Skip to main content
Category: Supervisory Authorities & Enforcement

Complaint-Handling Procedure

Also known as: Complaints Handling Procedure, Complaint Management Procedure, Complaints Process
Simply put

A complaint-handling procedure is a documented process an organisation uses to receive, acknowledge, assess, and respond to expressions of dissatisfaction about its products, services, staff, or the way it has managed a previous complaint. It typically sets out how quickly a complaint is acknowledged, who is responsible for handling it, and how the complainant is kept informed. Such procedures are commonly used across many sectors and are not, on the evidence provided here, tied to any specific data protection legal instrument.

Formal definition

A complaint-handling procedure is an internal framework governing how an organisation manages complaints, where a complaint is understood as an expression of dissatisfaction made to or about the organisation relating to its products, services, staff, or its handling of a prior complaint. Common features identified in good-practice guidance include a named point of contact, timely acknowledgement of the complaint (for example, within a defined number of working days of receipt), assignment of the complaint to a relevant person or team, clear communication with the complainant about the steps taken, and resolution within stated timeframes. Such procedures are frequently defined by scope (for example, applying to all service contracts between a provider and its clients) and are typically shaped by sector-specific guidance, regulatory expectations, or ombudsman standards rather than by a single legal source. Note: the evidence supplied does not address the relationship between general complaint-handling procedures and the rights of data subjects to lodge complaints under data protection law; that specific context should be verified against the applicable statutory text and regulator guidance and is out of scope for this definition.

Why it matters

A complaint-handling procedure is a core governance and accountability control. It gives an organisation a consistent, documented way to receive and respond to expressions of dissatisfaction about its products, services, staff, or the way it has managed a previous complaint. Without a defined process, complaints may be handled inconsistently, acknowledged late, or lost between teams, which can erode trust and expose the organisation to reputational and regulatory risk.

Good-practice guidance treats predictable, timely handling as central. For example, guidance from the Legal Ombudsman indicates that an effective complaints process should have a named point of contact and acknowledge a complaint within two working days of receipt. Clear timeframes and defined responsibilities help demonstrate that an organisation takes complaints seriously and manages them in an efficient manner, as reflected in sector guidance such as that used in insurance complaint procedures.

Because these procedures are typically shaped by sector-specific guidance, regulatory expectations, or ombudsman standards rather than by a single legal source, their exact requirements vary by context. Readers should note that the evidence here does not address how a general complaint-handling procedure relates to a data subject's right to lodge a complaint under data protection law; that specific relationship is out of scope for this definition and should be verified against the applicable statutory text and regulator guidance.

Who it's relevant to

Compliance and governance leads
Those responsible for accountability frameworks need a documented process for receiving, acknowledging, assessing, and responding to complaints. A clear procedure with defined responsibilities and timeframes supports consistent handling and helps demonstrate that complaints are managed efficiently, in line with applicable sector guidance and regulatory expectations.
Service providers and their client-facing teams
Providers that deliver services under contract often define their complaints procedure by scope, for example applying it to all contracts for the provision of services between the provider and its clients. A named point of contact and clear steps help staff route and resolve complaints consistently.
Staff who receive or handle complaints
Front-line and case-handling staff benefit from a procedure that specifies acknowledgement timeframes, who a complaint is assigned to, and how to keep the complainant informed. Guidance such as acknowledging a complaint within two working days of receipt gives staff concrete expectations to work to.
Data protection officers and privacy teams
Privacy professionals may interact with complaint-handling processes, but note that the evidence supporting this definition does not address the relationship between general complaint-handling procedures and data subjects' rights to lodge complaints under data protection law. That context is out of scope here and should be verified against the applicable statutory text and current regulator guidance.

Inside Complaint-Handling Procedure

Intake and Logging
A defined mechanism for receiving data subject complaints and internal grievances, typically capturing the complainant's identity (where provided), the nature of the concern, the date of receipt, and the personal data or processing activity at issue. A complaint register or log generally supports traceability and demonstrates accountability.
Identity Verification
A proportionate process to verify the complainant where the request relates to their own personal data, balancing the need to confirm identity against the risk of collecting excessive additional data. The rigour applied should generally be calibrated to the sensitivity of the data and the risk of unauthorised disclosure.
Triage and Categorisation
An assessment step that classifies the complaint, for example by whether it concerns an alleged breach of data subject rights, a security incident, unlawful processing, or a service matter. Categorisation typically informs escalation routing and applicable timescales.
Escalation and Responsibility Allocation
Clear allocation of ownership, which in many organisations involves the Data Protection Officer or an equivalent function where one is designated. Escalation paths should distinguish the organisation's role as controller or processor, since a processor generally forwards or refers certain complaints to the relevant controller.
Investigation and Assessment
A structured review of the facts, the relevant processing, and the applicable legal basis under Article 6 (and any additional Article 9 condition for special category data), producing a reasoned position on whether the complaint is well-founded, in whole or in part.
Response and Communication
Communication of the outcome to the complainant within a defined and reasonable timeframe, describing any remedial action taken and, where appropriate, the reasons for the position reached. The specific statutory timescales should be verified against the current text of the applicable law.
Signposting to the Supervisory Authority
Information advising the complainant of their ability to lodge a complaint with a supervisory authority and, where relevant, to pursue a judicial remedy. The competent authority may vary depending on the applicable regime, for example the EU GDPR versus the UK GDPR.
Record-Keeping and Review
Retention of records of complaints and their resolution to support accountability, together with periodic review to identify systemic issues, trends, or process improvements. Retention periods should be defined and proportionate.

Common questions

Answers to the questions practitioners most commonly ask about Complaint-Handling Procedure.

Does an organisation only need a complaint-handling procedure if it is a controller?
Not necessarily. While the obligation to facilitate the exercise of data subject rights and respond to requests falls primarily on the controller, processors typically also need internal procedures to recognise complaints or requests they receive and to route them promptly to the relevant controller, as required under their Article 28 processing arrangements. The precise allocation of responsibility should be assessed against the specific controller-processor relationship and the terms of the applicable data processing agreement.
Is a data subject required to complain to the organisation before going to a supervisory authority?
Generally no. A data subject typically retains the right to lodge a complaint with a supervisory authority regardless of whether they have first raised the matter with the organisation, and an internal complaint-handling procedure does not remove or condition that right. An effective internal procedure may resolve matters earlier and reduce escalation, but it should not be presented to individuals as a mandatory precondition. Positions can vary by member state implementing law, so verify against the applicable national rules.
How quickly should an organisation respond to a complaint received through its procedure?
Where a complaint also constitutes a data subject rights request, the applicable response timeframes for that request generally apply, which under the GDPR is typically without undue delay and within a defined period that may be extended in certain cases subject to conditions. For complaints that are not tied to a specific statutory right, organisations often set internal service standards. You should confirm the exact statutory periods and any extension conditions against the current official text.
Who within the organisation should own the complaint-handling procedure?
Ownership is typically assigned to a function accountable for data protection compliance, and where a Data Protection Officer has been designated, the DPO often has a role in monitoring compliance and acting as a contact point, subject to the DPO's independence. Day-to-day handling may sit with operational teams. The allocation should be documented and reflect the organisation's structure and accountability arrangements rather than a single fixed model.
What should a complaint-handling procedure document or record?
Procedures commonly provide for recording the nature of the complaint, the identity verification steps taken where relevant, the actions and decisions made, and the response provided, in a manner that supports the accountability principle. Records should be handled consistently with data minimisation and retention requirements. The specific records to keep should be assessed against the organisation's obligations and any applicable supervisory authority guidance.
How should a procedure handle a complaint that reveals a possible personal data breach?
The procedure should generally include a mechanism to escalate matters that may indicate a personal data breach to the relevant breach-assessment process, since breach notification obligations and timeframes operate separately from complaint handling. Treating the two processes as linked helps ensure that a complaint does not obscure a notifiable event. The assessment of whether an incident is a notifiable breach should follow the organisation's established breach procedure and applicable guidance.

Common misconceptions

A complaint-handling procedure is only needed to respond to individuals who contact the organisation directly.
Complaints may reach an organisation through multiple channels, including internal staff, third parties, or referral from a supervisory authority. A procedure typically needs to accommodate more than a single direct channel, and the organisation's obligations can differ depending on whether it is acting as controller or processor.
Every complaint must be resolved in the complainant's favour to be handled compliantly, or that acknowledging a complaint admits a breach.
A well-founded procedure assesses each complaint on its facts and may reasonably conclude that a complaint is not upheld. What generally matters is that the assessment is reasoned, documented, and communicated, not that the outcome always favours the complainant. Acknowledgement is a procedural step, not an admission of liability.
Handling the complaint internally removes the individual's ability to go to a regulator.
An internal procedure does not displace a data subject's ability to lodge a complaint with a supervisory authority or, where available, pursue other remedies. Procedures generally should signpost these avenues rather than present internal resolution as the only route.

Best practices

Maintain a complaint register that logs receipt, categorisation, ownership, key dates, and outcome, to support accountability and to surface recurring or systemic issues.
Define proportionate identity-verification steps that confirm the complainant without collecting excessive additional personal data, calibrated to the sensitivity and risk involved.
Establish clear escalation routing that reflects the organisation's role, ensuring that where the organisation acts as a processor, complaints are referred to the relevant controller as appropriate, and that the DPO or equivalent function is involved where designated.
Set and monitor reasonable internal response timescales, and verify any statutory deadlines against the current applicable text before publishing them in the procedure.
Signpost complainants to their ability to approach the competent supervisory authority and, where relevant, to seek judicial remedies, noting that the competent authority may differ between the EU GDPR and UK GDPR.
Review complaint records periodically to identify trends and feed lessons back into policies, training, and processing practices.