← Back to Regulatory Updates
Data Protection 19 JUNE 2026 · UNITED KINGDOM

Every business now needs a data complaints procedure — the law changed on 19 June 2026

The Data (Use and Access) Act 2025 created a new legal obligation for businesses that hold client personal data. A documented complaints process is now required where the Act applies, and failure to have one exposes you to ICO enforcement.

Reviewed / published: In force 19 June 2026

In short

The Data (Use and Access) Act 2025 created a new legal obligation for businesses that hold client personal data. A documented complaints process is now required where the Act applies, and failure to have one exposes you to ICO enforcement.

What changed

The Data (Use and Access) Act 2025 received Royal Assent on 19 June 2025. Exactly one year later, on 19 June 2026, the provisions covering data protection complaints handling came into force. This applies to every sole trader who holds personal data about clients — including sole traders and small clinics that hold client personal data.

The obligation is specific. You must provide a clear, accessible way for individuals to submit a data protection complaint to you — including an electronic route such as an online form or email address. That complaint must be acknowledged within 30 days of receipt. You must investigate without undue delay, keep the complainant informed of progress, and document the complaint from receipt through to outcome.

This represents a structural change to the UK data protection landscape. Previously, individuals could go directly to the ICO with concerns about how their data was handled. The new regime creates a mandatory first step: they must raise it with you before the ICO will accept the complaint. The ICO has already confirmed it will use this gateway as a supervisory monitoring tool. Businesses that cannot demonstrate a functioning procedure when a complaint is made will face a harder regulatory conversation.

The maximum fine for ICO enforcement action under UK GDPR is £17.5 million or 4% of global annual worldwide turnover — for a sole trader, the latter is the relevant figure. Beyond the financial penalty, the reputational consequence of an upheld ICO complaint can be damaging in sectors where client trust is the business.

Who this affects

All sectors

Regulatory body: ICO / Information Commissioner's Office

What businesses should review

  • In force: 19 June 2026. Already law.
  • Acknowledgement deadline: 30 days from the day after the complaint is received.
  • Action now: Your CompliPass pack includes a ready-made Data Complaints Procedure covering acknowledgement timescales, investigation steps, and ICO escalation wording. Add a reference to this procedure in your client-facing privacy notice. Set up a dedicated email address or form for data complaints so you can evidence the receipt date. Keep a log of every complaint received.
  • If you don't: ICO enforcement action, data protection claims from individuals, and public reputational damage. A sole trader who receives a complaint and ignores it will be in a worse position with the ICO than one who follows a documented process even imperfectly.