What changed
In February 2026 the ICO confirmed that organisations must introduce a formal process for handling data protection complaints. This requirement will come into force on 19 June 2026 as part of the Data (Use and Access) Act implementation.
The guidance states that organisations must be able to receive complaints, acknowledge them within 30 days, and operate an internal process for reviewing and responding to those complaints.
Importantly, the ICO also confirmed that there are no exemptions from this requirement.
What counts as a data protection complaint?
A data protection complaint is any concern raised by an individual about how an organisation has handled their personal data. This could include concerns about subject access requests (SARs), marketing communications, data accuracy, data sharing, or general privacy practices.
Why this matters
Many organisations currently deal with privacy complaints informally, particularly smaller teams where concerns are handled through general customer support channels.
The new requirement means organisations must have a clearly defined complaints process. This includes logging complaints, acknowledging them within 30 days, and ensuring responsibility for reviewing and responding to complaints is defined internally.
Organisations should also monitor future developments through the Regulatory Updates page.
What organisations should do
Organisations should begin preparing their complaints process now rather than waiting until the June commencement date.
- Create a clear internal workflow for handling data protection complaints.
- Define who within the organisation is responsible for reviewing and responding to complaints.
- Ensure complaints can be logged and tracked internally.
- Make sure acknowledgement procedures allow complaints to be recognised within the required 30-day period.
Practical takeaway
Organisations should implement a simple complaints workflow now. Waiting until June may create unnecessary pressure, particularly for small teams that currently deal with complaints informally.
Grounded in
ICO guidance on the complaints-handling requirement introduced through the Data (Use and Access) Act, including confirmation that complaints must be acknowledged within 30 days and that the requirement applies to all organisations.
Sources
- Information Commissioner’s Office: statement on the commencement of the Data (Use and Access) Act , February 2026.
- ICO guidance on complaints handling and organisational accountability under UK data protection law.