UK data protection complaints procedure requirements

A useful complaints procedure must do more than publish an email address. It should help people complain, give staff a clear handling sequence and leave a reliable record of what the organisation did.

By Business Compliance Tools7 minute readReviewed against official sources on

The core obligation

For the ordinary UK controller route supported by our complaints tool, the organisation should facilitate the making of a complaint, acknowledge receipt within 30 days, take appropriate steps to respond and tell the complainant about progress and the outcome without undue delay.

The organisation should also keep a record of the complaint and the action taken. That record is operational evidence. It should be usable by the person handling the case, by a reviewer and, where necessary, by the organisation’s regulator or adviser.

What the published procedure should explain

The public procedure should tell a person how to make a complaint and what happens next. It should use clear language, provide workable contact routes and avoid making a particular form compulsory.

It should also explain that a complaint may contain a separate data rights request. The organisation should identify and route that request without treating the complaints process as a substitute for the relevant rights-request deadline.

  • How to contact the organisation and where to send supporting information
  • What information will help the organisation understand the complaint
  • When receipt will be acknowledged and how progress will be communicated
  • How the investigation, outcome and any corrective action will be recorded
  • How to ask for an alternative format or communication adjustment
  • How to raise concerns with the ICO after the organisation has had a chance to respond

What staff need behind the public procedure

A short public page is not an internal operating procedure. Staff need a controlled handling document that assigns ownership, preserves the first receipt date, describes escalation points and keeps the acknowledgement clock visible.

The procedure should also require a proportionate investigation. That means identifying the complaint points, preserving relevant material, recording decisions and giving the person a useful outcome rather than a generic closing message.

  • A named owner and an alternate owner
  • A central intake route with a process for complaints received elsewhere
  • A case reference, chronology and evidence index
  • Checks for representative authority, safeguarding and urgent harm
  • A separate route for rights requests and sector-specific duties
  • Approval, version control and a scheduled review date

Cases that need separate review

A standard controller procedure cannot safely decide every case. Law-enforcement processing, safeguarding concerns, urgent risk of harm, disputed representative authority, joint-controller questions and sector-specific complaints may require another process or specialist review.

A bounded tool should surface these issues and stop short of deciding them. The organisation remains responsible for the legal assessment, the investigation and the final outcome.

Turning the requirement into working evidence

ICO guidance explains the obligation. A case-ready pack should turn it into usable files: the controlled procedure, a public version, a staff handling procedure, correspondence templates, a case register, an acknowledgement reminder, a chronology and a dated sources and assumptions record.

Those files should share the same case reference, dates and rule-pack version. That consistency is what allows another person to understand how the case was handled later.

Material reviewed for this guide

This guide is general operational information, not legal advice. Check the official material and obtain appropriate advice for circumstances outside the stated scope.