New statutory right for data access - employers take note
- Jul 6
- 3 min read

The Data (Use and Access) Act 2025 has introduced a new statutory right for individuals, including employees to complain directly to data controllers about alleged UK GDPR infringements. For employers and other data controllers, this is a significant practical compliance change, not merely a technical footnote.
From 19 June 2026, privacy notices, DSAR templates and internal complaints processes will need to reflect this new change. Employers will have to be able to show that complaints are easy to raise, properly investigated and dealt with without unwarranted delay.
This marks a significant departure from previous legislation, creating a positive obligation for companies and employers: whereas a DSAR request previously needed to be clearly identified as such when submitted, this new obligation could be triggered by something as simple as a general complaint or concern being raised about how data is being used.
Employers take note
Employers that have not yet reviewed their arrangements should act now. Tightening templates, updating notices, documenting complaint procedures, training your teams and putting audit mechanisms in place should be immediate priorities.
The right to complain directly to the Information Commissioner’s Office remains as a channel but the new framework is designed to encourage data disputes to be resolved before that escalation. It also creates an obligation on data controllers to specifically inform individuals of their right to complain to the ICO.
A new complaints regime is here
The new section 164A of the Data Protection Act 2018 gives individuals the right to complain to a data controller if they consider that their personal data has been processed in breach of the UK GDPR.
Data controllers must therefore have a clear process for handling those complaints. In broad terms, they need to be able to:
provide at least one accessible route for submitting complaints
acknowledge complaints within 30 days of receipt
keep records of complaints and outcomes
investigate and respond without undue delay
keep individuals informed of progress and outcome
signpost the right to complain in privacy notices and relevant response templates
The concept of a “data protection complaint” can cover concerns about DSARs, retention, transparency, direct marketing, tracking technologies, security incidents or the lawful basis for processing. That makes the change operationally significant. Employers need the right signposting embedded across privacy notices, DSAR responses and other data subject rights communications.
Employers should be ready to show what was received, when it was acknowledged, how it was investigated, what outcome was reached and why.
To keep on top of this, employers should focus on the following priorities:
Privacy notices, DSAR templates and data subject rights responses should explain the right to complain to the organisation, how to do so and the continuing and established right to complain to the ICO.
Frontline staff, HR, legal, compliance and DPOs should know how to recognise a data protection complaint, where to escalate it and the timelines that apply.
Create a documented process covering intake, acknowledgement, classification, escalation, investigation, response, record-keeping and governance oversight.
These complaints should be logged, monitored and evidenced. Internal systems should capture receipt dates, key milestones, investigation notes, outcomes, repeat issues and management reporting.
Check whether processor, outsourcing and group arrangements support complaint investigations and wider data subject rights handling, especially where personal data processing is outsourced or shared across entities.
The takeaway: act before complaints escalate
The new regime is part of a wider shift towards demonstrable and clear accountability. From 19 June 2026, employers now need to do more than comply in substance. They have to be able to show that complaints can be received, managed and resolved in a structured, transparent and timely way.
A well-run business should theoretically have most of these arrangements in place. However if not, now is the time to implement formal structures to handle such complaints.
Failure to act on these new requirements could lead to increased interrogation from the ICO and/or additional focus under the regulatory microscope.
Should you require any tailored advice on the above, please get in touch.
By Ronan d'Cruz, Solicitor, Constantine Law
