4.8Top Rated Service 2026verified by TrustindexTrustindex verifies that the company has a review score above 4.5, based on reviews collected on Google over the past 12 months, qualifying it to receive the Top Rated Certificate.
Under the UK GDPR, individuals can raise concerns about how an organisation handles their personal data. Businesses should have a clear complaints process, keep appropriate records, and make sure privacy concerns are handled consistently as part of wider accountability.
Under the UK GDPR, people can complain if they are concerned about how an organisation handles their personal data. Businesses should have a clear process for recognising complaints, responding consistently, keeping records, and showing that privacy concerns are managed as part of wider accountability.
Need
A clear internal process for identifying and handling complaints
Need
Records of concerns, decisions, responses, and escalation steps
Need
A practical route for resolving issues before they become bigger risks
A data protection complaint is not limited to formal legal wording. It can be any concern that an individual raises about how their personal data has been collected, used, shared, stored, secured, retained, or responded to. Businesses should train staff to recognise privacy concerns early, even when the person does not use the words “UK GDPR”.
This might include complaints about marketing, unexpected contact, account handling, profiling, online forms, or data being used for a purpose the person did not expect.
A complaint may arise if a subject access request, deletion request, objection, correction request, or other rights issue is delayed or handled poorly.
Complaints can also relate to security, confidentiality, inappropriate access, accidental disclosure, or possible data breaches.
Complaint handling connects closely to transparency, accountability, and rights management because it shows whether an organisation can respond clearly when something has gone wrong or been questioned.
A good complaints process does not need to be complicated, but it should be clear enough that staff know what to do, individuals know how to raise concerns, and the organisation can evidence how the issue was handled.
People should be able to understand where to send privacy complaints or concerns. This route should be visible in relevant privacy information and internal staff guidance.
Staff should know how to recognise a data protection complaint, who to pass it to, and when it may also involve a rights request, security incident, or regulatory issue.
The organisation should record what was raised, what was checked, what decision was made, what response was given, and what follow-up action was needed.
More serious complaints may need senior review, legal input, technical investigation, supplier checks, or a decision about whether the ICO should be contacted.
A complaint may sit alongside a formal rights request. Businesses should be careful not to treat every concern as informal only, because some complaints may trigger specific UK GDPR response obligations.
The person may be unhappy with how their data was used, shared, explained, retained, secured, or responded to. The organisation should investigate and reply clearly.
If the person asks for access, erasure, restriction, rectification, portability, or objection, the organisation may need to follow rights request rules and deadlines.
When a complaint includes a rights request, separate the issues internally. Track the complaint response and the rights request response so neither is missed. For access requests, see Subject Access Requests Under UK GDPR.
Complaint handling problems usually happen because the organisation does not recognise the issue early, does not keep a record, or gives a generic response without properly checking what happened.
Some complaints need data protection review, especially where the issue involves access rights, data sharing, security, marketing, retention, or inaccurate information.
If the issue later escalates, the organisation may struggle to show what it did, what it found, who reviewed it, and why it responded in that way.
A simple complaints log, internal escalation route, staff guidance, and clear privacy contact point can prevent small concerns from becoming larger compliance problems.
Complaints can appear in different parts of the business, not only through a formal privacy email address. Staff should know when a message may need data protection review.
A person complains that they did not expect to receive marketing, cannot unsubscribe, or does not understand how their details were obtained.
A person says their subject access request, deletion request, correction request, or objection has not been handled properly.
A person reports that their information was sent to the wrong person, visible to someone else, or accessed inappropriately.
A person says the organisation did not explain clearly what data was collected, why it was used, who it was shared with, or how long it would be kept.
A complaint can reveal a wider weakness in privacy notices, lawful basis decisions, marketing systems, retention practices, supplier controls, or staff training. Handling it well helps the organisation fix the issue and evidence accountability.
This article is based on ICO guidance on data protection complaints, individual rights, complaint handling, and accountability under the UK GDPR. It connects to wider duties around accountability, transparency, privacy notices, and individual rights such as subject access requests.
Use the glossary for key terms, or download the checklist if you want a practical starting point for reviewing complaint routes, escalation steps, complaint records, SAR handling, response templates, and ICO escalation risk.
We use cookies and similar technologies to make our website work and to provide optional features such as live chat.
Some cookies are strictly necessary for the website to function. Optional cookies support tools such as live chat and will only be used if you choose to allow them.
We also use privacy-friendly, cookieless website analytics to understand aggregated website usage. This does not use cookies or track you across websites.
You can choose to accept all cookies, reject non-essential cookies, or manage your preferences.