New UK Data Protection Complaint Rules Explained
If you run a business that handles personal data, which in practice means almost every organisation, you may have seen mention of new complaint handling rules coming into force in 2026 and wondered what they actually require of you. The good news is that these changes are designed to give organisations a clearer, more structured process to follow, rather than adding an extra layer of bureaucracy. Here is what has changed, why it matters, and what you need to have in place.
What Has Changed?
From 19th June 2026, all organisations that process personal data as controllers are legally required to have a clear process for handling data protection complaints. This new requirement comes from the Data (Use and Access) Act 2025, which inserted a new section 164A into the Data Protection Act 2018, creating a statutory right for individuals to complain directly to an organisation before escalating to the Information Commissioner's Office.
According to the ICO's own guidance on how to deal with data protection complaints, there are no exemptions to this requirement. It applies regardless of the size or sector of your organisation. The ICO has been clear that even before the legal requirement took effect, following this guidance represented good practice, so if you have not yet reviewed your processes, now is the time to do so.
What Actually Counts as a Data Protection Complaint?
This is broader than many businesses initially assume. The ICO's guidance on what counts as a complaint explains that if someone considers you have infringed data protection law because of the way you have handled their personal information, that is a complaint, regardless of whether they use formal legal terms or quote specific legislation. This could include concerns about how a subject access request was handled, dissatisfaction with the security measures used to protect personal data following a breach, worries about direct marketing, or questions about how long data has been retained.
Importantly, the rules do not require complaints to be submitted through a specific channel. A complaint can be made by email, by phone, in writing, through social media, or even raised verbally in conversation with a member of staff. Your organisation must be ready to recognise and respond to a complaint however it arrives, not only through a formal complaints form.
What Your Process Needs to Include
Once the new rules apply, organisations must acknowledge receipt of a complaint within 30 days of the day after it is received. Following acknowledgement, you are required to investigate the complaint without undue delay, including making appropriate enquiries and keeping the complainant updated on progress. Once your investigation concludes, you must inform the individual of the outcome without unjustifiable or excessive delay, explaining clearly what steps were taken and what the outcome was, and reminding them of their right to escalate the matter to the ICO if they remain unhappy.
The ICO's guidance is explicit that having a clear complaints process is not just a legal requirement, but good for business, since it gives organisations the opportunity to resolve issues directly with individuals before they feel the need to involve the regulator.
You also need to keep appropriate records throughout the process, covering when a complaint was received, how and when it was acknowledged, the steps taken to investigate it, and the eventual outcome. The ICO may reference these records if a complainant later escalates the matter, so keeping them organised and accessible matters in practice.
Handling Complaints from Children and Third Parties
The new rules also set out specific expectations where complaints involve children or are made by someone acting on another person's behalf. Where a third party submits a complaint, organisations must verify that they are authorised to act before investigating it. Where a complaint comes from or concerns a child, you are expected to assess whether the child has sufficient understanding to exercise their own rights, and to communicate with them using clear, age-appropriate language throughout the process.
What You Should Be Doing Now
Start by updating your privacy notices to clearly explain individuals' right to complain directly to you, and ensure your subject access request response templates also signpost this right, since both are explicit requirements under the new rules. Review your internal procedures to make sure staff across the business, not just your data protection team, know how to recognise a complaint and what to do when one arrives, given that complaints may come through customer service, social media, or general correspondence as easily as through a formal channel.
It is also worth checking your contracts with any data processors you work with, to confirm they support your ability to investigate and respond to complaints within the required timeframes, particularly where a complaint might involve data that a third party processes on your behalf.
Where you already have a customer complaints process in place, you do not necessarily need to build something entirely new. Many organisations are adapting their existing frameworks to ensure data protection complaints are properly identified, tracked, and escalated within them, rather than creating a separate parallel system.
These changes formalise something many organisations were already doing informally, but they raise the bar in terms of consistency, record keeping, and accountability. With the requirement now in force, the organisations that benefit most will be those that treat their complaints process as a genuine opportunity to resolve concerns early, rather than a box ticking exercise.
If you are uncertain whether your current complaints process meets the new requirements, or you would like support reviewing your privacy notices and internal procedures, seeking specialist advice now will help you avoid gaps being exposed later by a real complaint or a regulator's enquiry.
How Can Gerrish Legal Help?
Gerrish Legal is a dynamic digital law firm. We pride ourselves on giving high-quality and expert legal advice to our valued clients. We specialise in many aspects of digital law such as GDPR, data privacy, digital and technology law, commercial law, and intellectual property.
We give companies the support they need to successfully and confidently run their businesses whilst complying with legal regulations without the burdens of keeping up with ever-changing digital requirements.
We are here to help you, get in contact with us today for more information.