From 19 June 2026, a significant change to UK data protection law has taken effect, placing a statutory duty on employers to facilitate and manage data protection complaints. This change, introduced by the Data (Use and Access) Act 2025, fundamentally alters how workplace data disputes must be handled.
Previously, employees could take a complaint directly to the Information Commissioner’s Office (ICO). The new law requires that individuals must first raise their concerns with their employer, giving organisations the primary responsibility for resolving data protection disputes internally. This obligation covers complaints about an employer’s handling of a Subject Access Request (SAR), a data breach, or the general use of an individual’s personal data.
To comply, employers must establish a clear and accessible process for receiving complaints. While the law does not mandate a specific method, the ICO suggests options such as a dedicated email address, an online form, or a complaints portal. Importantly, even if an employer encourages a particular channel, a complaint made through any other method—such as social media or directly to a staff member—must still be accepted and actioned.
Once a complaint is received, strict statutory timelines apply. The employer must formally acknowledge the complaint within 30 days of receipt. Following this, the employer is required to take appropriate steps to investigate the matter “without undue delay,” which the ICO interprets as meaning without unjustifiable or excessive delay. This includes making relevant enquiries, keeping the complainant informed of progress, and communicating the final outcome without unnecessary delay.
The new duty does not just end with having a policy; it requires active management. Employers should update their privacy notices to inform staff of their right to complain directly to the organisation. It is also considered good practice to train all staff so they can recognise a data protection complaint and know how to escalate it internally. Furthermore, detailed records of each complaint, including the dates of receipt and acknowledgement and the outcome, should be maintained to demonstrate compliance to the ICO. Failure to implement and follow these new statutory complaints process could result in regulatory scrutiny and enforcement action from the ICO.