The 19 June 2026 Deadline: Why Every Organisation Needs a Data Protection Complaints Process
5th May 2026
Most of the Data (Use and Access) Act 2025 (DUAA) softened obligations for organisations. However, it did enhance the rights of individuals by adding a new Right to Complain. From 19 June 2026, every controller in the UK, from the smallest charity to the largest multinational, must have a formal process for handling data protection complaints.
Section 103 of the DUAA inserts a new Section 164A into the Data Protection Act 2018. The Information Commissioner’s Office (ICO) published its final guidance on 12 February 2026, and there are no exemptions. If you’re a controller, you need a process, and you need it before 19 June.
What the law requires
Under Section 164A, controllers must:
- Provide a means of making a data protection complaint (email, web form, postal address, or similar).
- Acknowledge receipt within 30 days.
- Investigate without undue delay, and keep the complainant informed of progress.
- Inform them of the outcome.
- Tell them about their right to escalate to the ICO if they’re not satisfied.
Put simply, you need a way for people to complain, a clock that starts when they do, and a paper trail showing how you handled it.
What counts as a ‘data protection complaint’
The ICO’s guidance draws a useful distinction. A data protection complaint is one where the individual believes their personal data has been handled in a way that infringes UK data protection law. That’s the threshold. It isn’t the same as a customer service complaint that happens to mention data, and it isn’t the same as an HR grievance with a Subject Access Request bolted on.
A few examples to make this concrete:
- A customer says you sent them a marketing email after they unsubscribed. That’s a data protection complaint.
- A former employee says their personal file was kept too long after they left. That’s a data protection complaint.
- A data subject complains that you have not handled their objection to processing or subject access request correctly. That’s a data protection complaint.
- A customer says your website is slow. That isn’t.
Many of these patterns come up again and again. We covered the most frequent technical breaches made by controllers in our piece on common GDPR mistakes small businesses make.
What ‘good’ looks like
The ICO’s guidance sets out what organisations must, should and could do. The ‘should’ list, where the ICO will look hardest if a complaint is escalated, includes:
- The process is easy to find. Signposting in your privacy notice is the most obvious place.
- Multiple intake channels are offered: email at minimum, ideally an online form, postal address and phone too.
- Frontline staff are trained to recognise complaints. The receptionist who takes the call needs to know what to do with it.
- Complaints are logged centrally, with documented investigations, clear ownership and timelines.
- Internal escalation routes exist, so a complex complaint reaches a senior decision-maker quickly.
What to do before 19 June 2026
The ICO does not require a brand-new system; you can usually plug data protection complaints into your existing customer or HR complaints process:
- Write or adapt a complaints handling policy covering the 30-day acknowledgement, the right to escalate, and the right wording.
- Update your privacy notice to explain how individuals can complain to you and to the ICO.
- Refresh your DSAR response templates so the right to complain is mentioned when data is provided.
- Set up the intake mechanism. A dedicated inbox (privacy@ or dataprotection@) with auto-acknowledgement is enough for most SMEs, or a simple online form in MS or Google Forms which sends an alert when submitted.
- Train your frontline. A short awareness session and a one-page reference sheet usually does the trick.
- Run a ‘mystery complaint’ to test the process. Better to find the gaps in May than after a real complaint lands in July.
Why this matters more than it looks
The ICO has been candid that, once the duty is in force, the absence of a process will be evidence in itself of poor accountability. It sits alongside other accountability foundations like a current Record of Processing Activities as one of the first things the ICO will ask to see. There’s a commercial dimension too: a working complaints process turns dissatisfied customers into early-warning intelligence. Most data protection issues, caught early and dealt with well, never become regulatory problems. Caught late or ignored, they grow.
How Griffin House Consultancy Can Help
With the 19 June deadline approaching fast, this is the time to take stock. We help organisations write or refresh their data protection complaints policies, update privacy notices and DSAR templates, train frontline staff, and stress-test the new process before it goes live. Get in touch with us at Griffin House Consultancy, or call us on 01673 885533, and we’ll help you be ready well before 19 June.
Author: Mike Martin LLM
Mike is an information rights law specialist and one of the founding Directors of the Griffin House Consultancy, a leading specialist data protection and information governance consultancy firm that supports hundreds of clients annually with their training, consulting and auditing requirements.
Sources
ICO, How to deal with data protection complaints (final guidance, 12 February 2026)
ICO, Data (Use and Access) Act 2025
Legislation.gov.uk, Data (Use and Access) Act 2025, Section 103