← Back to Regulatory Updates

Regulatory Update • March 2026

Preparing for the ICO’s New Complaints Process Requirement

Published: March 2026 Topic: DUAA / Complaints Handling Source: ICO Guidance

Organisations should now be preparing for the ICO’s new requirement to operate a formal data protection complaints process, which will come into force on 19 June 2026.

The ICO confirmed in February that organisations must be able to receive complaints, acknowledge them within 30 days, and operate a clear internal process for handling and resolving them. The guidance states that there are no exemptions.

Reading time 2 minutes

What changed

In February 2026 the ICO confirmed that organisations must introduce a formal process for handling data protection complaints. This requirement will come into force on 19 June 2026 as part of the Data (Use and Access) Act implementation.

The guidance states that organisations must be able to receive complaints, acknowledge them within 30 days, and operate an internal process for reviewing and responding to those complaints.

Importantly, the ICO also confirmed that there are no exemptions from this requirement.

What counts as a data protection complaint?

A data protection complaint is any concern raised by an individual about how an organisation has handled their personal data. This could include concerns about subject access requests (SARs), marketing communications, data accuracy, data sharing, or general privacy practices.

Why this matters

Many organisations currently deal with privacy complaints informally, particularly smaller teams where concerns are handled through general customer support channels.

The new requirement means organisations must have a clearly defined complaints process. This includes logging complaints, acknowledging them within 30 days, and ensuring responsibility for reviewing and responding to complaints is defined internally.

Organisations should also monitor future developments through the Regulatory Updates page.

What organisations should do

Organisations should begin preparing their complaints process now rather than waiting until the June commencement date.

  • Create a clear internal workflow for handling data protection complaints.
  • Define who within the organisation is responsible for reviewing and responding to complaints.
  • Ensure complaints can be logged and tracked internally.
  • Make sure acknowledgement procedures allow complaints to be recognised within the required 30-day period.

Practical takeaway

Organisations should implement a simple complaints workflow now. Waiting until June may create unnecessary pressure, particularly for small teams that currently deal with complaints informally.

Grounded in

ICO guidance on the complaints-handling requirement introduced through the Data (Use and Access) Act, including confirmation that complaints must be acknowledged within 30 days and that the requirement applies to all organisations.

Sources

Future Implementation Support Waitlist