preloader

· digital-privacy gdpr compliance europe data-protection dpo privacy-engineering

Since June 19 Every UK Controller Needs a Documented Complaints Process. Six Weeks In, Most Have Not Tested Theirs

Source: Information Commissioner's Office

Since 19 June 2026, every organisation that controls personal data in the UK has been legally required to maintain a working process for handling data protection complaints, not a generic contact form, but a documented procedure that acknowledges a complaint within 30 days and responds to it without undue delay. The requirement comes from the Data (Use and Access) Act 2025 and applies regardless of company size, sector, or how much data processing the organisation actually does. Six weeks into enforcement, a large share of controllers still have not tested whether their process actually works under a real complaint.

What the law actually requires

The obligation is specific: acknowledge receipt within 30 days of a complaint arriving, take appropriate steps to investigate it including making reasonable inquiries, keep the complainant informed of progress, and communicate an outcome. The 30-day acknowledgement clock starts the day after the complaint is received, weekends and public holidays included, with the deadline rolling to the next working day only if it lands on one. There is no prescribed statutory deadline for the substantive response, but the ICO’s own template complaint letter points organisations toward a 30-day response benchmark as good practice. Critically, individuals only have standing to escalate a complaint to the ICO after going through this internal process first, or after 45 days without a resolution, which means a broken internal process now sits directly upstream of regulatory exposure that did not exist before June 19.

The ICO is triaging too, and privacy groups are unhappy about it

On its own side, the ICO adopted a risk-based triage framework earlier this year for complaints that do reach the regulator, scoring each one on a low, moderate, or high harm scale and weighing the vulnerability of those affected, how many people are significantly impacted, and whether the matter fits the regulator’s strategic priorities. Complaints that do not clear that bar get logged for information purposes rather than investigated. The ICO’s own numbers explain the pressure behind the change: data protection complaints rose from 39,721 in 2023/24 to 42,881 in 2024/25, with 2026 forecasts running as high as 55,000. Privacy advocacy groups including the Open Rights Group have argued the triage approach is inconsistent with UK GDPR’s underlying rights and that a meaningful share of legitimate complaints will now be logged and never substantively investigated.

What this means in practice for a controller

The combined effect is that a well-run internal complaints process is now doing double duty: it is a legal obligation in its own right, and it is also the organisation’s best chance of resolving a complaint before it ever reaches an under-resourced regulator that may not investigate it anyway. Organisations that treat this as a compliance checkbox, a policy document with no operational process behind it, are exposed the first time a real complaint arrives and nobody in the business knows who owns the 30-day clock, what “appropriate steps to investigate” looks like for their specific processing activities, or how to document the outcome in a way that would satisfy the ICO if the complainant escalates anyway.

If your organisation needs to build, document, or pressure-test an internal data protection complaints process against the DUAA requirements, or wants a GDPR compliance review ahead of your next audit, contact Excello Digital. We help European organisations turn regulatory obligations into processes that actually work when a real complaint comes in.

These news items are automatically aggregated from industry sources and are not individually reviewed. Any inaccuracies are unintentional — let us know and we'll correct or remove it.

We’ll help you resolve your infrastructure challenges

Our team of experts is ready to help you with your infrastructure challenges. We’ll give you honest and personal treatment. Get in touch to learn more.

Get in touch!