After the deadline itself, this is the most-asked question about the new duty: when does a message actually count as a data protection complaint — the kind that starts the 30-day clock under section 164A?[2] Get it too narrow and you miss a statutory deadline; too broad and you drown a small team in acknowledgements it does not owe. This guide draws the line.
The core idea
The complaint-handling regime lives in sections 164A to 164C of the Data Protection Act 2018, in force from 19 June 2026.[2][6] In plain terms, a data protection complaint is an expression of dissatisfaction about how an organisation has handled someone's personal data — that you held it without a basis, kept it too long, shared it, lost it, used it in a way they object to, or failed to act on an earlier request about it.
Two features tend to be present in a genuine complaint: it concerns personal data (not a general grumble about service, price or delivery), and it carries a note of grievance rather than simple curiosity. Where both are present, treat it as a complaint and start the clock. Where the boundary is unclear, the safe default is to treat it as a complaint — acknowledging something that turns out to be a query costs you little; missing something that turns out to be a complaint can cost you a s.164A breach.
What is not a complaint
Three things are commonly mistaken for complaints:
A general query. "How long do you keep my data?" or "Who is your data protection officer?" is a question, not a grievance. Answer it as an enquiry. If the tone shifts — "how long do you keep my data, because you should have deleted it months ago" — it has become a complaint about retention, and the clock starts.
A subject access request. A request to see a copy of their data is a DSAR on its own separate timeline, not a s.164A complaint. The two arrive the same way and are constantly confused; use the one-line test in complaint vs subject access request. A single message can be both, in which case you run both tracks.
A non-data complaint. Dissatisfaction about a late delivery, a faulty product or a rude staff member is a customer-service complaint, not a data protection complaint — unless it turns on how their personal data was handled. The subject matter, not the label the person uses, decides it.
The grey cases
Most of the difficulty sits in a few recurring patterns. Our reading, which we operationalise in the product, is:
- "Why do you even have my details?" — Often a genuine complaint about lawful basis or retention, dressed as a question. If the person is objecting to your holding the data, treat it as a complaint.
- A complaint sent to the wrong place — A grievance about your data handling posted as a product review or a social-media reply is still a complaint on receipt; the channel does not change what it is.[2]
- A complaint bundled inside a service issue — "My order was late and you've been emailing me for months after I unsubscribed" contains a data protection complaint (the marketing after opt-out) alongside a service issue. Split it: log the data strand as a complaint, handle the rest through your normal channel.
- An anonymous or third-party complaint — Someone complaining about your handling of another person's data, or complaining anonymously, can still engage the duty. Do not dismiss it because there is no obvious complainant to reply to; record it and take advice on the specific facts.
Where you land on a genuine grey case, write down why. A short, dated note of your classification decision is exactly what demonstrates a considered process if the ICO ever asks.[4]
Why the classification is the whole game
Every downstream duty — the 30-day acknowledgement, the substantive response without undue delay, the evidence trail — hangs on the first decision that this is a complaint.[2] Classify consistently, default to "complaint" in genuine doubt, keep the DSAR and query paths separate, and note your reasoning on the edge cases. That single discipline, applied on every inbound message across every channel, is what turns the duty from a source of risk into a routine.
Frequently asked questions
What makes something a data protection complaint rather than a query?
A complaint carries dissatisfaction about how an organisation has handled someone's personal data; a query just asks for information. "Who is your DPO?" is a query; "you should have deleted my data months ago" is a complaint that starts the 30-day acknowledgement clock under section 164A.[2] In genuine doubt, treat it as a complaint.
Is a subject access request a data protection complaint?
No — a subject access request is a request to see a copy of your data, on its own timeline, not a s.164A complaint. But one message can be both a DSAR and a complaint, in which case you run both. See complaint vs subject access request.
Does a complaint have to use the word "complaint" to count?
No. What decides it is the substance — dissatisfaction about the handling of personal data — not the label the person uses or the channel they use.[2] A grievance posted as a social-media reply still counts on receipt.