Legal update

Data (Use and Access) Act 2025

A new statutory right for employees and other individuals to raise data protection complaints directly with their employer

On 19 June 2026, the final data protection provisions of the Data (Use and Access) Act 2025 (DUAA) came into force, creating a new statutory right for individuals, including employees, to raise data protection complaints directly with their employer or other data controller (a controller). The Information Commissioner’s Office (ICO) has also updated its online guidance to reflect the changes.

New right to complain directly to the controller

A data subject (e.g. an employee) may now make a complaint to the controller if they consider that, in connection with their personal data, there is an infringement of the UK GDPR or the Data Protection Act 2018.

  • Controllers must facilitate the making of complaints by taking steps such as providing a complaint form which can be completed electronically or by other means.
  • Controllers must acknowledge receipt of a complaint within 30 calendar days from when the complaint is received.
  • They must also, without undue delay, take appropriate steps to respond to the complaint, including making enquiries into the subject matter to the extent appropriate and informing the complainant about progress and the outcome.

Employer considerations

Employers should:

  • Establish or update an internal data protection complaints procedure that meets the requirements.
  • Consider providing an electronic complaints form and at least one alternative channel (e.g. a postal address) so that complaints are accessible to all employees.
  • Make clear to staff how to raise a data protection complaint.
  • Keep anyone who raises a complaint updated on progress and record all enquiries and outcomes in a complaints log to ensure transparency.

Employers should ensure that the new data protection complaints procedure sits clearly alongside (and does not duplicate or conflict with) existing grievance, whistleblowing, and subject access request procedures. It may be helpful to include a brief explanation in employee handbooks clarifying when each procedure applies and how they interact.

Updated subject access request (SAR) guidance

The DUAA makes clear that organisations are only required to make “reasonable and proportionate” searches when responding to a SAR, codifying what was previously a regulatory expectation.

  • Controllers must respond without undue delay and within one month of receipt, however, the period may be extended by up to a further two months where necessary if the request is complex or the data subject has made a number of requests.
  • Where the controller asks the data subject for clarification (only where reasonably required), the one month time limit pauses on the day clarification is requested and resumes the day after clarification is received.
  • When refusing a SAR, the controller must now inform the individual of the reasons for refusal, their right to complain to the controller and the ICO, and their ability to enforce the right through the courts.

Employer considerations

  • Employers should update SAR procedures to reflect the “reasonable and proportionate searches” standard.
  • The ICO’s updated guidance may be beneficial for employers.
  • Additionally, employers should train relevant staff (such as HR, Legal and IT) on the “stopping the clock” mechanism for clarification requests and on the one month (extendable) timescale.
  • It is also key that SAR refusal letters include all required information, including the individual’s new right to complain to the controller and to the ICO.

Consequences of breach

The ICO has signalled that its initial focus will be on helping organisations embed good practice, rather than taking immediate or early enforcement action. However, employers should not treat this as a reason to delay compliance. It should be noted that the ICO can take action, including enforcement notices and impose financial penalties, where organisations fail to engage constructively or where there are serious or repeated failures, including for example, against organisations that fail to comply with the new complaints duty. Employers should ensure they can demonstrate a proactive approach to compliance if challenged.

Employers should review contracts and internal policies (including employee data processing agreements and privacy notices) to ensure that they reflect the new requirements, and in respect of third party processors, to ensure the contracts reflect the requirement for that processor to notify them promptly if a complaint is received and to cooperate with any enquiries. Employers should take the time to train HR teams and managers to recognise and deal with complaints effectively.

Disclaimer

This update should not be treated as legal advice and only provides general information on the issues discussed.

Previous
Back to overview