Blog

Data Protection Complaints Under UK GDPR: What Businesses Must Have in Place

Under the UK GDPR, individuals can raise concerns about how an organisation handles their personal data. Businesses should have a clear complaints process, keep appropriate records, and make sure privacy concerns are handled consistently as part of wider accountability.

Estimated reading time: 6 minutesTopic: GovernanceRelated terms: Personal data and UK GDPR
Quick answer

What businesses need for data protection complaints

Under the UK GDPR, people can complain if they are concerned about how an organisation handles their personal data. Businesses should have a clear process for recognising complaints, responding consistently, keeping records, and showing that privacy concerns are managed as part of wider accountability.

Need

A clear internal process for identifying and handling complaints

Need

Records of concerns, decisions, responses, and escalation steps

Need

A practical route for resolving issues before they become bigger risks

Section one

What counts as a data protection complaint

A data protection complaint is not limited to formal legal wording. It can be any concern that an individual raises about how their personal data has been collected, used, shared, stored, secured, retained, or responded to. Businesses should train staff to recognise privacy concerns early, even when the person does not use the words “UK GDPR”.

Concern

How data has been used

This might include complaints about marketing, unexpected contact, account handling, profiling, online forms, or data being used for a purpose the person did not expect.

Concern

How a request was handled

A complaint may arise if a subject access request, deletion request, objection, correction request, or other rights issue is delayed or handled poorly.

Concern

How data has been protected

Complaints can also relate to security, confidentiality, inappropriate access, accidental disclosure, or possible data breaches.

Complaint handling connects closely to transparency, accountability, and rights management because it shows whether an organisation can respond clearly when something has gone wrong or been questioned.

Section two

What businesses should have in place

A good complaints process does not need to be complicated, but it should be clear enough that staff know what to do, individuals know how to raise concerns, and the organisation can evidence how the issue was handled.

An internal triage process

Staff should know how to recognise a data protection complaint, who to pass it to, and when it may also involve a rights request, security incident, or regulatory issue.

A response and record system

The organisation should record what was raised, what was checked, what decision was made, what response was given, and what follow-up action was needed.

An escalation route

More serious complaints may need senior review, legal input, technical investigation, supplier checks, or a decision about whether the ICO should be contacted.

Section three

How complaints connect to individual rights

A complaint may sit alongside a formal rights request. Businesses should be careful not to treat every concern as informal only, because some complaints may trigger specific UK GDPR response obligations.

Complaint

Focuses on a concern or dissatisfaction

The person may be unhappy with how their data was used, shared, explained, retained, secured, or responded to. The organisation should investigate and reply clearly.

Rights request

May require a specific UK GDPR response

If the person asks for access, erasure, restriction, rectification, portability, or objection, the organisation may need to follow rights request rules and deadlines.

The practical way to handle overlap

When a complaint includes a rights request, separate the issues internally. Track the complaint response and the rights request response so neither is missed. For access requests, see Subject Access Requests Under UK GDPR.

Section five

Examples of complaints businesses may receive

Complaints can appear in different parts of the business, not only through a formal privacy email address. Staff should know when a message may need data protection review.

Marketing complaints

A person complains that they did not expect to receive marketing, cannot unsubscribe, or does not understand how their details were obtained.

Rights request complaints

A person says their subject access request, deletion request, correction request, or objection has not been handled properly.

Security concerns

A person reports that their information was sent to the wrong person, visible to someone else, or accessed inappropriately.

Transparency complaints

A person says the organisation did not explain clearly what data was collected, why it was used, who it was shared with, or how long it would be kept.

Why this distinction matters

A complaint can reveal a wider weakness in privacy notices, lawful basis decisions, marketing systems, retention practices, supplier controls, or staff training. Handling it well helps the organisation fix the issue and evidence accountability.

Grounded in

What this article is grounded in

This article is based on ICO guidance on data protection complaints, individual rights, complaint handling, and accountability under the UK GDPR. It connects to wider duties around accountability, transparency, privacy notices, and individual rights such as subject access requests.

Next step

Keep building your understanding

Use the glossary for key terms, or download the checklist if you want a practical starting point for reviewing complaint routes, escalation steps, complaint records, SAR handling, response templates, and ICO escalation risk.

Future Implementation Support Waitlist