The Information Commissioner’s Office (ICO) has issued a reminder that all organisations acting as data controllers will be subject to new statutory complaints-handling obligations from 19 June 2026 under the Data (Use and Access) Act 2025.

The new requirements will mandate organisations to maintain a formal and accessible data protection complaints procedure, including obligations to:

  • Provide individuals with a clear route to raise data protection complaints;
  • Acknowledge complaints within 30 days;
  • Investigate complaints without undue delay; and
  • Communicate complaint outcomes to complainants appropriately.

The ICO has confirmed these duties will apply to all organisations, including SMEs.

Organisations are advised to review and update existing privacy notices, internal escalation and governance arrangements, complaint recording mechanisms, and staff training programmes ahead of implementation. Evidence of compliance and audit trails relating to complaint handling are also likely to become increasingly important from an accountability perspective.

Contact your DPO for advice.

Source: ICO