The UK New Complaints Requirement under the Data (Use and Access) Act 2025: What You Need to Know

The Data (Use and Access) Act (DUAA) has introduced new rules on Data Protection complaints, requiring Data controllers to establish a formal complaints-handling procedure by 19 June 2026.

📢 What is Changing?

Under the DUAA, Data subjects are entitled to lodge a complaint directly with the Data controller if they believe their personal Data has been mishandled. The DUAA formalises a statutory complaints mechanism at a controller level and requires controllers to operate a structured procedure for receiving and responding to complaints.

While Data subjects retain the right to complain to the ICO, the new framework strengthens the expectation that complaints will first be raised with the controller. If the matter is not addressed appropriately, it may then be escalated to the ICO. This effectively introduces an intermediary stage in the complaints process and reinforces the controller’s primary responsibility to investigate and resolve complaints in a structured and accountable manner.

📝 What must Data controllers do?

By 19 June 2026, Data controllers must:

• Have a Data Protection complaint-handling process in place.

• Facilitate the means for individuals to make complaints either electronically (such as a complaints form) or by other means.

• Acknowledge receipt of the complaint within 30 days of receiving it.

• Without undue delay take appropriate steps to respond to the complaint, including making enquiries into the subject matter of the complaint, and keeping the complainant updated on progress.

• Without undue delay inform the complainant about the outcome of the complaint.

• Demonstrate compliance with the accountability requirements under Article 5(2) of the UK GDPR.

💡 New ICO guidance on How to deal with Data Protection complaints

On 12 February 2026, the ICO published detailed guidance explaining how Data controllers are expected to meet the new statutory requirements.

Although the legal requirements take effect from 19 June 2026, the ICO encourages organisations to prepare now.

The guidance makes clear that there are no exemptions: every controller must have a process for handling Data Protection complaints.

Some of the key points from the guidance include:

1. What counts as a complaint?

Any expression of concern about how personal Data has been handled may amount to a Data Protection complaint. Controllers are responsible for recognising this.

2. Accessible complaint routes

Controllers must provide a clear and accessible way for individuals to complain. This may include electronic forms, email, telephone, post or other channels. Complaints must be accepted regardless of how they are submitted, including via social media.

3. Clear communication and transparency

Controllers must inform individuals of their right to complain in Privacy notices and, in certain circumstances, when responding to Data subject rights requests. Language must be clear and accessible.

4. Investigation and timeliness

Complaints must be acknowledged within 30 days and investigated without undue delay. Controllers must keep complainants informed of progress and provide a reasoned explanation of the outcome.

5. Record-keeping and accountability

Controllers should maintain clear records of complaints, investigations and outcomes. The ICO emphasises that organisations must be able to justify how each complaint was handled, particularly if it is escalated.

6. Staff training and governance

All staff should be trained to recognise a Data Protection complaint and know how to escalate it internally. Controllers should also ensure arrangements remain in place during staff absences or organisational closures.

The guidance adopts a “must, should, could” approach, distinguishing legal requirements from good practice. While some measures are not mandatory, following the ICO’s recommendations will place controllers in a stronger position if complaints are escalated.

Formalising your Data Protection complaints process is now a regulatory requirement rather than simply good practice. For Life Sciences and Healthcare organisations in particular, where sensitive Data and regulatory scrutiny are heightened, a robust and defensible complaints framework will be critical. At MDT, we have specialist expertise supporting Life Sciences and Healthcare organisations in navigating Data Protection developments.

Please contact us if you would like assistance reviewing or implementing your complaints procedures ahead of the June 2026 deadline.

Author: Elmira Mamedova

Prev post
Next post
Powered by MyData-TRUST

Want to subscribe to our newsletter ?

Name(Required)
Privacy(Required)