How to publish an accessible data protection complaints procedure
A complaints procedure should be easy to find, understand and use. Accessibility is part of making the complaints route work in practice, not a decorative step after the document is approved.
Publish a short public procedure
The controlled internal procedure and the public-facing page have different jobs. The public version should explain how to complain, what information is helpful, what will happen next and how the person can ask for another format or communication adjustment.
Place it under a clear page title such as “Data protection complaints”. Link to it from the privacy notice, contact page and any relevant support or complaints pages. Do not hide it behind an account or a general-purpose chatbot.
Offer reasonable ways to complain
A form can help collect useful details, but it should not be the only route. Provide a monitored email address and any other channels the organisation can operate reliably. Staff who receive a complaint elsewhere should know how to preserve the first receipt date and route it internally.
Ask for information that helps identify and investigate the complaint. Make optional fields visibly optional, and do not make the person repeat information already held by the organisation merely to start the process.
Use a readable page structure
Use a descriptive page title, one clear main heading and short sections in a logical order. Headings should describe the user’s task rather than internal department names. Use ordinary sentences, informative link text and lists only where they make scanning easier.
- How to make a complaint
- Information that will help us investigate
- What happens after we receive it
- When we will acknowledge it
- How we will keep you informed
- Alternative formats and communication support
- How to contact the ICO
Build an accessible form
Every form control should have a visible label. Group related options with a fieldset and legend. Give specific error messages, associate them with the relevant field and move focus to the first invalid field after submission.
Do not rely on colour alone. Keep keyboard focus visible, support browser zoom and reflow at narrow widths, and test the form without a mouse. A downloadable PDF can supplement the page, but it should not be the only usable version.
Ask about communication needs
Include an optional way for the person to tell the organisation about an alternative format, interpreter, communication preference or reasonable adjustment. Route the request to someone who can act on it, rather than collecting it without an operating process.
Equality Act duties depend on the circumstances and may require specific review. The procedure should identify the internal escalation route instead of trying to make an automated decision about the adjustment.
Test and maintain the published route
Test the page with keyboard-only navigation, common screen-reader workflows, 200 and 400 per cent zoom and a 320 CSS-pixel viewport. Confirm that every contact channel reaches the correct team and that automated receipts do not state an inaccurate deadline.
Record the owner, approval date, version, next review date and source-review date. Re-test the route after content, form, email or case-system changes. An accessible procedure is an operating service, not only a document.
Material reviewed for this guide
- How to deal with data protection complaintsInformation Commissioner’s Office
- How to prepare to handle data protection complaintsInformation Commissioner’s Office
- What to do when you receive a complaintInformation Commissioner’s Office
- Equality Act 2010, section 20legislation.gov.uk
This guide is general operational information, not legal advice. Check the official material and obtain appropriate advice for circumstances outside the stated scope.