Every UK controller now needs a data protection complaints process. Section 164A of the Data Protection Act 2018 came into force on 19 June 2026. It gives people a statutory right to complain to an organisation before going to the ICO. There are no exemptions, and that includes every law firm.
What changed on 19 June 2026?
Section 103 of the Data (Use and Access) Act 2025 inserted sections 164A and 164B into the Data Protection Act 2018. The commencement instrument was SI 2026/82.
Until then the gap was odd. People could complain to the ICO under the UK GDPR, but nothing obliged an organisation to run an internal process at all. The ICO encouraged it. No law required it.
Now a data subject may complain directly to the controller where they think there has been an infringement of the UK GDPR or Part 3 of the 2018 Act. The duties bite on complaints received on or after 19 June 2026.
The ICO published guidance in February 2026 and confirmed the obvious point: no exemptions, whatever the size or sector of the organisation.
What does a data protection complaints process have to do?
Four things, and they are specific.
Provide at least one accessible route for complaints. In practice that means an electronic form, plus an alternative such as email or post.
Acknowledge receipt within 30 days. That is a hard limit.
Take appropriate steps to investigate, including making enquiries into the subject matter, without undue delay.
Keep the complainant informed of progress and of the outcome, again without undue delay.
Note what is missing. There is no statutory deadline for the substantive outcome, only the undue delay standard. A complaint left drifting for months is the enforcement risk here, not a late acknowledgement.
Does this apply to law firms?
Yes, twice over.
A firm is a controller for its own client and staff data, so the duty applies directly. Nothing about being a regulated professional carves it out.
Firms also advise clients who now carry the same duty, and some of those clients sit under a second complaints regime. Telecoms operators answer to Ofcom. Payment firms and e-money institutions answer to the FCA under DISP, where written complaints attract prompt acknowledgement, which the FCA reads as five business days rather than 30.
The ICO guidance does not address that overlap. Running one integrated process usually works better than two, but the shorter acknowledgement clock governs.
A firm without a complaints route is now in breach by default, not merely exposed if something goes wrong. The 30-day acknowledgement is a hard deadline. Complaints handled badly at firm level are the ones that reach the ICO with a paper trail attached.
What has to change in privacy notices?
More than most firms have noticed, because the signposting duties reach documents that already exist.
Privacy notices must tell people about the right to complain to the controller, not only to the ICO.
Article 12(4) of the UK GDPR now bites harder. Where a controller declines to act on a request, such as rectification, erasure or restriction, it must tell the individual about two rights: the right to complain to the ICO under section 165, and the right to complain to the controller under section 164A.
Subject access responses carry the same duty under Articles 15(1)(ea) and (f). That is the change most likely to be missed, because standard SAR response templates predate it.
What should firms do now?
The duty has been live for six weeks. Anything not done yet is late rather than early.
Check the privacy notice names the internal right to complain. Check the SAR response template names both rights. Check the refusal wording used when a rectification or erasure request is declined.
Put a named owner on the 30-day acknowledgement, and log complaints on receipt so the clock is evidenced rather than assumed.
Keep records. The whole direction of this reform is demonstrable accountability, and a process nobody can evidence is worth very little when the ICO asks.
The Legal Brief covered earlier ICO work on automated decision-making in its roundup on the ICO consultation, and the profession’s wider technology obligations in its report on the Master of the Rolls on machine-age justice.
The provision itself sits at section 164A of the Data Protection Act 2018. DLA Piper has published a readiness note on the new complaints handling rules, and Squire Patton Boggs a fuller analysis of the new right to complain.