider publishing a complaints procedure on your website covering: how to submit a complaint; what supporting information is needed; acceptable forms of ID and authority (for complaints made on someone else’s behalf); and expected timescales for acknowledgement, updates and outcomes.

You must also tell individuals about their right to complain—both to you and to the ICO—when collecting personal data and when responding to subject access requests. Update your privacy policy and any Subject Access Response template letters accordingly.

Internally, develop procedures for handling and resolving complaints—including those received informally. These policies need not be published, but staff must be trained on them. A structured approach builds accountability, strengthens trust, and reduces the risk of escalation to the ICO.

Your action list

Key steps to take now:

  1. Update your privacy policy (and SAR template letters) to inform data subjects of their right to complain, with clear guidance on how to do so.
  2. Create a formal data complaints policy setting out your process and assigned responsibilities.
  3. Put accessible mechanisms in place for receiving complaints—adapt existing systems where possible.
  4. Set up processes to acknowledge complaints within 30 days and provide timely updates.
  5. Train staff to recognise data protection complaints (as distinct from service complaints) and follow escalation procedures.

Need help? For support reviewing your data protection compliance or implementing these changes, contact our Commercial team by email or call 01293 558562.

About the authors


about the author img

Rebecca Leeves

Senior Associate

Advises on all areas of Commercial Law and business matters with experience gained across a broad range of industry sectors including education and IT.
about the author img

Sasha Floate

Paralegal

Supports the Commercial team on a variety of matters.

Stay connected, sign up for updates

Stay connected

Recent articles

Insights

The EU’s new AI transparency rules: what you need to know

If in doubt, stick to the core principle: make it clear when AI is being used in a way that could mislead people.

29/06/2026

Insights

DMH Stallard advises SAVANA on first international acquisition of Gutter Games portfolio

Leading South East law firm DMH Stallard has advised French board game publisher SAVANA SAS on the acquisition of the Gutter Games brand portfolio from Razor Group...

27/05/2026

Insights

Has data protection compliance become a little easier?

Three changes that may simplify your day-to-day compliance and a new complaints’ regime arriving this summer.

07/04/2026

Insights

The Data (Use and Access) Act 2025 and Subject Access Requests

The Data Act 2025 brings a significant update, introducing reforms to the UK GDPR and the Data Protection Act 2018.

07/10/2025

DISCLAIMER:

THIS INFORMATION IS FOR ILLUSTRATIVE PURPOSES AND IS NOT INTENDED TO AMOUNT TO LEGAL ADVICE ON WHICH RELIANCE SHOULD BE PLACED. WE, DMH STALLARD LLP, DISCLAIM ALL LIABILITY AND RESPONSIBILITY ARISING FROM ANY RELIANCE PLACED ON THIS INFORMATION. ANY RELIANCE ON THIS INFORMATION IS SOLELY AT YOUR RISK. The provision of this information does not create a business or professional services relationship. This information is not exhaustive and does not attempt to address every issue relevant to a particular situation. If you require advice on a specific legal issue, please contact a lawyer listed on our website, dmhstallard.com, or send an email to [email protected].