Data protection solutions: Preparing for the Data (Use and Access) Act 202

New data protection complaints procedures and what they mean for businesses

From 19 June 2026, the Data (Use and Access) Act 2025 (‘DUAA’) introduces a new right for data subjects to complain to organisations about the handling of their personal data. Accompanying this right is the mandatory requirement for organisations to implement a data protection complaints procedure to allow that right to be exercised.

The new provisions effectively codify a complaints process alongside the existing and familiar data subject access request process. One of the main aims is to encourage the data subject to approach the company first, rather than approaching the Information Commissioner’s Office (ICO).

The most immediate implication for businesses is that handling complaints will become a more frontline compliance obligation. Organisations will no longer be able to rely on the informal handling of data concerns. They must operate in a structured manner that allows complaints to be received and acknowledged within 30 days, and investigated and responded to without undue delay. This will put pressure on operations, including the need for clear ownership of complaints, clearly defined escalation routes and a comprehensive record-keeping system. Suitable data protection solutions can help businesses manage these requirements consistently.

 

Another key commercial concern is that businesses face greater regulatory risk if complaints are not handled properly internally. Because data subjects will now generally be expected to deal with the business first, the quality of the organisation’s response may form part of the evidential basis for any subsequent ICO investigation.

This new regime also puts pressure on training and resources. Complaints may not always be formally labelled and may arise through various channels, including customer interactions and informal communications. It is essential that businesses ensure staff can recognise a data protection complaint in practice and escalate it appropriately. Not only does this emphasise the need for a clear central inbox and appropriate controls, but it will likely require additional training and data protection awareness to be integrated across the workforce, rather than remaining confined to legal and compliance departments.

From a more strategic perspective, DUAA frames complaints handling as an opportunity to learn. Effective internal processes and data protection solutions can enable early detection and resolution, reduce the involvement of the ICO and potentially improve data subjects’ trust in your business. On the other hand, inadequate data protection procedures risk increasing management overheads and causing reputational damage where issues escalate unnecessarily.

Overall, DUAA moves complaint handling from an ad hoc administrative task to a core, customer-facing element of data protection and governance. Most business websites and social media accounts will therefore require a refresh and/or clearer signposting to data protection complaints-handling policies and contact details.

If you’re unsure whether your organisation is ready for these changes, now is the time to act. Get in touch with our team to discuss how our data protection solutions can help you prepare.

Start your stress-free legal journey today.

Contact us

Stay up to date with In-House legal Solutions.

Sign up

Get Your Free Ethics Handbook

Sign up to receive our expert-led newsletter, packed with practical guidance, regulatory insights, and updates on in-house legal solutions—tailored to your business.