UK · Complaints procedure

UK Data Protection Complaints Procedure: A Practical DUAA Checklist

A UK organisation should provide an accessible way to complain about its use of personal information, acknowledge a data protection complaint within 30 days, investigate appropriately and communicate the outcome without undue delay. The 30 days is an acknowledgement period, not a universal deadline to finish every case.

By The Data Protection OfficersReading time: 4 min
Original UK complaint procedure illustration showing intake, acknowledgement, investigation and outcome

Publish a clear route and classify the message

The Data (Use and Access) Act 2025 added duties for organisations handling data protection complaints. Provide an accessible means to complain, including an electronic route, and make it clear how a person can use it. A message about a company's use of personal data can be a complaint even if it uses no legal term.

At intake, distinguish the complaint from a subject access request, an erasure request or an incident report. One message can trigger more than one process. Route each issue to its owner and preserve the received date for each applicable deadline.

Acknowledge within 30 days

The ICO explains that organisations must acknowledge a data protection complaint within 30 days of receipt. Start investigating when the complaint arrives; do not wait until the acknowledgement is sent. Explain the contact route, next step and whether more information is needed.

Illustrative acknowledgement: “We received your complaint on 29 September about access to your account data. Our privacy team is investigating the facts and may contact you for clarification. We will update you on the outcome without undue delay. You can reply to this message or use the contact route in our privacy notice.” Adapt the wording to the real case.

Use an investigation and outcome log

Assign an investigator who can obtain records from the relevant team. Record the allegation, systems and people involved, evidence reviewed, steps taken, findings, outcome and any remedial action. Limit access to the complaint file because it may contain sensitive personal data.

FieldIllustrative entry
Issue / receivedAccount deletion complaint / 29 September
AcknowledgementSent through secure support channel; copy retained
Evidence / ownerDeletion ticket and backup policy / privacy lead
Outcome / actionExplain finding; correct notice wording if needed
Close and learnSend outcome, log follow-up owner and review process

Communicate the result without undue delay

Tell the complainant what was investigated, the outcome and the next route if they remain dissatisfied, while protecting other people's information. The ICO's guidance does not turn the 30-day acknowledgement into a universal 30-day investigation deadline. Track cases actively and explain material delay.

Analyse recurring complaints for product or policy defects. A complaint procedure is useful only if its findings can reach a team with authority to fix the issue.

Frequently asked questions

Must every UK data protection complaint be resolved in 30 days?

No. The 30-day duty concerns acknowledgement. Investigate appropriately and communicate the outcome without undue delay.

Can a complaint also be a DSAR?

Yes. A single message can contain both. Log and handle each applicable process and deadline.

Keep researching

A practical next step

Make the next privacy decision clearer

Bring your organisation, processing, jurisdictions, current documents, internal owners, and deadline. We can help identify the right scope before an appointment or wider workstream begins.

This guide provides general information, not legal advice or a conclusion that a particular obligation applies. Confirm the legal scope and practical next steps against your organisation's facts.

Sources: ICO: How to deal with data protection complaints, ICO: What do we do when we receive a complaint?

Choose the Right Data Protection Service

Compare the role and scope that fit the jurisdictions and processing activities that matter to your business.

Find the Right Data Protection Service in Minutes

Select your jurisdictions, compare annual pricing, and continue with the service that fits your scope.

View Data Protection Services