Guides

Handling data-protection complaints: the process the ICO expects

24 June 2026 5 min read GuardianStack
On this page

Short answer: a data-protection complaint isn’t just a message in your inbox — it’s a formal signal the ICO expects you to handle with a process, not improvise. And there’s a quieter truth underneath it: a complaint made to you is a chance to put things right before it becomes a complaint to the regulator. The thing that decides which way it goes isn’t how well you meant to handle it — it’s whether you can show how you handled it. The evidence trail is what you’re judged on.

A complaint is more than an awkward email

When a customer says “I’m not happy with how you’ve handled my data” — or asks you to stop marketing to them, or questions why you hold something — that’s a data-protection complaint, whether or not they use the word. It’s the person exercising rights UK GDPR gives them, and it comes with expectations about how you respond.

Treating it as a one-off customer-service message is the mistake. A complaint is a documented event that may later be reviewed — by the person, by a B2B partner running due diligence, or by the regulator if it escalates. How you respond, and whether you can show how you responded, is the point.

First, don’t conflate three different things

Part of handling a complaint calmly is recognising what you’ve actually received — because a complaint, a data request, and a breach are three different events with three different clocks. Mixing them up is how deadlines get missed.

Concept · Three different events, three clocks

Don’t conflate a complaint, a data request, and a breach

They arrive looking similar and get mixed up — but each carries a different duty and a different clock.

complaintComplaint

Someone’s unhappy with how you handled their data.

Clock: acknowledge within 30 days; investigate and respond without undue delay.
DSARData request

A request for a copy of their data, or to erase/correct it.

Clock: one calendar month (a right with its own deadline).
breachPersonal-data breach

Personal data lost, destroyed, altered, or disclosed/accessed without authority.

Clock: if it risks people’s rights, notify the ICO without undue delay, within 72 hours where feasible (Art 33).
Source: ICO — Individual rights & personal data breaches · UK GDPR Arts 15, 33

The process the ICO expects you to have

The ICO’s consistent expectation is that organisations handling personal data can deal with complaints properly — which means having a process, not making it up each time. For a small business that’s a short, repeatable path.

Framework · The process, not the panic

A short, repeatable path from complaint to closed

Decide who does each step before a complaint arrives. Then you follow a path instead of freezing — and the record proves you did.

1Receiveany channel counts 2Acknowledgeowner + logged 3Investigatelook into it, act 4Respondreasoned, timely 5Recordwhat, when, why the record at the end is the deliverable — "show your working", with dates
Source: ICO — Make a complaint · Accountability and governance

None of this requires a legal department. It requires deciding in advance who does what, so that when a complaint arrives you follow a path instead of freezing.

Honest note: under the ICO’s complaints-handling rules (in force from 2026), you must acknowledge a data-protection complaint within 30 days, then investigate and respond without undue delay and keep the person informed. And if the complaint is really a rights request in disguise (an objection to marketing, a request to erase or access data), that right’s own deadline applies too — a subject access request, for instance, starts a one-month clock. This is guidance, not a verdict on your specific situation, and not legal advice.

Where a mishandled complaint heads

Most complaints never reach the ICO. The ones that do usually got there through neglect, not malice — each missed step makes escalation a little more likely.

Concept · Where a mishandled complaint heads

Escalation is a ladder, not a lightning bolt

Most complaints never reach the ICO. The ones that do usually climbed these rungs through neglect — each is avoidable.

T1 No response — the complaint goes unanswered
T2 No record — you acted, but can’t show what or when
T3 Still unhappy — the person escalates to the ICO
T4 Pattern / breach — repeated complaints, or a breach behind it (higher ICO attention risk)
Source: ICO — Make a complaint · Taking action

Why the evidence trail is the real deliverable

Accountability — UK GDPR Article 5(2) — means it isn’t enough to do the right thing; you must be able to show it. A complaint is where that principle gets tested. Two businesses can respond identically, but the one that kept a clear record of what was raised, what it decided, and when it acted is in a completely different position if the matter escalates.

Diagnostic · Run this when one lands

Six things a defensible response covers

Not a legal department — a path decided in advance, and a record that proves you followed it.

1
A route in

Is there a findable way to raise a concern — a privacy email in your notice?

2
Acknowledge

Does the person know it’s been received, with an owner assigned?

3
Investigate

Have you looked into what happened and acted where needed?

4
Timely reply

Acknowledged within 30 days, and a reasoned response without undue delay?

5
Rights deadlines

If it’s really a data request, are you meeting that right’s own clock?

6
The record

Is what was raised, decided, and done written down — with dates?

Source: ICO — Accountability and governance · UK GDPR Art. 5(2)

This is the quiet through-line of good compliance: the difference between “we think we handled it” and “here is exactly how we handled it, with dates”. The first is a hope; the second is evidence — the same evidence a B2B buyer’s due-diligence form asks for, and the same discipline that keeps a privacy notice honest against your live stack.

What being ready actually buys you

The point isn’t fear of the ICO — it’s that a complaint stops being a panic. Being ready is mostly about the basics being in place before you need them: a clear contact route in your privacy notice, a named owner, and the habit of recording what happened. GuardianStack is built around that evidence-first idea — findings are cited to the rule behind them, and the workspace keeps an audit trail of what was checked and approved, so “show your working” is the default rather than a scramble. The free public check is the honest starting point — about 30 seconds, read-only.

The bottom line

A data-protection complaint is a process, not a surprise. Decide the route in, the owner, the response, and the record before one arrives — keep the evidence — and you turn a stressful escalation into something routine and defensible.

Sources

The primary sources behind this guide — check them yourself:

Frequently asked questions

Does a small business need a formal complaints process for data protection?

Yes, in practice. The ICO expects organisations that handle personal data to deal with data-protection complaints properly — a clear route in, an owner, a timely reasoned response, and a record — even for a small business. It doesn't need to be elaborate, but it does need to exist before a complaint arrives.

What counts as a data-protection complaint?

Any time someone raises a concern about how you handle their personal data and is unhappy with it — questioning why you hold data, objecting to marketing, or saying your handling was wrong. They don't need to use the word "complaint" for it to be one. Note that some of these (asking to erase or correct data, objecting to marketing) are also _rights requests_ with their own deadlines — a message can be both at once.

How quickly do I have to respond to a complaint?

Under the ICO's complaints-handling rules (in force from 2026), you must acknowledge a data-protection complaint within 30 days, then investigate and respond without undue delay while keeping the person informed. If the complaint is actually a rights request (access, erasure, objection to marketing), that right's own deadline applies too — a subject access request, for example, must be answered within one calendar month. And a personal-data _breach_ is different again: where it's likely to risk people's rights, you must notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware.

Why does keeping records of complaints matter?

Because of the accountability principle (UK GDPR Article 5(2)): you must be able to demonstrate compliance, not just claim it. If a complaint escalates to the ICO, a clear record of what was raised, what you decided, and when you acted is what lets you evidence your handling.

See where your store actually stands

Run a free outside-in compliance check of your website — no login required, results in about 30 seconds.

Run the free website check
← Back to all articles