The s.164A compliance question, answered.

Why not just an email address?

It is the most common objection UK organisations raise. Under s.164A of the Data Protection Act 2018, an email inbox leaves six compliance gaps — each one capable of turning a manageable complaint into an ICO investigation.

01

There is no 30-day clock.

Section 164A of the Data Protection Act 2018 requires you to acknowledge a complaint within 30 days. An email inbox has no clock. No automation. No reminder. Someone has to notice, count, and chase. On busy weeks, nobody does. When the ICO asks for evidence of the acknowledgement — and they do ask — you are looking for a sent-items entry dated three months ago.[2]

02

There is no tamper-evident audit trail.

The ICO's February 2026 guidance is explicit: you need a record of how each complaint was handled, start to finish, in a form that cannot be edited after the fact. An email thread can be deleted, forwarded with modifications, or simply lost when someone leaves. Hash-chained audit logs cannot. When you are asked to evidence compliance, the difference between "we have the record" and "we are looking for it" is the difference between a managed investigation and a penalty notice.

03

It only captures one channel.

The ICO's February 2026 guidance treats complaints submitted via social-media accounts as in-scope. So does a complaint posted to your LinkedIn page. Or sent via your web contact form. Or phoned in and noted by reception. An email address captures the complaints people choose to send by email. TheDutyDesk captures every channel into one inbox — email-to-ticket, a hosted form, an embeddable widget — and applies the 30-day clock to all of them from the moment they arrive.[4]

04

There is no one-click ICO evidence pack.

When a regulator opens an investigation, they ask for your complaint-handling records. With an inbox, that means searching Sent Items, assembling email threads, locating any attached documents, and producing something coherent under time pressure. With TheDutyDesk, every case produces a complete, timestamped, hash-chained evidence pack — one click, one PDF, ready to send. The difference in effort is not small. It is days versus seconds.

05

It stops working when the owner goes on holiday.

The 30-day clock does not pause because your Data Protection Lead is at a conference. A shared inbox with three people who all assume someone else is monitoring it is worse than an inbox belonging to one person — at least the single owner knows when they have missed something. TheDutyDesk keeps the clock running, sends escalation alerts, and makes every case visible to everyone with access. Leave does not pause a deadline.

06

It hides the true volume.

Most organisations underestimate how many data-protection complaints they receive. Some arrive by email. Some come in via the web form labelled "general enquiry". Some are threaded inside a longer customer-service exchange. An inbox conflates all of them. TheDutyDesk separates complaints from other correspondence at intake, so you see the real number — and so does the ICO, if they ask.

Asked at 11pm on a Friday to evidence your complaint-handling to the ICO, the person with TheDutyDesk clicks once and sends a complete, timestamped pack. The person with an inbox opens Sent Items and starts searching.

[2] The duty applies to every UK data controller. Evidence must be producible on demand.

What TheDutyDesk does instead.

Intake

Every channel — email-to-ticket, hosted form, embedded widget — routes into one inbox with a timestamp and a case number. Nothing falls through.

Clock

The 30-day clock starts the moment the complaint is received. It does not stop for weekends, holidays, or handover emails.

Audit

Every state change, note, and attachment is timestamped and hash-chained. The record cannot be edited after the fact. The ICO can review it.

Evidence pack

One click produces a complete, regulator-ready PDF. Every case. Every time. No assembly required.

See what we cover →