Guides

How to acknowledge a data protection complaint within 30 days

From 19 June 2026 you must acknowledge a data protection complaint within 30 days of receipt. This guide walks through the steps: confirm it is a complaint, record the receipt date, acknowledge early, say the right things, and keep the evidence.

TheDutyDesk Editorial18 July 20265 min readReviewed 18 July 2026

From 19 June 2026, section 164A of the Data Protection Act 2018 requires every UK controller to acknowledge a data protection complaint within 30 days of receiving it.[2][6] The acknowledgement is the first — and cheapest — thing the regulator will expect you to evidence. This guide sets out how to do it reliably.

What the law actually requires

The statutory duty is narrow and specific: where you receive a data protection complaint, you must acknowledge receipt to the complainant within 30 days.[2] You must then respond substantively without undue delay.[2] The 30 days are calendar days and run from receipt on any channel, not from the moment someone inside your organisation notices — we cover that timing in detail in the 30-day complaint clock explained.

Everything below the statutory line — what the acknowledgement says, how quickly you send it, how you log it — is good practice we operationalise in the product. We flag which is which as we go.

The steps

1. Confirm it is actually a complaint

Before you start the clock, check what you are dealing with. A request to see data is a subject access request on its own timeline, not a complaint — the two are constantly confused, and mixing them up starts the wrong clock. If you are unsure, use the one-line test in complaint vs subject access request. A single message can be both, in which case you run both tracks.

2. Record the date of receipt

The clock starts on receipt.[2] Log the date the complaint arrived at your published channel — web form, email, social media, post or phone — as a fact, separate from the date anyone read it. This receipt date is the anchor for the whole duty, so capture it once and do not let it drift.

3. Acknowledge early — don't spend the full 30 days

The statute gives you 30 days, but treating that as a target is a risk, not a plan. Our reading, which we build into the product, is to send an explicit acknowledgement within the first three to five working days of receipt. The acknowledgement is cheap insurance: producing a full response but missing the 30-day cliff because the investigation ran long is an avoidable s.164A breach. Send the acknowledgement first, then investigate.

There is one exception the ICO's February 2026 guidance allows: a substantive response sent within the 30-day window discharges the acknowledgement duty without a separate step.[4] Reserve that for the narrow cases where a complete answer inside the month is genuinely certain; for everything else, acknowledge first.

4. Say the right things

The statute requires acknowledgement of receipt; it does not prescribe wording.[2] As good practice, a strong acknowledgement confirms you have received the complaint, gives it a reference the complainant can quote, states in plain terms what happens next and roughly when, and names a contact or channel for follow-up. Keep it short, plain and dated. Avoid promising an outcome or a resolution date you cannot guarantee — acknowledge receipt, set expectations, and name a route for follow-up.

5. Keep the evidence

An acknowledgement you cannot prove you sent is, for regulatory purposes, an acknowledgement you did not send. Record what you sent, to whom, on what date, and by which channel, against the receipt date from step 2. If an ICO investigation ever asks whether you acknowledged in time — on every complaint, including the social-media ones — this record is your answer. A system of record with an immutable, timestamped log turns that answer from qualitative to quantitative, which is what the ICO's evidence standard implies.[4]

Frequently asked questions

How long do I have to acknowledge a data protection complaint?

Thirty days from receipt, under section 164A(3) of the Data Protection Act 2018, in force from 19 June 2026.[2][6] The 30 days are calendar days and run from when the complaint arrives, not from when someone reads it. As good practice, acknowledge within the first few working days rather than waiting.

Do I have to fully resolve the complaint within 30 days?

No. The 30-day duty is to acknowledge receipt.[2] You must then respond substantively without undue delay, which is a separate requirement.[2] If you can give a complete substantive response within 30 days, the ICO's guidance treats that as also discharging the acknowledgement.[4]

What if the complaint comes in by social media?

The clock still starts on receipt, whatever the channel.[2] A complaint sent as a direct message or a reply on your social account is received when it reaches that account. If your data-protection function does not see those channels, the acknowledgement clock can run unnoticed — connected or monitored intake with an audit trail is how you close that gap.

Sources used in this article

  • [2]Data Protection Act 2018 (post-DUAA consolidated) — s.164A
  • [4]ICO statutory guidance on complaint handling, February 2026
  • [6]SI 2026/82 (commencement order)

Source verification and SHA-256 hashes are maintained in our sources index.

Last reviewed: 18 July 2026. Next review: 18 July 2027, or sooner if relevant guidance changes.

TheDutyDesk helps you manage data protection complaints with a structured process and an audit trail.