From 19th 2026 June, UK organisations are required to operate an internal data protection complaints process. Individuals must raise complaints directly with the organisation first, and these must be acknowledged within 30 days and handled without undue delay before escalation to the ICO. Businesses without a clear process in place risk complaints being escalated more quickly to regulatory review.
What the Act is and why it matters now
The Data (Use and Access) Act 2025 forms part of the UK Government’s wider data reform programme, designed to modernise how personal data is used across the economy while maintaining core privacy protections under UK GDPR, the Data Protection Act 2018 and PECR.
The Government has positioned the reforms as a way to reduce unnecessary administrative burden on organisations and improve the practical use of data across both the public and private sectors. This includes improving efficiency in areas such as public service delivery, healthcare administration and regulatory processes, where large volumes of personal data are routinely handled.
The aim is not to weaken data protection standards, but to make compliance more proportionate and operationally workable for organisations, particularly where existing rules have been considered overly complex or resource intensive.
Looking for a deeper dive? For the full parliamentary history, political context and the AI copyright debate, read our comprehensive guide: Data Use and Access Act 2025 Explained.
Key changes businesses need to know
One of the most important changes is the new complaints process. Individuals will generally need to raise a data protection complaint with the organisation first, rather than going straight to the ICO. That means businesses must be able to receive, log, acknowledge and respond to complaints properly.
The Act also introduces a more practical approach to subject access requests. Organisations will no longer be expected to carry out unnecessarily exhaustive searches where that would be unreasonable. Instead, the standard moves towards searches that are reasonable and proportionate.
There are also changes to automated decision-making, legitimate interests, privacy notices, children’s online services, cookies, and PECR enforcement. Some of these changes reduce administrative burden, but others increase the need for strong internal controls.
Alongside these operational changes, the wider regulatory structure is also expected to evolve, with the Information Commissioner’s Office (ICO) moving towards a more formalised commission-style model similar to other UK regulators. This reflects a broader shift towards more structured oversight and clearer enforcement expectations for organisations
What organisations need to do in practice
The Act introduces several operational changes that organisations will need to implement across complaints handling, DSARs marketing compliance and governance.
At a minimum, organisations should:
- Implement a formal complaints handling process with clear escalation routes
- Review DSAR procedures to ensure requests are handled proportionately
- Update PECR and marketing compliance approaches
- Ensure privacy notices and cookie practices reflect current requirements
- Strengthen internal governance and record-keeping processes
- Review use of automation or AI for additional safeguards
Who it applies to
The Act applies to any organisation that processes personal data in the UK. That includes private businesses, charities, public bodies, membership organisations, professional services firms, agencies and online businesses.
It is especially relevant if you:
Handle customer, client, employee or supplier data.
Use direct marketing by email, SMS or other electronic channels.
Operate a website that uses cookies or analytics.
Rely on legitimate interests as a lawful basis.
Use profiling or automated decision-making.
Process children’s data or operate online services likely to be used by children.
Receive complaints or requests relating to personal data.
Even if data protection is not central to your business model, the Act may still affect how you operate. If you collect personal information, you need to understand your obligations.
The complaints process and 30-day response expectation
The complaints requirement is one of the most commercially important parts of the Act. It means organisations must be ready to handle data protection complaints internally before they reach the ICO.
That creates a need for a proper process, not an informal inbox. Complaints should be recorded, reviewed and acknowledged quickly, with a clear route for investigation and response. The expectation is that complaints will be acknowledged within 30 days and dealt with without undue delay.
For businesses, the risk is that a poor or slow response can escalate a relatively straightforward issue into a regulatory problem. A clear process, supported by trained staff, is now essential.
Risks of non-compliance and enforcement
The main risk of non-compliance is not just a fine. It is the possibility of regulatory attention, reputational damage and avoidable escalation from a complainant who feels ignored.
If an organisation does not have a proper complaints process, or fails to respond in time, it may create the impression that it is not taking data protection seriously. That can make future complaints harder to manage and may increase the chance of ICO involvement.
There are also financial risks to consider. PECR penalties are significantly higher than they were previously, and failures involving email marketing, SMS, cookies or telemarketing can now lead to much more serious consequences. Businesses that rely on digital marketing should take this particularly seriously.
Recent enforcement activity highlights this regulatory focus. In 2026, the ICO issued a penalty to MediaLab.AI Inc, owner of Imgur, following concerns around the handling of children’s personal data. The case reinforces the importance of making sure that appropriate safeguards are in place where vulnerable data subjects are involved, particularly in online environments where profiling or behavioural data may be used.
How Privacy Helper supports implementation
Privacy Helper helps organisations translate the Act into practical compliance steps. That means more than simply explaining the law. It means reviewing how your business actually handles data, complaints, requests and marketing activity.
Support may include assessing current procedures, identifying gaps, updating policies and helping staff understand what needs to happen in practice. For many businesses, the biggest value is having a clear, business-friendly interpretation of what the law means day to day.
This is especially useful where compliance and commercial activity overlap, such as marketing, website tracking, customer service and internal data handling.
Relevant industries and use cases
This legislation affects a range of sectors, but it is particularly relevant to:
Professional services firms.
Marketing agencies.
Charities and membership organisations.
Recruitment businesses.
Healthcare and care providers.
Education providers.
E-commerce and online businesses.
Organisations using AI, automation or profiling tools.
If your organisation falls into one of these groups, the Act is likely to have a direct impact on how you collect, use and respond to personal data. That makes this a good time to review your compliance position and make sure your procedures are fit for purpose.
Next steps
The Data (Use and Access) Act 2025 is a reminder that privacy compliance is becoming more operational and more visible. Organisations that prepare now will be in a much stronger position than those that wait until a complaint or request forces the issue.
If you need help understanding what the Act means for your organisation, Privacy Helper can support you with practical compliance advice.















