UK organizations now need a data protection complaints process
The last parts of the Data (Use and Access) Act are in force. The regulator says its focus is on helping firms comply, but many still think the change passes them by
- The ICO’s complaints guidance uses worked examples of common complaints, including subject access requests, inaccurate data and marketing
- The Act lets the ICO fine up to £17.5m or 4% of global turnover under the Privacy and Electronic Communications Regulations
- New ICO powers include compelling a witness to attend an interview
- The ICO has started work on a statutory code of practice on AI and automated decision-making
Name an owner for complaints and publish the route on the website and in the privacy notice. Track each complaint against its deadline in the same system used for security incidents, because a complaint about wrong or exposed data is often the first sign of a breach. Check that suppliers who hold customer data pass complaints on promptly, since the duty to respond sits with the business that controls the data.
“We recognise that some businesses, especially smaller ones, may still be adjusting.”Emily Keaney, deputy commissioner, regulatory policy, Information Commissioner’s Office
Every UK organization that handles personal data must now give people a clear way to raise a data protection complaint, acknowledge it within 30 days, investigate it and report the outcome, the Information Commissioner’s Office (ICO) said on 23 June 2026.
The duty comes from the Data (Use and Access) Act, whose outstanding provisions all took effect on 19 June. The ICO says its research shows more than two in three businesses aware of the Act either do not know whether the change applies to them or wrongly believe it does not.
Small firms start furthest behind. In the ICO’s Data Controller Study 2025, published in June and based on a survey of 2,292 data controllers by IFF Research between November 2025 and January 2026, 62% of organizations said they knew of the ICO before taking part, ranging from 60% of sole traders to 90% of large organizations. A quarter (25%) did not know about the requirement to register with the regulator.
Sources
- ICO, “New data protection complaints law now in force”, news release, 23 June 2026. https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/06/new-data-protection-complaints-law-now-in-force/
- ICO, “One year on: marking the 12-month commencement of the Data (Use and Access) Act”, blog, 23 June 2026. https://ico.org.uk/about-the-ico/media-centre/news-and-blogs/2026/06/one-year-on-marking-the-12-month-commencement-of-the-data-use-and-access-act/
- ICO, “Data Controller Study 2025: findings report”, June 2026. https://ico.org.uk/about-the-ico/research-reports-impact-and-evaluation/research-and-reports/data-controller-study/data-controller-study-2026/
