New legal obligations came into effect on 19 June 2026 for organisations to follow when handling data protection complaints under the Data (Use and Access) Act 2025. The changes place greater responsibility on employers to resolve concerns internally before they are escalated to the Information Commissioner’s Office (ICO).
For employers, this means having a clear and accessible process for receiving, investigating and responding to concerns about how personal information is collected, stored or used.
One of the most significant changes is that individuals do not need to use legal language or submit a formal complaint. A simple comment such as “I’m not comfortable with how my personal information has been used” may be enough to trigger the employer’s responsibilities.
Complaints can be raised through a variety of channels, including email, telephone, in person, online forms or even social media. If there is any uncertainty about whether someone is making a data protection complaint, the ICO recommends seeking clarification rather than dismissing the concern.
All organisations must now have a documented process for handling data protection complaints. As a minimum, employers are required to:
Failure to meet these requirements could itself amount to a breach of data protection legislation.
Previously, many concerns were raised directly with the ICO. The new framework encourages organisations to resolve issues themselves before regulatory involvement.
Having an effective complaints procedure can help employers identify weaknesses in their data handling practices, resolve issues more quickly, strengthen employee trust and reduce the likelihood of formal regulatory investigations.
The ICO also recommends ensuring staff understand how to recognise a data protection complaint, even when it is raised informally, and maintaining records of how complaints are handled and resolved.
We help our clients understand how changing legislation like this affects their business and impacts their training needs and internal processes. We recommend reviewing your existing complaints procedures to ensure its incorporates data protection concerns and is easily accessible to employees and other individuals. Privacy notices, internal policies and staff training should also be updated where necessary so that everyone understands how data protection complaints are managed.
You can read more about the recent changes on the ICO website here. You can also talk to our team about how the changes specifically impact your organisation and what action you should take.