About TheDutyDesk.
A UK platform for handling personal-data obligations — complaints, access requests, breach reporting and the audit trail that regulators now expect.
What it handles
Data-protection complaints under s.164A, subject-access requests, breach reporting, records of processing — one product, one audit trail.
Who it's for
DPOs, Heads of Compliance, Operations Directors and Founders at UK organisations of every size — from five people to five thousand.
When it's needed
The 30-day complaint duty under s.164A commenced 19 June 2026 — and applies to every UK organisation, with no size exemption.
Resources.
Free tools to help you get ready for the duty and make the case internally.
Free PDF · 2 pages
Not ready to decide? Take the checklist.
The eight things every UK small business must have in place for the 30-day complaint duty. Free PDF, no obligation — we'll email it and nothing else unless you ask.
Who we are.
A UK team, building UK regulatory tech.
TheDutyDesk is built and run in the UK. We are not owned by a US privacy vendor. We are not on a procurement panel. We work alongside the people who have to handle this every day.
The law is precise, and our writing must be too. Every factual claim about the Data (Use and Access) Act 2025 or the Data Protection Act 2018 cites primary sources — statute text or official ICO guidance.
Trust & security.
TheDutyDesk is a UK data controller and a UK data processor. We host customer data in the UK. We treat our own data-protection obligations the way we expect our customers to treat theirs.