Just received a subject-access request or data complaint? Start the clock the right way →

Data duties handled. Customer confidence earned.

Every UK organisation has to handle data-protection complaints, subject-access requests and breaches — on the clock, with an audit trail the ICO can review. TheDutyDesk runs those duties end to end and keeps the proof — so every customer question about their data is answered properly, and every buyer, insurer and regulator sees high standards, not promises.

From £19.99 / month · 14-day free trial · no card required.

Built to ICO guidance.UK-hosted.Audit-grade by design.

Why it pays for itself

Handling data well isn't a cost — it's how you win and keep customers.

The same standards, processes and evidence that satisfy the regulator are what make customers, enterprise buyers and insurers confident in you. Done properly, data handling is a commercial asset, not an overhead.

Build customer confidence.

Customers do business with organisations that respect their data. High standards, real compliance, and a proper, visible process for answering any question about their data turn "we take data seriously" into something they can feel — and check. Confidence they can see is trust you keep, and repeat business you earn.

Win bigger customers.

Enterprise buyers run vendor security and data-protection reviews before they sign. Hand them a live commitment page and a one-click evidence pack instead of a scramble.

No evidence, no contract.

Renew your cyber-insurance.

Insurers increasingly want proof you handle complaints, breaches and access requests properly. Show your controls and your audit trail on demand.

Better answers, better cover.

Pass due diligence.

Fundraising or selling? Data-protection gaps stall deals and shave valuations. Walk in with every obligation logged, timestamped and exportable.

Diligence-ready, day one.

Every personal-data duty in one place.

Complaints, subject-access requests, breach reporting and the records behind them — one platform, one audit log, one place the ICO's questions get answered.

Now live

Data-protection complaints

s.164A DPA 2018

Track the 30-day clock, send the acknowledgement, keep the evidence the ICO can review.

[2]
On the platform

Subject-access requests

UK GDPR Art.15

One-month clock. Intake, identity-check, search, redaction, response pack.

[3]
On the platform

Other data-subject rights

UK GDPR Art.16–22

Rectification, erasure, restriction, portability, objection.

[3]
Available

Breach reporting

UK GDPR Art.33

The 72-hour clock. Pre-filled ICO notification, internal escalation.

[3]
Available

Records of processing

UK GDPR Art.30

The living RoPA. Connected to every complaint and DSAR.

[3]
On the roadmap

DPIAs and vendor risk

UK GDPR Art.35

Pre-processing assessment, vendor register, residual risk.

[3]

Every obligation runs on the same audit log. Move from a complaint to a DSAR to a breach without re-keying a single fact.

See what we cover →

The Duty Mark

Turn "we take data seriously" into something buyers can verify.

The Duty Mark is a badge you display that opens your public commitment page and lets anyone raise a data complaint directly — backed by a live process on TheDutyDesk, not a static promise. Put it in your footer, your proposals and your security questionnaires: a signal to customers and procurement teams that your data duties are actually handled. It's a pledge, not a certification — but it's a pledge you can prove.

The evidence moat

When the regulator asks, you click once.

Every complaint, request and breach produces a complete, timestamped evidence pack — a tamper-evident audit trail plus a one-click export the ICO can read. An inbox and a spreadsheet can't prove what happened, or when. TheDutyDesk can.

And it compounds: every complaint, request and breach you handle adds to a permanent, exportable history — the more you run through TheDutyDesk, the stronger your position and the more there is to lose by going back to an inbox and a spreadsheet.

See a sample evidence pack →

By the numbers

Data complaints are real — and rising

Every year the UK data regulator (the ICO) handles tens of thousands of complaints and reports about how organisations use people's data.

42,881

data-protection complaints to the ICO in a year

↑ 8%

up on the year before
(39,721 the previous year)

44,400+

nuisance-call reports a year

~29,000

spam-email reports a year

£19.6m

in ICO penalties — 28 notices in a single year

Customer complaints about data are a standing reality of doing business in the UK.

Source: ICO Annual Report 2024/25 [SRC-007].

Frequently asked.