How the ICO deals with data protection complaints
What is a data protection complaint
Understand what counts as a data protection complaint - and what doesn't - under the Data (Use and Access) Act 2025.
A data protection complaint is a concern raised when someone believes you have not handled their personal information correctly under data protection law.
Common examples of data protection complaints
People can make a complaint directly to you if they think you have:
- responded incorrectly to a subject access request (SAR)
- responded incorrectly to other information rights requests
- collected, used, stored or shared their personal information improperly or unfairly
- kept their information for too long
- held inaccurate personal information about them
- failed to protect their personal information with appropriate security measures
People do not need to use legal language or refer to specific laws when making a complaint.
What doesn't count as a data protection complaint
Not every complaint involving personal information is a data protection complaint. For example:
- an employee may raise a workplace grievance, and also request copies of their personal information
- a customer may complain about service quality, and also ask you to delete their information
In these situations, the complaint itself may not be about data protection, even though the person is exercising their information rights. If you are unsure whether someone is making a data protection complaint, ask them to clarify.
You should identify and record data protection complaints as early as possible so you can handle them appropriately under the Data (Use and Access) Act 2025.
Also on this siteContent category
Source URL
/content/what-data-protection-complaint
Links
Prepare to handle data protection complaints
How to prepare your organisation for receiving, investigating and responding to data protection complains.
Under the Data (Use and Access) Act 2025, you must have a clear process for receiving, investigating and responding to data protection complaints.
As part of this process, you should:
- provide clear ways for people to complain
- tell people about their right to complain
- verify identity and authority where necessary
- train staff to recognise complaints
- maintain effective records
- establish clear complaints procedures
- meet your responsibilities as a data controller or processor
A clear process helps you comply with data protection law and resolve concerns quickly, reducing the risk of escalation to the Information Commissioner's Office (ICO).
Give people a way to complain
You must allow people to make data protection complaints directly to you. You can offer them different ways to do this. For example, you could:
- provide a complaint form (a digital or paper copy)
- accept complaints by email, post, telephone or in-person
- provide an online complaints portal
- offer a live chat service with an option to speak to a staff member
You do not need to set up a separate system for receiving complaints. You can adapt an existing complaints process if it enables you to meet your data protection obligations.
People are not required to follow your preferred process. They may complain through any channel, including by contacting employees directly.
You must accept data protection complaints regardless of how they are received.
Complaints on social media
People may use social media to raise data protection concerns. You should plan how you will identify and handle these complaints, and check if the person expects a response. Social media is generally not a secure way to discuss personal information, so ask to move conversations to a secure channel where appropriate.
Complaints from children
Children have the same data protection rights as adults. When responding to complaints from children, you should use clear and age-appropriate language and assess whether the child can understand and exercise their rights.
If your organisation falls within the scope of the Age Appropriate Design Code, you should ensure your complaints process meets the relevant requirements.
Tell people they can complain
You must tell people they can complain to you and to the ICO. You must tell them this:
- when collecting personal information, such as in a privacy notice
- when responding to a subject access request (SAR)
You must use clear and accessible language when providing this information, especially if you are addressing a child.
Organisations processing personal data for law enforcement purposes must tell people about their right to complain at key points in the process, unless a restriction applies.
Write a complaints procedure
If you don't already have one, consider documenting and publishing a complaints procedure. A written complaints procedure helps people understand:
- how to complain
- what information they need to provide
- what identification you may require
- how complaints made on behalf of others are handled
- expected timescales
- how outcomes are communicated
Write your complaints procedure in plain English and explain any legal or technical terms. You can publish this information on your website or include it within existing documents, such as your privacy notice.
Verify identity and authority
If you have reasonable doubts about the identity of the person complaining, you may ask for proof of identity. In this case, you should request identification as early as possible, and only request information necessary to confirm identity. If you already have enough information to verify the person's identity, you must not ask for additional proof.
Where complaints are submitted on behalf of another person (for example, by family members, solicitors or advocacy organisations), you must check that the representative has authority to act before investigating the complaint. Evidence may include a power of attorney or a signed letter of authority. If there is no evidence of authority, you must not investigate the complaint until appropriate authorisation is provided.
Consider other legal obligations
Data protection law may not be the only legal framework that applies when handling complaints. You may also need to consider:
- equality and discrimination legislation
- sector-specific requirements
- your own organisational complaint-handling policies
You can integrate data protection complaints into existing complaint processes, provided you continue to meet your data protection obligations and avoid undue delay. If a wider complaint includes a data protection issue, you should provide an outcome on the data protection aspect as soon as possible.
Maintain effective records
You should have a record management system that is accurate, organised, up to date and easy to search. Good record keeping helps you investigate complaints efficiently and provide timely responses.
Train staff to recognise complaints
All staff should understand what a data protection complaint is, how to recognise one, where to direct it internally, and what their role is in the complaints process. You should include complaint handling in your data protection training programme.
Meet your responsibilities as a joint controller or processor
A data controller decides why and how personal data is used. A data processor acts on behalf of the controller and processes data following their instructions.
If you are a joint controller, you should have a clear agreement with other controllers that sets out how data protection complaints will be handled. This should include how complaints are received, who investigates them, who communicates with complainants and how response times will be managed. The response period begins when any controller receives the complaint.
If you use processors, your contracts should ensure they notify you of any complaints they receive, provide information needed to support investigations and assist you in meeting your obligations.
In all instances, the controller remains responsible for handling data protection complaints.
If you need to share information with another controller or joint controller to investigate a complaint, you should take into account the data sharing code of practice.
ActionsAlso on this siteContent category
Source URL
/content/prepare-handle-data-protection-complaints
Links
How to respond to a data protection complaint
You must acknowledge the receipt of complaint within 30 days, investigate without undue delay, keep the complainant informed, and record your actions.
When you receive a data protection complaint, you must:
- acknowledge the complaint within 30 days
- investigate the complaint without undue delay
- keep the complainant informed of progress
- provide an outcome without undue delay
- keep appropriate records of your actions
Having a clear and structured approach can help resolve concerns more quickly and reduce escalation to the Information Commissioner's Office (ICO).
Time limits for acknowledging the complaint
You must acknowledge receipt of a data protection complaint within 30 days. The time limits state that:
- This 30-day period begins on the day after you receive the complaint.
- If the deadline falls on a weekend or public holiday, you have until the next working day to acknowledge the complaint.
Keep a record of when and how you acknowledged the complaint to show you met the 30-day rule. During staff absences, put in place arrangements to ensure complaints are acknowledged within the appropriate time limits.
How to acknowledge the complaint
In your acknowledgement, you should confirm that you have received the complaint and will investigate it. You can normally respond using the complainant's preferred contact method where possible, unless they ask you to respond in a different way.
How to investigate the complaint
Your obligation to investigate begins when you receive the complaint, not after the 30-day acknowledgement period. You must investigate complaints without undue delay.
The investigation should be proportionate to the circumstances and may include:
- reviewing relevant records and evidence
- speaking to relevant staff members
- comparing the complaint with the information you hold
- checking compliance with your policies, procedures and legal obligations
If the complaint is unclear, seek clarification as soon as possible. You can also ask what outcome they want (for example – an apology, correction or process change) to help you narrow the scope of investigation and resolve the complaint more quickly.
What does 'without undue delay' mean?
Without undue delay means without an unjustifiable or excessive delay. The time needed to investigate a complaint will depend on many factors, including:
- the complexity of the issues
- the scale of the issue
- any harm the complainant may be experiencing as a result of the issue
If you decide to use any internal timescales, these must not delay your investigation. You must complete the investigation as soon as the circumstances allow. You must also be able to explain the approach you have taken.
Keep the complainant informed
You must keep the complainant updated on progress without undue delay. If your investigation is likely to take time, you should:
- explain the expected timescales
- provide updates on progress
- explain any delays
- give a point of contact for questions
Maintaining clear communication with the complainant can help build trust and support early resolution. At the end of your investigation, you must provide an outcome to the complainant.
Keep records of your data protection complaint actions
You should keep accurate and up-to-date records of:
- when the complaint was received
- when it was acknowledged
- relevant conversations and evidence
- the outcome of the complaint
- any actions taken as a result
Good record keeping provides evidence of compliance and can help you identify recurring issues or opportunities for improvement. Do not keep personal information for longer than you need it.
ActionsAlso on this siteContent category
Source URL
/content/how-respond-data-protection-complaint
Links
How to close a data protection complaint investigation
What to do after you finish a data protection complaint investigation, how to communicate the outcome and identify lessons learned.
Once you have completed your data protection complaint investigation, you must provide the complainant with an outcome without undue delay. This is also a good time to consider if any improvements are needed to prevent similar complaints in future.
Provide an outcome to the complainant
You must tell the complainant the outcome of your investigation without undue (unjustifiable or excessive) delay.
In some cases, you may provide the outcome and the acknowledgement of the complaint together if both can be completed within the required 30-day timeframe.
Your response should explain:
- the conclusions you reached
- the reasons for your decision
- any action you have taken, or plan to take, as a result of the complaint
- where relevant, why you believe you have complied with data protection law
You should provide enough information to help the complainant understand how you reached your decision. Where a complaint covers multiple issues, it may be helpful to address each issue separately.
If the complainant is unhappy with the outcome
If the complainant is unhappy after you close the investigation, you may offer more detail or clarify your decision, or consider having a review process, if appropriate.
It's also good practice to remind them of their right to complain to the Information Commissioner's Office (ICO). People can complain to the ICO at any point; they do not need to wait for your outcome.
Find out how the ICO deals with data protection complaints.
Review lessons learned
After closing the complaint, you should review what happened and record any recurring issues or trends, actions taken to address problems, and opportunities to improve compliance and service delivery.
ActionsAlso on this siteContent category
Source URL
/content/how-close-data-protection-complaint-investigation
Links
How the ICO deals with data protection complaints
What happens if someone makes a data protection complaint to the Information Commissioner's Office (ICO) about your business.
People can complain to the Information Commissioner's Office (ICO) if they are unhappy with how you have handled their personal information.
The ICO usually expect people to raise their data protection concerns with you first and give you an opportunity to resolve the issue.
When the ICO receives a complaint, they first assess if it is something they can help with. They can only deal with data protection complaints. If the complaint includes other issues (for example customer service or employment matters), you may need to refer the person to another service.
When the ICO assesses a complaint, they may consider:
- the nature of the issue
- any harm or impact resulting from the issue
- the steps an organisation has taken to address the concern
- whether they received similar complaints or information on the issue
Read the full ICO criteria for triaging data protection complaints.
Depending on the circumstances, they may:
- record the complaint for information
- ask you to review the issue and consider relevant guidance
- contact you for further information
- investigate the matter further
Not every complaint will result in an investigation or regulatory action. Where appropriate, the ICO may provide advice, guidance or recommendations instead to help you improve your data protection practices.
Also on this siteContent category
Source URL
/content/how-ico-deals-data-protection-complaints
Links