DutySME

The 30-day complaints duty: no exemptions, no exceptions

Every UK organisation must have a way to take data protection complaints and must acknowledge them within 30 days. It applies whether you employ five people or five thousand. Here is what you actually need in place.

TheDutyDesk Editorial1 June 20263 min readReviewed 7 June 2026

From 19 June 2026, anyone can complain to your organisation if they think you have mishandled their personal data, and you have a legal duty to deal with it properly.[2] [6] This is new, it is enforceable, and the ICO has been clear that it applies to every organisation regardless of size or sector.[4]

If you have been assuming this is a big-company problem, it is not.

What the duty asks of you

Three things, in order.

Make it easy to complain. You must offer an online form and at least one other route, such as email or post. You also have to accept complaints however they arrive, including by phone or social media.[4]

Acknowledge within 30 days. Once a complaint reaches you, the clock starts. You have 30 calendar days to confirm you have received it.[2]

Investigate and respond. You then have to look into it without undue delay, take any steps that are needed, and tell the person the outcome.[2]

There is one more shift worth understanding. Your organisation is now the first port of call. A person can only escalate to the regulator after they have come to you and you have responded, or failed to respond in time.[4] That puts the responsibility, and the opportunity to put things right, with you first.

What this means for you

You do not need a legal department. You need a simple, reliable process and a way to prove you followed it.

At minimum: a named person who owns complaints, a clear route for people to reach you, a way to log when each complaint arrived, and a habit of checking those routes often enough that nothing sits unread. The 30 days run from when the complaint lands, not from when someone notices it, so an unwatched inbox is a risk.

The reason to write it down is evidence. If the regulator ever asks, "did you handle this properly?", the answer should be a record, not a memory.

Sources used in this article

  • [1]Data (Use and Access) Act 2025
  • [2]Data Protection Act 2018 (post-DUAA consolidated), s.164A
  • [6]Commencement regulations (SI 2026/82)
  • [4]ICO guidance on complaint handling

Source verification and SHA-256 hashes are maintained in our sources index.

Last reviewed: 7 June 2026. Next review: 1 December 2026, or sooner if relevant guidance changes.

TheDutyDesk helps you manage data protection complaints with a structured process and an audit trail.