Soundbite: Data Protection Complaints Procedure – New requirement for employers from 19 June 2026

Data Protection Complaints Procedure – New requirement for employers from 19 June 2026

We have noticed an increasing use of data subject access requests (DSARs) in workplace disputes, often as a tactical tool alongside grievances or Employment Tribunal claims. DSARs are also becoming more commonplace as employees are more aware of their rights and increasingly use AI tools to guide them.

Against that backdrop, a key legal change is coming into force very shortly which employers must prepare for.

What is changing?

From 19 June 2026, new provisions under the Data (Use and Access) Act 2025 will require employers to have a formal data protection complaints procedure in place. This will give employees the ability to raise a complaint directly with their employer about how their personal data has been handled, including how a DSAR has been dealt with.

Importantly, this does not replace complaints to the Information Commissioner’s Office (ICO). Employees can still escalate matters externally after raising an internal complaint. Therefore, this change is likely to increase the administrative burden on employers.

Even where employers have already responded to a DSAR, employees will now be able to challenge how that request was handled via an internal complaints process. Employers will need to acknowledge complaints within a specified timeframe (expected to be within 30 days), carry out a reasonable investigation into the concerns raised, provide a clear written response to the employee and keep records of complaints and outcomes. This undoubtedly creates an additional layer of process alongside existing DSAR obligations and grievance procedures.

With the deadline fast approaching, we recommend that employers take the following steps before 19 June 2026:

  1. Put a data protection complaints procedure in place
    You will need a standalone, clear and accessible procedure setting out how employees can raise concerns and how those concerns will be handled.
  1. Update your privacy notice
    Your privacy information should clearly signpost the internal complaints route so employees understand how to raise concerns from the outset.
  1. Train key staff
    Managers, HR and/or anyone responsible for handling DSARs should understand how to identify a data protection complaint and the steps that must be followed.

We understand that the intention behind this change is to reduce the burden on the ICO, which handles a significant volume of complaints each year. In practice, however, that burden will likely shift to employers. We are already seeing DSARs used more frequently in disputes and this new internal complaints procedure is likely to become another tool used by employees in contentious situations. Having a clear, well-drafted procedure in place will therefore be essential, both for compliance and for managing risk effectively.

We are currently preparing a data protection complaints procedure that can be adapted for your organisation. If you would like support with drafting a procedure, updating your privacy notice, or training your team, please do get in touch.

Our retained clients

If you are one of our Gold or Platinum retained clients, you do not need to take any immediate action. We will be updating your handbook to include a compliant data protection complaints procedure and ensuring that your documentation is aligned with the new requirements.

If you have any questions in the meantime or you would like to discuss how this change affects your organisation, please feel free to contact us.