From 19 June 2026, anyone can complain to your organisation if they think you have mishandled their personal data, and you have a legal duty to deal with it properly.[2] [6] This is new, it is enforceable, and the ICO has been clear that it applies to every organisation regardless of size or sector.[4]
If you have been assuming this is a big-company problem, it is not.
What the duty asks of you
Three things, in order.
Make it easy to complain. You must offer an online form and at least one other route, such as email or post. You also have to accept complaints however they arrive, including by phone or social media.[4]
Acknowledge within 30 days. Once a complaint reaches you, the clock starts. You have 30 calendar days to confirm you have received it.[2]
Investigate and respond. You then have to look into it without undue delay, take any steps that are needed, and tell the person the outcome.[2]
There is one more shift worth understanding. Your organisation is now the first port of call. A person can only escalate to the regulator after they have come to you and you have responded, or failed to respond in time.[4] That puts the responsibility, and the opportunity to put things right, with you first.
What this means for you
You do not need a legal department. You need a simple, reliable process and a way to prove you followed it.
At minimum: a named person who owns complaints, a clear route for people to reach you, a way to log when each complaint arrived, and a habit of checking those routes often enough that nothing sits unread. The 30 days run from when the complaint lands, not from when someone notices it, so an unwatched inbox is a risk.
The reason to write it down is evidence. If the regulator ever asks, "did you handle this properly?", the answer should be a record, not a memory.