Data Protection · From the Auditor's Desk

DUAA 2025: how to build a compliant data-complaints process

The UK's new data-protection complaints duty is now in force. Every organisation that handles personal data needs a clear way for people to complain, a 30-day acknowledgement clock, and a documented process to investigate and respond — whatever its size. Here is the step-by-step, mapped to ISO 27001.

Jason Misters · IRCA® Registered Principal Auditor · 29 June 2026

A quiet but significant change to UK data-protection law has just taken effect. The Data (Use and Access) Act 2025 (DUAA) introduces an explicit complaints duty on organisations that process personal data — and the Information Commissioner's Office has confirmed it is now in force. In plain terms: if someone wants to complain about how you handle their personal data, you must make it easy for them to do so, acknowledge it on a clock, and deal with it properly. There is no exemption for small organisations.

If you already run an ISO 27001-style information security management system, this is a small, well-defined addition rather than a scramble. If you don't, it's a clear, contained procedure you can stand up this week. This piece sets out exactly what the duty requires and gives you a step-by-step data-complaints process, mapped to the relevant ISO 27001 controls, plus the legal-register entry to record it.

What the DUAA complaints duty actually requires

The DUAA amends the existing UK data-protection regime (UK GDPR and the Data Protection Act 2018) to place a direct obligation on controllers to facilitate the making of complaints by data subjects, and to handle them within set timeframes. The core requirements:

  • Provide a clear route to complain — for example a complaints form or a clearly signposted contact channel — so a person can raise a concern about your processing of their personal data without having to dig for it.
  • Acknowledge within 30 days. Once a complaint is received, you must acknowledge it within 30 days of receipt.
  • Take appropriate steps to respond — investigate the complaint and respond without undue delay, keeping the complainant informed of progress and the outcome.
  • No size exemption. The duty applies to organisations of any size that act as controllers — sole traders, SMEs and large enterprises alike.

Alongside the duty on organisations, the reforms strengthen the ICO's hand: the regulator can ask complainants to raise the matter with the organisation first, and has clearer powers where organisations fail to deal with complaints properly. The practical message is simple — the complaint should land with you first, and you need a process that handles it visibly and on time.

The duty in one line

Give people an obvious way to complain about how you use their personal data, acknowledge it within 30 days, investigate it, and tell them the outcome — and keep a record that you did.

Why this maps neatly onto ISO 27001

If you hold or are working towards ISO 27001:2022, you already have most of the scaffolding. The complaints duty touches several Annex A controls and management-system clauses directly:

DUAA complaints requirement Where it lives in ISO 27001:2022
A clear, documented complaints procedure Clause 7.5 (documented information); A.5.1 (policies for information security)
Handling complaints about personal-data processing A.5.34 (privacy and protection of personally identifiable information)
Identifying the legal obligation itself A.5.31 (legal, statutory, regulatory and contractual requirements) — i.e. your legal register
Investigating and recording the complaint as an event A.5.24-A.5.28 (information security incident management); A.5.34 where personal data is involved
Acting on findings & preventing recurrence Clause 10.1 / 10.2 (improvement and corrective action)

In other words, the DUAA doesn't ask you to build a parallel system — it asks you to make sure your existing information-security and privacy management explicitly covers data-protection complaints, with a named owner, a clock, and an audit trail.

A step-by-step data-complaints procedure

Here is a procedure you can adopt directly. Keep it short, assign an owner, and make sure the timings are visible to whoever handles complaints.

1

Publish a complaints route

Put a clearly-labelled "data protection complaint" option on your website privacy notice and contact page (a form or a monitored mailbox). Tell people what to include and what happens next. Make it findable without having to ask.

2

Log every complaint on receipt

Record the date received, the complainant, the substance of the complaint and the data involved. The received date starts the 30-day acknowledgement clock — capture it precisely.

3

Acknowledge within 30 days

Send a written acknowledgement within 30 days confirming you've received the complaint, who is handling it, and the expected timescale for a substantive response. Don't let this slip — it's the one hard deadline in the duty.

4

Investigate without undue delay

Assign an owner, gather the facts, and assess what happened against your obligations. Treat it like a mini incident investigation — what was processed, was it lawful, what went wrong, and what's the remedy.

5

Respond with the outcome

Give the complainant a clear, plain-English response: your findings, what you've done or will do, and their right to escalate to the ICO if they remain dissatisfied.

6

Act on the root cause & record it

If the complaint exposed a weakness, raise a corrective action and close the loop. Keep the full record — receipt, acknowledgement, investigation, response and any action — as your evidence the duty was met.

The 30-day acknowledgement is the part organisations trip over — not because the complaint is hard, but because no one owns the clock. Assign an owner and put the received date and acknowledge-by date on every entry, and the duty largely looks after itself.

Put it on your legal register

The final, easily-forgotten step is to record the obligation itself. ISO 27001 control A.5.31 expects you to identify and keep up to date the legal and regulatory requirements relevant to your information security — and an auditor will look for the DUAA complaints duty on your legal register now that it's in force. A good entry captures the regulation, the authority (the ICO), what you must do (facilitate complaints, acknowledge within 30 days, investigate and respond), the evidence (your procedure and complaint log), and a review date.

Doing it in PICMS

This is exactly the kind of obligation PICMS is built to absorb. The Cyber & Privacy pack and the legal register keep the DUAA complaints duty recorded against ISO 27001 control A.5.31, with the procedure stored as controlled documented information and complaints logged and tracked against the 30-day clock. The AI evidence-to-clause mapping then shows the complaints procedure sitting against A.5.34 and the relevant management-system clauses, so when an assessor asks "how do you meet the new data-complaints duty?", the answer is a few clicks rather than a fresh project.

To be plain about what software does and doesn't do: PICMS doesn't make you compliant on its own, and this article is general guidance rather than legal advice. What it does is keep the obligation on your register, the procedure current, and every complaint logged and answered on time — so demonstrating you meet the duty is a matter of pulling up the record rather than reconstructing it under pressure.

Jason Misters — IRCA® Registered Principal Auditor

Lead auditor and ISO consultant. Founder of Training Assurance Consultancy and PICMS. Writes from years of hands-on experience implementing and auditing information security and privacy management systems in UK businesses. Verifiable on the CQI-IRCA register.

Get the DUAA complaints duty on your register — and keep it audit-ready.

The PICMS Cyber & Privacy pack records the data-complaints duty against ISO 27001, stores your procedure as controlled documented information, and logs every complaint against the 30-day clock.

Start a Free Trial Book a Demo