New Data Protection Complaints Process: Is Your Business prepared?
From 19 June 2026, all organisations must have a data protection complaints process in place.
The new requirements?
The ICO has made clear that under the Data Use and Access Act 2025 (DUAA), organisations must have an internal process for handling data protection complaints.
The new law means that you must:
- give people a clear way to raise a data protection complaint;
- acknowledge it within 30 days of receipt
- without undue delay, take appropriate steps to investigate and keep people informed; and
- tell the complainant of the outcome.
What has changed
In the past, individuals may have complained directly to the ICO about an organisation’s data protection practices. Under the new process, the complainant must first raise the complaint with the organisation concerned before it can be escalated to the ICO.
What is a data protection complaint?
A data protection complaint is made when an individual considers that you have failed to comply with your data protection obligations in your handling of their personal data and submits a complaint to you as a result.
Data protection complaints commonly arise from issues such as Subject Access Requests (SARs), data breaches, security measures in place to store personal information, and how information has been collected.
Act now
With less than one month remaining before these requirements come into force, your organisation should take immediate steps to put this complaints process in place.
At Carson McDowell our specialist Data team can help you ensure that your organisation takes the appropriate steps to comply. For more information please contact our Head of Data Protection and Information Law Laura Cunningham.