New employee right to raise data protection complaints with employers

24 June 2026 3 min read

By Rachel Chapman

At a glance

  • A new statutory right under the Data (Use and Access) Act 2026 (DUAA) took effect on 19 June 2026, requiring organisations to handle data protection complaints internally.
  • Employers must provide a means to complain, acknowledge complaints within 30 days, investigate them, and issue an outcome without undue delay.
  • Employees can raise concerns about how their personal data is collected, used, stored or secured, including issues relating to subject access requests or data breaches.
  • Complaints do not need to be labelled as such and can be handled through existing processes, such as grievance procedures, provided statutory obligations are met.
  • This development shifts responsibility onto employers to maintain effective complaint-handling processes and increases the risk of regulatory scrutiny and disputes if processes are inadequate.

A new statutory right for employees and other individuals to complain directly to organisations about data protection concerns came into force on 19 June 2026. Under the DUAA, organisations must have arrangements in place to receive and manage data protection complaints. They must:

  • Provide a way for individuals to make data protection complaints.
  • Acknowledge complaints within 30 days of receipt.
  • Take appropriate steps to respond without undue delay.
  • Notify the complainant of the outcome without undue delay.

This is a significant shift. Many data protection disputes previously went straight to the Information Commissioner’s Office (ICO), but employers must now be able to show that they have effective internal processes for receiving, investigating and resolving concerns. An employee may complain if they believe their employer has breached data protection law in the way it has handled their personal information. Complaints may relate to, for example:

  • How the employer handled a subject access request or other rights request.
  • The security measures used to protect their information, including where they have been affected by a data breach, whether or not it is reportable to the ICO.
  • How the employer has collected, used or retained their personal information, including where it is stored, how long it is kept, and whether it is accurate

Employees do not need to use specific language, refer to the DUAA, or label their concern as a ‘complaint’. Employers do not need a separate complaints tool. Data protection complaints can be built into existing processes, such as grievance procedures, provided the employer can still meet its data protection obligations, including investigating and providing an outcome without undue delay.

Employers must tell employees, when collecting their personal information, that they can complain directly to the employer, for example through the employee privacy notice. Employers can decide who within the organisation is best placed to handle data protection complaints and should ensure that staff can recognise a data protection complaint and know where to direct it. Internal data protection training should also cover how complaints are handled.

If the employee is unhappy with the employer’s response, or if the employer fails to address the issue, complaints can be escalated to the ICO.

The ICO has published guidance on meeting these new requirements.

What happens if employers get this wrong?

  • Increased ICO scrutiny: Where there are repeated employee escalations this may trigger wider investigation – we have seen this with recent enforcement activities.
  • Employment disputes: Risk of grievances and tribunal claims, particularly where complaints relate to disciplinary matters, monitoring, or breaches.
  • Reputational harm: Damage to employer brand from publicised enforcement or high-profile complaints.

Immediate next steps for employers

Employers should now take steps to:

  • Review existing processes and confirm whether they can meet the statutory timelines.
  • Update employee privacy notices to include the new complaint right.
  • Designate responsibility for handling complaints.
  • Train relevant staff (eg managers) to recognise and escalate data protection complaints.
  • Prepare template acknowledgment and response documents.
  • Implement a system to log and track complaints and timelines.
Questions? Launch AI Assist