A data protection complaints procedure became a statutory requirement for every UK controller on 19 June 2026. Section 164A of the Data Protection Act 2018, inserted by the Data (Use and Access) Act 2025, gives data subjects the right to complain to the controller about an infringement of the UK GDPR, and puts three duties on the controller: to facilitate complaints, to acknowledge each one within 30 days, and to respond without undue delay and tell the person the outcome.
In the same amendment, Article 77, the right to complain to a supervisory authority, was removed from the UK text. This guide explains what the new duty requires, why Article 77 has gone, and what a compliant procedure, form, log and set of letters look like.
What this guide covers
- What section 164A requires of a data protection complaints procedure
- Why Article 77 is gone
- What counts as a complaint
- The five steps of a data protection complaints procedure
- The log and what it has to show
- The data protection complaints procedure and the Commissioner
- Common failures in a data protection complaints procedure
- Building a data protection complaints procedure
- Frequently asked questions about the data protection complaints procedure

What section 164A requires of a data protection complaints procedure
The section is short and its duties are specific. A data subject may make a complaint to a controller if they consider that, in connection with their personal data, there has been an infringement of the UK GDPR. The controller must facilitate the making of complaints by taking appropriate steps, and the Act gives the example of providing a complaint form that can be completed electronically and by other means.
On receiving a complaint the controller must acknowledge receipt within the period of 30 days beginning when it is received. It must then, without undue delay, take appropriate steps to respond, including making enquiries into the subject matter and informing the complainant about progress, and inform them of the outcome.
Section 164B adds a reserve power to the data protection complaints procedure regime: the Secretary of State may by regulations require controllers to notify the Commissioner of the number of complaints they receive in a period. No regulations have been made at the date of writing, but the log has to be kept in a way that could produce the count if they are.
Why Article 77 is gone
The EU GDPR’s Article 77 gives every data subject the right to lodge a complaint with a supervisory authority. The UK never had supervisory authorities in the EU sense; it had the Commissioner, and the right to complain to the Commissioner was in Data Protection Act 2018 section 165. The 2025 Act tidied this up: it omitted Article 77 and the related Article 57(1)(f), and moved the whole complaints structure into the 2018 Act, with section 164A for complaints to the controller and section 165 for complaints to the Commissioner.
The right to go to the Commissioner has not been lost, and a data protection complaints procedure must still state it. What has changed is that a privacy notice, a DSAR response letter or a policy that cites “Article 77” is citing a provision that no longer exists in UK law, and the Commissioner will expect the controller route to have been offered first. Our guide to UK GDPR vs EU GDPR lists the other places the texts have parted.
What counts as a complaint
For the data protection complaints procedure, a complaint is an expression by a data subject that the controller has infringed the UK GDPR in connection with their personal data. It does not have to use the word “complaint”, cite an article, or arrive through the form. “You keep emailing me after I unsubscribed” is a complaint about Article 21.
“You sent my medical report to the wrong address” is a complaint about Article 32 and probably a breach as well. “Why have you still got my data from 2015” is a complaint about storage limitation. Staff who handle customers need to recognise these and pass them to the person who runs the procedure the same day, because the 30 days run from receipt by the organisation, not by the privacy team.
| The complaint is also | What runs alongside |
|---|---|
| A rights request (access, erasure, objection) | The rights procedure on the Article 12A applicable time period; the complaint acknowledgement on its own 30-day clock |
| A personal data breach | The breach procedure on the 72-hour clock under Article 33; the complaint is acknowledged and its outcome reported after the breach assessment |
| A marketing objection | Immediate suppression under Article 21(2); the complaint outcome confirms it |
| A customer service complaint with no data protection element | The ordinary complaints process; section 164A does not apply, but record the classification decision |
The five steps of a data protection complaints procedure
1. Facilitate. Publish an electronic complaint form, accept complaints by email, post and telephone, and state the route in every privacy notice and every rights response letter. The form should ask what the person thinks went wrong, when, which part of the organisation was involved, and what they would like done; it should not ask them to identify the article they think was breached.
2. Log and acknowledge. Log the complaint on the day of receipt with the acknowledgement due date. Send a written acknowledgement within 30 days that restates the complaint as understood, names the handler, and tells the person they may also complain to the Commissioner. In practice an acknowledgement within a few days is the sensible standard; 30 days is the statutory maximum.
3. Enquire. Establish what processing is involved, whether an infringement occurred, what harm resulted, and whether a rights request or a breach is also in play. Where enquiries take longer than a few weeks, send a progress update; the Act names informing the complainant about progress as one of the appropriate steps.
4. Decide and inform. Reach an outcome: upheld, partly upheld or not upheld; what the organisation will do; any remedy. Inform the complainant in writing with reasons and the Commissioner route. “Without undue delay” has no fixed number, but it means the enquiries are started promptly and the outcome follows as soon as they are complete.
5. Learn. Record the root cause and feed it to the annual review. A complaint that reveals a systemic problem, such as a suppression list that is not being applied, is a control failure to fix, not an individual case to close.
The log and what it has to show
The log is the evidence that the data protection complaints procedure operates, and it needs to show the 30-day clock being met on every row. Columns: reference, date received, channel, complainant, summary, acknowledgement due date, date acknowledged, handler, enquiries and updates, outcome, date outcome sent, remedy, root cause, escalated to the Commissioner, status. Kept this way, it also answers a section 164B count for any period without further work. The record of processing and the rights request register are the two other registers the Commissioner reads beside it.
The data protection complaints procedure and the Commissioner
Section 165 continues to allow a complaint to the Commissioner, and the Commissioner’s own practice is to ask whether the person has first raised the matter with the controller. Where a complaint reaches the Commissioner, expect a request for the organisation’s handling of the same matter under section 164A: the date received, the acknowledgement, the enquiries, the outcome. An organisation that can produce those from the log is in a strong position; one that cannot has two problems instead of one. Our guide to the UK GDPR covers the Commissioner’s wider enforcement powers.
Common failures in a data protection complaints procedure
- No form. The Act’s example of facilitation is an electronic form; a privacy notice that says “contact us” with an email address is thin evidence of facilitation.
- Complaints handled as customer service tickets with no data protection classification, so the 30-day acknowledgement is never tracked.
- Acknowledgement without substance. An auto-reply that says “we have received your message” does not restate the complaint or name a handler; whether it meets the duty is arguable, and there is no reason to be arguing it.
- Article 77 still in the notices. Every privacy notice, DSAR letter and policy needs the reference removed and the two UK routes stated.
- Outcome not sent. The duty is to inform the complainant of the outcome; a case closed internally with no letter is not closed.
- The clock started late. A complaint made to a shop assistant on the 1st and reaching the privacy team on the 20th has 10 days left, not 30.
Building a data protection complaints procedure
The build is small: a two-page procedure, a complaint form, an acknowledgement letter, a progress update, an outcome letter, a log, and a paragraph for each privacy notice. Two things take longer: training customer-facing staff to recognise a complaint, and removing Article 77 from everything that mentions it.
The UK GDPR Toolkit ships the procedure, the form and the three letters, a complaints log with the acknowledgement due date built in, and nine privacy notices that already carry the section 164A and section 165 routes. For the change that brought the duty in, see our summary of the Data (Use and Access) Act 2025; for the notice wording, our guide to the UK GDPR privacy notice.
Frequently asked questions about the data protection complaints procedure
Does section 164A apply to small organisations?
Yes. The duty falls on every controller, with no size threshold. A sole trader who processes customer data must acknowledge a data protection complaint within 30 days like anyone else.
Is 30 days the response deadline?
No. Thirty days is the acknowledgement deadline. The response and outcome must follow without undue delay, which depends on the enquiries the complaint needs.
Can a person still complain to the ICO?
Yes, under Data Protection Act 2018 section 165. The controller route is an addition, and the Commissioner will generally expect it to have been used first.
Do we have to report complaint numbers?
Not yet. A data protection complaints procedure must keep the count producible because section 164B allows regulations requiring it, and none have been made at the date of writing. Keep the log so that a count for any period can be produced if they are.