New statutory requirements for internal data protection complaints processes came into force on 19 Jun 2026, completing a number of changes made by The Data (Use and Access) Act 2025.
Businesses must ensure complaints from the public are handled following clear and accessible procedures. They should also be acknowledged (within 30 days of receipt), investigated (keeping the complainant updated) and responded to in a timely manner. The public are still encouraged to raise a complaint with an organisation first before contacting the Information Commissioner’s Office.
Businesses should review their privacy notices and template responses which inform individuals of their right to make a data protection complaint, including information such as when personal data is collected and when responding to data subject rights requests.
Internal procedures and staff training need to reflect that complaints are identified and acknowledged within the 30-day period. Businesses also need to review contracts with suppliers to ensure they alert the business to any complaints and help them to resolve them.
Most businesses will have existing processes in place which need to be updated, rather than drafting new ones however it is always a useful opportunity to review them all to ensure compliance.
Other changes under the Act affect how organisations can use personal information, so contacts and notices should be reviewed accordingly. This includes:
Automated decision making – The organisation can use personal information to make significant automated decisions about a person if it can show it has a legitimate interest. This should outweigh the impact on the person’s rights and freedoms but won’t be allowed for some protected information such as race, ethnic origin or sexual orientation.
Direct marketing ‘soft opt in’ – a charity which has collected personal information because the person has supported it or expressed an interest in their work, can send direct marketing emails to them unless the data subject asks not to receive them.
Archiving in the public interest – an organisation can give out the personal information of a data subject when it is needed for the purposes of archiving in the public interest, even if the data subject only provided consent to the information being used for a different reason.
National security exemption – a law enforcement agency such as the police does not have to follow some of the usual rules about how it can use someone’s personal information if it is necessary to protect national security.
Designation notices – law enforcement agencies and the intelligence services who are working together on joint operations can work to the same intelligence services’ rules when using a person’s information if the Secretary of State authorises it.
Cookies – an organisation no longer needs an individual’s consent to set some cookies if the intrusion of privacy is limited, i.e. those that improve the functionality of a website.
Organisations do need to think specifically about children and online services when using personal information and make sure it properly protects them.
Also with privacy notices, an organisation no longer needs to inform the person that it intends to re-use their personal information for research, archiving in the public interest or generating statistics if it would involve a disproportionate effort to do so. It must protect an individual’s rights in other ways and still explain what it is doing by publishing details on its website.
In summary businesses should now:
- Familiarise themselves with the changes to make sure they comply with all of them.
- If they provide online services that children are likely to use, make sure enough is being done to consider their needs.
- Review and update complaints procedures.
- Review if the changes allow the business to streamline any data processes which may allow for more innovation.
Peter Kouwenberg is a partner at Taylor Walton Solicitors www.taylorwalton.co.uk