Data Protection Complaints Handling Compliance Check
Check whether your business meets the new legal duty to handle data protection complaints — in force since 19 June 2026 — including the 30-day acknowledgement rule.
Why this matters
Since 19 June 2026, every organisation that handles personal data — sole trader, charity, or large company — has been under a new legal duty introduced by the Data (Use and Access) Act 2025 to operate a proper process for data protection complaints. This is separate from responding to Subject Access Requests: it covers any complaint that someone’s personal data has been mishandled, whether that relates to marketing, retention, cookies and tracking, a security incident, or the lawful basis relied on for processing. Businesses must provide an accessible way for people to raise a complaint, acknowledge it within 30 days of receipt (starting the day after receipt, running even over weekends and bank holidays), make appropriate enquiries, keep the complainant updated, and provide an outcome without undue delay. The ICO has published dedicated guidance and has confirmed it expects organisations to be able to evidence this process if challenged.
For most small businesses this is a genuinely new operational requirement rather than a policy tweak — many have never had a defined internal route for data protection complaints, relying instead on a general “contact us” inbox with no tracking or deadline discipline. The ICO’s stated approach is that if someone can show they complained to a business and got no response, or the business cannot demonstrate proper handling, that itself becomes a point of regulatory concern — separate from whatever the underlying complaint was about. Getting this wrong risks ICO enforcement even where the original data protection issue was minor, because the complaints-handling failure becomes the primary breach. Any business without a documented complaints process, an owner for logging and diarising the 30-day acknowledgement, and a route to close out complaints should treat this as an urgent gap to fix.
What you'll need
- Whether you currently have any documented process for handling data protection complaints
- Who in your business is responsible for logging and responding to complaints
- Whether your privacy policy or website tells people how to complain about data handling
- Any data protection complaints you've received in the last 12 months and how they were handled
What you'll get
A personalised compliance report covering: a score out of 100, an executive summary, a list of findings ranked by severity, and a prioritised action plan with timeframes.
This check reviews whether your business meets the new legal duty — in force since 19 June 2026 — to handle data protection complaints properly, including the 30-day acknowledgement rule and evidence the ICO expects you to keep.
General guidance only — not legal advice. Consult a qualified UK solicitor for specific issues.