Site navigation

Businesses Given One Month to Meet New ICO Data Protection Complaints Rules

Graham Turner

,

Microsoft 365 security
The ICO is urging organisations, particularly SMEs, to prepare now under the Data (Use and Access) Act.

Businesses across the UK have just under one month to put a data protection complaints process in place before new legal requirements come into force.

From 19 June 2026, all organisations will be legally required to handle data protection complaints under the Data (Use and Access) Act 2025. The Information Commissioner’s Office (ICO) is urging businesses, particularly small and medium-sized enterprises, to read its guidance and take the steps needed to comply.

The new rules mean organisations must give people a clear way to raise a data protection complaint, acknowledge complaints within 30 days of receipt, take appropriate steps to investigate without undue delay, keep people informed, and tell complainants the outcome.

The ICO said its guidance, published in February following a public consultation that received more than 85 responses, sets out what organisations must, should and could do to comply. The guidance also includes practical tips for each stage of the complaints process.

Emily Keaney, Deputy Commissioner, Regulatory Policy at the ICO, said: “Today marks one month to go, and I want to be clear: there is still plenty of time to act, and the ICO is here to support you.

“We know that smaller organisations are less likely to have formal complaints processes in place, and that is exactly why we have designed this guidance with you in mind: with practical steps and real examples that you’ll have encountered on a day-to-day basis.

“A data protection complaint can come from any customer at any time. Having a clear process means you can respond quickly, resolve issues fairly and protect the trust your customers place in you.

“We are not here to catch businesses out, we are here to help you get ready. With 19 June fast approaching, now is the time to read the guidance and make sure you’re prepared.”

New Legal Duties

The ICO said it is supporting organisations to meet the new requirements, adding that resolving complaints quickly and fairly can benefit businesses as well as customers.


Recommended reading


According to the regulator, effective complaints handling can prevent issues from escalating, protect customer trust, and reduce the likelihood of regulatory involvement.

The sectors where data protection complaints are most common include healthcare, financial services, technology, and retail. The ICO said its message to businesses is that having a clear complaints process is not just a legal requirement, but also good for business.

Businesses are being encouraged to read the guidance and take action ahead of the 19 June deadline, with tailored advice also available for small and medium-sized businesses.

Graham Turner

Sub Editor

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data