Data Protection complaints: new employer obligations now in force

Adrian Fryer
On 19 June 2026, a significant change to UK data protection law came into force. Under the Data (Use and Access) Act 2025, employees and other individuals now have a statutory right to raise data protection complaints directly with their employer before escalating concerns to the Information Commissioner’s Office (ICO).
For HR professionals, this means becoming the first port of call for a growing range of data-related concerns. Complaints may involve employee monitoring, inaccuracies in personnel records, delays in responding to subject access requests, inappropriate sharing of information, or concerns about the use of AI in workplace decision-making.
Importantly, employees do not need to use legal terminology or even describe their concern as a ‘complaint’. A simple statement such as ‘I don’t think you should be using my information in that way’ may trigger an employer’s obligations.
The legislation requires organisations to provide a mechanism for making complaints, acknowledge receipt within 30 days and, without undue delay, investigate and respond. Failure to comply could itself amount to a breach of data protection law.
This represents a notable shift in responsibility. Previously, many data protection disputes landed directly with the ICO. Now, employers must demonstrate that they have effective systems for receiving, investigating and resolving concerns internally.
For HR teams, preparation is key. Policies, complaint channels, training programmes and escalation processes should all be reviewed to ensure data protection complaints are identified and handled appropriately.
The organisations that invest time now in developing a clear framework are likely to reduce regulatory risk, improve employee trust, and minimise the likelihood of complaints progressing to the ICO.
| 
