Businesses across the UK have just under one month to put a data protection complaints process in place before new legal requirements come into force.
From 19 June 2026, all organisations will be legally required to handle data protection complaints under the Data (Use and Access) Act 2025. The Information Commissioner’s Office (ICO) is urging businesses, particularly small and medium-sized enterprises, to read its guidance and take the steps needed to comply.
The new rules mean organisations must give people a clear way to raise a data protection complaint, acknowledge complaints within 30 days of receipt, take appropriate steps to investigate without undue delay, keep people informed, and tell complainants the outcome.
The ICO said its guidance, published in February following a public consultation that received more than 85 responses, sets out what organisations must, should and could do to comply. The guidance also includes practical tips for each stage of the complaints process.
Emily Keaney, Deputy Commissioner, Regulatory Policy at the ICO, said: “Today marks one month to go, and I want to be clear: there is still plenty of time to act, and the ICO is here to support you.
“We know that smaller organisations are less likely to have formal complaints processes in place, and that is exactly why we have designed this guidance with you in mind: with practical steps and real examples that you’ll have encountered on a day-to-day basis.
“A data protection complaint can come from any customer at any time. Having a clear process means you can respond quickly, resolve issues fairly and protect the trust your customers place in you.
“We are not here to catch businesses out, we are here to help you get ready. With 19 June fast approaching, now is the time to read the guidance and make sure you’re prepared.”
New Legal Duties
The ICO said it is supporting organisations to meet the new requirements, adding that resolving complaints quickly and fairly can benefit businesses as well as customers.
Recommended reading
- New Scottish Centre of Excellence For Digital Trust Launches
- How Important Are Digital Trust Frameworks to Firms?
- DIGIT Expo 2025 | Is Digital Consumer Trust on The Brink?
According to the regulator, effective complaints handling can prevent issues from escalating, protect customer trust, and reduce the likelihood of regulatory involvement.
The sectors where data protection complaints are most common include healthcare, financial services, technology, and retail. The ICO said its message to businesses is that having a clear complaints process is not just a legal requirement, but also good for business.
Businesses are being encouraged to read the guidance and take action ahead of the 19 June deadline, with tailored advice also available for small and medium-sized businesses.





