From 19 June 2026, organisations that process personal data face an important new legal responsibility under the Data (Use and Access) Act 2025 (DUAA).
For many organisations, this change may require a significant shift in how data protection complaints are identified, recorded, investigated and resolved.
The message from the legislation is clear: organisations must take ownership of data protection complaints and provide individuals with a meaningful opportunity to have concerns addressed internally before they escalate matters to the Information Commissioner’s Office (ICO).
A Data Protection Complaint Could Arrive Anywhere
One of the biggest misconceptions organisations have is that data protection complaints only arrive through formal channels.
In reality, a complaint may be raised through:
- A social media message
- A live chat conversation
- A customer service enquiry
- An HR discussion
- An email to a member of staff
- A complaint made during a meeting
- A concern raised to a manager or supervisor
Under the new requirements, the channel used does not change the organisation’s responsibilities.
If an individual is expressing concern about how their personal data has been collected, used, stored, shared or managed, your organisation may have a legal obligation to act.
This means every employee—not just compliance teams or Data Protection Officers—needs to understand how to recognise and escalate a data protection complaint.
What Does the Law Require?
The DUAA introduces specific expectations around complaint handling.
Organisations should ensure they can demonstrate that they have:
Acknowledged Complaints Promptly
Complaints must be acknowledged within 30 days of receipt.
Individuals should be informed that their concern has been received and advised of the next steps.
Investigated Concerns Appropriately
Complaints should be reviewed without unnecessary delay.
Organisations should have clear internal procedures outlining who investigates complaints, how evidence is gathered and how decisions are reached.
Kept Individuals Informed
People raising concerns should receive updates throughout the process and be provided with a clear explanation of the outcome.
Good communication is not only a legal requirement—it also helps build trust and confidence.
Maintained Detailed Records
Organisations should maintain clear audit trails showing:
- When the complaint was received
- How it was identified
- Who was responsible for the investigation
- Actions taken
- Communications with the complainant
- The final outcome
If the ICO becomes involved, these records may be essential in demonstrating compliance.
Why Staff Training Matters More Than Ever
Many organisations already provide annual GDPR or data protection training.
However, the DUAA highlights the need for practical awareness across the workforce.
Ask yourself:
- Would your reception staff recognise a data protection complaint?
- Would your HR team know when to escalate a concern?
- Would customer service staff know how to log and record an issue?
- Would managers understand their responsibilities?
If the answer is “not sure”, there may be a compliance gap that needs addressing.
The most effective organisations are moving beyond compliance-only training and ensuring that everyone understands their role in the complaint handling process.
Accessibility and Inclusion Cannot Be Overlooked
An often-overlooked aspect of complaint handling is accessibility.
People may choose different communication methods because of:
- Disability
- Neurodivergence
- Language barriers
- Cultural preferences
- Literacy levels
- Digital exclusion
Organisations should ensure complaint processes are accessible, inclusive and responsive to individual needs.
Providing multiple routes for raising concerns, using clear language and offering reasonable adjustments can help ensure that nobody is disadvantaged when exercising their data protection rights.
Embedding equality, diversity and inclusion into complaint handling processes is not only good practice—it supports compliance, trust and fairness.
Five Actions Organisations Should Take Now
- Review existing complaint handling procedures.
- Ensure data protection complaints can be identified across all communication channels.
- Train staff on recognising and escalating complaints.
- Implement robust recording and audit trail processes.
- Review accessibility and equality considerations within complaint procedures.
The Bottom Line
The Data (Use and Access) Act 2025 is more than a technical compliance update.
It places greater accountability on organisations to recognise, investigate and resolve data protection complaints effectively.
Those that invest now in staff awareness, accessible processes and robust complaint management systems will be better positioned to reduce risk, maintain public trust and demonstrate compliance.
The question is not whether your organisation will receive a data protection complaint.
The question is whether every member of staff will know what to do when one arrives.
