Skip to content
PeekWellThe Rulebook
Join now

Data protection complaint: no clear way to complain

At a glance

UK-08MediumDPA 2018 s. 164A (inserted by DUAA 2025 s. 103); UK GDPR Art. 13(2)(ca); DPA 2018 ss. 149(5A) and 157(4A)

Peeky reads your privacy, contact and help pages for a described way to complain about how you handle personal data, and checks that the route it names opens.

Last checked against the source:

I need to fix thisI need the rule

The rule

Section 164A was inserted into the Data Protection Act 2018 by section 103 of the Data (Use and Access) Act 2025. Subsection (1) gives a data subject the right to “make a complaint to the controller” if they consider that there is an infringement of the UK GDPR or Part 3 of the Act in connection with their personal data. Subsection (2) says the controller “must facilitate the making of complaints … by taking steps such as providing a complaint form which can be completed electronically and by other means.” Subsection (3) requires the controller to acknowledge receipt “within the period of 30 days beginning when the complaint is received.” Subsection (4) requires it, “without undue delay”, to take appropriate steps to respond and to inform the complainant of the outcome. Subsection (5) adds that those steps include enquiries “to the extent appropriate” and keeping the complainant informed of progress.

The duty falls on every controller. It has no size threshold and no sector carve-out, and the ICO’s guidance says there are no exemptions.

Section 103 came into force in full on 19 June 2026 (S.I. 2026/82, reg. 3). The regulations add a transitional rule: the acknowledgement and response duties in section 164A(3) and (4) apply only to a complaint that the controller receives on or after that date (reg. 7).

The rule has a second part that sits in the privacy notice. UK GDPR Article 13(2)(ca) now lists “the right to make a complaint to the controller under section 164A of the 2018 Act” among the items a controller gives people when it collects their data. The ICO says to tell people at collection, for example in the privacy notice, and when you answer a subject access request. UK-07 reads the notice itself. This check reads the route.

What the ICO says is the minimum matters here, because it is less than the check might suggest. The ICO’s guidance says that you must give people a way to complain, acknowledge within 30 days, respond and give the outcome. Writing a complaints procedure is listed as something you “could” do, with the suggestion that you publish it on your website or give it to people early. The guidance adds that an existing complaints form can be adapted, and that people can complain in any way they choose, so you must accept a complaint however it reaches you.

Enforcement runs through the Commissioner’s ordinary powers. Section 149(5A) adds a fifth type of failure, where a controller “has failed, or is failing, to comply with section 164A”, for which an enforcement notice may be given. Section 157(4A) sets the maximum penalty for an infringement of section 164A at the standard maximum amount, which section 157 puts at GBP 8.7 million or 2% of an undertaking’s total annual worldwide turnover, whichever is higher. The ICO also says that, in most cases, when someone complains to it about how you handled their information, it will ask them to raise the complaint with you first.

No ICO decision under section 164A has been found at the ICO’s own pages. The duty applies only to complaints received since 19 June 2026, so the record is still empty.

What PeekWell checks and how

UK-08 asks one question: does the site describe a way to complain about how it handles personal data, and does the route it names work? The scan answers it from the public pages, not from what the company says it does behind the scenes.

The scan reads the policy, contact and help pages it can reach from the site. A language model reads the text and reports whether a complaints process is described, such as a heading, a paragraph in the privacy notice or a page of its own. A deterministic step then checks that the route the text names works, such as a link that opens. If no description is found, the check records an absence. The model only reads and explains.

This is a check on what the pages say. The statute asks for a way to complain. It does not ask for a published procedure, and the ICO lists writing one as a good idea. So a finding means that no complaints route was described on the pages Peeky read. It does not mean the company has no way to receive a complaint, and the report says so.

The scan has limits, and the report says so. It sees the public pages it visited and nothing behind a sign-in. It does not submit forms, test passwords or open addresses nobody linked to. It cannot see whether a complaint is acknowledged in time, whether anyone reads the inbox, or how a complaint is investigated, because all of that happens after a person writes in. It does not decide what your policy means in law. A Passed means a complaints route was described and opened on the pages scanned. It does not say the site complies.

Why it matters for a company

This check is a different shape from most in the Rulebook. It is about what happens when a person writes in, and the first test of that is whether they can find where to write.

Two things make the route worth looking at. First, the duty is new and universal, so a company that has never handled a data complaint formally is in the same position as one that has. Second, the ICO’s guidance says it, or industry bodies, may ask to see your records of a complaint if one is made about you later, and it suggests keeping the date received, your acknowledgement, the outcome and any action taken. Complaints are the doorway to everything else. A complaint to the ICO can reach beyond the first complaint, so the way a company handles this first step can shape what follows.

The ICO’s published material is about what controllers must do, not about outcomes. What the statute gives is the structure: an enforcement notice route under section 149(5A) and a penalty ceiling under section 157(4A).

UK-09 covers the route for subject access requests and UK-07 covers the privacy notice.

Smaller companies and larger companies

The rule has no size threshold. The ICO says how you set up the route is up to you, so long as you can meet the duties.

In a small company the problem tends to arise by omission. The privacy notice is a template written before 2026, with the right to complain to the regulator and nothing else. There is a contact address on the site, but nobody has said it is also where data complaints go, and whoever reads that inbox may be on leave for weeks. The ICO says you must arrange cover for acknowledging complaints during staff absence. A small company can meet the duty with an adapted form or an email address and a note in its privacy notice.

In a larger company the route usually exists but is scattered: a customer complaints form, a data protection officer mailbox, a rights portal and a social media team can each receive a data complaint. Since people can complain through any channel, every one has to recognise one, log the date and pass it on. The site may describe one route while complaints arrive through three others.

Enforcement cases

Published decisions about other companies, listed for context. Each links to the authority's own page. They say nothing about any particular website.

The Officer, squinting at a file.

Larger companies

No decision is listed here yet.

Smaller companies

No enforcement decision under section 164A has been found at the ICO's own pages, and none for a smaller company, so none is listed. The duty has applied only to complaints received since 19 June 2026.

How to fix it

These steps follow the ICO’s own list of what a complaints route can include.

  1. Choose the route. The statute gives an electronic form plus other means as its example of the steps to take (“and by other means”). The ICO lists an email address, a phone line, a portal and live chat. The ICO says an existing complaints tool can be adapted to include data protection complaints.
  2. Say where it is. Add a short section to your privacy notice, headed with the word “complaint”, that names the route and tells people they can also complain to the ICO. Article 13(2)(ca) now asks for the right to complain to you to be stated, so check that a notice copied from an older template includes it.
  3. Write a short procedure and publish it. The ICO suggests covering the method for receiving complaints, what evidence and proof of identity you need, what authority you need if someone complains for another person, and that you acknowledge within 30 days, keep people informed and explain the outcome.
  4. Make the acknowledgement automatic where you can. The ICO says an automatic reply to an email or form can serve as the acknowledgement. Log the date received and the date acknowledged, since the ICO says a record helps show you met the 30 days.
  5. Brief everyone who might receive one. Support, sales and social media can all be first to see a complaint. Give them one line: log it, forward it to a named person, do not wait.
  6. Re-scan. Publish the page, link it from the footer and the privacy notice, and run a scan again. The finding should clear once the route is described and the link opens.
<section id="data-protection-complaints">
  <h2>Data protection complaints</h2>
  <p>If you think we have handled your personal data wrongly, tell us.
  Use <a href="/complaints/data-protection/">our complaint form</a>
  or email privacy@example.com. We will confirm we have received it
  within 30 days, look into it and tell you the outcome. You can also
  complain to the Information Commissioner's Office.</p>
</section>

The wording above is a starting point and not legal advice. Whether a particular procedure meets section 164A is a question for your legal adviser, and Peeky reports only what it sees.

Questions

Do I need a data protection complaints procedure?

You need a way for people to complain to you about how you handle their personal data, and a way to deal with what comes in. The ICO says there are no exemptions, so the duty applies to every organisation that decides how personal data is used, whatever its size. A written, published procedure is not itself a legal requirement. The ICO calls it something you could do, and a sensible one.

How long do I have to reply to a data protection complaint?

You have 30 days to confirm you received it. After that you must look into it and tell the person the outcome without undue delay, and keep them updated while you do. The ICO says the 30 days start the day after the complaint arrives, and the investigation starts when you receive it, not when the 30 days end.

Does a data protection complaint need a form?

No, but the law asks you to make complaining easy, with steps such as an electronic form plus other routes. The ICO lists an email address, a phone line, a portal and a live chat as options. People can also complain any way they like, and you must accept it however it reaches you.

What changed on 19 June 2026 for data protection complaints?

A new section 164A of the Data Protection Act 2018 came fully into force. It gives people a right to complain to the organisation that holds their data, and puts duties on that organisation to make it possible, acknowledge it and respond. It applies to complaints received on or after that date.

How does Peeky check for a complaints route?

Peeky reads your privacy, contact and help pages for a described way to complain, then checks that the link it names opens. It never sends a complaint and never signs in. How a scan works has the full path.

Filed with

The rule

Data Protection Act 2018, s. 164A (complaints by data subjects to controllers), inserted by the Data (Use and Access) Act 2025, s. 103, in force 19 June 2026

Read the rule (Data Protection Act 2018, s. 164A (complaints by data subjects to controllers), inserted by the Data (Use and Access) Act 2025, s. 103, in force 19 June 2026)

Your site

Is your website affected? Join now to find out.

Join now

Sources

  1. Data (Use and Access) Act 2025, s. 103 (complaints by data subjects), legislation.gov.uk
  2. Data Protection Act 2018, s. 164A, legislation.gov.uk, as in force from 19 June 2026
  3. Data Protection Act 2018, s. 149 (enforcement notices), legislation.gov.uk
  4. Data Protection Act 2018, s. 157 (maximum amount of penalty), legislation.gov.uk
  5. UK GDPR, Art. 13, legislation.gov.uk
  6. The Data (Use and Access) Act 2025 (Commencement No. 6 and Transitional and Saving Provisions) Regulations 2026 (S.I. 2026/82), regs. 3 and 7
  7. ICO, How to deal with data protection complaints (published 12 February 2026, updated 8 May 2026)
  8. ICO, How do we prepare to handle data protection complaints?
  9. ICO, What do we do when we receive a complaint?
  10. ICO, How does the ICO deal with complaints?
  11. ICO, Statement on the commencement of the Data (Use and Access) Act, 5 February 2026

Last checked against the source:

For information only. Not legal advice.