Analyzing critical legal trends and developments across data, cyber, AI and digital regulations from around the world and beyond borders

On 19 June 2026, Section 103 of the Data (Use and Access) Act 2025 (“DUAA“) came into force, inserting the new statutory “right to complain” into Section 164A and 164B of the Data Protection Act 2018.

This new right requires organisations to acknowledge complaints from individuals within 30 days and investigate and respond without undue delay. If the individual remains dissatisfied with the outcome, or the organisation fails to handle the complaint appropriately, the individual may complain to the ICO.

The ICO is therefore expecting a significant increase in escalated complaints from individuals and has recently updated its data protection complaints framework (the “Framework“) to set out: (i) the factors that the ICO will consider when assessing complaints from individuals; and (ii) the range of actions the ICO may take against an organisation in response to a complaint.

How does the ICO triage complaints?

The Framework states that the ICO has a duty to investigate a complaint “to the extent appropriate” and inform the complainant of the outcome. The Framework includes a list of factors that the ICO will use to assess whether it intends to investigate a complaint in more detail. The ICO is likely to look at a complaint where it:

  • causes, or is likely to cause, a high level of harm;
  • significantly affects (or is likely to significantly affect) anyone, including vulnerable people (e.g. children);
  • has, or is likely to have, a significant adverse impact on a substantial number of people;
  • would, if examined, materially improve data protection rights or practice;
  • involves data individuals have no practical choice but to provide;
  • aligns with the ICO’s strategic priorities or is in the public interest(such as a new or high-profile data protection issue); or
  • concerns an issue of which the ICO has previously been made aware and which has yet to be addressed.

The ICO is less likely to investigate a complaint in more detail where:

  • it already knows about the issue and it is being addressed;
  • the organisation is already taking adequate steps to respond to the complaint;
  • the ICO considers the organisation has complied with data protection law; or
  • the organisation has addressed the data protection issue and taken appropriate action, for example by fixing the problem and putting preventative measures in place.

The ICO has made clear that the list is not exhaustive and that it will review these criteria periodically.

What does the ICO do if it investigates a complaint in more detail?

The ICO may simply log and record the complaint with no further action or tell the complainant that the organisation appears to have complied with data protection law. However, there may be circumstances where the ICO decides to investigate the complaint in more detail before providing an outcome. If it does, it will: (i) assign a case officer to fairly and impartially weigh up the facts; (ii) ask the organisation or the complainant for more detail; and (iii) provide an outcome to the complainant.

At this stage, the ICO may decide to take no further action (and simply log the complaint) or it could:

  • recommend improvements to how the organisation handles personal data, such as reviewing policies, procedures or standards; or
  • take regulatory action where it is proportionate to do so, focusing on areas where the ICO can have the biggest impact. The ICO is clear that it will not take regulatory action for every individual complaint.

A dissatisfied complainant can request a review, and an organisation can also raise a complaint if it disagrees with the outcome.

What is the ICO doing with the complaints it receives?

The ICO records every complaint it receives about each organisation and monitors volumes. The Framework sets out that, if the ICO receives twelve complaints about an organisation in a one-month period, it will investigate in more detail, for example by looking for patterns in complaints about the same issues. The Framework also sets out that the ICO will share this information across teams within the ICO to support wider regulatory work.

The ICO is clear that reaching the threshold doesn’t automatically mean that it will take regulatory action against the organisation. For example, the ICO may not act if it believes that there is no evidence of a wider data protection issue within the organisation. However, the ICO will take further action when an organisation reaches the threshold if doing so is consistent with its regulatory approach and priorities.

The ICO states that organisations should not contact it to ask whether they have met the threshold. However, organisations can review the ICO’s published complaints data sets, which set out the number of complaints received by the ICO about that organisation and are published quarterly.

What should organisations be doing?

In light of the Framework, organisations should:

  • maintain a central log of data protection complaints to internally monitor volumes, identify recurring issues and ensure timely remediation. AI-generated complaints are expected to increase, so organisations should have a plan in place to address increased volumes;
  • prioritise complaints involving factors likely to attract greater ICO scrutiny (e.g. children);
  • document the investigation, outcome and any remedial or preventative action taken, so that the organisation can demonstrate to the ICO that the complaint has been handled appropriately;
  • periodically review the ICO’s published data to understand the volume of complaints made about the organisation; and
  • monitor changes to the Framework and the ICO’s strategic priorities, as the ICO has indicated that its assessment criteria will be reviewed periodically.
Author

Author

Vin leads our London Data Privacy practice and is also a member of our Global Privacy & Security Leadership team bringing his vast experience in this specialist area for over 22 years, advising clients from various data-rich sectors including retail, financial services/fin-tech, life sciences, healthcare, proptech and technology platforms.

Author

Author

Ben advises clients in a wide range of industry sectors, focusing in particular on data protection compliance, including healthcare, financial services, adtech, video games, consumer and business-to-business organisations. Ben regularly assists clients with global data protection compliance projects and assessments as well as specific data protection challenges such as international transfers and data security breaches. Ben is also regularly involved in drafting and negotiating data protection clauses in agreements for various clients in a wide range of industry sectors. Ben also regularly advises clients on electronic direct marketing and cookies.