Skip to main content
Complaints Handling Under the DUAA: Your 2026 Readiness ChecklistSupervisory Authorities & Enforcement
5 min readFor Data Protection Officers (DPOs)

Complaints Handling Under the DUAA: Your 2026 Readiness Checklist

Scope - What This Guide Covers

This guide focuses on the new requirement for UK controllers to establish formal data protection complaint handling processes under section 164A of the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025. This obligation begins on 19 June 2026 and applies to all organizations, regardless of size, sector, or processing volume.

You'll learn about the procedural requirements, integration strategies, and operational steps needed to comply. This isn't about creating a separate compliance function; it's about incorporating complaint handling into your existing data protection framework to demonstrate accountability and respect data subject rights.

Key Concepts and Definitions

Data protection complaint: A concern raised by a data subject regarding how you've processed their personal data. This is different from a DSAR (which requests access to data) or a personal data breach (a security incident). Complaints might question your lawful basis, retention period, or handling of previous rights requests.

Controller obligation: Under section 164A, you must provide a mechanism for receiving complaints and follow specific procedural steps. The responsibility lies with the controller, but processors support this role, similar to their obligations around other data subject rights.

Without undue delay: The DUAA uses this term for investigation and outcome communication. The ICO hasn't set a fixed timeframe beyond the 30-day acknowledgement window, but "without undue delay" means you can't indefinitely delay complaints. Document your investigation timeline and justify any delays.

Requirements Breakdown

1. Receipt Mechanism (Section 164A(2)(a))

You must offer data subjects a way to submit complaints directly. The ICO's guidance allows multiple channels:

  • Online forms or portals
  • Email addresses
  • Telephone lines
  • Postal submissions
  • In-person complaints
  • Live chat interfaces

You must accept complaints through any channel, even if it's not your designated route. If someone tweets a complaint or mentions it to a customer service representative, your obligations are triggered. Train your front-line staff to recognize and escalate data protection complaints regardless of how they arrive.

2. Acknowledgement Timeline (Section 164A(2)(b))

Acknowledge receipt within 30 days. This is a strict deadline. Your acknowledgement should confirm:

  • Receipt of the complaint
  • Treatment as a data protection complaint under section 164A
  • Next steps in your process
  • Expected timeline for investigation (if known)

3. Investigation and Communication (Section 164A(2)(c))

"Without undue delay, take appropriate steps to respond to complaints, including making appropriate enquiries, and keep people informed."

This involves:

Investigation: Verify the facts, review relevant processing activities, consult with business units that handle the data, and determine whether your processing complies with UK GDPR obligations.

Ongoing communication: Don't go silent. If your investigation takes three weeks, send an interim update. If you need additional information from the complainant, ask promptly. Document every touchpoint.

4. Outcome Notification (Section 164A(2)(d))

Inform the complainant of the outcome without undue delay. Your response must:

  • Explain your findings
  • Describe any remedial actions taken
  • Inform them of their right to complain to the ICO
  • Provide ICO contact details

Even if your processing is compliant, explain why. A dismissive "we've investigated and found no issues" doesn't meet the standard.

Implementation Guidance

Integrate with Existing Rights Management

You likely have workflows for DSARs, erasure requests, and rectification requests. Complaints handling should integrate into the same case management system. Use a shared ticketing platform, common SLA tracking, and unified record-keeping.

Key integration points:

Identity verification: Apply the same verification standards used for DSARs. If someone complains about marketing emails, ensure they're the data subject before discussing processing details.

Multi-controller scenarios: If you're a joint controller, your arrangement should specify who handles complaints about which processing activities. If you're working with processors, your contracts must require the processor to notify you of complaints within a defined timeframe (24-48 hours is reasonable).

Escalation triggers: Define when a complaint becomes a potential personal data breach, a reportable incident to the ICO, or a legal claim. Your complaints process should have clear handoff procedures to your incident response team or legal counsel.

Training Requirements

Your staff need to recognize complaints. A customer service agent who receives a call saying "I don't think you should have my address" must understand that's potentially a data protection complaint, not just a service query.

Training should cover:

  • How to identify data protection complaints versus other customer issues
  • Immediate acknowledgement language (even verbal: "I'm noting this as a data protection complaint and our team will contact you within 30 days")
  • Escalation procedures and internal contacts
  • Special considerations for children's complaints (age-appropriate language, parental authority verification)

Run scenario-based training. Use real examples from your processing activities: "A user emails saying we're still sending them newsletters after they unsubscribed. What do you do?"

Common Pitfalls

Treating complaints as DSARs: A complaint about your retention period isn't a request for data access. Don't default to your DSAR process, you need a distinct investigation and response.

Ignoring informal channels: Social media mentions, comments to sales staff, or remarks during customer service calls all count. If you only monitor your formal complaint form, you'll miss obligations.

Processor blind spots: If a processor receives a complaint about your processing, they must notify you. But that only happens if your contract requires it and they understand the requirement. Review your processor agreements now, don't wait until June 2026.

No trend analysis: The ICO expects you to review complaints periodically and identify patterns. If you're getting repeated complaints about unclear privacy notices or excessive data collection, that's a signal to improve your processing practices. Document these reviews, they demonstrate accountability under Article 5(2) of the UK GDPR.

Missing the 30-day acknowledgement: This is the only hard deadline in the statute. If you receive a complaint on 1 July, your acknowledgement must be sent by 31 July. Build calendar reminders into your case management system.

Quick Reference Table

Requirement Timeline Action Record
Accept complaint Immediate Receive via any channel; don't require specific format Date received, channel, complainant details
Acknowledge receipt Within 30 days Confirm receipt, outline process, set expectations Date acknowledged, method, next steps communicated
Investigate Without undue delay Verify facts, consult relevant teams, assess compliance Investigation steps, findings, delays justified
Provide updates Ongoing during investigation Keep complainant informed of progress Date of each update, content shared
Communicate outcome Without undue delay after investigation Explain findings, describe remedial actions, inform of ICO right Date notified, outcome, actions taken, ICO details provided
Record retention Duration appropriate to demonstrate compliance Maintain complaint log with all correspondence and actions Complaint reference, full timeline, resolution

Contractual requirement for processors: Notification of complaints within 24-48 hours; cooperation with investigation; provision of relevant processing records.

Privacy notice update required: Add section explaining right to complain directly to controller, outline of complaint process, and ICO contact information.

The 19 June 2026 deadline isn't far off, it's twelve months to build, test, and train on a new operational process. Start with your existing rights management infrastructure, extend it to cover complaints, and ensure every team member who touches personal data knows how to recognize and escalate a complaint. Your ability to handle complaints effectively won't just meet a statutory obligation, it'll surface processing issues before they become supervisory authority investigations.

You Might Also Like