Welcome to the Integritis Knowledge and Press Hub

They say knowledge is power...

For all press and media enquiries, please contact Tom Bestwick, Head of Brand & PR, at tom@integritis.uk.

 

 

True or false... does my business need a data protection complaints process? 

Short answer: true. Since 19 June 2026, every organisation needs a way to handle data protection complaints, whatever its size, sector, or shape. 

Your list of non-negotiables just got longer. You already know the kind of list we mean: the things your organisation simply has to have in place, whether or not they feel urgent. Since 19 June, a data protection complaints process belongs officially on that list too. 

That does not make the Data (Use and Access) Act 2025 the bad egg in the data protection legal framework. It is not here to cause panic. It is here to make complaint handling clearer, more consistent and easier to evidence when something goes wrong. The problem is that much of the commentary around it has made the change sound more complicated than it needs to be. 

True or false: the right to complain to the ICO has disappeared 

False. This is one of the things that has been easy to misread. The old Article 77 route has changed location, but the right to complain to the Information Commissioner’s Office has not vanished. People can still complain to the ICO about how their personal information has been handled. 

That matters because the new internal complaints route is not a replacement for the regulator. It sits alongside it. Your organisation now needs to be ready to receive and respond to complaints directly, while recognising that the ICO route remains available. 

True or false: this is only a big-company problem 

False. This is the point many smaller organisations are most likely to miss. Large organisations often had some kind of complaints process already, usually because they were used to more scrutiny, stronger governance expectations or formal management standards. 

The change is that complaint handling is no longer something mature organisations choose to formalise. It is now a legal requirement for every organisation that falls within scope. If you handle personal information, you need a route people can use, a process your team understands, and records that show what happened. 

True or false: people must complain to you before they go to the ICO 

False. The new rules are about strengthening the route into your organisation, not closing the route to the regulator. A person may complain to you first. They may also complain to the ICO before, during or after your process. The practical point is simple: you should assume the complaint may arrive with you directly, and you should be ready when it does. 

True or false: you have 30 days to resolve the complaint 

False. The 30-day deadline is for acknowledging the complaint, not for conducting the investigation. Once a complaint arrives, you must acknowledge it within 30 days and begin investigations without undue delay. You also need to start taking appropriate steps to respond, including gathering evidence , which means the investigation cannot simply wait until the acknowledgement deadline has passed. 

True or false: you need a dedicated complaints form or email address 

False. You need to give people a way to complain, but the law does not prescribe one specific channel. A form may help. A dedicated email address may help. So might an existing complaints route, if it is adapted properly. What matters is that people can use the route, staff can recognise a data protection complaint when it arrives, and the organisation can handle it in line with the law. 

Lack of formalism is important here. A complaint is not less acceptable  because it arrived in the wrong inbox, came through a member of staff, or was raised in a message on social media. Your preferred route is useful, but not binding. 

True or false: children can make data protection complaints 

True. Children have data protection rights too. If your organisation handles children’s personal information, your complaints process needs to be understandable to them, not just technically available. That may mean clearer wording, a different tone, and internal escalation routes where urgency, safeguarding or age-appropriate handling is relevant. 

What should you check now? 

If you only do one thing after reading this, check whether your organisation can answer these five questions clearly: 

  • Are people aware of how to make a data protection complaint to you? 
  • Does your privacy notice explain that route in plain language? 
  • Would staff recognise a data protection complaint if it arrived outside the official process? 
  • Who owns the 30-day acknowledgement clock? 
  • Is your complaint process designed to accept complaints before the ICO steps in? 

 
If the answer to any of those is “not sure”, the gap is worth closing now. Not because the law should put your team on edge, but because a complaint is easier to handle when the route, the owner and the record already exist. 

Your non-negotiable list just got longer 

The Data (Use and Access) Act 2025 should not be treated as another piece of legal noise. It is a practical reminder that data protection is not only about policies, contracts, and regulator-facing documents. It is also about what happens when a person says: “I do not think you handled my personal data properly.” 

That moment now needs a defined route. It needs an owner. It needs an acknowledgement. It needs a record. And it needs wording in your privacy materials that tells people the route exists. 

In other words, this is not a bad egg in the data protection framework. It is one more non-negotiable to put in place before you need it. 

Image credit: Claudio Schwarz (Unsplash)

Information icon

We need your consent to load the translations

We use a third-party service to translate the website content that may collect data about your activity. Please review the details in the privacy policy and accept the service to view the translations.