Today (19 June 2026), a significant change to UK data protection law has come into force. Organisations that process personal data are now legally required to operate a formal data protection complaints process under the Data (Use and Access) Act 2025.
The Information Commissioner’s Office (ICO) has confirmed that from 19 June 2026 all organisations must provide individuals with a mechanism to raise data protection complaints, acknowledge complaints within 30 days, investigate concerns appropriately and communicate outcomes without undue delay.
The ICO has described the new requirements as an important step in strengthening accountability and helping organisations resolve privacy concerns before they escalate to regulatory intervention. For information governance, records management and privacy professionals, this represents one of the most significant operational compliance changes introduced to the UK data protection framework in recent years. [ico.org.uk], [privacymat…apiper.com]
What’s happened?
The Information Commissioner’s Office (ICO) has been preparing organisations for this change for several months, publishing guidance and encouraging businesses to review their complaints handling arrangements before the legislation came into effect.
The ICO has specifically highlighted the importance of ensuring that complaints can be received, recorded, investigated and resolved in a timely and transparent manner. [ico.org.uk], [privacymat…apiper.com]
Original sources:
Why this matters
This is much more than an administrative change.
The new requirements are designed to encourage organisations to resolve data protection concerns before they escalate to the regulator. In effect, organisations are now expected to have a customer-focused, documented and auditable process for handling privacy complaints. [privacymat…apiper.com], [ico.org.uk]
For information governance, records management and privacy professionals, this means ensuring that:
- Complaints can be submitted through appropriate channels.
- Staff know how to recognise a data protection complaint.
- Complaints are tracked and monitored.
- Outcomes are documented.
- Evidence of investigations is retained.
- Lessons learned are identified and acted upon. [privacymat…apiper.com], [ico.org.uk]
The changes also reflect a wider global trend. Regulators around the world are increasingly expecting organisations to demonstrate accountability, transparency and responsiveness when handling concerns about personal information. Similar developments have been seen across Europe, North America and Australia as privacy laws mature and regulators demand stronger evidence of compliance. [groundlabs.com], [iapp.org]
Similar developments around the world
The UK is not alone in strengthening individual rights and organisational accountability. Recent privacy developments have included:
- New consumer privacy legislation in several US states, expanding rights and complaint mechanisms. [groundlabs.com], [iapp.org]
- Increased scrutiny of AI systems and automated decision-making by regulators worldwide. [groundlabs.com], [iapp.org]
- Enhanced requirements for organisations to demonstrate compliance with privacy obligations through documented governance processes and evidence. [groundlabs.com], [zasio.com]
Taken together, these developments point towards a future where organisations must be able to prove—not merely claim—that they are protecting personal information appropriately.
The real issues behind this story
The introduction of these requirements highlights a challenge that many organisations continue to face: privacy complaints are often poorly managed.
In many organisations, complaints arrive via email, telephone calls, website forms, social media platforms or informal conversations with staff. Without a clear process, complaints can be missed, delayed or incorrectly handled. [privacymat…apiper.com]
Common issues include:
- No formal complaint handling process.
- Unclear ownership and accountability.
- Poor recordkeeping.
- Lack of staff awareness.
- Failure to identify trends and recurring issues.
- Inconsistent communication with complainants.
- Insufficient evidence to demonstrate compliance. [privacymat…apiper.com], [ico.org.uk]
What are organisations getting wrong?
Many organisations have focused heavily on privacy notices, subject access requests and security controls while overlooking complaint management.
Historically, there has been no explicit legal requirement to operate a formal data protection complaints process. As a result, many organisations have relied on general customer services teams or generic complaints procedures that may not adequately address privacy concerns. [privacymat…apiper.com]
In practice, organisations often lack:
- Defined workflows.
- Response times.
- Investigation procedures.
- Escalation routes.
- Recordkeeping requirements.
- Reporting mechanisms for senior management. [privacymat…apiper.com], [ico.org.uk]
How could these issues have been prevented?
The good news is that most of the required controls are neither complex nor expensive.
Organisations should:
- Implement a documented data protection complaints procedure.
- Train staff to recognise and escalate complaints.
- Ensure privacy notices explain how complaints can be submitted.
- Maintain a complaints register.
- Record actions taken and outcomes reached.
- Monitor trends and recurring issues.
- Use complaints as a source of organisational learning and improvement. [privacymat…apiper.com], [ico.org.uk]
The most mature organisations will go further by integrating complaints management into their broader information governance, risk management and compliance frameworks.
How Leadership Through Data can help
For many organisations, the challenge is not understanding what the law requires—it is implementing practical, sustainable processes that work in the real world.
At Leadership Through Data, we help organisations build information governance frameworks that are proportionate, compliant and easy to operate.
Our services can help organisations:
✅ Design and implement data protection complaints procedures.
✅ Review and update privacy notices, policies and governance documentation.
✅ Develop complaint registers and investigation workflows.
✅ Deliver staff awareness and specialist privacy training.
✅ Assess compliance against UK GDPR, the Data Protection Act 2018 and the Data (Use and Access) Act 2025.
✅ Establish robust records management and evidence retention practices.
✅ Create governance frameworks that support accountability and regulatory readiness.
Contact us to see how we can help.
To wrap things up…
The introduction of the new complaints regime is a reminder that privacy compliance is not just about avoiding enforcement action—it is about building trust.
Organisations that can respond quickly, transparently and effectively to concerns about personal data will be better placed to maintain customer confidence, demonstrate accountability and reduce regulatory risk.




