Data Protection Complaints

Most people are aware that they can raise concerns with the Information Commissioner’s Office (ICO) if they believe an organisation has mishandled their personal data. However, since 19 June 2026, organisations have been expected to take a more active role in resolving data protection complaints before matters are escalated to the ICO.

These changes stem from the Data (Use and Access) Act 2025 and accompanying ICO guidance. The aim is to introduce a clearer complaints process and encourage issues to be resolved directly between individuals and organisations wherever possible.

What is a Data Protection Complaint?

A data protection complaint is any concern that an organisation has not complied with data protection law when processing personal data.

A complaint can be raised by anyone whose personal data is processed by the organisation, including:

  • Employees
  • Job applicants
  • Customers and clients
  • Suppliers and contractors
  • Service users
  • Website visitors
  • Any other individuals whose personal data the organisation holds

Complaints could be about any concern with how personal data has been processed. With the rising volume of data subject access requests (DSARs), we anticipate the right to complain to see a similar uplift.

How Complaints Now Work

Individuals have a statutory right to complain directly to an organisation about how their personal data has been handled. This right has been added to the Data Protection Act 2018 and requires organisations to have a clear process for managing data protection complaints.

In most cases, organisations are expected to consider and respond to complaints before individuals decide whether to escalate the matter to the ICO.

The ICO has confirmed that all organisations, regardless of size or sector, should have an appropriate internal process for handling data protection complaints.

What Organisations Must Do

Organisations must be able to demonstrate that they have clear and effective procedures for handling data protection complaints. This may include:

  • Providing a clear method for submitting complaints, such as an email address, online form or telephone number
  • Acknowledging complaints within 30 days
  • Investigating complaints without undue delay
  • Keeping complainants informed about progress
  • Providing a clear outcome once the investigation has concluded

Organisations are not necessarily required to create entirely new systems. However, existing complaints and data protection procedures should be reviewed regularly to ensure they remain accessible, effective and aligned with legal requirements and ICO expectations.

The ICO’s Role

The ICO’s role has also evolved. The intention behind the new regime is to encourage more complaints to be resolved directly between organisations and individuals before regulatory intervention is required.

Where a complaint is escalated, the ICO is likely to expect evidence that the organisation has handled the matter appropriately. As a result, maintaining clear records and communicating effectively with complainants has become increasingly important.

Next Steps

Organisations should ensure their complaints procedures reflect the new requirements and are capable of dealing with data protection concerns effectively. In practice, this means:

  • Reviewing privacy notices to ensure they explain individuals’ right to complain
  • Making complaint routes easy to find and use
  • Training staff to recognise and appropriately handle all data rights, including the right to complain
  • Ensuring complaints are managed consistently and within appropriate timescales
  • Maintaining records of complaints, investigations and outcomes

The changes place greater responsibility on organisations to resolve concerns directly and transparently. By having effective procedures in place, organisations can improve trust, demonstrate accountability and reduce the likelihood of ICO involvement.

If this is something you need assistance with, please contact our Data Protection team.

This article was co-written by Max Miliffe, Data Protection Specialist and Mia Beavis, Paralegal in our Intellectual Property, Data Protection and Technology team.