UK Data Protection Complaints Procedure: A Practical DUAA Checklist
A UK organisation should provide an accessible way to complain about its use of personal information, acknowledge a data protection complaint within 30 days, investigate appropriately and communicate the outcome without undue delay. The 30 days is an acknowledgement period, not a universal deadline to finish every case.

Publish a clear route and classify the message
The Data (Use and Access) Act 2025 added duties for organisations handling data protection complaints. Provide an accessible means to complain, including an electronic route, and make it clear how a person can use it. A message about a company's use of personal data can be a complaint even if it uses no legal term.
At intake, distinguish the complaint from a subject access request, an erasure request or an incident report. One message can trigger more than one process. Route each issue to its owner and preserve the received date for each applicable deadline.
Acknowledge within 30 days
The ICO explains that organisations must acknowledge a data protection complaint within 30 days of receipt. Start investigating when the complaint arrives; do not wait until the acknowledgement is sent. Explain the contact route, next step and whether more information is needed.
Illustrative acknowledgement: “We received your complaint on 29 September about access to your account data. Our privacy team is investigating the facts and may contact you for clarification. We will update you on the outcome without undue delay. You can reply to this message or use the contact route in our privacy notice.” Adapt the wording to the real case.
Use an investigation and outcome log
Assign an investigator who can obtain records from the relevant team. Record the allegation, systems and people involved, evidence reviewed, steps taken, findings, outcome and any remedial action. Limit access to the complaint file because it may contain sensitive personal data.
| Field | Illustrative entry |
|---|---|
| Issue / received | Account deletion complaint / 29 September |
| Acknowledgement | Sent through secure support channel; copy retained |
| Evidence / owner | Deletion ticket and backup policy / privacy lead |
| Outcome / action | Explain finding; correct notice wording if needed |
| Close and learn | Send outcome, log follow-up owner and review process |
Communicate the result without undue delay
Tell the complainant what was investigated, the outcome and the next route if they remain dissatisfied, while protecting other people's information. The ICO's guidance does not turn the 30-day acknowledgement into a universal 30-day investigation deadline. Track cases actively and explain material delay.
Analyse recurring complaints for product or policy defects. A complaint procedure is useful only if its findings can reach a team with authority to fix the issue.
Frequently asked questions
Must every UK data protection complaint be resolved in 30 days?
No. The 30-day duty concerns acknowledgement. Investigate appropriately and communicate the outcome without undue delay.
Can a complaint also be a DSAR?
Yes. A single message can contain both. Log and handle each applicable process and deadline.
Keep researching
Related resources
A practical next step
Make the next privacy decision clearer
Bring your organisation, processing, jurisdictions, current documents, internal owners, and deadline. We can help identify the right scope before an appointment or wider workstream begins.
This guide provides general information, not legal advice or a conclusion that a particular obligation applies. Confirm the legal scope and practical next steps against your organisation's facts.
Sources: ICO: How to deal with data protection complaints, ICO: What do we do when we receive a complaint?
