The UK's new data-protection complaints duty is now in force. Every organisation that handles personal data needs a clear way for people to complain, a 30-day acknowledgement clock, and a documented process to investigate and respond — whatever its size. Here is the step-by-step, mapped to ISO 27001.
A quiet but significant change to UK data-protection law has just taken effect. The Data (Use and Access) Act 2025 (DUAA) introduces an explicit complaints duty on organisations that process personal data — and the Information Commissioner's Office has confirmed it is now in force. In plain terms: if someone wants to complain about how you handle their personal data, you must make it easy for them to do so, acknowledge it on a clock, and deal with it properly. There is no exemption for small organisations.
If you already run an ISO 27001-style information security management system, this is a small, well-defined addition rather than a scramble. If you don't, it's a clear, contained procedure you can stand up this week. This piece sets out exactly what the duty requires and gives you a step-by-step data-complaints process, mapped to the relevant ISO 27001 controls, plus the legal-register entry to record it.
The DUAA amends the existing UK data-protection regime (UK GDPR and the Data Protection Act 2018) to place a direct obligation on controllers to facilitate the making of complaints by data subjects, and to handle them within set timeframes. The core requirements:
Alongside the duty on organisations, the reforms strengthen the ICO's hand: the regulator can ask complainants to raise the matter with the organisation first, and has clearer powers where organisations fail to deal with complaints properly. The practical message is simple — the complaint should land with you first, and you need a process that handles it visibly and on time.
Give people an obvious way to complain about how you use their personal data, acknowledge it within 30 days, investigate it, and tell them the outcome — and keep a record that you did.
If you hold or are working towards ISO 27001:2022, you already have most of the scaffolding. The complaints duty touches several Annex A controls and management-system clauses directly:
| DUAA complaints requirement | Where it lives in ISO 27001:2022 |
|---|---|
| A clear, documented complaints procedure | Clause 7.5 (documented information); A.5.1 (policies for information security) |
| Handling complaints about personal-data processing | A.5.34 (privacy and protection of personally identifiable information) |
| Identifying the legal obligation itself | A.5.31 (legal, statutory, regulatory and contractual requirements) — i.e. your legal register |
| Investigating and recording the complaint as an event | A.5.24-A.5.28 (information security incident management); A.5.34 where personal data is involved |
| Acting on findings & preventing recurrence | Clause 10.1 / 10.2 (improvement and corrective action) |
In other words, the DUAA doesn't ask you to build a parallel system — it asks you to make sure your existing information-security and privacy management explicitly covers data-protection complaints, with a named owner, a clock, and an audit trail.
Here is a procedure you can adopt directly. Keep it short, assign an owner, and make sure the timings are visible to whoever handles complaints.
Put a clearly-labelled "data protection complaint" option on your website privacy notice and contact page (a form or a monitored mailbox). Tell people what to include and what happens next. Make it findable without having to ask.
Record the date received, the complainant, the substance of the complaint and the data involved. The received date starts the 30-day acknowledgement clock — capture it precisely.
Send a written acknowledgement within 30 days confirming you've received the complaint, who is handling it, and the expected timescale for a substantive response. Don't let this slip — it's the one hard deadline in the duty.
Assign an owner, gather the facts, and assess what happened against your obligations. Treat it like a mini incident investigation — what was processed, was it lawful, what went wrong, and what's the remedy.
Give the complainant a clear, plain-English response: your findings, what you've done or will do, and their right to escalate to the ICO if they remain dissatisfied.
If the complaint exposed a weakness, raise a corrective action and close the loop. Keep the full record — receipt, acknowledgement, investigation, response and any action — as your evidence the duty was met.
The final, easily-forgotten step is to record the obligation itself. ISO 27001 control A.5.31 expects you to identify and keep up to date the legal and regulatory requirements relevant to your information security — and an auditor will look for the DUAA complaints duty on your legal register now that it's in force. A good entry captures the regulation, the authority (the ICO), what you must do (facilitate complaints, acknowledge within 30 days, investigate and respond), the evidence (your procedure and complaint log), and a review date.
This is exactly the kind of obligation PICMS is built to absorb. The Cyber & Privacy pack and the legal register keep the DUAA complaints duty recorded against ISO 27001 control A.5.31, with the procedure stored as controlled documented information and complaints logged and tracked against the 30-day clock. The AI evidence-to-clause mapping then shows the complaints procedure sitting against A.5.34 and the relevant management-system clauses, so when an assessor asks "how do you meet the new data-complaints duty?", the answer is a few clicks rather than a fresh project.
To be plain about what software does and doesn't do: PICMS doesn't make you compliant on its own, and this article is general guidance rather than legal advice. What it does is keep the obligation on your register, the procedure current, and every complaint logged and answered on time — so demonstrating you meet the duty is a matter of pulling up the record rather than reconstructing it under pressure.
The PICMS Cyber & Privacy pack records the data-complaints duty against ISO 27001, stores your procedure as controlled documented information, and logs every complaint against the 30-day clock.