Skip to main content
Category: Supervisory Authorities & Enforcement

Complaint

Also known as: complaint to a supervisory authority, data subject complaint
Simply put

A complaint is a formal expression of dissatisfaction or objection that someone raises about how something has been handled. In a legal setting, it can also refer to the document that formally starts a court case. The available evidence draws mainly on general and US legal dictionary definitions rather than data protection law specifically.

Formal definition

In general usage, a complaint is a formal statement expressing grievance, objection, or dissatisfaction, or the reason or grounds for such objection. In US procedural law, as reflected in the cited legal sources, a complaint is the initial pleading that commences a case, typically setting out the jurisdictional basis for the court's authority and the claimant's cause of action. Note: the evidence provided consists of general-language and US-law dictionary definitions and does not include the GDPR's specific treatment of complaints; readers should verify the data protection meaning (for example, a data subject's right to lodge a complaint with a supervisory authority) against the current official text of the applicable regulation, as that specialized usage is not established by the sources here.

Why it matters

The term "complaint" carries two distinct meanings that matter in different contexts. In general usage, as reflected in the cited dictionary sources, a complaint is a formal expression of grievance, objection, or dissatisfaction. In US procedural law, as reflected in the cited legal sources, a complaint is the initial pleading that commences a court case, setting out the jurisdictional basis for the court's authority and the claimant's cause of action. Understanding which sense is in play affects how the term is read in any given document or process.

For readers working in data protection, an important caution applies: the evidence available here consists of general-language and US-law dictionary definitions and does not establish the meaning of "complaint" under the GDPR or other data protection frameworks. In that specialized context, the term is commonly used to describe a data subject's right to lodge a complaint with a supervisory authority, but that usage is not supported by the sources cited for this entry. Readers should verify the data protection meaning against the current official text of the applicable regulation and relevant regulatory guidance before relying on it.

Because the general and procedural senses can diverge significantly, and because the data protection meaning is not confirmed by the evidence here, treating one usage as universal risks misinterpretation. Where precision matters, identify the source and legal framework that governs the term in the specific document or proceeding at issue.

Who it's relevant to

Litigators and procedural counsel
For those working in US procedural contexts, the complaint is the pleading that commences a case, setting out the jurisdictional basis and the cause of action, as reflected in the cited legal sources. This procedural meaning is distinct from the general-language sense of a grievance.
Data protection officers and privacy counsel
Readers focused on data protection should treat this entry with caution: the sources here do not establish the GDPR meaning of a complaint, such as a data subject's right to lodge a complaint with a supervisory authority. That specialized usage should be verified against the current official text of the applicable regulation and relevant regulatory guidance.
General readers and drafters
For anyone interpreting the word in everyday or business documents, a complaint is a formal expression of dissatisfaction or objection, or the grounds for one, as described in the cited dictionary sources. Identifying the intended sense helps avoid conflating a general grievance with a formal legal pleading.

Inside Complaint

Data subject standing
A complaint is typically lodged by a data subject who considers that the processing of personal data relating to them infringes applicable data protection law. Under the GDPR framework this right is generally exercisable regardless of whether harm has occurred, though the precise conditions can be shaped by national implementing law.
Supervisory authority as recipient
A complaint is generally directed to a supervisory authority, which is the independent public body responsible for monitoring application of the Regulation. The data subject may in most cases choose the authority in the member state of their habitual residence, place of work, or place of the alleged infringement.
Subject matter of the alleged infringement
The substance of a complaint identifies the processing activity said to be unlawful and, where possible, the controller or processor involved. Distinguishing whether the respondent acts as controller or processor can affect responsibility, though this determination is subject to assessment of the actual roles.
Internal complaint to a controller
Separately from a regulatory complaint, individuals may raise concerns or objections directly with a controller, for example when exercising data subject rights. This internal route is distinct from lodging a complaint with a supervisory authority and does not generally replace it.
Handling and outcome expectations
A complaint typically triggers a handling process by the supervisory authority, which may inform the complainant of progress and outcome. The specific timeframes, escalation paths, and remedies available can vary between regulators and under national law.
Relationship to judicial remedies
Lodging a complaint with a supervisory authority is generally without prejudice to other administrative or judicial remedies that may be available to the data subject. The interaction between these routes can depend on national procedural rules.

Common questions

Answers to the questions practitioners most commonly ask about Complaint.

Do I need to prove harm or damage before I can lodge a complaint with a supervisory authority?
No. The right to lodge a complaint under the GDPR generally does not require the data subject to demonstrate that they have suffered material damage or distress. A data subject who considers that the processing of their personal data infringes the GDPR may lodge a complaint, and the supervisory authority's role is to handle and, where appropriate, investigate it. A separate right to compensation exists but follows different requirements, and thresholds for compensation are subject to interpretation and evolving case law.
Does filing a complaint with a regulator mean I have given up my right to go to court?
No. Lodging a complaint with a supervisory authority is generally without prejudice to other administrative or judicial remedies. A data subject typically retains the right to an effective judicial remedy, including against a controller or processor, and separately against a supervisory authority in certain circumstances. These routes can, in most cases, be pursued in parallel or in sequence, though the precise interaction can depend on national procedural law and should be verified against the applicable rules.
Which supervisory authority should a data subject lodge a complaint with?
A data subject may generally lodge a complaint with a supervisory authority, in particular in the member state of their habitual residence, place of work, or the place of the alleged infringement. Where cross-border processing is involved, the one-stop-shop mechanism may mean a lead supervisory authority coordinates the matter, but the complaint can typically still be raised with the local authority. The specific competent authority and any onward transfer of the complaint depend on the facts and the cooperation procedures between regulators.
How should an organisation handle a complaint routed to it by a supervisory authority?
An organisation acting as controller or processor should generally treat a regulator-referred complaint as a matter requiring prompt, documented engagement. This typically includes identifying the relevant processing, cooperating with the supervisory authority, and providing requested information within the timeframes set by that authority. The appropriate response depends on the role of the organisation, the nature of the alleged infringement, and applicable national procedure, so internal escalation and, where relevant, involvement of the data protection officer are advisable.
Should complaints be logged and tracked internally, and if so, what should be recorded?
Maintaining an internal record of complaints is generally regarded as good practice supporting accountability. Records typically capture the date received, the substance of the complaint, the processing activities and legal basis involved, actions taken, and the outcome. This documentation can assist in demonstrating how the organisation handled the matter to a supervisory authority. The precise contents and retention period should be determined in light of accountability obligations and applicable retention requirements.
Can a data subject complain first to the organisation before involving a supervisory authority?
In most cases, a data subject may raise concerns directly with the controller before, or instead of, approaching a supervisory authority, and many organisations operate an internal complaints channel. However, the availability of a direct complaint to the organisation does not remove or condition the data subject's right to lodge a complaint with a supervisory authority. Whether internal resolution is required or merely encouraged can depend on the context and any applicable guidance, which should be verified.

Common misconceptions

A complaint can only be made after the individual has suffered demonstrable harm.
The right to lodge a complaint is generally available where a data subject considers processing infringes the Regulation, and does not typically require proof of material damage, though national law may add procedural conditions.
A complaint must always be lodged with the supervisory authority in the country where the controller is established.
A data subject may generally choose among the authority of their habitual residence, place of work, or place of the alleged infringement. Where cross-border processing is involved, cooperation mechanisms between authorities may apply, so the reader should verify the applicable process.
Raising a concern directly with a controller is the same as filing a regulatory complaint.
An internal complaint or objection to a controller is distinct from lodging a complaint with a supervisory authority. Using one route does not, in most cases, remove the ability to use the other or to pursue judicial remedies.

Best practices

Confirm at the outset whether the individual is acting as a data subject and whether the matter concerns personal data within scope, since anonymous data and, generally, data of legal entities or deceased persons fall outside the core framework.
Identify whether the respondent is acting as a controller or a processor before assessing responsibility, as this determination is subject to analysis of the actual roles and influences how a complaint should be directed.
Advise complainants that they may generally select the supervisory authority of their habitual residence, place of work, or place of the alleged infringement, and check whether national implementing law adds procedural requirements.
Distinguish clearly between an internal complaint or objection made to a controller and a formal complaint to a supervisory authority, and document which route is being used.
Preserve records of the alleged processing, the identity of the parties involved, and relevant correspondence, so the complaint can be substantiated during the authority's handling process.
Verify current procedural timeframes, escalation options, and available remedies against the relevant supervisory authority's guidance, recognising that these can vary between regulators and under national law.