21 Jan UK Data (Use and Access) Act 2025: new complaints procedure requirements affect organisations internationally
From 1 June 2026, organisations will be legally required to have a publicly accessible internal data protection complaints procedure under the UK’s Data (Use and Access) Act 2025 (DUAA). This gives individuals a straightforward way to raise concerns if they believe their personal data has been mishandled—whether due to a suspected data breach, inappropriate retention, or worries about automated decision‑making and AI.
What the complaints procedure must include
Under the DUAA, your internal procedure must:
- clearly explain what information an individual needs to provide, such as proof of identity;
- acknowledge the complaint within 30 days;
- provide a response or request further information without undue delay;
- keep the individual regularly informed about the progress of the investigation; and
- issue a final outcome promptly.
The law allows individuals to raise complaints in many different ways, including informal ones. This means organisations should be alert to comments, messages, or interactions that might represent a complaint – even if the individual doesn’t label it as such.
Why this matters: mandatory first step before ICO involvement
Importantly, the internal complaints procedure becomes the first mandatory step before an individual can escalate a concern to the Information Commissioner’s Office (ICO) about potential breaches of the UK GDPR or the Data Protection Act 2018.
This puts additional weight on organisations to ensure their processes are:
- robust,
- transparent, and
- capable of resolving issues early.
Once a complaint has been acknowledged (and clarified where needed), the organisation must investigate the matter without undue delay, maintain open communication with the individual, and provide a clear and timely outcome.
The outcome should outline:
- how the investigation was carried out,
- what information was considered,
- the conclusion reached, and
- the reasoning behind it.
If the individual is still unhappy and approaches the ICO, your handling of the matter—including the clarity and fairness of your investigation – may be scrutinised.
Jurisdictional reach: who must comply?
– A UK Act with broad territorial scope
The DUAA is UK legislation, applying across the United Kingdom. It integrates into and amends the UK’s existing data‑protection framework, which includes the UK GDPR and the Data Protection Act 2018.
– It applies to all UK data controllers
Any organisation acting as a data controller under UK law must comply, regardless of its sector or size.
– Non‑UK organisations are also caught if they fall under the UK GDPR
Just like the UK GDPR, the DUAA’s obligations also apply to organisations outside the UK if they:
- offer goods or services to individuals in the UK, or
- monitor the behaviour of individuals located in the UK.
This means that overseas tech companies, international retailers, and digital service providers may also need to implement a complaints procedure if they target or track users in the UK. It will also apply to organisations and companies sponsoring clinical trials in the UK.
– Applies to all individuals whose data falls under UK GDPR
Anyone whose data is processed under the UK GDPR can complain, including:
- UK residents
- non‑UK nationals located in the UK at the time of processing
- children (who retain full rights to raise complaints).
What should organisations do now?
To prepare for these obligations coming into force:
– Create or update your internal complaints procedure
Ensure it meets all legal requirements and is easy for people to find and use. Consider placing it prominently on your website and linking it through your privacy notices.
– Strengthen your investigation processes
Your approach must withstand scrutiny if an individual later asks the ICO to review your handling of the complaint.
– Assign responsibility
Identify a person or team to oversee complaints handling and ensure the process is followed consistently.
– Keep thorough records
Maintain a log of:
- all complaints received,
- how each was handled, and
- the outcome reached.
These records help ensure consistent decision‑making and may be requested by the ICO.
Our colleagues at Willans LLP solicitors can assist with all of the above – just let us know if you need help and we’ll put you in touch.