19 June 2026: DUAA complaints-handling duties come into force for UK controllers.
DUAAShield
DUAA Complaints Policy Pack for the 19 June 2026 Deadline

DUAA Complaints Policy & Tracker Pack for UK Controllers

From 19 June 2026, UK organisations that act as data controllers must have a process for handling data protection complaints. Generate a ready-to-publish complaints policy, website wording and internal tracker in minutes.

Mandatory Regulation Deadline: 19 June 2026

Requirement starts 19 June 2026. Put a documented complaints process in place before customers or staff need to use it.

Loading timer...
Applicable Scope

Who needs to comply with this requirement?

A common misconception is that these requirements only apply to large corporations or customer-facing operations. Under the Data (Use and Access) Act 2025, **the complaints-handling duty applies to all UK organisations that act as data controllers.**

Small Businesses & Startups

If you manage customer accounts, details, or processing pipelines, you must have an active data complaints route.

Sole Traders & Freelancers

Even as a single individual, if you control client or supply chain personal data, you are legally classified as a data controller.

Charities & Non-profits

Handling donor list databases, volunteer logs, or fundraising campaign directories requires compliance.

Ecommerce Stores

Managing purchase histories, customer addresses, checkout sessions, and marketing tracking cookies.

Consultants & Agencies

Working with client databases, CRM records, employee HR rosters, or third-party processor systems.

Clubs & Associations

Processing memberships, subscription tracking, contact directories, or event booking logs.

The Legislation Explained

What does the DUAA complaints requirement mandate?

Under Section 103 of the Data (Use and Access) Act 2025 (which inserts Section 164A into the Data Protection Act 2018), data subjects have a statutory right to submit complaints if they believe their personal data has been handled incorrectly.

Strict 30-Day Acknowledgment SLA

You must issue a formal, written acknowledgement confirming receipt of the complaint within 30 calendar days (beginning the day after receipt).

Investigate & Communicate Outcomes

You must investigate the complaint without undue delay, provide updates where appropriate, state your findings, and provide remedies if necessary.

Supervisory Authority Signposting

Your policy must explicitly signpost the user's right to escalate the dispute directly to the Information Commissioner's Office (ICO).

Author: DUAA Shield Compliance Editorial Team
Last updated: 18 June 2026
Regulatory Risk & Escalation

ICO Scrutiny and Audits

Failing to have a complaints process may increase regulatory risk, ICO scrutiny, and the likelihood of escalation.

Bespoke Costs

£400+ Solicitor Drafts

Bespoke legal drafting can be expensive. This pack gives small organisations a practical, ready-to-adapt starting point for £20.

What you download

What does the pack include?

The pack is a standardized, ready-to-adapt policy and tracker pack designed to support compliance with the DUAA complaints-handling requirement.

Data Protection Complaints Policy

A structured document detailing procedures, designated data contact, 30-day receipt acknowledgements, and outcome timelines.

Website Wording Notices

Clear, customer-facing paragraph phrasing to display on your complaints page or footer links.

Complaint Acknowledgement Wording

Written template response to satisfy the mandatory 30-day SLA receipts acknowledgement rule.

Complaint Outcome Template

Formal notification message explaining findings, remedial measures, and the complainant's right to escalate to the ICO.

Internal complaints tracker CSV

Excel/CSV structured layout file containing the precise headers needed to demonstrate compliant logging under audits.

Privacy Notice Amendment Wording

A copy-pasteable paragraph updating your existing site Privacy Policy regarding data protection complaint paths.

Set-up instructions

A simple 3-step walk-through outlining where to upload and publish the assets to achieve full operational readiness.

Record Keeping

Why maintaining a complaints tracker is crucial

Legislation requires you to have a workflow, but regulatory compliance depends on proof. If the ICO requests an audit or an individual disputes your handling, you must produce clear records.

The ICO expects organisations to be able to show the date a complaint was received, when it was acknowledged, the nature of the dispute, correspondence records, outcomes reached, and any remedial improvements made.

tracker-headers.csvICO Audit Format
"Date Received", "Complainant Name", "Nature of Complaint", "Date Acknowledged", "Investigating Officer", "Date Resolved", "Outcome/Action Taken"
"19/06/2026", "John Doe", "DSAR delay - db check", "20/06/2026", "Representative", "25/06/2026", "Files sent"
"22/06/2026", "Jane Smith", "Consent withdrawal", "23/06/2026", "Representative", "24/06/2026", "Opt-out synced"
Standardized Process

Built around the ICO workflow

The policy maps to the required step-by-step regulatory workflow to ensure no complaints fall through the cracks.

1

1. Receive

Accept data protection complaints raised verbally, in writing, or via any support route.

2

2. Acknowledge

Issue a formal written confirmation within the mandatory 30-day statutory SLA.

3

3. Investigate

Analyze data logs, processor systems, and storage without undue delay.

4

4. Update

Inform the complainant if technical complexity requires an extension or delay.

5

5. Outcome

Notify the complainant in writing of your final decision, reasons, and remedies.

6

6. Record

Log all correspondence, dates, and resolutions inside your complaints tracker ledger.

7

7. Improve

Implement process modifications to correct underlying systemic processing issues.

SME Scopes

Designed specifically for small UK organisations

Ideal for controllers seeking a fast compliance-support deliverable to bridge the gap without bespoke solicitor rates.

Small Businesses
Sole Traders
Charities
Ecommerce Stores
Consultants & Agencies
Professional Services
Employers
Landlords & Managers
Clubs & Associations

How DUAA Shield compares

Solicitor-drafted bespoke policy

Fully tailored, legal representation.

£400+
Generic privacy policy template

Rarely includes the DUAA complaints SLA.

May not cover DUAA
DUAA Shield compliance pack

Ready-to-adapt custom policy + tracker.

£20

What happens after purchase?

1
Complete the questionnaire

Provide your company legal registration details and designated complaints lead name below.

2
Pay securely by Stripe

Execute a one-time £20.00 payment. No accounts or recurring subscription contracts.

3
Download PDF and CSV tracker

Receive immediate download access plus an automated email copy containing the documents.

4
Publish the complaints procedure

Upload the PDF or paste the text notice directly onto your organisation's website.

5
Start logging complaints

Begin logging incoming data inquiries in the spreadsheet to create a compliant audit trail.

Instant Generation Wizard

Generate Your DUAA Shield Pack

Provide your details to generate your customized Complaints Policy PDF, website notices, and CSV internal complaints tracker spreadsheet.

Questionnaire: Step 1 of 3

Step 1: Company Profile Details

Compliance Coverage:By completing this form and paying the £20 fee, the DUAA Shield pack takes care of designating a lead complaints handler, designing a complaints notice layout, amending your privacy policy wording notice, and deploying the internal complaints tracker log.
Not a substitute for legal advice: The DUAA Shield complaints policy and tracker pack is a standardized, ready-to-adapt compliance-support document set. It does not constitute formal legal representation, advocacy, or counsel. Complex organizations or operations processing high volumes of special category data should seek specialist solicitors.

Frequently Asked Questions

What is the DUAA complaints procedure requirement?

Under Section 103 of the Data (Use and Access) Act 2025 (which inserts Section 164A into the Data Protection Act 2018), UK organisations acting as data controllers must operate a complaints procedure. It requires establishing channels for data complaints, logging records, and meeting acknowledgment timelines.

When does the DUAA complaints requirement start?

The complaints-handling duties come into force on **19 June 2026**. Data controllers must have their complaints policy and tracker operational by this date.

Does the DUAA complaints duty apply to small businesses?

Yes. The legislation applies to UK organisations that act as data controllers. Small businesses, sole traders, and charities are not exempt if they process personal data.

Do sole traders need a data protection complaints process?

Yes. If you are a sole trader processing personal data (such as client databases, emails, or supplier records) and you act as a data controller, you fall under the scope of this requirement.

What must a DUAA complaints policy include?

It must outline the channels to submit complaints, state the statutory 30-day receipt acknowledgement SLA, name your complaints handler, describe investigation workflows, and link to the Information Commissioner's Office (ICO).

How quickly must we acknowledge a data protection complaint?

You must formally acknowledge receipt of any data protection complaint in writing within 30 calendar days. The 30-day window begins the day after receipt (including weekends and holidays).

What does “without undue delay” mean for DUAA complaints?

It means executing investigations and sending outcome notifications without unjustifiable delay, taking into account details like system logs, database scopes, and query complexity.

Is a complaint form required under DUAA?

No. A specific online form is not required. You must accept complaints through any available channel (email, letter, or verbally) and not force users into using one path.

Do we need to publish a data protection complaints procedure on our website?

Yes. The Act requires data controllers to make the complaints procedure publicly accessible to data subjects.

What records should we keep for data protection complaints?

You must maintain records detailing: date of receipt, complainant name, nature of complaint, date of written acknowledgement, investigating officer details, resolution date, outcome decisions, and action taken.

Is this the same as a subject access request?

No. A Subject Access Request (SAR) is a request to receive copies of your data. A data protection complaint relates to allegations that data has been mismanaged, opt-outs ignored, or SARs delayed.

Can a customer complain without mentioning UK GDPR or DUAA?

Yes. Complainants do not need to use specific legal terminology. Any written or verbal statement expressing dissatisfaction with how you process their personal data counts.

What happens if we do not have a data protection complaints process?

Failing to have a complaints process may increase regulatory risk, ICO scrutiny, and the likelihood of escalation. It leaves you exposed to immediate compliance audits.

Is the DUAA complaints process required by the ICO?

Yes. The ICO is the UK's supervisory authority responsible for auditing and enforcing compliance with the Data Protection Act 2018 (as amended by DUAA 2025).

Can this pack be used by charities, clubs or sole traders?

Yes. The templates are designed as a ready-to-adapt starter set suitable for small charities, non-profits, sports clubs, community associations, and sole traders.