Data (Use and Access) Act 2025 – Mandatory Complaint Procedure Requirement
- Robert Bell

- Jun 17
- 2 min read
Just when we all felt that we had finally got to grips with GDPR, data protection requirements have shifted again. The Data (Use and Access) Act 2025 introduces a series of updates to the UK’s privacy and data protection framework, and a range of significant reforms designed to support innovation and streamline data use.
Among the changes are new provisions around automated decision making, data sharing, and the powers of the Information Commissioner’s Office. While much of the attention has focused on measures to reduce the burden on firms, there is one significant requirement that means that firms will now have to have a dedicated data protection complaints process in place, by 19 June 2026. There are two key requirements:
1. Create, publish and use a dedicated data protection complaints process
The DUAA allows for individuals to make complaints to a firm that processes their data about the way the firm has handled their personal information. For example, if someone feels that a subject access request reply has not fully covered all of the information the firm holds about them, or if someone has been impacted by a data breach.
FCA regulated firms will be very familiar with the creation of complaints processes in line with DISP, but non-financial services firms may be relatively new to processes that need to be created in line with legislative requirements.
This is a mandatory requirement – firms must have a compliant data protection complaints process in place by 19 June 2026. This means that data subjects won’t now go straight to the ICO with their complaints, they must first raise their complaint to the firm in question.
The process should be easy to read and understand and set out how complaints can be submitted, how the investigation happens, the timescales for acknowledging and responding to complaints and how outcomes will be communicated to complainants.
2. Give people a way to complain to you
The ICO make it clear that the DUAA means that firms must give people a way to make data protection complaints directly to the firm. It doesn’t specify how this must be done, allowing some flexibility for business type and size. It does make clear that firms are “not required to set up a separate tool for receiving complaints, as long as you can still meet your obligations.” It suggests that firms could:
Provide a complaint form that people can submit either by email or post
Provide an email address for people to submit complaints to
Allow people to make complaints over the phone
Provide an online complaints portal
Have a live chat function with the option to escalate to a human if needed or
Give people a way to make complaints to you in person (e.g. if you don’t have an online presence).
For many firms, a ready-made complaints template can provide a useful starting point. Save time and reduce compliance risk: Download our template, which incorporates the key requirements of the Data (Use and Access) Act and reflects best practice.







Comments