The ICO can assess data-protection handling and regulatory compliance, but it is not a general compensation ombudsman.
The Information Commissioner’s Office is the UK regulator for data protection and information rights. You can complain about matters such as mishandled SARs, inaccurate data, unlawful processing, security failures and other data-protection concerns.
The ICO will usually expect you to have raised the issue with the organisation first. The strongest complaint is focused, evidenced and clear about what remains unresolved.
Key points
- Provide the original request/complaint and the organisation’s response.
- Identify the specific unresolved data-protection issues.
- The ICO can assess compliance and use regulatory powers, but it does not simply award consumer compensation in the way an ombudsman may.
- Court remedies remain separate.
What to send
Send a short chronology, the key correspondence, a schedule of unresolved issues and supporting documents. Avoid expecting an ICO case officer to find the issue inside hundreds of unindexed pages.
What the ICO may consider
The ICO can consider whether the controller complied with rights requests, principles and other requirements. Its regulatory response can range from advice and casework outcomes to formal enforcement depending on seriousness and wider factors.
What the ICO does not decide
The ICO does not determine every contractual dispute or whether a debt is legally owed. If the complaint is fundamentally about service, credit affordability or contract formation, another body may be needed even if data accuracy is also involved.
In practice
- Frame the ICO complaint around information-rights law.
- Show exactly what you asked the controller to fix and how it responded.
- Run sector complaint routes in parallel where they address a different issue.
What to do
A practical next-step plan
- Complete the organisation’s complaint route.
- Create an unresolved-issues summary.
- Attach the key evidence.
- Submit the ICO complaint within the regulator’s recommended timeframe.
- Keep the ICO reference and outcome with the case file.
Common traps
Things that often confuse the issue
- Do not ask the ICO to decide a pure breach-of-contract dispute.
- Do not send an undifferentiated document dump.
- Do not assume an ICO finding automatically produces compensation.
Evidence worth keeping
Know what to do with the outcome.
If the ICO gives an outcome you disagree with, read the route and deadline stated in the correspondence. The ICO currently says that a complaint about its data-protection decision making should normally be raised for case review within three months. Separately, individuals may be able to enforce data-protection rights through the courts; legal advice is sensible before litigating.
Useful framing.
“The unresolved issue is [x]. I asked the controller to [y] on [date]. It refused/failed to address the point because [brief reason]. The attached documents A–C show [facts]. I ask the ICO to consider whether the controller complied with [right/principle].”
Build a small evidence pack around the alleged breach.
- A short chronology with the key dates.
- The original rights request or complaint.
- The organisation’s acknowledgement and substantive response.
- The exact personal data/document showing the problem.
- Any evidence contradicting the organisation’s factual position.
- A short statement of what remains unresolved and what outcome you sought.
Avoid burying the central issue in hundreds of pages without explanation. Refer to attachments by name/date and map them to numbered complaint points.
Give the organisation a focused chance to resolve the data issue first.
Current ICO public guidance recommends first making a data-protection complaint to the organisation and allowing it the opportunity to resolve the matter. Since 19 June 2026 the organisation has express legal duties around receiving, acknowledging, investigating and concluding data-protection complaints. You can approach the ICO at any point, but a completed internal record often makes the unresolved issue much clearer.
The ICO is a regulator, not a general compensation tribunal.
The ICO can consider whether an organisation appears to have complied with data-protection law and can use regulatory powers where appropriate. Its complaint process is not the same as a civil damages claim and it does not simply calculate compensation for distress or inconvenience. If your goal includes compensation, correction of a contractual outcome or another non-data remedy, identify the separate route as well.
Official sources
Check the rules behind this guide
- Make a data-protection complaint - ICO
- Handling data-protection complaints - ICO
- ICO: Make a complaint ↗
- ICO: How organisations deal with data protection complaints ↗
These are official or primary sources for this topic. Rules, scheme terms and deadlines can change, so check the live source before relying on a formal time limit or procedure.