• New data protection complaint rules: What businesses need to do

New data protection complaint rules: What businesses need to do

From 19 June 2026, all organisations that control personal data (data controllers) must have a process for handling data protection complaints, with no exceptions for small businesses. Businesses must make it easy for individuals to complain and acknowledge complaints within 30 days. They must investigate and take steps to deal with complaints, keep complainants updated, and provide an outcome without undue delay.

Profile picture of Nicholas Campion.

Written by

16 minute read Published:

If you’ve recently started a business or set up a limited company, you’ll likely handle various types of personal data. Personal data means information relating to an identified or identifiable person. This might include your customer information, employee records, or supplier contact details. If you handle this data, you’ll need to follow UK data protection rules.

On 19 June 2026, new legal rules on handling data protection complaints came into force. In practical terms, this means businesses acting as data controllers now need an effective process for handling data protection complaints. This is an important accountability change, which adds more rules for businesses to follow.

For smaller businesses without formal complaints governance, this may be a completely new concept to deal with. You’ll now need an organised way to recognise, investigate, and respond to any data protection complaints you receive in line with legal rules.

Newly formed companies might not yet have a data protection lead or team, so the company’s directors should understand the rules and ensure the process is handled properly by the right people (e.g. those with some data protection knowledge).

This might sound daunting, but it’s manageable if you take the right steps, and a complaints process doesn’t need to be complicated.

This guide introduces the new data protection complaint handling rules, why they’re important, and best practice tips to help you handle complaints effectively as a small business.

Why is data protection law compliance important for startups and small businesses?

Data protection law applies to virtually every business that handles personal data. This covers sole traders, startups, and newly formed companies, as well as much larger organisations.

Data protection law obligations can begin as soon as you start collecting or using personal data and (in some situations) even before you start trading.

The main data protection legislation UK businesses need to follow includes:

The Data (Use and Access) Act 2025 (DUA Act) introduces targeted amendments to these laws, including a new requirement for organisations that control personal data to have a process for handling data protection complaints.

Failing to comply with data protection law can lead to regulatory action, financial penalties, and reputational damage.

The highest maximum amount a business can be fined for the most serious data protection law breaches is the higher of either £17.5 million or 4% of the total worldwide annual turnover in the last financial year. In practice, a small business is unlikely to face such heavy fines – but this shows just how serious breaching data protection laws can be.

Compliance is also a commercial priority. Customers, investors, and business partners increasingly expect organisations to handle personal data responsibly and lawfully before entering contracts or commercial or investment relationships. For start-up businesses, this is especially important, as you’ll likely start looking for business partners and investment opportunities from an early stage. Savvy business customers will also often vet new businesses to check their compliance with data protection laws before they work with them.

The new complaint handling requirement is only one part of a much wider framework of data protection requirements that UK businesses need to follow. You should review your compliance obligations from the very start of your business journey and take legal advice if you’re unsure which data protection law rules apply to your business. The rules to follow aren’t one-size-fits-all and depend on the business and how it handles personal information.

What is a data controller?

The data protection complaints rules apply to data controllers.

A data controller is a person or organisation that decides why and how personal data is collected and used.

Put simply – a controller calls the shots over personal data. They decide what personal information to collect, how to use it, and how long to keep it.

In practice, this includes most businesses. For instance, if you decide how you use your customer information or employee data, you’re likely acting as a data controller.

Data controllers have the main responsibilities under UK data protection laws, since they decide how to use personal information.

What are the new data protection complaint rules?

The DUA Act introduced new requirements for data controller complaint handling by inserting section 164A into the DPA 2018.

Section 164A gives people the right to complain directly to a data controller if they think that organisation has breached rules under the UK GDPR or Part 3 of the DPA 2018 (explained further below) when handling their data.

Before these changes, people could already complain to the data protection regulator, the Information Commissioner’s Office (ICO), by making an Information Commissioner complaint, if they believed an organisation had breached data protection law.

Before the new rules came into force, data controllers were not under this specific duty – but the ICO still generally expected individuals to raise concerns with organisations before escalating them.

The new rules apply to sole traders, startups, one-person limited companies and bigger companies, charities, and larger organisations. There’s no exemption for small businesses.

If you’re a data controller, you now need to:

  • Tell people about their right to complain to your business and the ICO.
  • Give people a clear way to make data protection complaints electronically or in other ways.
  • Acknowledge receipt of complaints within 30 days.
  • Take appropriate steps to investigate each complaint without undue delay (meaning without unjustifiable or excessive delay).
  • Keep anyone who has made a formal complaint informed of progress without undue delay.
  • Provide an outcome without undue delay.

People don’t need to complain in a specific way, use legal language, or refer to data protection law. They could complain via email, letter, telephone, online form, social media, or in person.

Your business should be able to recognise a data protection complaint, pass it to the right individuals to deal with it, handle it in line with legal rules, keep records, and explain the outcomes of complaints clearly.

People may complain directly to your organisation, complain to the ICO (“an Information Commissioner or ICO complaint”), and may also have access to other legal remedies. However, the ICO will usually expect them to raise their concerns with you first. That allows you to investigate the issue and resolve the complaint before it goes any further.

What counts as a data protection complaint?

Broadly speaking, a data protection complaint is a concern that an organisation has broken data protection law in some way when handling its data. Specifically, it’s about an infringement of the UK GDPR (the UK’s main data protection law rules) or Part 3 of the DPA 2018. Part 3 of the DPA covers rules around law enforcement processing (e.g. where bodies like the police process personal data for law enforcement purposes).

It could be from someone complaining you’ve breached their data protection rights, or about another issue, e.g. a data security breach.

Complaints could come from your employees, customers, or other people you process personal data about. They don’t necessarily need to mention the law or that they’re making a “GDPR complaint”, so watch this carefully.

Examples of complaints could include:

  • your privacy notice contains the wrong information
  • you used personal data for a purpose you didn’t explain
  • you didn’t respond to a Subject Access Request (a request for a copy of personal data)
  • you didn’t keep personal data secure
  • you kept personal data longer than needed

Someone can also make a complaint on another person’s behalf. For example, a family member or solicitor may complain on behalf of the individual concerned. In those situations, check that the person is authorised to act on the individual’s behalf.

If you’re unsure whether you’ve received a data protection complaint, look carefully at what the person is concerned about and whether it relates to how your business handled personal data. If their concern is unclear, ask them to clarify it.

 Is a request a data protection complaint, customer service complaint, or subject access request?

You’ll need to identify the type of request your business receives as early as possible, as different rules apply depending on what the request covers.

  • Data Protection Complaint. This means the person complains about how you’ve handled personal data.
  • Customer Service Complaint. This means the person complains about a product or service, rather than about how you’ve handled their personal data.
  • Subject Access Request (SAR). This means the person asks for a copy of their personal data and information about how you use it.

Sometimes a request can include more than one issue. For example, a person may make a Subject Access Request and a data protection complaint at the same time. When this happens, separate the issues out and handle each one under the correct process to make sure you follow the correct legal obligations.

What should you do if you receive a data protection complaint?

If someone complains about how you’ve handled their personal data, follow a clear process and document what you do, in case it’s ever escalated to the ICO.

You should also refer to the ICO’s data protection complaints guidance for information on how to handle complaints effectively.

The following steps reflect legal requirements and best practice steps you can take if you get a complaint:

1. Record the complaint

Record the complaint when you receive it and decide if it’s a data protection complaint or another request, so you can take the right steps.

2. Acknowledge the complaint within 30 days

If you decide that you’ve received a data protection complaint, acknowledge it within 30 days of receiving it.

Let the individual know you’ve received their complaint and that you’ll investigate it.

Although the legal requirement is to acknowledge the complaint within 30 days, you should do so as soon as possible and begin investigating without undue delay.

3. Check identity or authority if you need to

If you have doubts about the identity of the person making the complaint, you may need to ask for proof of identity. Don’t request proof of identity if you already have enough information to identify the individual.

If someone is acting on behalf of another person, check that they have the authority to do so before investigating the complaint: Only ask for information that’s reasonable and proportionate.

4. Investigate the complaint

Start your investigation as soon as possible, as you’ll need to do so without undue delay.

You may need to:

  • check relevant records
  • speak to people involved internally
  • review your privacy information, policies, and procedures
  • gather any evidence required
  • ask the person who complained for further information where it’s necessary

Your enquiries must be appropriate to the nature, seriousness, and complexity of the complaint. You should be able to justify the approach you’ve taken.

5. Keep the individual updated

Keep the individual updated without undue delay while you investigate the complaint.

If the investigation is taking longer than expected, explain the reason for the delay and tell them when they’ll receive a further update.

Where appropriate, explain the next steps, whether you’ll need any extra information, and when they can expect an update or outcome.

6. Explain the outcome

Once you’ve completed your investigation, explain the outcome without undue delay.

There’s no fixed time limit for providing an outcome. The time required will depend on the nature, complexity, and circumstances of the complaint.

Address each issue raised in the complaint and clearly explain:

  • what you investigated
  • what you found
  • any relevant evidence
  • whether you complied with data protection law
  • whether anything went wrong
  • any action you’ve taken
  • what the individual can do if they’re still dissatisfied

If something went wrong, explain what you’ve done to put it right. If you believe your business did comply with data protection law, explain how you reached that conclusion and give enough information for the individual to understand your decision.

Tell the individual they can complain to the ICO if they’re unhappy with the outcome.

7. Keep a record

It helps to keep a record of:

  • when you received the complaint
  • when you acknowledged it
  • what you investigated
  • relevant correspondence and documents
  • the outcome
  • any actions you took

A complaints log can provide valuable evidence of how you handled the complaint if the individual later complains to the ICO. Keep copies of relevant emails, documents, and investigation records together, so you can demonstrate how you handled it. However, remember not to keep personal information for longer than necessary.

8. Review any lessons

Use complaints as an opportunity to identify and fix recurring issues around data protection law compliance.

Repeated complaints about the same issue might show a wider problem with your processes, policies, procedures, or training.

Review what happened, identify any lessons learned, and consider what changes you could make to help prevent similar complaints in the future.

How to set up a data protection complaints procedure

As a small business, you can keep your data protection complaints procedure simple and proportionate. You have flexibility in how you set it up, and there’s no need for a complex system. The aim is to make it easy for people to raise a data protection complaint and make sure you handle complaints consistently, fairly, and efficiently.

Your process should be appropriate for the volume, type, and complexity of complaints you’re likely to receive.

Key steps include:

1. Updating your privacy notices and policies

You need to tell people that they can complain when you first collect their personal data. Data controllers typically provide individuals with a privacy notice or privacy policy to explain how they handle personal data.

Your privacy notices and policies must tell people that they can complain to you and to the ICO, and explain how they can do so. You can also explain how your complaints process works and what they can expect from it.

Keep this information clear, accessible, and easy to find. You may also want to add in FAQs or other guidance to help people understand the complaints process.

You also need to tell people about the right to complain when you respond to a Subject Access Request.

2. Giving people a clear way to complain

You must provide a way for people to make a complaint.

Examples of how to receive complaints include:

  • email
  • post
  • telephone
  • live chat
  • an online form
  • face to face

For a startup, this could be as simple as providing and regularly monitoring an email address, such as dataprotectioncomplaints@yourbusiness.co.uk, and assigning one person to handle complaints.

But you must make sure someone is responsible for checking complaints and ensuring they’re dealt with promptly.

Be aware that people can make a complaint to a data controller in many different forms (including social media) and you still need to respond – there’s no specific way they need to complain, and you can’t force them to follow your chosen process.

3. Training staff to recognise complaints and consider a written complaints policy

A data protection complaint can land anywhere across the business. In practice, one of the biggest pain points for a small business will likely be recognising a data protection complaint.

If you’re starting up and use little personal data, this might not be a big issue at first. But, as you grow, hire more staff and expand your customer base, your use of personal information will likely increase, and the risk of data protection complaints will increase, too.

Staff should be trained properly to understand:

  • what a data protection complaint looks like
  • the difference between a complaint and other requests
  • where complaints should be escalated to
  • how complaints are handled by the business

Customer-facing staff or HR teams may need more detailed guidance if they’re more likely to receive complaints directly.

To help, you can use a strong data protection complaints policy setting out roles, responsibilities, and the steps staff should follow. The key point is that data protection complaints need to be spotted and passed on to the right people to handle them correctly.

4. Deciding who is responsible

Make sure someone is responsible for handling data protection complaints. This could be your data protection lead or Data Protection Officer, if you have one.

5. Keeping records and review regular issues

Keep records of your complaints to demonstrate compliance and to help you identify repeated problem issues you can improve on.

It’s important to make sure you handle this process correctly, especially as it’s a new legal requirement. There might be complaints you can handle confidently, for instance, where someone has misunderstood an issue.

But you may find you receive more complex complaints – such as complaints about service providers handling data on your behalf, or complaints from children or vulnerable people. These situations give rise to more complex considerations, so take legal advice if you get a complicated request or you’re unsure how to handle one.

What happens if you don’t comply?

If you don’t handle data protection complaints properly, the individual may choose to escalate the matter to the ICO.

If the ICO investigates, it may ask how you handled the complaint. If you can’t show that you handled the complaint appropriately, you could face greater scrutiny and find it more difficult to demonstrate compliance with data protection law.

Failing to comply may lead to regulatory action. Depending on the circumstances, this could result in various consequences, including financial penalties. As the law is so new, how this will be enforced in practice remains to be seen.

This is why it’s important to take this seriously and invest in a clear complaints process to reduce risk.

The benefits of a strong complaints process

Once you’ve investigated a complaint, provided a clear outcome, and taken all necessary action, you’ll be in a stronger position to demonstrate that you’ve handled the matter properly if the individual later complains to the ICO. It can also give you greater confidence that you’ve met your obligations and followed data protection laws.

As a small or new business, you can view data protection complaints rules as an opportunity rather than simply a compliance burden.

These rules give you a chance to develop good data protection practices and address concerns before they escalate, putting things right where necessary and improving trust. They also give you a chance to spot where things are going wrong and fix issues to improve your data protection law compliance.

If you need support with data protection compliance, you can explore our Hassle-Free Compliance Service, which includes our UK GDPR Compliance Package. This service includes a comprehensive package of data protection template documents to help small businesses, as well as access to expert compliance support.

Disclaimer

The information in this article is high-level, introductory, and provided for general information. The law and guidance may change. If you’re unsure about your legal obligations and the specific complaints process your business needs, you should obtain advice on your specific circumstances from a suitably qualified solicitor. This guide is aimed at startups and small businesses, but larger organisations may need more detailed governance processes and documentation.

Frequently asked questions

About the author

Nicholas Campion is Director of Company Secretarial at 1st Formations, where he oversees statutory filings and ensures that company secretarial procedures across the organisation comply with UK company law. He is responsible for maintaining high standards of governance within the company secretarial team and ensuring that staff are trained in current Companies House requirements and regulatory procedures.

Share This Post

Related Posts

Join The Discussion