Data Protection Complaints

Most people are aware that they can raise concerns with the Information Commissioner’s Office (ICO) if they believe an organisation has mishandled their personal data. However, since 19 June 2026, organisations have been expected to take a more active role in resolving data protection complaints before matters are escalated to the ICO.

These changes stem from the Data (Use and Access) Act 2025 and accompanying ICO guidance. The aim is to introduce a clearer complaints process and encourage issues to be resolved directly between individuals and organisations wherever possible.

What is a Data Protection Complaint?

A data protection complaint is any concern that an organisation has not complied with data protection law when processing personal data.

A complaint can be raised by anyone whose personal data is processed by the organisation, including:

  • Employees
  • Job applicants
  • Customers and clients
  • Suppliers and contractors
  • Service users
  • Website visitors
  • Any other individuals whose personal data the organisation holds

Complaints could be about any concern with how personal data has been processed. With the rising volume of data subject access requests (DSARs), we anticipate the right to complain to see a similar uplift.

What This Means for Employers and HR Teams

For many organisations, data protection complaints are likely to arise within the context of employment and recruitment. Employees, workers and job applicants may raise concerns about the handling of records, personnel files, absence and health information, payroll data and grievance or disciplinary processes. This can include how their personal data has been collected, used, shared or stored.

Data protection issues can often overlap with employment disputes. For example, an employee involved in a grievance or disciplinary process, or a candidate who is unsuccessful in applying for a role, may also question how their personal data has been handled. Employers should be alert to situations where an employment issue can result in a data protection complaint. Effective complaint handling can help organisations resolve concerns at an early stage and reduce the likelihood of involving the ICO.

As the new right to complain comes into force, employers should consider whether their HR and recruitment processes are equipped to recognise and manage data protection concerns, ensure privacy information is clear and accessible and provide training to HR teams and managers responsible for handling complaints and data protection issues.

Effective internal complaint handling not only helps reduce the need for regulatory involvement, but can also strengthen trust and transparency across organisations.

How Complaints Now Work

Individuals have a statutory right to complain directly to an organisation about how their personal data has been handled. This right has been added to the Data Protection Act 2018 and requires organisations to have a clear process for managing data protection complaints.

In most cases, organisations are expected to consider and respond to complaints before individuals decide whether to escalate the matter to the ICO.

The ICO has confirmed that all organisations, regardless of size or sector, should have an appropriate internal process for handling data protection complaints.

What Organisations Must Do

Organisations must be able to demonstrate that they have clear and effective procedures for handling data protection complaints. This may include:

  • Providing a clear method for submitting complaints, such as an email address, online form or telephone number
  • Acknowledging complaints within 30 days
  • Investigating complaints without undue delay
  • Keeping complainants informed about progress
  • Providing a clear outcome once the investigation has concluded

Organisations are not necessarily required to create entirely new systems. However, existing complaints and data protection procedures should be reviewed regularly to ensure they remain accessible, effective and aligned with legal requirements and ICO expectations.

The ICO’s Role

The ICO’s role has also evolved. The intention behind the new regime is to encourage more complaints to be resolved directly between organisations and individuals before regulatory intervention is required.

Where a complaint is escalated, the ICO is likely to expect evidence that the organisation has handled the matter appropriately. As a result, maintaining clear records and communicating effectively with complainants has become increasingly important.

Next Steps

Organisations should ensure their complaints procedures reflect the new requirements and are capable of dealing with data protection concerns effectively. In practice, this means:

  • Reviewing privacy notices to ensure they explain individuals’ right to complain
  • Making complaint routes easy to find and use
  • Training staff to recognise and appropriately handle all data rights, including the right to complain
  • Ensuring complaints are managed consistently and within appropriate timescales
  • Maintaining records of complaints, investigations and outcomes

The changes place greater responsibility on organisations to resolve concerns directly and transparently. By having effective procedures in place, organisations can improve trust, demonstrate accountability and reduce the likelihood of ICO involvement.

If this is something you need assistance with, please contact our Data Protection team.

This article was co-written by Max Miliffe, Data Protection Specialist and Mia Beavis, Paralegal in our Intellectual Property, Data Protection and Technology team.