What businesses need to know about the Data (Use and Access) Act 2025 complaint-handling obligations
Terry Griffin, partner in our regulatory, compliance and licensing team, and Helen Russell, lead HR consultant and solicitor in our employment team, look at the new statutory duties for organisations handling data protection complaints.
What is changing?
The Data (Use and Access) Act 2025 introduces a more formal requirement for individuals to be able to complain directly to an organisation about the way their personal information has been handled.
Until now, many organisations have had complaints processes as a matter of good practice, customer service or broader regulatory compliance. The new regime makes this a specific data protection obligation for controllers.
The obligation is not limited to large organisations. Smaller businesses may also be affected if they act as controllers and handle personal data about individuals.
What counts as a data protection complaint?
A data protection complaint is likely to arise where an individual considers that an organisation has failed to comply with data protection law in the way it has handled their personal information.
This may include complaints about:
- How the organisation responded to a subject access request or another data rights request
- Whether personal data has been collected fairly and transparently
- How long personal data has been retained
- Whether information held about the individual is accurate
- Whether personal data has been shared appropriately
- The security measures used to protect personal data
- How an organisation has responded to a data breach
Individuals do not need to use legal terminology or refer to the UK GDPR, the Data Protection Act 2018 or the Data (Use and Access) Act 2025 for their complaint to be valid. A complaint may be made in ordinary language, and staff will need to be able to recognise when a service complaint or customer query also raises a data protection issue.
For example, a customer who says that a business has sent their account information to the wrong address may be raising a data protection complaint, even if they describe it as a customer service issue. An employee who says their personnel file contains inaccurate information may also be making a data protection complaint, even if the issue arises within a grievance or disciplinary process.
What must organisations do?
The Act and the Information Commissioner’s Office guidance set out a number of practical considerations for organisations handling data protection complaints.
Businesses will need to have a process that allows people to complain directly to them. This may be a dedicated complaint form, an email address, an online portal, a telephone route, live chat, or an adapted version of an existing complaints process.
Organisations will also need to:
- Acknowledge receipt of a complaint within 30 days
- Make appropriate enquiries into the subject matter of the complaint without undue delay
- Keep the complainant informed about progress
- Provide an outcome once the investigation has been completed
- Keep records of the complaint, the investigation, the outcome and any action taken
The duty to investigate starts when the complaint is received. Organisations should not treat the 30-day acknowledgement period as a reason to delay looking into the issue.
There is no single fixed deadline for completing every investigation. The time required will depend on the complexity of the complaint, the information involved, the number of people who need to be consulted and the potential harm to the individual. However, businesses should avoid rigid internal timescales that create unjustified delay where a complaint can be resolved sooner.
Why does this matter?
The new rules are intended to give individuals a clearer route to raise data protection concerns with the organisation before the matter is escalated to the Information Commissioner’s Office.
For businesses, this creates both a compliance obligation and an opportunity to resolve issues at an earlier stage. A clear process can reduce the risk of complaints being mishandled, overlooked or escalated unnecessarily.
It will also assist organisations in demonstrating accountability. If a complaint is later referred to the ICO, a business that can show it acknowledged the complaint, investigated it promptly and properly, communicated with the complainant and took appropriate action will be in a stronger position than one with incomplete records or an informal process.
This is particularly important where complaints reveal wider compliance issues, such as recurring problems with subject access requests, poor data retention practices, inadequate staff training or weaknesses in processor arrangements.
What should businesses do now?
Businesses should review whether their existing complaints and data protection procedures are sufficient.
Practical steps include:
- Checking whether the organisation is a controller, processor or joint controller for each main category of personal data it handles
- Reviewing privacy notices and website information to ensure individuals are told how to make a data protection complaint
- Deciding which teams will receive, triage and investigate complaints
- Training frontline staff to identify data protection complaints, even where the complaint is not labelled as such
- Putting a record-keeping system in place to capture receipt dates, acknowledgements, enquiries, updates, outcomes and remedial action
- Reviewing contracts with processors to ensure complaints are promptly passed to the controller and relevant information can be obtained
- Agreeing arrangements between joint controllers so that responsibility for handling complaints is clear
- Checking retention periods for complaint records so that evidence is kept for an appropriate period but not longer than necessary
Where organisations already operate complaints procedures under another regulatory framework, it may not be necessary to create a completely separate data protection complaints process. However, the existing process should be adapted so that data protection complaints are identified and handled in line with the new requirements.
Conclusion
The Data (Use and Access) Act 2025 moves data protection complaints onto a more formal footing. Organisations will need to ensure that individuals have a clear route to complain, that complaints are acknowledged promptly, and that investigations are carried out and recorded properly.
If you would like to understand what the Data (Use and Access) Act 2025 could mean for your business or would like support reviewing your data protection and complaints procedures, contact Harrison Drury’s regulatory, compliance and licensing team on 01772 258 321.