New UK statutory data protection complaints regime now in force

Published on 18 September 2026

The question

What do the UK’s new statutory data protection complaints requirements mean for organisations handling personal data and what steps should be taken now to ensure compliance?

The key takeaway

All organisations must now operate a compliant data protection complaints process as a legal requirement, including acknowledging complaints within 30 days of receipt and handling them appropriately. Businesses should review governance, customer support and privacy processes to ensure they can identify, investigate and respond to data protection complaints effectively.

The background

The remaining data protection provisions of the Data (Use and Access) Act 2025 (DUAA) came into force on 19 June 2026, introducing new statutory obligations on all organisations to operate an effective data protection complaints process. DUAA is the post-Brexit data protection statute in the UK, and the complaints procedure is the most substantive day-to-day change to the UK data protection regime for most organisations.

The development

The new regime requires organisations to provide individuals with an accessible way to make a data protection complaint such as by online form, email or phone, and to acknowledge those complaints within 30 days. Organisations must then investigate complaints appropriately, keep complainants informed and communicate the outcome without undue delay.

For organisations with a significant online presence, the Information Commissioner’s Office (ICO) acknowledges social media as a likely channel for data protection complaints and recommends implementing appropriate processes to identify and manage complaints, including transferring the interaction to a more secure channel once the complaint has been received.

The ICO also reinforces transparency expectations: organisations should inform people they can complain to the organisation and to the ICO, including at the point of data collection (for example in privacy notices) and when responding to subject access requests, using clear and plain language particularly where children are concerned. In practice, many organisations are likely to need to put in place a more formal complaints procedure or policy and introduce a complaints log where these interactions are documented and tracked.

Why is this important?

The new requirements transform data protection complaints handling from a matter of good practice into a legal compliance obligation. The ICO has emphasised that there are no general exemptions from the requirements and has encouraged organisations to review any existing arrangements they have in place to ensure they comply with the new legal framework.

Any practical tips?

The ICO has published detailed guidance for organisations and individuals explaining the new requirements, which may be a good starting point for most businesses.

Organisations processing personal data should consider:

  • reviewing whether existing customer complaints procedures adequately capture data protection complaints or whether additional routing, escalation and record-keeping mechanisms are required to comply with the new requirements
  • revisiting privacy notices, online complaint forms and internal guidance to ensure these clearly explain how individuals can raise data protection concerns and how those complaints will be handled
  • training staff on responsibilities for customer support, privacy, trust and safety
  • ensuring that legal functions understand when a complaint falls within the statutory regime and that appropriate investigation and response processes are followed, and
  • maintaining evidence of compliance, as documented complaints handling may become increasingly important if matters are subsequently referred to the ICO.

Autumn 2026

Stay connected and subscribe to our latest insights and views 

Subscribe Here