New UK GDPR rules — do you have a complaints process?

From 19 June 2026, the Data (Use and Access) Act 2025 requires every UK organisation that processes personal data to have a formal, documented procedure for handling data protection complaints. This applies to businesses of all sizes — a sole trader with a customer email list is in scope.

What changed

Previously, there was no explicit legal requirement for most organisations to have a documented complaints process for data protection matters. The DUAA changes that. Data subjects must now raise their complaint with the controller first before escalating to the Information Commissioner’s Office.

Controllers must:

  • Provide at least one accessible way for individuals to submit complaints electronically (an online form or email address)
  • Acknowledge complaints promptly
  • Respond within 30 calendar days
  • Maintain records of complaints and outcomes
  • Inform individuals of their right to escalate to the ICO if unsatisfied

What this means for your business

If you process any personal data — customer records, staff details, email lists, supplier contacts — this applies to you. The ICO has signalled a measured approach to enforcement during the transition period, but having a documented process in place is now a legal requirement.

Most small businesses handle complaints informally (a customer emails someone, a manager replies, treated as customer service rather than a legal process). That approach no longer meets the standard.

Practical steps

  1. Draft a complaints-handling policy — set out how complaints are received, acknowledged, investigated, and responded to
  2. Publish the process — make it accessible on your website or via a dedicated contact route
  3. Train staff — ensure the right people know how to identify and escalate a data protection complaint
  4. Keep records — log receipt dates, actions taken, and outcomes
  5. Coordinate with DSAR handling — complaints and subject access requests are separate processes with different timelines

How we can help

If you need to put a compliant complaints process in place, we can help — from drafting the policy to integrating it with your existing procedures.

Get in touch to discuss data protection compliance.