This article summarises the forthcoming Data (Use and Access) Act 2025 (“DUAA”) obligations on handling data subject complaints and highlights the practical actions organisations should take now to get ready for the new regime.
New rules on handling data protection complaints
The DUAA creates a statutory right for individuals to raise complaints directly with controllers. Organisations will need a documented complaints handling process in place by 19 June 2026.
In particular, organisations will need to:
- offer clear and accessible routes for submitting complaints;
- acknowledge a complaint within 30 days of receipt;
- take proportionate steps to investigate and respond without undue delay; and
- keep the complainant updated on progress and the eventual outcome.
In March, the Information Commissioner’s Office (“ICO”) issued guidance on meeting these requirements. The guidance distinguishes between what organisations must do (legal requirements), what they should do (recommended good practice), and what they could do (optional measures).
https://ico.org.uk/for-organisations/how-to-deal-with-data-protection-complaints/
Getting ready
Organisations must tell individuals, at the point their personal data is collected, that they can complain directly to the organisation as well as to the ICO. This is typically addressed in the relevant privacy notice and in template correspondence (for example, subject access request (“SAR”) response letters). The ICO also recommends (but does not require) having a written complaints process that is easy to find (for example, published on a website).
Organisations must provide at least one way for people to complain but can choose the channel(s) that work best. The ICO suggests options such as an online form, a dedicated email inbox, or a live chat function. Complaints may also be raised through social media where you have an online presence, so organisations should consider how these will be identified and routed. The guidance notes that social media is not a secure channel and organisations should request an alternative contact method to continue the complaint safely.
Individuals may complain via any route, regardless of whether it appears in an organisation’s published procedure. Staff who might receive complaints should therefore be trained to spot them and escalate them appropriately. It is advisable to review and refresh internal policies to reflect the new rules and the statutory timeframes.
Steps to take once a complaint is received
Complaints must be acknowledged within 30 days of receipt. The 30-day period begins on the day after the complaint is received (regardless of the day of the week).
The ICO also explains that where the deadline falls on a weekend or public holiday, the acknowledgement can be provided on the next working day.
After acknowledgement, organisations must investigate and provide a substantive response without undue delay. In practice, this typically involves:
- collecting relevant information to understand and assess the complaint;
- making appropriate enquiries and investigating the issues raised;
- updating the individual as the matter progresses; and
- keeping an audit trail (the complaint, acknowledgement, investigation steps, outcome, and any resulting actions).
When setting out the outcome, the ICO indicates organisations should:
- set out clearly what was done to address the complaint, including any remediation steps;
- explain the basis on which the organisation believes it has met the relevant data protection requirements; and
- remind the individual they can escalate the matter to the ICO and provide the ICO’s contact details.
Practical actions to take now
Alongside the raft of changes coming into force with the Employment Rights Act 2025, organisations should add another job to their ‘to do’ list and consider undertaking the following steps before 19 June 2026:
- revise privacy notices and SAR/right-request templates to signpost the right to complain directly to the organisation;
- update internal policies and train relevant staff on how to identify data protection complaints, escalate them correctly, and follow the statutory response deadlines;
- if the organisation hasn’t got a formal complaints handling process in place, ensure that this is set up before 19 June 2026;
- review contractual arrangements with processors to confirm they support effective complaint handling (including timely cooperation, information-sharing, and record keeping where relevant);
- keep clear records of complaints, the investigation steps taken, communications issued, and outcomes reached to evidence compliance.
Speak with our specialist experts Michelle Morgan ,Diane Yarrow and Peter James to make sure your business is prepared for the Data (Use and Access) Act 2025 complaint-handling rules.