Understanding the Data (Use and Access) Act 2025: Compliance & The June 19 Deadline
UK businesses are currently racing against time to meet the imminent June 19, 2026 deadline introduced by the new Data (Use and Access) Act 2025 (DUAA). Under the revised mandates, the Information Commissioner's Office (ICO) has finalized enforcement directives requiring all controllers—regardless of size—to operate public-facing complaints processes.
Failing to provide a statutory compliance framework for data protection complaints is no longer a minor governance oversight. Under the DUAA, it is classified as a severe regulatory violation, exposing independent retailers, consultants, agencies, and corporations alike to steep structural audits and penalty structures.
Need a legally sound policy and tracker in 60 seconds?
Generate your custom DUAA Data Complaints Policy and internal complaints tracker CSV for just £20.00. No subscription required.
1. What is the Data (Use and Access) Act 2025?
The Data (Use and Access) Act 2025 (DUAA) is the UK government's latest major update to data privacy and digital governance post-Brexit. It streamlines several elements of the UK GDPR and the Data Protection Act 2018 (DPA) to reduce administrative overhead for businesses, but establishes much stricter consumer protection safeguards in critical areas.
One of the central changes lies in Section 103 of the Data (Use and Access) Act 2025 (which introduces the complaints procedure requirement by inserting a new Section 164A into the Data Protection Act 2018). While previous guidelines allowed businesses to handle privacy inquiries informally, the DUAA codifies complaint resolution into a strict statutory obligation. An individual has the right to file a complaint if they believe the controller has failed to safeguard their personal details, breached transparency rules, or mismanaged a Data Subject Access Request (DSAR).
What Qualifies as a Data Protection Complaint?
Under Section 103 (Section 164A of the DPA 2018), a data protection complaint covers any written or verbal expression of dissatisfaction regarding how an organisation handles personal data. Importantly, individuals do not need to use formal legal terminology or explicitly cite the Data (Use and Access) Act for their submission to be treated as a valid complaint. Common triggers include:
- Data Security & Breaches: Unauthorized access, accidental disclosure, or loss of personal records.
- DSAR Delays: Failing to provide a copy of an individual's personal data within statutory time limits, or restricting access without a valid exemption.
- Consent & Opt-Out Issues: Continuing to send marketing communications after a user has unsubscribed or withdrawn consent.
- Rights Infringement: Denying data subjects their rights to rectification, erasure, or restriction of processing.
What is excluded: General customer service complaints (e.g. issues with product quality or service response times) and employment grievances do not count as data protection complaints, even if they contain personal details. Similarly, expressing dissatisfaction that a DSAR was not expedited—despite being responded to within the standard legal timeframe—does not constitute a valid complaint under these rules.
2. The June 19 Deadline & Compliance Requirements
June 19, 2026 marks the end of the transition period granted by the ICO. By this date, every business acting as a "data controller" (which includes any business processing customer emails, billing details, marketing cookies, or staff payroll) must satisfy three core conditions:
- Public complaints policy: A clearly written document, hosted on your website, outlining the channels, SLA timelines, and procedure to submit complaints.
- Designated handler: A named representative or specific role (such as Data Protection Lead or Representative) assigned to handle complaints.
- Audit-ready internal CSV log: A structured register documenting every complaint received, receipt dates, investigation summaries, and outcome tracking.
Who is Covered Under the New Mandate?
A common misconception is that these requirements only apply to customer-facing interactions. In reality, the DUAA mandates cover personal data processed for customers, current and former employees, suppliers, and service users. If your organisation holds records for any of these cohorts, you are a data controller and must operate a compliant complaints process.
Reviewing Existing Complaints Procedures
Many organisations already have general customer grievance or internal HR processes. Standard channels are rarely configured to track and satisfy the strict 30-day statutory data protection SLA. Legal experts advise organisations to update their existing frameworks rather than creating standalone systems.
Keep in mind that there is no requirement to procure separate, standalone complaints tools—adapting your existing internal workflows, ticketing systems, or spreadsheets is perfectly acceptable. However, you must accept data complaints through any channel they are received, even if the complainant does not use your preferred online form or dedicated email.
Practical Checklist for June 19 Compliance
To prepare for the June 19 enforcement date, organisations should execute these key steps:
- Staff Training: Train front-of-house, client support, HR, and IT staff to recognize data protection complaints. Because individuals do not need to quote legislation, staff must be able to spot issues like opt-out failures or DSAR delays.
- Privacy Notice Integration: Ensure your privacy notices and policies are updated to link directly to your complaints channel.
- Designate a Lead: Confirm who owns the process internally (e.g., your DPO, privacy lead, or operations director) and define escalation routes.
- Deploy the Ledger: Establish a structured log (such as a CSV or spreadsheet) to record all received complaints, receipt dates, investigation notes, and outcomes.
- Contractual Review: Review your agreements with third-party data processors to ensure they include clauses requiring them to notify you immediately of any complaints received, so you can respond within the statutory timeframe.
Automate your checklist steps today
Completing our questionnaire and paying the £20 one-time fee instantly takes care of the bottom 4 of these 5 checklist requirements (Privacy Notice Integration, Designating a Lead, Deploying the Ledger, and Contractual Review) with tailored, ready-to-use files.
ICO Fines & Enforcement
Failing to operate this framework exposes your business to an immediate ICO compliance audit. Statutory fines under the DUAA range up to a maximum of £17.5M or 4% of global turnover, with individual officers held accountable for systemic operational negligence.
3. The 30-Day Acknowledgement Rule
The most significant administrative trap of the new DUAA framework is the **30-Day Acknowledgement Guarantee**. Unlike general customer service complaints, data protection inquiries trigger a strict statutory SLA starting the moment they arrive.
Key parameters of the rule:
Receipt SLA
The business must issue a formal, written acknowledgement confirming receipt of the complaint within 30 calendar days. This 30-day timeline begins the day after receipt (including weekends and public holidays). If the 30th day falls on a weekend or public holiday, the deadline is extended to the next working day.
Resolution Timeline
While resolution timeline is flexible depending on system complexity, investigation must progress "without undue delay," and you must legally provide status updates to the complainant.
If a business fails to send the formal acknowledgement within the 30-day window, the complainant has the immediate right to escalate the dispute directly to the regulator. In such cases, the ICO is statutory-bound to review the controller's internal complaints record ledger.
Generate Your Legal Compliance Files
Get an instant, customized DUAA complaints policy PDF designed to support compliance under Section 103 of the DUAA plus a pre-styled ICO audit CSV log for £20.
Conclusion: Protect Your Business from June 19
With the compliance deadline falling on June 19, 2026, manual drafting can lead to oversight traps or overpriced legal fees. Our generator allows you to secure a fully compliant, ICO-aligned document instantly, shielding your business from audits.
Ensure you paste the generated Complaints Policy onto a dedicated web portal, designate a staff member to handle inbound queries, and maintain your tracking log to record complaints. Late compliance is always preferred to non-compliance in the eyes of the ICO.