From 19 June 2026, businesses in the UK are subject to new statutory data protection complaints handling requirements, intended to give individuals a clearer route for raising data protection complaints directly with businesses before escalating matters to the Information Commissioner’s Office (“ICO”).

Although the new rules are unlikely to require significant operational changes for most businesses, particularly those that already have data subject rights or customer complaints processes in place, they do require controllers to ensure that data protection complaints can be identified, acknowledged, investigated and responded to in a timely manner. This will include making sure that privacy notices flag that: (i) individuals have the right to complain; and (ii) how they can exercise it.

The New Requirements

From 19 June 2026, businesses will need to:

  1. Have a process for handling data protection complaints. For many businesses, this can be a light-touch process that is incorporated into existing privacy, data subject rights request or customer complaints procedures, provided that data protection complaints are appropriately identified and escalated.
  2. Give individuals a way to make data protection complaints. The ICO has indicated that this could be as simple as providing an email address. Businesses do not necessarily need to create a dedicated complaints inbox, provided their privacy notice or other relevant materials explain clearly how individuals can complain.
  3. Acknowledge receipt within 30 days. Businesses must acknowledge data protection complaints within 30 days of receiving them. This will require businesses to track complaints in the same way they do other individual rights requests.
  4. Respond without undue delay. Businesses must take appropriate steps to respond to complaints, including making appropriate enquiries and keeping individuals informed.
  5. Communicate the outcome without undue delay. Businesses must tell individuals the outcome of their complaints once they have been considered. There is no hard deadline, however, within which to substantively respond to the complaint.

What Should Businesses Do Now?

For many businesses, preparing for the new rules should be a relatively contained exercise. Practical steps may include:

  • reviewing privacy notices to ensure they clearly explain that individuals have the right to complain and how they can do so;
  • confirming whether an existing email address or contact route is sufficient for complaints;
  • updating data subject rights request, privacy or customer complaints procedures to include data protection complaints;
  • ensuring relevant teams know how to recognise and escalate complaints about personal data such that they are treated appropriately; and
  • maintaining basic records of complaints received, steps taken and outcomes communicated.

Businesses may also wish to review template responses for data subject rights requests to ensure they accurately signpost individuals to both the business’s internal complaints route and the ICO.

Key Takeaways

The new regime is not expected to be a material compliance burden for most businesses, but it does create a clear procedural requirement that should not be overlooked. Businesses that already have privacy governance processes in place may be able to address the changes through targeted updates to existing notices, policies and internal escalation procedures.

***

To subscribe to the Data Blog, please click here.

The cover art used in this blog post was generated by ChatGPT.