The New Statutory Right to Complain: Burden or Opportunity?

The Data Use and Access Act (DUAA) has introduced an important new right into UK data protection law — a right for individuals to complain directly to data controllers if they believe their personal data has been mishandled.

This right, set out in section 164A of the Data Protection Act 2018, gives people a formal route to raise concerns before going to the regulator — now renamed the Information Commission under the DUAA.

The detail of how this right works will be fleshed out by guidance from or via the regulator, but it’s worth knowing about it now and thinking about some of the key things to do to implement it.

About the Author
Michael has many years’ experience supporting, developing and improving effective data protection and GDPR compliance systems. He has worked in this field in the public, private and charity sectors including at Board level. This experience has made him the ideal lead trainer for WuDo Solutions’ five-star rated GDPR training course.

 

What’s New and Why It Matters

In practice, this change formalises what’s already been happening. When people complain directly to the Information Commission, the regulator often redirects those cases back to the organisation concerned for resolution.

That’s because regulators like the Commission are designed to handle systemic or serious issues — not every local complaint. Many of these should rightly be addressed by the organisation responsible, in the same way that Freedom of Information internal reviews are handled locally before escalation.

There’s also a practical reason: the regulator is overwhelmed with complaints, and performance metrics have shown growing backlogs.

Encouraging resolution at source is both more efficient and more proportionate.

 

What Controllers Need to Do

Controllers — the organisations that decide how and why personal data is processed — now have clear duties. They must:

  1. Provide a way to make a complaint, ideally including an online form.
  2. Acknowledge the complaint within 30 days.
  3. Investigate and communicate the outcome, explaining both the process and the reasoning.

Most public authorities already have similar procedures under other laws, and many companies have customer complaint routes that can be adapted. But they’ll need to make sure staff can recognise when a complaint relates to data protection rights.

 

Man completing a complaint form

 

Enjoying this content?
Get articles like this direct to your inbox with our free newsletter. Full of articles, news and resources with all our content accessible in one place. Plus subscribers get exclusive content, priority access to events, and exclusive special offers. You can unsubscribe any time and we won;t use your data for anything else.

Sign Up Here:

 

To Complaint: Burden or Opportunity?

It’s easy to see this as yet another administrative demand. But seen differently, it’s an opportunity.

Handled well, these complaints can be a valuable feedback loop. They help you:

  • Identify weak points in your processes,
  • Build trust with customers, patients, or citizens, and
  • Resolve issues before they reach the regulator or the media.

In the long run, that builds resilience, accountability, and confidence — all key elements of good governance and reputation management.

 

How to Comply (and Add Value)

Here’s a practical framework:

  1. Create a clear route for people to make data-related complaints.
  2. Train staff to recognise when someone is exercising a statutory right.
  3. Assign responsibility — ideally to your Data Protection Officer or an equivalent lead.
  4. Develop internal service standards to ensure timely investigation and response.
  5. Communicate clearly and empathetically. In my experience people with complaints often need some form of additional help
  6. Always remind complainants that they can still escalate to the Information Commission if unsatisfied.

 

A Final Thought

The new statutory right adds process. However, I think most organisations have some form of complaints process that can be amended or improved with relative ease. It also adds opportunity — to show professionalism, accountability, and respect for people’s rights.

It delivers not just functional value (better compliance) but also emotional and social value — building trust, credibility, and ethical reputation.

Learn About the GDPR

Gain the practical skills you need to identify and manage data protection and GDPR with this five-star rated training course.

Available in person, online or in-house the focus on practical skills and unique post-course support you get by learning with us will ensure you and your organisation can tackle this key governance activity with confidence.

Five star training testimonial