This article is part of The Duty.

The 30-day clock.

The law requires acknowledgement of complaints within 30 days. Here is what that means in practice.

Day 1

The clock starts the day the complaint is received by your organisation — not the day it reaches the privacy team. If a customer emails a generic support address complaining about data handling, the 30-day clock has started.

Acknowledgement

Within one month of receipt (approximately 30 days), you must acknowledge the complaint. This means a substantive communication confirming receipt and opening a dialogue. An automated "we have received your email" auto-responder does not satisfy the requirement if it is not specifically acknowledging a data-protection complaint.

Resolution

The law requires you to respond "without undue delay". While the acknowledgement has a hard 30-day deadline, the resolution must happen as quickly as reasonably possible depending on the complexity of the complaint.

The Audit Trail

If the ICO investigates, they will ask for proof of when the complaint was received and when it was acknowledged. Without a tamper-proof system of record, you cannot prove you met the 30-day deadline.

Read next