← Back to Regulatory Updates

Regulatory Update • March 2026

ICO Clarifies Data Protection Complaint Handling Expectations

Published: March 2026 Topic: Data Protection Complaints Source: ICO Guidance

The Information Commissioner’s Office has published guidance explaining how organisations should prepare for the new requirement to operate a formal data protection complaints process.

The guidance helps organisations prepare ahead of the 19 June 2026 implementation date and clarifies practical expectations around receiving, acknowledging and responding to complaints.

Reading time 2 minutes

What changed

The Information Commissioner’s Office has published guidance explaining how organisations should prepare for the new requirement to operate a formal data protection complaints process.

The guidance outlines how organisations should receive complaints, acknowledge them within 30 days, and operate an internal process for investigating and responding to concerns raised by individuals about the handling of their personal data.

These expectations form part of the Data (Use and Access) Act reforms and will come into force on 19 June 2026. The ICO guidance is intended to help organisations prepare their internal processes before the requirement becomes legally enforceable.

What counts as a data protection complaint?

A data protection complaint is any concern raised by an individual about how an organisation has handled their personal data. This could include concerns about subject access requests (SARs), marketing communications, data accuracy, data sharing, or broader privacy practices.

Why this matters

Many organisations currently manage data protection complaints informally or through general customer support channels. The new requirement means organisations must move to a more structured approach.

The ICO expects organisations to be able to receive complaints, acknowledge them within 30 days, and review and respond to them through a defined internal process.

This is particularly relevant for smaller teams that have not previously operated a dedicated privacy complaints workflow. Organisations should also monitor future developments through the Regulatory Updates page.

What organisations should do

Organisations should begin preparing their complaints process now rather than waiting until the June commencement date.

  • Create a clear internal workflow for handling data protection complaints.
  • Define who is responsible for reviewing and responding to complaints.
  • Ensure complaints can be logged and tracked internally.
  • Make sure acknowledgement procedures support the required 30-day timeframe.

Practical takeaway

Organisations should implement a simple complaints workflow now. Waiting until June may create unnecessary pressure, particularly for smaller teams that currently deal with complaints informally.

Grounded in

ICO guidance on the new complaints-handling requirement introduced through the Data (Use and Access) Act, including the expectation that complaints must be acknowledged within 30 days.

Sources

Future Implementation Support Waitlist