The Data (Use and Access) Act 2025 (“DUAA“), introduces a new statutory requirement for all controllers, with no exceptions, to implement a formal process to handle data protection complaints by 19 June 2026.

Key changes

The DUAA received Royal Assent on 19 June 2025 and introduces a number of amendments to the UK’s data protection regime. Although data subjects have the right under the UK GDPR to lodge complaints directly with the ICO, there was no explicit obligation on organisations to maintain an internal complaints procedure.

The DUAA addresses this by inserting a new section 164A into the Data Protection Act 2018 – creating a statutory right for individuals to raise complaints directly with controllers before escalation to the ICO. To assist with this, all controllers must have a process in place to handle data protection complaints by 19 June 2026.

Under the DUAA controllers must:

  • give data subjects a way of making data protection complaints directly;
  • acknowledge receipt of complaints within 30 days of receiving them;
  • without undue delay, take appropriate steps to respond to complaints, including making appropriate enquiries, and keep people informed; and
  • without undue delay, tell people the outcome of their complaints.

ICO Guidance

The ICO has published new Guidance on preparing for data protection complaints, which sets out practical steps organisations should take ahead of the new requirements coming into force on 19 June 2026:

  • The Guidance is clear that organisations must ensure individuals are able to submit data protection complaints directly. The ICO allows flexibility in how this is achieved, suggesting a range of channels such as complaint forms, email, telephone, online portals, live chat, or in‑person submissions. Existing complaint frameworks can be adapted, rather than creating entirely new systems. Importantly, the Guidance is clear that organisations should be ready to accept complaints through any channel – even where this is not through the set processes – including informal routes such as social media or contact with staff.
  • Organisations must inform individuals of their right to complain, including in privacy notices, and provide clear, plain‑language explanations of the process. Specific protections should be in place when handling complaints from children, including using age‑appropriate language.
  • The ICO also highlights operational requirements, including verifying identity and authority (where complaints are made on behalf of others), maintaining adequate record‑keeping systems, and ensuring staff are properly trained to recognise and manage complaints.  Organisations must also consider how complaints will be handled in more complex scenarios, such as where multiple controllers or processors are involved, ensuring clear allocation of responsibilities and effective coordination.
  • Once a complaint is received, organisations must acknowledge receipt of the complaint within 30 days and then investigate the issue without undue delay. Controllers are required to maintain communication with the complainant, providing updates on progress and any anticipated timelines. They must also keep detailed records of complaints, including receipt, correspondence, investigation steps, outcomes and any remedial actions taken, both to demonstrate compliance and to identify recurring issues or trends.
  • Once the investigation is completed, the complainant must be informed about the outcome without an unjustifiable or excessive delay, with a clear explanation of the steps that have been taken to resolve the complaint and any actions taken. Individuals must also be informed of their right to complain to the ICO and be provided with the ICO’s contact details. 

What steps should organisations be taking now?

With 19 June 2026 fast approaching, organisations should act now to ensure data complaints processes are ready for the new requirements, including:

  • implementing a clear internal process for receiving and handling complaints in line with the new requirements under DUAA. This should include processes to identify, acknowledge and respond to complaints within the required timeframes;
  • updating privacy notices and communications to inform data subjects of the right to complain directly to the controller.
  • ensuring processes are in place to record complaints, including, the date the complaint was received, the acknowledgement of the complaint, any relevant conversations and documents, the outcome of the complaint; and any actions taken as a result of the investigation;
  • assessing policies, procedures and employee training to ensure that complaints will be identified, investigated and handled consistently;
  • reviewing processor contracts to ensure that processors are obliged to notify complaints in a timely fashion and provide support to the controller (similar to other data subject rights); and
  • undertaking periodic reviews of complaints to consider whether there is anything to learn as an organisation in relation to the circumstances that lead to complaints, with a view to making improvements to how personal data is processed and recording what these are. This is key for demonstrating accountability.