How will the Data (Use and Access) Act 2025 impact data protection complaints for employers? - Berry Smith

How will the Data (Use and Access) Act 2025 impact data protection complaints for employers?

A significant change to UK data protection law came into force on 19 June 2026 following the introduction of the Data (Use and Access) Act 2025 (“DUAA”). Berry Smith’s Commercial team have published an overview and explanation of the key changes of the DUAA expected in 2026, a link to the article can be found here. However, the requirements surrounding the processing and handling of data protection complaints have been tightened, and we explore what this means for employers and organisations below.

Before June 2026, whilst individuals had a right under Article 77 UK GDPR to raise complaints with the Information Commissioner’s Office (“ICO”), organisations had no express statutory framework under either UK GDPR or Data Protection Act 2018 to maintain a formal internal complaints process for data protection issues.

The DUAA has introduced a formal right for individuals to raise data protection complaints directly with organisations, requiring all data controllers to operate an internal complaints process to deal with any data protection concerns, before those concerns are raised before the ICO, and regulatory involvement becomes necessary.

Importantly, the right applies not only to employees, but also to workers, former employees, job applicants and anyone else whose personal data is processed by an organisation.

While many employers and organisations already deal with concerns about personal data voluntarily and informally, the DUAA has created a structured legal framework that organisations must now follow, and we explore this further below.

ICO guidance published ahead of the June 2026 reforms note that employers and organisations must:

· give people a way of making data protection complaints to you;

· acknowledge receipt of complaints within 30 days of receiving them;

· without undue delay, take appropriate steps to respond to complaints, including making appropriate enquiries, and keep people informed; and

· without undue delay, tell people the outcome of their complaints.

What does this mean for employers?

It is important that any existing data protection and GDPR policies and governance documents are updated to reflect the new reforms to ensure that they are meeting the current requirements. We explore what this looks like in practice.

Accessibility

Organisations and businesses must give individuals a clear way to raise a data protection complaint. Whilst organisations have flexibility on how exactly their internal complaints process is run, it must provide clear and easy channels (such as online electronic forms) for people to submit any data protection complaints.

30-Day Acknowledgement

All complaints must be acknowledged within 30 days. ICO guidance notes that there is no specific wording to be used in an acknowledgement, but it must confirm safe receipt and that the complaint is being looked in to. This 30-day period begins the day after receipt, and if the final day falls on a weekend or public holiday, extends until the next working day.

Timely Response

Businesses should begin investigating a complaint from when it is received – not from the date of acknowledgement – and with undue delay. Once investigated, the complainant must be informed of the outcome without delay. Please note that businesses are not expected to carry out any investigation that is unreasonable or disproportionate to the complaint.

What types of issues could lead to a data protection complaint?

The definition of a data protection complaint is broad and may include a number of concerns including, but not limited to:

· Subject Access Requests (SARs)

· Employee monitoring

· Security incidents or data breaches

· Transparency and privacy information provided to staff

As a result, it is common for data protection complaints to arise during an individual’s day-to-day course of employment and everyday HR processes such as grievances, disciplinary investigations, sickness absence management and recruitment activities.

Practical steps for employers

To ensure compliance, employers should review their existing data protection arrangements and consider whether further measures are required.

1. Update privacy notices to clearly explain an individual’s right to make a data protection complaint to the organisation, and the individual’s continuing right to escalate concerns to the ICO.

2. Implement a formal complaints process which governs data protection complaints handling, which covers receiving and recording complaints, investigation and escalation processes, response timescales, communication with the complainant and record-keeping requirements.

3. Provide training to managers, HR teams and anyone responsible for handling employee concerns should understand what constitutes a data protection complaint, how complaints should be escalated, and relevant time limits and record-keeping obligations.

This is particularly important because complaints may first be raised informally with line managers rather than through formal channels.

To find out more about the DUAA or if you need any assistance relating to your businesses data protection, please do not hesitate to contact us at commercial@berrysmith.com or on 029 2034 5511.

For any employment related disputes relating to use of data, please feel free to contact employment@berrysmith.com