Thursday, 1 October 2026

Where technology leaders come to think out loud

The BriefCybersecurity

UK organizations now need a data protection complaints process

The last parts of the Data (Use and Access) Act are in force. The regulator says its focus is on helping firms comply, but many still think the change passes them by

The facts
  • The ICO’s complaints guidance uses worked examples of common complaints, including subject access requests, inaccurate data and marketing
  • The Act lets the ICO fine up to £17.5m or 4% of global turnover under the Privacy and Electronic Communications Regulations
  • New ICO powers include compelling a witness to attend an interview
  • The ICO has started work on a statutory code of practice on AI and automated decision-making
What to do now

Name an owner for complaints and publish the route on the website and in the privacy notice. Track each complaint against its deadline in the same system used for security incidents, because a complaint about wrong or exposed data is often the first sign of a breach. Check that suppliers who hold customer data pass complaints on promptly, since the duty to respond sits with the business that controls the data.

“We recognise that some businesses, especially smaller ones, may still be adjusting.”Emily Keaney, deputy commissioner, regulatory policy, Information Commissioner’s Office

Every UK organization that handles personal data must now give people a clear way to raise a data protection complaint, acknowledge it within 30 days, investigate it and report the outcome, the Information Commissioner’s Office (ICO) said on 23 June 2026.

The duty comes from the Data (Use and Access) Act, whose outstanding provisions all took effect on 19 June. The ICO says its research shows more than two in three businesses aware of the Act either do not know whether the change applies to them or wrongly believe it does not.

Small firms start furthest behind. In the ICO’s Data Controller Study 2025, published in June and based on a survey of 2,292 data controllers by IFF Research between November 2025 and January 2026, 62% of organizations said they knew of the ICO before taking part, ranging from 60% of sole traders to 90% of large organizations. A quarter (25%) did not know about the requirement to register with the regulator.

Sources
  1. ICO, “New data protection complaints law now in force”, news release, 23 June 2026. https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/06/new-data-protection-complaints-law-now-in-force/
  2. ICO, “One year on: marking the 12-month commencement of the Data (Use and Access) Act”, blog, 23 June 2026. https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/06/one-year-on-marking-the-12-month-commencement-of-the-data-use-and-access-act/
  3. ICO, “Data Controller Study 2025: findings report”, June 2026. https://ico.org.uk/about-the-ico/research-reports-impact-and-evaluation/research-and-reports/data-controller-study/data-controller-study-2026/
AdvertisementZoomInfo
More from The BriefAll briefs
Department for Science, Innovation and Technology

Half of surveyed security providers refer to UK security codes

Claranet

Claranet buys rival MSP Six Degrees through an administrators’ sale

Department for Science, Innovation and Technology

Most UK firms using AI have no policy for it, official survey finds

Department for Science, Innovation and Technology

UK funds £20m alliance to track AI’s impact on entry-level tech jobs

Get the briefs every week in The VETTDD Briefing.