A data-protection complaint should identify the processing problem and the outcome you want - not just say “GDPR breach”.
From 19 June 2026, DUAA provisions require organisations to provide a process for complaints from data subjects about data-protection compliance. The ICO has published guidance on the new complaints procedure.
A focused complaint helps the controller investigate and gives the ICO a clear record later. Separate each issue: access, accuracy, lawful basis, retention, security, sharing or handling of a rights request.
Key points
- Identify the personal data and processing activity.
- State the principle/right you believe is affected where you can.
- Explain practical consequences.
- Ask for a specific remedy: correction, re-search, restriction, deletion, explanation or process change.
Structure the complaint
Use a short chronology, numbered issues and a requested outcome for each. Attach only the evidence needed to understand the point. A complaint handler should be able to see what happened without reconstructing a year of correspondence.
Keep data rights separate
A SAR asks for access; rectification corrects; erasure deletes in qualifying cases; restriction limits use; objection challenges specified processing. One letter can exercise several rights, but label each requested action clearly.
Ask the organisation to answer the actual questions
If the complaint asks which system was searched and why a record was absent, a generic response saying “we take privacy seriously” is not an answer. Use a failure-to-answer schedule if necessary.
In practice
- Use the organisation’s DPO/privacy route where available but do not assume a request sent elsewhere is invalid.
- Keep an issue list and mark each response as answered/partial/unanswered.
- Preserve final response dates for ICO escalation.
What to do
A practical next-step plan
- Write a concise chronology.
- Number the data-protection issues.
- Attach supporting evidence.
- State the remedy for each.
- Audit the response.
- Escalate unresolved issues to ICO.
Common traps
Things that often confuse the issue
- Do not turn a data complaint into a general complaint about customer service unless the data issue is clear.
- Do not send every file you possess without an index.
- Do not accept an apology as resolution if the inaccurate data remains live.
Evidence worth keeping
Escalate with an evidence pack, not just the correspondence volume.
If the organisation does not resolve the complaint, the ICO can consider data-protection concerns. The ICO recommends giving the organisation an opportunity to complete its complaint process first, although a person can complain to the ICO at any point. A regulator complaint should identify the unresolved data-protection issue, relevant dates, the organisation’s final position and the documents that prove it.
Useful wording.
“Please record this as a data-protection complaint under the current statutory complaints framework. I have numbered the issues below. Please acknowledge it, investigate each issue, keep me informed and provide a reasoned outcome stating what corrective action will be taken.”
Do not let “customer service complaint” and “data rights request” get merged into one vague ticket.
Label the communication clearly as a data-protection complaint and separately identify any live statutory request such as rectification, restriction or subject access. A complaint about mishandling a SAR does not reset or replace the original SAR obligations. Likewise, a new rectification request may carry its own rights-response timetable.
Make the complaint easy to adjudicate.
Number each issue and connect it to a requested outcome. For example: inaccurate address → rectify and notify recipients; missing SAR records → conduct further searches and disclose; objection ignored → identify lawful basis and decide the objection; excessive ID request → explain necessity and proportionality.
| For each issue include | Example |
|---|---|
| What happened | “Your SAR response omitted the call recording referred to in note 14.” |
| Why it matters | “The recording contains my personal data and falls within the request.” |
| Evidence | “Your own note dated 3 May says ‘call saved’.” |
| Remedy | “Search the call-recording system and disclose it or explain the lawful basis for withholding it.” |
Since 19 June 2026, complaint handling itself has explicit statutory requirements.
The Data (Use and Access) Act 2025 introduced a legal complaints process for organisations handling personal data. They must give people a way to make a data-protection complaint, acknowledge receipt within 30 days, take appropriate steps to investigate without undue delay, keep the complainant informed and communicate an outcome without unjustifiable or excessive delay.
The 30 days is an acknowledgement deadline, not a licence to wait 30 days before investigating. ICO guidance says the obligation to investigate starts when the complaint is received.
Official sources
Check the rules behind this guide
- Handling data-protection complaints - ICO
- Make a data-protection complaint - ICO
- ICO: How to deal with data protection complaints ↗
- ICO: New data protection complaints law now in force ↗
These are official or primary sources for this topic. Rules, scheme terms and deadlines can change, so check the live source before relying on a formal time limit or procedure.