29/05/2026

From 19 June 2026, organisations handling personal data must have an internal complaints process in place under changes introduced by the Data (Use and Access) Act 2025.

It will no longer be enough to simply direct individuals to the ICO. Organisations must be able to:

  • receive and investigate data protection complaints;
  • respond within statutory timescales; and
  • explain escalation rights.

If an individual cannot easily find:

  • how to complain,
  • who to contact,
  • expected response times, and
  • their right to escalate to the ICO,

then the organisation is likely to struggle to demonstrate compliance with the new requirements under the Data (Use and Access) Act 2025.

For most organisations, the safest approach is:

  • update the privacy notice; and
  • publish a short standalone data protection complaints procedure online.

For many organisations, this also means reviewing polices and procedures, website content and staff practices.

This is one of the quieter changes within the DUAA 2025, but potentially one of the most overlooked.

With the deadline approaching quickly, now is the time to check whether your organisation’s data protection complaints process is actually in place and whether staff know how to use it.

If you need some bespoke guidance, new policy or complaints procedure email dpo@jhdataprotection.com

Leave a comment

  • With Great Power Comes Great Responsibility:

    Why AI Makes Data Protection More Important Than Ever 26/08/2026 I have always been fascinated by emerging technology. Part of working in data protection is trying to keep ahead of the game: understanding not only what technology can do now, but what it might be capable of next, and what that means for the people…

  • Cyber security is a data protection issue: lessons from the ICO’s ACRO reprimand

    14/08/2026 The Information Commissioner’s Office (ICO) has reprimanded ACRO Criminal Records Office following cyber security failings which potentially exposed the personal information of up to 10,920 people. The case is a useful reminder for organisations that cyber security is not simply an IT issue. It is a fundamental part of data protection compliance, accountability and…

  • Council officer convicted for unlawfully accessing personal data

    24/07/2026 The Information Commissioner’s Office (ICO) has recently highlighted an important reminder for all organisations that handle personal information: having access to a system does not mean you are entitled to access every record within it. A former Herefordshire Council employee has received a suspended prison sentence after unlawfully accessing approximately 490 personal records and…

  • Why Smart Companies Keep Getting Data Protection Wrong

    12/07/2026 The biggest data protection risk? It’s certainty. The organisations most likely to get into difficulty with data protection are rarely the ones asking difficult questions. They’re the ones convinced they’re already compliant. Whether it’s a multinational or a start-up, the mistakes are remarkably similar: Collecting data because they can, not because they need to.…