Every business must have a data protection complaints procedure

Where accounting meets insight

September 15, 2026

Organisations are now required to provide a clear way for customers and anyone they have data for to make data protection complaints, and an acknowledgement of the complaint being received must be sent within 30 days.

 

These new legal requirements came intoforce on June 19, and mean all organisations based in the UK are legallyrequired to have a procedure to handle data protection complaints under the Data (Use and Access Act) 2025.

 

This includes even small businesses, who may think they are unlikely to get a data protection complaint. But even these businesses must be ready to respond in a planned way and within short timeframes.

 

What does this mean in practice?

All complaints must be investigated properly, with appropriate steps taken at each stage so the person who made the complaint is kept continually informed, and they must also be told the outcome of the investigation.

 

Guidance is available on the Information Commissioner’s Office website, which small and medium-sized enterprises can refer to. This guidance suggests offering a way to contact your business via an online form that can be filled in and emailed or posted to you, providing a specific email address where complaints can be sent to, allowing complaints via phone or through alive chat option that can escalate to a human, or by providing a complaints portal online.

 

You don’t have to specifically have a portal like this, according to the ICO, but you need to have a clear way for complainants or their representatives to contact you.

 

Are there other ways people can complain?

Customers or their representatives can actually complain in any way they want to, which could even include speaking to a member of staff or contacting any part of your organisation. So, it’s important to ensure all your employees are well trained and understand that no matter who contacts them with a data protection complaint, it must always be passed on in a timely way.

 

If a complaint is made on social media, you would need to ask for a secure way to speak to the complainant, as it is not something you can ask them to discuss publicly. Children have the same rights over their data as adults, and they need specific protection, as they may not be aware of the risks of data processing in the way an adult might be. They need to also understand their rights when you process their personal information.

 

Children need special considerations in other ways too, as you need to use very clear language in your responses to them so they understand what you’re saying. This must be taken into consideration at every stage of the process. You must also assess the competence of the child “to understand and exercise their rights”, according to the ICO website.

 

David Gomez, SeniorAdviser on Ethics at the ICAEW, said: “The level of trust people have in abusiness is influenced by their perception of how you handle their data.

 

“Putting in place appropriate governance frameworks, having an accessible complaints process, and ensuring staff have the relevant training, all contribute to that trust, and are part of promoting an ethical culture within business.”

 

We can help you meet your obligations

If you would like to know more about how these changes might affect your business, then please get in touch and we would be happy to give you the guidance you need.