UK Data Protection Complaints Rule in Force: What the ICO Expects of Websites and Apps
Since June 19, 2026, organizations covered by UK data protection law have had to run a proper process for handling data protection complaints. The UK Information Commissioner's Office (ICO) confirmed in a news item dated June 23, 2026 that the requirement, introduced by the Data (Use and Access) Act 2025, is now in force.
For most businesses this is not a paperwork exercise. It lands on the product: the contact form, the privacy notice, the help desk queue and the back office tools that staff use to find a customer's records. If you are planning or maintaining a site or app with UK users, it is worth treating the complaints route as a small feature in your website and web application development backlog rather than a legal footnote.
This article summarizes what the ICO has published, at a high level. It is not legal advice, and you should confirm how the rules apply to your organization with a qualified adviser.
What changed on June 19, 2026
The ICO had flagged the date well in advance. In its statement of February 5, 2026, the regulator said most of the Act's remaining data protection provisions took effect that day, and that the requirement for organizations to have a complaints procedure would follow on June 19, 2026. A reminder followed on May 19, 2026, one month before the deadline.
That date has now passed, so this is a current obligation and not an upcoming one. People already had the right to complain to the ICO. What is new is a legal duty on the organization itself to receive, acknowledge and resolve data protection complaints.
The four things the ICO says you must do
The ICO's guidance, How to deal with data protection complaints, separates what the law requires ("must") from good practice ("should") and optional ideas ("could"). According to that guidance, organizations must:
- give people a way to make data protection complaints directly to the organization;
- acknowledge receipt of a complaint within 30 days of receiving it;
- take appropriate steps to respond without undue delay, including making appropriate enquiries and keeping the person informed;
- tell the person the outcome without undue delay.
The same page states that there are no exemptions from having a process for handling data protection complaints. Size does not remove the duty, although the ICO says its guidance is written to work for organizations of all sizes.
How the 30-day clock works
The ICO's page on what to do when you receive a complaint explains that the 30 days start on the day after the complaint arrives. Weekends and public holidays count, but if the final day falls on one, the organization has until the next working day.
The 30 days cover the acknowledgement only. There is no fixed deadline for finishing the investigation. The standard is "without undue delay", and the ICO says the time needed depends on factors such as complexity and the harm involved. The guidance also says an automated reply, such as an auto-acknowledgement email, can be enough to meet the acknowledgement duty when a complaint arrives electronically.
What counts as a data protection complaint
The ICO describes a data protection complaint as one where someone believes the organization has infringed data protection legislation in the way it handled their personal information. Its examples include the response to a subject access request, security and data breaches, and how personal data was collected, stored, retained or kept accurate.
Complaints rarely arrive neatly labeled. A customer writing to support about a billing error may add that their address was shared with someone else. The ICO says that where it is unclear whether a message involves data protection, the organization should ask the person to clarify. That has a practical consequence: front-line support staff and chat tools need to recognize these messages and route them correctly.
What this means for a website, app or internal system
The points in this section are our interpretation of the guidance for software owners, not statements from the ICO.
The complaint channel
The ICO's page on preparing to handle complaints lists options an organization could offer, including an email address, an electronic or written complaint form, a phone line, an online portal, or live chat with escalation to a human. It also says you are not required to set up a separate tool as long as the obligations are met. For many businesses the simplest route is an existing contact form with a clear "data protection complaint" category that timestamps the submission and triggers an automatic acknowledgement.
The privacy notice
The same page says organizations must tell people that they can complain to the organization and to the ICO, at the point personal information is collected and when responding to a subject access request. In practice that usually means updating privacy notice text and any templates used to answer access requests.
Records and data retrieval
The ICO says organizations should keep records of the complaint date, the acknowledgement, the conversations and the outcome, and should be able to find the information they need quickly. An investigation is much easier when your systems can show what data you hold on a person, where it came from and who it was shared with. Older custom systems with data spread across several databases are where this tends to be slow.
Suppliers
The guidance says agreements with processors should address how they will help with complaint handling and investigations. If a hosting provider, a software agency or a SaaS vendor processes personal data on your behalf, check that your contract covers this. Our guide to outsourcing software development from the US and UK covers the wider contract questions.
Does it apply to US companies?
The requirement sits in UK data protection law, so it follows the reach of that law rather than where a company is incorporated. A US business that only serves US customers is unlikely to be affected. A US business that offers goods or services to people in the UK may be within scope of UK data protection law, and if so the complaints duty comes with it. Whether you are in scope is a legal question that depends on your facts, so take advice rather than assuming either way.
There is no US federal equivalent of this specific rule that we can point to. US privacy obligations vary by state and sector and are outside this article.
What to do next
If you have not yet reviewed your setup, a short and realistic checklist is:
- Confirm where a data protection complaint can be submitted, and test that it reaches a named person or team.
- Turn on a timestamped acknowledgement and decide who tracks the 30-day limit.
- Update the privacy notice and subject access response templates to mention the right to complain to you and to the ICO.
- Brief support staff, and review any chatbot scripts, so complaints are recognized and handed to a person.
- Log each complaint, the steps taken and the outcome in one place.
The ICO also explains how it deals with complaints: in most cases, if someone complains to the regulator about how you handled their information, the ICO will ask them to raise the complaint with you first. That makes your own process the first stop, and a well-run one may resolve issues before they go further.
The ICO's stated approach
In its June 23, 2026 news item, the ICO put the emphasis on supporting organizations. Emily Keaney, Deputy Commissioner for Regulatory Policy, described the change as being about good data protection becoming "business as usual". The ICO also reported research finding that more than two-thirds of businesses aware of the Act either did not know or misunderstood whether it applies to them, which suggests many organizations still have work to do.
A supportive tone does not make the duty optional. The safest reading is that a missing or neglected complaints route is now a compliance gap, and a visible one, since it shows up as soon as a customer tries to use it.
Conclusion
The UK data protection complaints rule has applied since June 19, 2026. The ICO's guidance sets out four duties: provide a way to complain, acknowledge within 30 days, investigate and keep people informed without undue delay, and communicate the outcome. For most businesses, meeting them is a modest piece of work touching a form, an automated email, some privacy notice text and a place to log cases.
If your site or app needs a complaints route, or your older system makes it hard to locate a customer's data when a complaint arrives, you can contact Entrant Technologies to talk through the options. For the legal position, rely on the ICO's guidance and your own adviser.