Handling data-protection complaints: the process the ICO expects
On this page
Short answer: a data-protection complaint isn’t just a message in your inbox — it’s a formal signal the ICO expects you to handle with a process, not improvise. And there’s a quieter truth underneath it: a complaint made to you is a chance to put things right before it becomes a complaint to the regulator. The thing that decides which way it goes isn’t how well you meant to handle it — it’s whether you can show how you handled it. The evidence trail is what you’re judged on.
A complaint is more than an awkward email
When a customer says “I’m not happy with how you’ve handled my data” — or asks you to stop marketing to them, or questions why you hold something — that’s a data-protection complaint, whether or not they use the word. It’s the person exercising rights UK GDPR gives them, and it comes with expectations about how you respond.
Treating it as a one-off customer-service message is the mistake. A complaint is a documented event that may later be reviewed — by the person, by a B2B partner running due diligence, or by the regulator if it escalates. How you respond, and whether you can show how you responded, is the point.
First, don’t conflate three different things
Part of handling a complaint calmly is recognising what you’ve actually received — because a complaint, a data request, and a breach are three different events with three different clocks. Mixing them up is how deadlines get missed.
Don’t conflate a complaint, a data request, and a breach
They arrive looking similar and get mixed up — but each carries a different duty and a different clock.
The process the ICO expects you to have
The ICO’s consistent expectation is that organisations handling personal data can deal with complaints properly — which means having a process, not making it up each time. For a small business that’s a short, repeatable path.
A short, repeatable path from complaint to closed
Decide who does each step before a complaint arrives. Then you follow a path instead of freezing — and the record proves you did.
None of this requires a legal department. It requires deciding in advance who does what, so that when a complaint arrives you follow a path instead of freezing.
Honest note: under the ICO’s complaints-handling rules (in force from 2026), you must acknowledge a data-protection complaint within 30 days, then investigate and respond without undue delay and keep the person informed. And if the complaint is really a rights request in disguise (an objection to marketing, a request to erase or access data), that right’s own deadline applies too — a subject access request, for instance, starts a one-month clock. This is guidance, not a verdict on your specific situation, and not legal advice.
Where a mishandled complaint heads
Most complaints never reach the ICO. The ones that do usually got there through neglect, not malice — each missed step makes escalation a little more likely.
Escalation is a ladder, not a lightning bolt
Most complaints never reach the ICO. The ones that do usually climbed these rungs through neglect — each is avoidable.
Why the evidence trail is the real deliverable
Accountability — UK GDPR Article 5(2) — means it isn’t enough to do the right thing; you must be able to show it. A complaint is where that principle gets tested. Two businesses can respond identically, but the one that kept a clear record of what was raised, what it decided, and when it acted is in a completely different position if the matter escalates.
Six things a defensible response covers
Not a legal department — a path decided in advance, and a record that proves you followed it.
Is there a findable way to raise a concern — a privacy email in your notice?
Does the person know it’s been received, with an owner assigned?
Have you looked into what happened and acted where needed?
Acknowledged within 30 days, and a reasoned response without undue delay?
If it’s really a data request, are you meeting that right’s own clock?
Is what was raised, decided, and done written down — with dates?
This is the quiet through-line of good compliance: the difference between “we think we handled it” and “here is exactly how we handled it, with dates”. The first is a hope; the second is evidence — the same evidence a B2B buyer’s due-diligence form asks for, and the same discipline that keeps a privacy notice honest against your live stack.
What being ready actually buys you
The point isn’t fear of the ICO — it’s that a complaint stops being a panic. Being ready is mostly about the basics being in place before you need them: a clear contact route in your privacy notice, a named owner, and the habit of recording what happened. GuardianStack is built around that evidence-first idea — findings are cited to the rule behind them, and the workspace keeps an audit trail of what was checked and approved, so “show your working” is the default rather than a scramble. The free public check is the honest starting point — about 30 seconds, read-only.
The bottom line
A data-protection complaint is a process, not a surprise. Decide the route in, the owner, the response, and the record before one arrives — keep the evidence — and you turn a stressful escalation into something routine and defensible.
Sources
The primary sources behind this guide — check them yourself:
Frequently asked questions
Does a small business need a formal complaints process for data protection?
Yes, in practice. The ICO expects organisations that handle personal data to deal with data-protection complaints properly — a clear route in, an owner, a timely reasoned response, and a record — even for a small business. It doesn't need to be elaborate, but it does need to exist before a complaint arrives.
What counts as a data-protection complaint?
Any time someone raises a concern about how you handle their personal data and is unhappy with it — questioning why you hold data, objecting to marketing, or saying your handling was wrong. They don't need to use the word "complaint" for it to be one. Note that some of these (asking to erase or correct data, objecting to marketing) are also _rights requests_ with their own deadlines — a message can be both at once.
How quickly do I have to respond to a complaint?
Under the ICO's complaints-handling rules (in force from 2026), you must acknowledge a data-protection complaint within 30 days, then investigate and respond without undue delay while keeping the person informed. If the complaint is actually a rights request (access, erasure, objection to marketing), that right's own deadline applies too — a subject access request, for example, must be answered within one calendar month. And a personal-data _breach_ is different again: where it's likely to risk people's rights, you must notify the ICO without undue delay and, where feasible, within 72 hours of becoming aware.
Why does keeping records of complaints matter?
Because of the accountability principle (UK GDPR Article 5(2)): you must be able to demonstrate compliance, not just claim it. If a complaint escalates to the ICO, a clear record of what was raised, what you decided, and when you acted is what lets you evidence your handling.
See where your store actually stands
Run a free outside-in compliance check of your website — no login required, results in about 30 seconds.
Run the free website check