July 26, 2026
navigating-the-new-uk-data-protection-landscape-the-implementation-of-the-data-use-and-access-act-2025-and-the-formalization-of-employee-complaints

The United Kingdom’s data protection framework is undergoing its most significant structural evolution since the post-Brexit transition, following the formal enactment of the Data (Use and Access) Act 2025 (DUAA). While much of the legislative debate surrounding the Act has focused on digital identity and smart data, one of the most operationally demanding changes for the UK’s business community is the introduction of a new statutory right for individuals—specifically employees—to lodge formal complaints directly with data controllers. This shift, which formalizes the grievance process under Section 164A of the Data Protection Act 2018, represents a pivot toward a "self-regulatory" first-response model intended to alleviate the administrative burden on the Information Commissioner’s Office (ICO) while simultaneously heightening the accountability of employers.

Beginning on June 19, all organizations acting as data controllers under the UK GDPR must adhere to a new, rigorous framework for handling data-related concerns. The reforms mandate that employers provide accessible complaint channels, acknowledge receipt of grievances within 30 days, and conduct transparent investigations into alleged infringements. For the modern employer, this is no longer merely a matter of best practice or human resources policy; it is a statutory obligation that requires a fundamental update to privacy notices, internal workflows, and staff training modules.

A Chronology of Reform: From Brexit to the DUAA 2025

The path to the Data (Use and Access) Act 2025 began shortly after the United Kingdom’s withdrawal from the European Union. In 2021, the UK government launched a consultation titled "Data: A New Direction," which sought to move away from the perceived "box-ticking" exercises of the EU’s GDPR toward a more flexible, pro-growth regime. However, maintaining "data adequacy" with the EU remained a priority, leading to a legislative balancing act.

The initial iterations of the reform—the Data Protection and Digital Information (DPDI) Bill—faced several delays due to changes in government leadership and the eventual 2024 General Election. Upon the formation of the new government, the core tenets of the DPDI Bill were refined and reintroduced as the Data (Use and Access) Act 2025. The Act received Royal Assent with the clear objective of streamlining data use for public services and the economy while modernizing the enforcement and complaint-handling mechanisms of the ICO.

The June 19 implementation date marks the culmination of this multi-year legislative journey. It signals the end of the transition period during which organizations could handle data complaints with relative informality. Under the new regime, the "informal chat" about how an employer handles an employee’s personal data is replaced by a structured legal process that carries regulatory weight.

The New Statutory Framework: Section 164A Explained

At the heart of these changes is the new Section 164A of the Data Protection Act 2018. This section establishes the legal right for a data subject to complain to a controller if they believe their personal data has been processed in a way that infringes upon the UK GDPR.

While individuals have always had the right to complain to the ICO under Section 165, the new Act introduces a mandatory middle step in the regulatory hierarchy. The government’s intent is to ensure that the ICO remains a regulator of last resort, dealing with systemic failures and high-impact breaches rather than individual grievances that could have been resolved at the source.

Under Section 164A, controllers are now legally required to:

  1. Facilitate the making of complaints by providing clear, accessible, and multiple channels for submission.
  2. Acknowledge the receipt of any complaint within a 30-day window.
  3. Take "appropriate steps" to investigate the substance of the complaint.
  4. Notify the complainant of the outcome of the investigation and any actions taken without undue delay.

This framework shifts the burden of proof regarding compliance from the individual to the organization. If an individual eventually takes their complaint to the ICO, the regulator will now ask for evidence of how the organization handled the initial Section 164A complaint. Failure to have followed the statutory process could, in itself, be viewed as a regulatory infringement, regardless of whether the underlying data processing was actually lawful.

Supporting Data: The ICO’s Regulatory Burden

The necessity for this reform is underscored by the sheer volume of complaints handled by the ICO in recent years. According to the ICO’s Annual Report for 2023-2024, the regulator received over 37,000 data protection complaints from the public. A significant portion of these—approximately 35%—related to Subject Access Requests (SARs), followed closely by concerns over data sharing and security.

Historically, the ICO has found that many of these complaints could have been resolved if the organization involved had communicated more effectively with the individual. By introducing the DUAA 2025 requirements, the government estimates that thousands of hours of regulatory time will be saved, allowing the ICO to focus on emerging threats such as Artificial Intelligence (AI) governance and international data transfers.

For employers, however, the data suggests a potential surge in internal administrative work. With the statutory right to complain now being explicitly "signposted" in every privacy notice and SAR response, employees are expected to utilize these channels more frequently. This is particularly relevant in the context of employment disputes, where data protection complaints are often used as leverage in wider litigation or grievance procedures.

Operational Shifts: Updating Articles 12 and 15

The DUAA 2025 does not merely create a new right; it weaves that right into the existing fabric of the UK GDPR. Specifically, Articles 12 and 15 have been amended to ensure that individuals are fully aware of their new powers.

Article 12(4) now dictates that if a controller decides not to take action on a request from a data subject (for example, refusing to delete data based on a "right to erasure" request), they must inform the individual of their right to complain to the controller under Section 164A, in addition to their existing right to complain to the ICO.

Furthermore, Article 15, which governs the "Right of Access," now requires that the information provided in response to a Subject Access Request must include clear instructions on how to lodge a complaint with the controller. This means that every SAR response template currently used by HR departments across the UK is likely out of date and requires immediate revision to remain compliant.

The Breadth of "Data Protection Complaints"

A common misconception among business leaders is that "data protection" only refers to major hacks or leaks. However, the ICO has clarified that the scope of the new complaint-handling regime is incredibly broad. A complaint under Section 164A can be triggered by any perceived infringement of the UK GDPR principles.

Common triggers include:

  • Direct Marketing: Employees or customers objecting to how their contact details are used for internal newsletters or promotional materials.
  • Retention Practices: Concerns that an employer is keeping "stale" disciplinary records or old recruitment CVs for longer than necessary.
  • Transparency: A belief that a privacy notice is too vague or does not accurately reflect the use of monitoring software (e.g., keystroke logging or webcam policies for remote workers).
  • Cookies and Tracking: Complaints regarding how an organization’s internal portal or public website uses tracking technologies without valid consent.
  • Lawful Basis: Challenges to the "legitimate interests" assessment an employer uses to justify certain types of data processing.

Crucially, the ICO has emphasized that a complaint does not need to be labeled as a "Section 164A Complaint" to trigger the statutory obligations. If an employee sends an email saying, "I’m not happy with how you’re using my health data," that constitutes a complaint. Organizations must therefore train their staff—not just the Data Protection Officer (DPO)—to recognize and route these communications correctly.

Expert Analysis: The Rise of the Auditable Trail

Legal experts suggest that the most significant impact of the DUAA 2025 is the formalization of "Accountability." Under the original GDPR, accountability was often a nebulous concept. Under the 2025 Act, it is highly specific and auditable.

"The new regime turns complaint handling into a measurable compliance metric," notes one legal analyst. "If the ICO investigates a company, one of the first things they will look for is the ‘Complaints Log.’ They will want to see the 30-day acknowledgments, the investigation notes, and the outcome letters. If a company cannot produce an audit trail for a complaint, they are in breach of the law, even if they did nothing wrong with the data itself."

This creates a new layer of risk for HR departments. In the past, a disgruntled employee might send several complaining emails that were handled inconsistently by different managers. Now, that inconsistency represents a systemic failure to adhere to the Data Protection Act.

Actionable Compliance Strategies for Employers

With the implementation date of June 19 now in effect, organizations are advised to move through a structured readiness checklist:

  1. Privacy Notice Audit: Update all external and internal privacy notices to include a specific section on "How to Complain to Us." This must be distinct from the section on complaining to the ICO.
  2. Template Revision: Review all standard response templates for SARs, data rectification, and data erasure requests. Ensure they contain the mandatory signposting to the Section 164A process.
  3. Centralized Intake: Establish a dedicated email address (e.g., [email protected]) or a web form to ensure complaints are captured in a single, monitored location rather than scattered across various departments.
  4. Staff Training: Conduct "spotter training" for HR, IT, and customer service teams. These are the frontline staff most likely to receive a verbal or informal written complaint. They must know how to trigger the formal 30-day clock.
  5. Record Keeping: Implement a "Data Protection Complaints Register." This should track the date of receipt, the nature of the complaint, the steps taken to investigate, and the date the outcome was communicated.

Broader Implications and Global Outlook

The UK’s move toward a mandatory internal complaint-handling system may serve as a blueprint for other jurisdictions looking to modernize their data laws without abandoning the core protections of the GDPR. While it introduces more "red tape" in the form of process, it offers organizations a valuable "right of first refusal" to fix errors before they escalate to a regulator that has the power to issue fines of up to £17.5 million or 4% of global turnover.

However, for international organizations operating across the UK and the EU, this creates a slight divergence. While the EU GDPR encourages internal resolution, it does not mandate the specific 30-day statutory framework found in the UK’s DUAA 2025. Multinationals will need to decide whether to adopt the UK’s more rigid standards globally for the sake of consistency or to maintain a specific "UK-only" complaints procedure.

In conclusion, the Data (Use and Access) Act 2025 represents a maturing of the UK’s data ecosystem. By empowering individuals with a formal right to complain and requiring controllers to meet high standards of responsiveness, the Act aims to foster a culture of transparency. For employers, the message is clear: data protection is no longer a silent background process; it is an active, auditable dialogue with the workforce. Those who fail to build the necessary infrastructure to support this dialogue risk not only the ire of their employees but the increasingly sharp teeth of the UK’s modernizing regulator.