Skip to main content
green back ground with gradient accents. The words "Your AI Agents Are Making Decisions. Can Your Security Team Explain Them?" And a "Download the Guide" button.
UK Data Complaints Regime: Five Mistakes You'll Make Before June 2026Data Privacy
5 min readFor GRC Leaders

UK Data Complaints Regime: Five Mistakes You'll Make Before June 2026

Why These Mistakes Keep Happening

The Data (Use and Access) Act 2025 introduces a controller-led complaints procedure for data protection issues. It seems straightforward: acknowledge within 30 days, investigate promptly, and inform the complainant of the outcome. Your team handles complaints already, right?

That's where many organizations will falter. The DUAA requirements intersect with customer service, legal obligations, and operational workflows. Your current complaint channels weren't built for these specific obligations. Your privacy team doesn't manage the inbox where complaints land. And with the 19 June 2026 deadline feeling distant, it's tempting to delay the necessary process redesign.

Here's where teams go wrong and how to fix it before you're scrambling next spring.

Mistake 1: Treating This as a Privacy Notice Update

Why it happens: You think adding a line to your privacy notice about the right to complain to the controller is enough. You update the template, send it for legal review, and consider it done.

The consequence: You've documented a right without the means to honor it. Complaints arriving through unmonitored channels (customer service emails, account deletion forms, social media) go unacknowledged past the 30-day window. The ICO doesn't care about your updated notice if you can't show that you processed complaints properly.

The fix: Map every channel where a data subject might express dissatisfaction about data processing. This includes customer service queues, account management systems, chatbots, and third-party platforms. Establish routing rules: how does a complaint via Twitter DM reach someone who understands DUAA obligations? Implement a triage mechanism to flag potential data protection complaints and route them to a trained team. Document and test this routing logic with representative scenarios before June.

Mistake 2: Building a Separate "DUAA Complaints Portal"

Why it happens: The requirement feels new, so you create a new tool. Your team researches platforms, debates features, and plans a lengthy procurement process.

The consequence: You've built a system that data subjects won't find or use. Complaints keep arriving through existing channels, and you're no better positioned to handle them. You're wasting budget and time on unnecessary infrastructure.

The fix: Use existing tools. Your current complaint systems, ticketing platforms, or a dedicated email can meet DUAA requirements. The legislation prescribes the process, not the form. Ensure you can acknowledge within 30 days, track investigation progress, and demonstrate timely resolution. Adapt your systems by adding fields for complaint type, acknowledgement dates, and outcome documentation. If using a CRM or service desk platform, create a "data protection complaint" category with automated templates and escalation rules. The ICO confirms that new tools aren't necessary.

Mistake 3: Assuming You Can Distinguish Complaints from Requests

Why it happens: You believe not all communications are "complaints" needing DUAA compliance. An employee grievance requesting personal data isn't a complaint. A deletion request in a customer service context isn't a complaint. You train your team to filter these out.

The consequence: Your staff become gatekeepers making judgment calls they're not qualified for. What about a Data Subject Access Request with criticism of retention practices? Or a deletion request mentioning data security concerns? Your team might miscategorize genuine complaints as "just a DSAR" or "just a service issue," failing to acknowledge them as complaints. The ICO's guidance is clear: clarify with the individual if there's uncertainty about their intent. By filtering proactively, you're creating compliance gaps.

The fix: Train your team to treat ambiguous communications as potential complaints. Implement an escalation protocol: if a message expresses dissatisfaction about data processing, security, or subject rights, flag it for review by a data protection expert. That person then clarifies intent with the individual. This approach is compliant, not inefficient. It's better to clarify ten borderline cases than miss one actual complaint and face ICO scrutiny.

Mistake 4: Defining "Without Undue Delay" as a Calendar Metric

Why it happens: Your team wants a concrete SLA. You decide "without undue delay" means 45 or 60 days, based on current workload.

The consequence: You've set a deadline that doesn't reflect the DUAA's risk-based approach. A complaint about a data breach affecting sensitive data needs faster action than one about email marketing preferences. Applying a blanket timeline means you're either over-investing in low-risk complaints or under-investing in high-risk ones. The ICO will assess whether your response was appropriate given the complexity, scale, and potential harm, not whether you met your self-imposed SLA.

The fix: Develop a triage framework considering the nature and severity of each complaint. High-risk complaints (involving security incidents, special category data, children's data, or potential large-scale harm) should trigger immediate investigation and frequent updates. Lower-risk complaints can follow a standard timeline, but document why that timeline is appropriate. Train your team to assess and document the factors influencing their response timeframe for each complaint. This creates an audit trail showing you applied judgment, not just a stopwatch.

Mistake 5: Treating Joint Controller Arrangements as Someone Else's Problem

Why it happens: You're a joint controller with another organization. Your agreement addresses data subject rights, so you assume complaint handling is covered.

The consequence: A complaint arrives, and both organizations assume the other is handling it. Or both respond independently, giving conflicting information. Or neither takes responsibility because the agreement doesn't clearly allocate duties. The DUAA requires updating joint controller arrangements to clarify complaint-handling responsibilities. Without this, you're both exposed.

The fix: Review every joint controller arrangement now. Add explicit provisions specifying which controller is responsible for acknowledging and investigating complaints, or how you'll coordinate if both are involved. Document the communication protocol: how will you notify each other when a complaint is received? Who maintains the complaint records? If processing personal data jointly with a partner, schedule a session before June 2026 to map out complaint scenarios and agree on handling protocols. Document these protocols in an addendum to your joint controller agreement.

Prevention Checklist

Before 19 June 2026, ensure you can answer "yes" to each of these:

  • We've mapped every channel where a data subject could submit a complaint about data processing.
  • We've established routing rules to ensure complaints reach a team trained on DUAA obligations.
  • Our privacy notice clearly explains how to complain to us (not just to the ICO).
  • We've adapted existing tools to track acknowledgement dates, investigation steps, and outcomes.
  • Our acknowledgement templates are ready and can be sent within 30 days.
  • We've trained front-line staff to recognize potential complaints and escalate ambiguous cases.
  • We've defined a triage framework that assesses complaint risk and determines appropriate response timelines.
  • We can generate records showing complaint receipt date, acknowledgement, investigation actions, and outcome.
  • We've reviewed and updated joint controller agreements to clarify complaint-handling responsibilities.
  • We've tested our complaint workflow with at least three representative scenarios.

Organizations that handle this transition smoothly won't be the ones with the fanciest complaint portals. They'll be the ones that recognize this as an operational integration challenge, not just a policy update. Start mapping your intake channels this quarter to avoid the June 2026 scramble.

Green background, the words "The Biggest AI Security Risk Isn’t the Model. It’s the Agent." A robot drawing. A button for "Get the Free Guide."

You Might Also Like