If the answer is "not sure", you are not alone. On 19 June 2026, a quietly significant change to UK data protection law came into force under the Data (Use and Access) Act 2025 (DUAA): individuals now have a specific statutory right to complain directly to the organisations that process their personal data, and those organisations must have a formal complaints process in place to receive them.
This is not an entirely new concept. Controllers have always been expected to handle data subject queries and concerns. What has changed is that the obligation is now express, enforceable and, crucially, structured. Organisations must acknowledge a complaint within 30 days of receipt (a period that runs through weekends and bank holidays), and must then respond "without undue delay", making appropriate enquiries, keeping the complainant updated, and telling them the outcome. The ICO has been clear that it expects organisations to have an accessible complaints process, including a visible link from their privacy notice, a usable complaint form (electronic or written), and clear information about timescales and handling procedures. Individuals do not have to use a designated channel either: the ICO expects organisations to recognise and handle a complaint made by any route, including by phone, in person, or through social media, not only through the official form.
The sectors most likely to feel early scrutiny are those the ICO has already flagged as high volume for data protection complaints: healthcare, financial services, technology and retail. But no sector is exempt. If you are a controller, you are caught.
What should you do?
Review your privacy notice now and check whether it signposts a complaints route to your organisation as well as to the ICO. If not, add one, and make sure the same signposting also appears in your subject access request responses . . Consider whether the right individual or team in your business handles complaints, is trained to recognise one however it arrives, and is empowered to resolve them. Keep a record of every complaint received, the steps taken to investigate it, and its outcome, so you can demonstrate compliance if the ICO comes knocking.
The wider picture matters too. The DUAA introduced a raft of changes to UK GDPR and the Data Protection Act 2018, being phased in throughout 2026. The complaints process obligation is one of the more concrete and time-bound. It will not be the last.
If you have any questions about data protection compliance or the changes introduced by the DUAA, please contact any member of the Edwin Coe Intellectual Property team.

/Passle/68ee0ab18676b883b68d6972/SearchServiceImages/2026-07-31-10-09-17-170-6a6c744de32fbef63cacc7e0.jpg)
/Passle/68ee0ab18676b883b68d6972/SearchServiceImages/2026-07-29-09-09-21-601-6a69c3413c54dccaed69fc5a.jpg)
/Passle/68ee0ab18676b883b68d6972/SearchServiceImages/2026-07-29-10-44-58-369-6a69d9aad6577ad78941c7df.jpg)
/Passle/68ee0ab18676b883b68d6972/SearchServiceImages/2026-07-28-15-09-08-603-6a68c6142f7f4abc6244fd06.jpg)