UK law now requires you to handle data protection complaints
Section 164A of the Data Protection Act 2018, added by the Data (Use and Access) Act 2025, applies from 19 June 2026.
In short
Placeholder 40 word summary: what the law requires, who it applies to, and the four duties every UK organisation has to meet when a person complains about how their personal data has been handled.
The four duties
Duty 1
Give people a way to complain
Placeholder: a clear route in, published where people can find it.
Duty 2
Acknowledge within 30 days
Placeholder: the acknowledgement clock and what it must say.
Duty 3
Investigate without undue delay
Placeholder: appropriate steps, proportionate to the complaint.
Duty 4
Tell them the outcome
Placeholder: what a written outcome should cover.
Guides
- Complaints procedure
How to write and publish your procedure
- Handle a complaint
Step by step from receipt to outcome
- Section 164A
What the section actually says
- DUAA requirements
What changed on 19 June 2026
- Complaint log
Records the ICO can ask to see
- Complaint form
What a compliant intake form needs
- Templates
Free downloads, no email required
- Complaint vs DSAR
Two different duties, two different clocks
Common questions
- Who has to follow the complaints duty?
- Placeholder answer covering which UK organisations are in scope.
- How long do we have to acknowledge a complaint?
- Placeholder answer covering the 30 day acknowledgement clock.
- What happens if we ignore a complaint?
- Placeholder answer covering ICO escalation and enforcement.
- Does this replace the ICO complaints route?
- Placeholder answer explaining people can still complain to the ICO.
This is general information, not legal advice.