ICO Data Protection Register

New rule from 19 June 2026: every UK organisation must have a data protection complaints process

Since 19 June 2026, every UK organisation that decides how personal data is used must give people a way to complain to it directly, acknowledge that complaint within 30 days, investigate without undue delay and tell the person the outcome. There is no exemption for small businesses or charities — but you can add this to the complaints process you already run.

Last updated 31 July 2026. This page explains the law as it stands on that date. It is general information, not legal advice.

The bottom line

Since 19 June 2026 every UK controller — sole traders, small charities, schools and parish councils included — must let people complain to them about how they handle personal data, acknowledge that complaint within 30 days, investigate it without undue delay and tell the person the outcome. There is no size exemption. You do not have to build a separate process, and you do not have to publish a form.

What the law requires now, and exactly when it started

The duty sits in new section 164A of the Data Protection Act 2018, inserted by section 103 of the Data (Use and Access) Act 2025. Schedule 10 to that Act — headed "complaints: minor and consequential amendments" — makes the changes that go with it. Both were brought into force on 19 June 2026 by regulation 3 of SI 2026/82, the Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026.

Section 164A(1) lets a data subject complain to the controller if they consider there is an infringement of the UK GDPR or Part 3 of the DPA 2018 in connection with their personal data. Subsections (2) to (5) set out what you must then do.

Duty What section 164A says Deadline
Let people complain Facilitate the making of complaints "by taking steps such as providing a complaint form which can be completed electronically and by other means" (s.164A(2)) Standing duty
Acknowledge Acknowledge receipt of the complaint (s.164A(3)) Within 30 days
Investigate and update Take appropriate steps to respond, including making enquiries "to the extent appropriate" and informing the complainant about progress (s.164A(4)(a), (5)) Without undue delay
Give an outcome Inform the complainant of the outcome (s.164A(4)(b)) Without undue delay

There is a transitional saving. Regulation 7 of SI 2026/82 says the duties in section 164A(3) and (4) "apply only in relation to a complaint that is received by the controller on or after the 19th June 2026". Anything already in your inbox on 18 June is not caught by the acknowledgement and response duties.

What did not change: people can still go straight to the ICO

Section 103(6) of the DUAA omits Article 77 of the UK GDPR — the right to lodge a complaint with the regulator — with effect from 19 June 2026. That is a relocation, not a removal. The same section rewrote section 165 of the DPA 2018 so that section 165(2) now covers UK GDPR infringements as well as Parts 3 and 4. The route to the ICO is intact.

Nobody has to come to you first. The ICO's guidance is explicit: "There's no obligation for people to wait for you to review your decision before complaining to us. People can complain to us at any point." In practice the ICO says that in most cases it will ask a complainant to raise the matter with the organisation first.

Does it apply to my small business or charity?

Yes. The ICO's guidance opens with the line: "You must have a process for handling data protection complaints within your organisation - there are no exemptions to this."

There is no turnover threshold, no staff-number threshold and no charity carve-out in section 164A. If you are a controller, the duty applies. That includes a sole trader with a customer list, a charity with donor records, a school, a landlord and a village hall committee. Note that this is not the same test as the data protection fee, which does have exemptions and tiers — being fee-exempt does not make you complaints-exempt.

Awareness is the weak point. ICO research reported on 23 June 2026 found that more than two in three businesses aware of the Data (Use and Access) Act either do not know whether the change applies to them or incorrectly think it does not.

The regulator's stated posture

Emily Keaney, Deputy Commissioner, Regulatory Policy, on 19 May 2026: "We are not here to catch businesses out, we are here to help you get ready." That is a statement of approach, not a legal exemption.

What counts as a data protection complaint?

There are no magic words. The ICO is clear that in order to complain, people "don't have to use legal terms or quote sections of the legislation". Someone who emails to say "you've had my details for years and I never said you could" has made a complaint.

The ICO gives these as typical examples:

Something that looks similar but is not automatically a data protection complaint: a service grievance that happens to sit alongside a rights request. The ICO's examples are an employee raising a grievance who also asks for copies of their personal information, and a customer complaining about service who also asks you to delete their information. Its advice where the position is unclear: "If you're not sure whether someone is making a data protection complaint, you should ask them to clarify."

The channel is irrelevant. People can complain "in any way they choose", including to any employee or any part of your organisation, and the ICO's instruction is blunt: "However you receive a complaint, you must accept it." That covers the phone, in person and social media. For social media the ICO says to ask for an alternative contact method, because it is generally not a secure way to send personal information.

You can bolt this onto your existing complaints procedure

This is the most misread part of the new duty. The ICO's guidance says: "There's no obligation to produce a separate or standalone process for data protection complaints. You can integrate data protection complaints into your existing processes, as long as you can continue to meet your data protection obligations."

Nor does the statute mandate a form. Section 164A(2) says you must facilitate complaints "by taking steps such as" providing a complaint form — an example, not a specification. The ICO lists acceptable options, including:

Two traps to watch. First, if a data protection complaint is wrapped inside a wider complaint and you can resolve the data protection part sooner, the ICO says you must: "Waiting to deal with all the issues at once without justification could cause an undue delay." Second, if you are a joint controller, the ICO says the timescale "begins as soon as the complaint is received by any of the controllers" — so agree in advance who does what. If you use processors, they can help administer complaints, but the obligation stays with you.

The 30 days: calendar days, and when you can skip the acknowledgement

Calendar days, not working days. The statute says you must acknowledge "within the period of 30 days beginning when the complaint is received". The ICO's guidance counts it slightly more generously: "The 30 days start the day after you receive the complaint. It doesn't matter if this day falls on a weekend or a public holiday." It adds that if the final day falls on a weekend or public holiday, you have until the next working day.

The worked example in the ICO's guidance: a complaint received on Thursday 5 June starts the 30 days on Friday 6 June, ending at the end of Saturday 5 July — and because that is a weekend, you have until the end of Monday 7 July. Those days of the week are 2025 dates, not 2026 ones: in 2026, 5 June is a Friday and 5 July a Sunday. Take the counting method from the example, not the calendar.

Where the statute and the guidance differ

The Act says the period begins when the complaint is received; the ICO's guidance says it begins the day after. The difference is one day. Working from the date of receipt itself keeps you inside both readings. The Act is the law; the guidance is the regulator's view of it.

If you have already sorted it out, you do not need to send a separate acknowledgement. The ICO says: "You may be able to investigate the complaint and provide an outcome within 30 days. In these instances, you're not required to provide an acknowledgement and outcome separately."

One common misconception worth killing: 30 days is not an investigation deadline. The ICO states that "your obligation to investigate begins when you receive the complaint, not after the 30-day acknowledgement period". Investigation, progress updates and the outcome are all governed by "without undue delay", with no fixed number attached.

What to change in your privacy notice and your SAR replies

The ICO names two specific documents. You must tell people they can complain to you as well as to the ICO at the point you collect their personal information (for example in your privacy notice, in clear and plain language), and again when you respond to a subject access request. Organisations processing for law enforcement purposes have further trigger points under DPA 2018 sections 44 to 48.

  1. Step 1 Add a complaints line to your privacy notice Say how someone can complain to you about how you handle their personal data, and that they can also complain to the ICO. Plain language, and simpler still if you address children.
  2. Step 2 Update your SAR response template Every SAR reply now needs the same two-route line. This is the change most likely to be missed, because SAR templates are often years old.
  3. Step 3 Brief whoever answers the phone and the inbox The ICO expects all staff to recognise a data protection complaint and know where to send it internally. A complaint made to any employee counts.
  4. Step 4 Record receipt, acknowledgement, outcome and actions The ICO says it, or industry bodies, may ask to see this if someone complains about you later.

Complaint and subject access request in the same email? Run two clocks. The SAR is governed by new UK GDPR Article 12A (in force 5 February 2026): one month from the relevant time, extendable by two further months for complexity or number. The complaint acknowledgement is 30 days under section 164A(3). Answer both — and remember that a grievance combined with a request for copies is not, by itself, a data protection complaint. If you cannot tell, ask.

Penalties, and whether the ICO sees your complaint numbers

Getting this wrong is enforceable. Section 157(4A) of the DPA 2018, inserted on 19 June 2026 by Schedule 10 paragraph 18 of the DUAA, provides that an infringement of section 164A attracts the standard maximum amount: £8,700,000 or, in the case of an undertaking, 2% of total annual worldwide turnover if that is higher. That is the lower of the two tiers. The higher maximum — £17,500,000, or 4% of turnover for an undertaking — does not apply to the complaints duty.

A statutory maximum is not a going rate, and a fine is not the only tool — the ICO's toolkit also includes reprimands and enforcement notices. But the ceiling is real, and it is not scaled down for small organisations.

On the numbers: the ICO does not currently see them. Section 164B gives the Secretary of State a power to make regulations requiring controllers to notify the Commissioner of how many complaints they receive, subject to the negative resolution procedure. No such regulations have been made as at 31 July 2026, so there is no reporting obligation today. The ICO also says that if someone tells you they are complaining to the regulator, "there's no need for you to tell us".

The ICO does suggest you "may wish to record the number of data protection complaints you receive, as well as recurring themes and trends" — as good practice for spotting your own compliance problems, not as a return to a regulator.

Common questions

Do I need to put a data protection complaints form on my website?

No. Section 164A(2) of the DPA 2018 says you must facilitate complaints "by taking steps such as" providing a complaint form — it is an example, not a requirement. The ICO accepts a complaints email address, a phone route, an online portal, live chat with escalation to a human, or an in-person route if you have no online presence. What you cannot do is refuse a complaint because it did not arrive through your preferred channel.

Is the 30 days working days or calendar days?

Calendar days. The Act says "within the period of 30 days beginning when the complaint is received". The ICO's guidance counts the 30 days from the day after receipt, and says that if the final day lands on a weekend or public holiday you have until the next working day. Weekends and bank holidays do not stop the clock running.

I'm a sole trader with a handful of clients. Does this really apply to me?

Yes. The ICO's guidance states there are no exemptions to the requirement to have a process for handling data protection complaints. There is no turnover or headcount threshold in section 164A. This is a different test from the data protection fee — being exempt from the fee does not exempt you from the complaints duty.

Someone sent a subject access request and a complaint in the same email. Which deadline applies?

Both, separately. The SAR runs to one month under new UK GDPR Article 12A (extendable by two further months for complexity or number of requests). The complaint must be acknowledged within 30 days under section 164A(3), with the investigation and outcome to follow without undue delay. Do not let one deadline absorb the other. If it is unclear whether the person is complaining or only exercising a right, the ICO says to ask them to clarify.

Do I still have to acknowledge a complaint if I've already fixed the problem?

Not separately, if you have given them the outcome inside the 30 days. The ICO's guidance says: "You may be able to investigate the complaint and provide an outcome within 30 days. In these instances, you're not required to provide an acknowledgement and outcome separately." If the matter will take longer, acknowledge it within 30 days and keep the person updated on progress.

Has the right to complain to the ICO been taken away?

No. The UK GDPR was amended, not replaced. Article 77 of the UK GDPR was omitted on 19 June 2026, but the right was moved into section 165(2) of the Data Protection Act 2018, which now covers UK GDPR infringements as well as Parts 3 and 4. People can complain to the ICO at any point and do not have to come to you first — although the ICO says it will usually ask them to raise it with the organisation first.

Sources

This page summarises the following primary sources. Where they disagree with this summary, they take precedence.

Related guidance