From 19 June 2026, UK organisations that act as data controllers must have a process for handling data protection complaints. Generate a ready-to-publish complaints policy, website wording and internal tracker in minutes.
Requirement starts 19 June 2026. Put a documented complaints process in place before customers or staff need to use it.
A common misconception is that these requirements only apply to large corporations or customer-facing operations. Under the Data (Use and Access) Act 2025, **the complaints-handling duty applies to all UK organisations that act as data controllers.**
If you manage customer accounts, details, or processing pipelines, you must have an active data complaints route.
Even as a single individual, if you control client or supply chain personal data, you are legally classified as a data controller.
Handling donor list databases, volunteer logs, or fundraising campaign directories requires compliance.
Managing purchase histories, customer addresses, checkout sessions, and marketing tracking cookies.
Working with client databases, CRM records, employee HR rosters, or third-party processor systems.
Processing memberships, subscription tracking, contact directories, or event booking logs.
Under Section 103 of the Data (Use and Access) Act 2025 (which inserts Section 164A into the Data Protection Act 2018), data subjects have a statutory right to submit complaints if they believe their personal data has been handled incorrectly.
You must issue a formal, written acknowledgement confirming receipt of the complaint within 30 calendar days (beginning the day after receipt).
You must investigate the complaint without undue delay, provide updates where appropriate, state your findings, and provide remedies if necessary.
Your policy must explicitly signpost the user's right to escalate the dispute directly to the Information Commissioner's Office (ICO).
ICO Scrutiny and Audits
Failing to have a complaints process may increase regulatory risk, ICO scrutiny, and the likelihood of escalation.
£400+ Solicitor Drafts
Bespoke legal drafting can be expensive. This pack gives small organisations a practical, ready-to-adapt starting point for £20.
The pack is a standardized, ready-to-adapt policy and tracker pack designed to support compliance with the DUAA complaints-handling requirement.
A structured document detailing procedures, designated data contact, 30-day receipt acknowledgements, and outcome timelines.
Clear, customer-facing paragraph phrasing to display on your complaints page or footer links.
Written template response to satisfy the mandatory 30-day SLA receipts acknowledgement rule.
Formal notification message explaining findings, remedial measures, and the complainant's right to escalate to the ICO.
Excel/CSV structured layout file containing the precise headers needed to demonstrate compliant logging under audits.
A copy-pasteable paragraph updating your existing site Privacy Policy regarding data protection complaint paths.
A simple 3-step walk-through outlining where to upload and publish the assets to achieve full operational readiness.
Legislation requires you to have a workflow, but regulatory compliance depends on proof. If the ICO requests an audit or an individual disputes your handling, you must produce clear records.
The ICO expects organisations to be able to show the date a complaint was received, when it was acknowledged, the nature of the dispute, correspondence records, outcomes reached, and any remedial improvements made.
The policy maps to the required step-by-step regulatory workflow to ensure no complaints fall through the cracks.
Accept data protection complaints raised verbally, in writing, or via any support route.
Issue a formal written confirmation within the mandatory 30-day statutory SLA.
Analyze data logs, processor systems, and storage without undue delay.
Inform the complainant if technical complexity requires an extension or delay.
Notify the complainant in writing of your final decision, reasons, and remedies.
Log all correspondence, dates, and resolutions inside your complaints tracker ledger.
Implement process modifications to correct underlying systemic processing issues.
Ideal for controllers seeking a fast compliance-support deliverable to bridge the gap without bespoke solicitor rates.
Fully tailored, legal representation.
Rarely includes the DUAA complaints SLA.
Ready-to-adapt custom policy + tracker.
Provide your company legal registration details and designated complaints lead name below.
Execute a one-time £20.00 payment. No accounts or recurring subscription contracts.
Receive immediate download access plus an automated email copy containing the documents.
Upload the PDF or paste the text notice directly onto your organisation's website.
Begin logging incoming data inquiries in the spreadsheet to create a compliant audit trail.
Provide your details to generate your customized Complaints Policy PDF, website notices, and CSV internal complaints tracker spreadsheet.
Under Section 103 of the Data (Use and Access) Act 2025 (which inserts Section 164A into the Data Protection Act 2018), UK organisations acting as data controllers must operate a complaints procedure. It requires establishing channels for data complaints, logging records, and meeting acknowledgment timelines.
The complaints-handling duties come into force on **19 June 2026**. Data controllers must have their complaints policy and tracker operational by this date.
Yes. The legislation applies to UK organisations that act as data controllers. Small businesses, sole traders, and charities are not exempt if they process personal data.
Yes. If you are a sole trader processing personal data (such as client databases, emails, or supplier records) and you act as a data controller, you fall under the scope of this requirement.
It must outline the channels to submit complaints, state the statutory 30-day receipt acknowledgement SLA, name your complaints handler, describe investigation workflows, and link to the Information Commissioner's Office (ICO).
You must formally acknowledge receipt of any data protection complaint in writing within 30 calendar days. The 30-day window begins the day after receipt (including weekends and holidays).
It means executing investigations and sending outcome notifications without unjustifiable delay, taking into account details like system logs, database scopes, and query complexity.
No. A specific online form is not required. You must accept complaints through any available channel (email, letter, or verbally) and not force users into using one path.
Yes. The Act requires data controllers to make the complaints procedure publicly accessible to data subjects.
You must maintain records detailing: date of receipt, complainant name, nature of complaint, date of written acknowledgement, investigating officer details, resolution date, outcome decisions, and action taken.
No. A Subject Access Request (SAR) is a request to receive copies of your data. A data protection complaint relates to allegations that data has been mismanaged, opt-outs ignored, or SARs delayed.
Yes. Complainants do not need to use specific legal terminology. Any written or verbal statement expressing dissatisfaction with how you process their personal data counts.
Failing to have a complaints process may increase regulatory risk, ICO scrutiny, and the likelihood of escalation. It leaves you exposed to immediate compliance audits.
Yes. The ICO is the UK's supervisory authority responsible for auditing and enforcing compliance with the Data Protection Act 2018 (as amended by DUAA 2025).
Yes. The templates are designed as a ready-to-adapt starter set suitable for small charities, non-profits, sports clubs, community associations, and sole traders.