top of page

19 June 2026: The data protection complaints deadline you need to know about

There's a new data protection obligation coming into force in ten days, and a surprising number of organisations aren't ready for it.


From 19 June 2026, the Data (Use and Access) Act 2025 (DUAA) introduces a statutory right for individuals to complain directly to controllers about alleged infringements of their rights under UK GDPR. That's you, if you process personal data as a controller — which includes the vast majority of UK businesses.


This post walks through exactly what's changing, what you need to do, and what it looks like in practice.


The legal mechanics

The new obligations flow from section 164A of the Data Protection Act 2018, inserted by the DUAA. They come into force via the Data (Use and Access) Act 2025 (Commencement No. 6) Regulations 2026.


At a high level, controllers must now:

  • Provide at least one accessible route through which individuals can submit a data protection complaint

  • Acknowledge complaints within 30 days of receipt

  • Take appropriate steps to investigate complaints without undue delay

  • Keep complainants informed of progress and outcome without undue delay

  • Update privacy notices to inform individuals of the right to complain to the controller (as well as to the ICO)

  • Maintain appropriate records of complaints and their resolution


There are also downstream changes to the transparency framework. Article 12(4) UK GDPR now requires controllers, where they decline to act on an individual's rights request (rectification, erasure, restriction), to inform the person of their right to complain both to the ICO and to you directly. Similarly, Articles 15(1)(ea) and (f) require this dual signposting in your DSAR responses.


These aren't minor tweaks. They require active updates to your privacy documentation and response templates.


What counts as a "data protection complaint"


The ICO's definition is deliberately broad. Complaints can arise from any alleged UK GDPR infringement — subject access requests, direct marketing, data retention, transparency obligations, cookies and tracking, security incidents, or reliance on an incorrect lawful basis.


Critically, a complaint doesn't have to be labelled as such. It doesn't have to come through your designated channel. It can be:


  • An email to a customer service inbox

  • A message on social media

  • A phone call to any member of staff

  • A letter to your offices


You must accept it regardless of how it arrives. That places a real premium on staff training — not just your DPO or privacy team, but frontline teams who are most likely to receive unstructured complaints in the wild.


Building your complaints process


The ICO guidance is clear that existing informal or fragmented approaches won't cut it. You need a documented process that covers:

Intake — at least one designated channel, clearly signposted. The ICO's examples include online forms, email, phone, portals, live chat, and in-person options. You don't need to build something new if you can adapt an existing complaints tool, as long as it meets the legal requirements.

Identity verification — if you have doubts about the complainant's identity, you can (and should) ask for proof of ID at the earliest opportunity, but only if you don't already have sufficient information.

Third-party representatives — someone acting on behalf of a data subject (family member, solicitor, advocacy service) must provide appropriate authority documentation before you investigate.

Acknowledgement — within 30 calendar days of receipt. This is a hard deadline.

Investigation — "appropriate steps" to look into the substance. You'll need to be able to demonstrate what you did and why, especially if the outcome is challenged.

Record-keeping — your system needs to capture receipt dates, investigation steps, decisions, and rationale. It also needs to distinguish complaints from DSARs and other rights requests, identify repeat or systemic issues, and support governance reporting.

Escalation — high-risk or complex matters need a clear escalation pathway, whether that's to your DPO, legal counsel, or senior management.


Processor and joint controller considerations


The statutory obligations sit with controllers — but controllers often depend on processors to investigate complaints relating to outsourced activities. Check your processor agreements now: do they require processors to assist with complaint investigations, route complaints received by the processor back to you, and provide you with the information you need to respond?


For joint controllers, the 30-day acknowledgement clock starts when any of the controllers receives the complaint. If your co-controller arrangement doesn't have a clear co-ordination mechanism, that needs to be fixed before 19 June.


Looking ahead: aggregate reporting

One provision worth flagging for future planning: section 164B of the DPA 2018 gives the Secretary of State power to require controllers to report aggregate complaints data to the ICO (number received, timeframes, outcomes). No such regime has been activated yet. But the provision is there, and complaints handling metrics may well become a formal part of the regulatory reporting landscape within the next few years.

If you build your tracking and record-keeping correctly now, you'll be ahead of the curve.


What you should do this week

Action

Owner

Deadline

Update privacy notice to include s.164A right

Legal / DPO

Before 19 June

Update DSAR response template (dual signposting)

Legal / DPO

Before 19 June

Designate and document complaints channel(s)

Ops / Legal

Before 19 June

Draft/finalise formal complaints procedure

Legal / Compliance

Before 19 June

Brief customer-facing and frontline teams

HR / DPO

Before 19 June

Review processor and joint controller agreements

Legal

Before 19 June

Confirm record-keeping system is adequate

Compliance / IT

Before 19 June

Need a hand?


If you're a UK business working through what this means in practice — whether you need a gap assessment, updated template language, or a complaints procedure drafted from scratch — Talking Fox offers rapid, cost-effective fractional GC support.

You don't need a full-time general counsel to get this right. You need the right expertise, at the right moment.



© Talking Fox Limited 2026. This content is for general information purposes only and does not constitute legal advice.

 
 
 

Comments


Talking Fox Limited is incorporated and registered in England and Wales with company ‎number 13394689 whose registered office is at 1 Mill End Cottages, Little Missenden HP7 ‎‎0RG ‎

Get Updates

Thank You!

bottom of page