True or false... does my business need a data protection complaints process?

Short answer: true. Since 19 June 2026, every organisation needs a way to handle data protection complaints, whatever its size, sector, or shape.
Your list of non-negotiables just got longer. You already know the kind of list we mean: the things your organisation simply has to have in place, whether or not they feel urgent. Since 19 June, a data protection complaints process belongs officially on that list too.
That does not make the Data (Use and Access) Act 2025 the bad egg in the data protection legal framework. It is not here to cause panic. It is here to make complaint handling clearer, more consistent and easier to evidence when something goes wrong. The problem is that much of the commentary around it has made the change sound more complicated than it needs to be.
True or false: the right to complain to the ICO has disappeared
False. This is one of the things that has been easy to misread. The old Article 77 route has changed location, but the right to complain to the Information Commissioner’s Office has not vanished. People can still complain to the ICO about how their personal information has been handled.
That matters because the new internal complaints route is not a replacement for the regulator. It sits alongside it. Your organisation now needs to be ready to receive and respond to complaints directly, while recognising that the ICO route remains available.
True or false: this is only a big-company problem
False. This is the point many smaller organisations are most likely to miss. Large organisations often had some kind of complaints process already, usually because they were used to more scrutiny, stronger governance expectations or formal management standards.
The change is that complaint handling is no longer something mature organisations choose to formalise. It is now a legal requirement for every organisation that falls within scope. If you handle personal information, you need a route people can use, a process your team understands, and records that show what happened.
True or false: people must complain to you before they go to the ICO
False. The new rules are about strengthening the route into your organisation, not closing the route to the regulator. A person may complain to you first. They may also complain to the ICO before, during or after your process. The practical point is simple: you should assume the complaint may arrive with you directly, and you should be ready when it does.
True or false: you have 30 days to resolve the complaint
False. The 30-day deadline is for acknowledging the complaint, not for conducting the investigation. Once a complaint arrives, you must acknowledge it within 30 days and begin investigations without undue delay. You also need to start taking appropriate steps to respond, including gathering evidence , which means the investigation cannot simply wait until the acknowledgement deadline has passed.
True or false: you need a dedicated complaints form or email address
False. You need to give people a way to complain, but the law does not prescribe one specific channel. A form may help. A dedicated email address may help. So might an existing complaints route, if it is adapted properly. What matters is that people can use the route, staff can recognise a data protection complaint when it arrives, and the organisation can handle it in line with the law.
Lack of formalism is important here. A complaint is not less acceptable because it arrived in the wrong inbox, came through a member of staff, or was raised in a message on social media. Your preferred route is useful, but not binding.
True or false: children can make data protection complaints
True. Children have data protection rights too. If your organisation handles children’s personal information, your complaints process needs to be understandable to them, not just technically available. That may mean clearer wording, a different tone, and internal escalation routes where urgency, safeguarding or age-appropriate handling is relevant.
What should you check now?
If you only do one thing after reading this, check whether your organisation can answer these five questions clearly:
- Are people aware of how to make a data protection complaint to you?
- Does your privacy notice explain that route in plain language?
- Would staff recognise a data protection complaint if it arrived outside the official process?
- Who owns the 30-day acknowledgement clock?
- Is your complaint process designed to accept complaints before the ICO steps in?
If the answer to any of those is “not sure”, the gap is worth closing now. Not because the law should put your team on edge, but because a complaint is easier to handle when the route, the owner and the record already exist.
Your non-negotiable list just got longer
The Data (Use and Access) Act 2025 should not be treated as another piece of legal noise. It is a practical reminder that data protection is not only about policies, contracts, and regulator-facing documents. It is also about what happens when a person says: “I do not think you handled my personal data properly.”
That moment now needs a defined route. It needs an owner. It needs an acknowledgement. It needs a record. And it needs wording in your privacy materials that tells people the route exists.
In other words, this is not a bad egg in the data protection framework. It is one more non-negotiable to put in place before you need it.

Image credit: Claudio Schwarz (Unsplash)
