The 30-day acknowledgement rule under section 164A(3)

Section 164A(3) gives you 30 days from receiving a data protection complaint to acknowledge receipt. The clock starts when the complaint reaches your organisation, not when you notice it. Automated acknowledgements are allowed if they are reliable and monitored.

What the deadline actually covers

The 30 days is for acknowledging receipt. It is not a deadline to investigate, to decide, or to put anything right. Those obligations sit in 164A(4) and are governed by the words without undue delay. Confusing the two leads organisations either to panic or to under-deliver.

When the clock starts

The period of 30 days begins when the complaint is received. Received means received by your organisation. It is the moment the email lands in a monitored address, the letter arrives, the call is taken or the message reaches your social account.

  • A complaint emailed to a general enquiries address is received that day, even if it sits unread.
  • A complaint made to a shop assistant or a volunteer is received that day, even if it is not written down.
  • A complaint routed to the wrong department is received on the day it first arrived, not the day it reaches the right desk.
  • A complaint by post is received when it arrives, not when it is opened.

Counting the 30 days

The wording is 30 days beginning when the complaint is received, so day one is the day of receipt. There is no working-days concession and no clock stop while you wait for information from the complainant. Treat 30 as calendar days and do not plan to use them all. Weekends, holidays and staff absence are your problem, not the complainant's.

Worked example
EventDateNote
Complaint emailed to info@1 JulyDay 1. Clock starts here
Email opened by staff9 JulyIrrelevant to the deadline
Logged as a complaint10 JulyLog the 1 July receipt date, not this one
Acknowledgement sent12 JulyCompliant, with 18 days to spare
Statutory latest acknowledgement30 JulyDo not aim for this

What a compliant acknowledgement says

Section 164A does not prescribe content. The point of an acknowledgement is to confirm you have the complaint and to set expectations, so keep it short and specific.

  1. Confirmation that you have received a data protection complaint, and the date you received it.
  2. A short restatement of what you understand the complaint to be about.
  3. A reference number or identifier so both sides can track it.
  4. Who is handling it and how to reach them.
  5. A realistic indication of when you expect to respond, and a commitment to update if it takes longer.
  6. That the person can also complain to the ICO, with a link.

Acknowledgement template

Dear [name]

Thank you for your message of [date received], which we have treated as a data protection complaint under section 164A of the Data Protection Act 2018.

Reference: [REF]

We understand your complaint to be about [one or two sentence summary]. If that is not right, please tell us and we will correct our record.

[Name], [role], is handling your complaint and can be reached at [email] or [phone]. We aim to give you a substantive response by [date], and we will keep you updated if we need longer.

You also have the right to complain to the Information Commissioner's Office at ico.org.uk/make-a-complaint at any time.

Yours sincerely
[Name]

Are automated acknowledgements allowed?

Yes. Nothing in section 164A requires a human to send the acknowledgement. An automated acknowledgement is compliant, and for most small organisations it is the safest way to meet the deadline, provided two conditions hold.

  • It is reliable. It fires for every route a complaint can arrive by, records what was sent and when, and does not silently fail.
  • It is monitored. Someone reads the incoming complaint and acts on it. An auto-reply on an unwatched inbox meets 164A(3) and then breaches 164A(4).

This is exactly where the operational burden sits: sending on time is easy, proving you sent on time months later is not. Complaint logging software stamps the receipt date, fires the acknowledgement and keeps both in the audit trail.

If you miss the 30 days

Acknowledge immediately, record why it was late, and say so plainly to the complainant. A missed deadline is a breach of a statutory duty, but a candid, prompt recovery with a clear record is far better than a silent one. Then fix the cause, which is nearly always an unmonitored channel.

Prove you met the duty, not just that you meant to

The work in section 164A is operational: spotting the complaint, dating it, acknowledging it within 30 days, keeping the person informed and recording the outcome. PrivacyComplaints does that part for small organisations.

Related guides

Acknowledge in 30 days and prove it.

Log complaints