How to handle a data protection complaint, step by step

A section 164A complaints procedure has nine steps: receive, log, acknowledge, investigate, update, decide, inform the outcome, signpost the ICO, and keep the record. Nothing here needs specialist legal input, but every step needs a date attached to it.

The nine steps

  1. 1Receive and recogniseThe hard part is recognition, not receipt. Staff need one sentence of training: if someone is unhappy about how we handled their information, it is a data protection complaint and it goes to [name] today. See what counts as a complaint.
  2. 2Log it with the receipt dateLog it the same day. Capture who complained, how to reach them, the date and channel it arrived by, and what they are unhappy about in their own words. The receipt date is the single most important field you will ever record for this duty.
  3. 3Acknowledge within 30 daysSend the acknowledgement early, not on day 29. Include a reference, a named handler and an expected response date. Automated acknowledgements are fine if they are reliable and monitored. See the 30-day acknowledgement rule.
  4. 4InvestigateSection 164A(5) names making enquiries into the subject matter as an appropriate step. Pull the actual records: the emails, the system logs, the consent record, the retention setting. Ask the staff involved while they still remember.
  5. 5Keep the complainant informedAlso named in 164A(5). Set an update rhythm, for example every 14 days, and stick to it even when the update is that you are still waiting on something.
  6. 6Decide the outcomeAddress each element separately. Upheld, partly upheld, or not upheld, with a reason. Decide what changes: delete the data, correct it, tighten a retention rule, retrain a team, apologise.
  7. 7Inform the complainant of the outcomeThis is the express duty in 164A(4). Say what you found, what you concluded and what you have done or will do. Plain language, no legal fog, no unexplained refusals.
  8. 8Signpost the ICOTell them they can complain to the Information Commissioner under section 165 of the DPA 2018 if they remain dissatisfied, and give the link. See section 164A vs ICO complaints.
  9. 9Record and countClose the record with the outcome and the dates. Keep it in a form you can count, because section 164B may one day require numbers.

A realistic timetable

StageInternal targetStatutory position
Log the complaintSame dayNo express deadline, but it sets your receipt date
AcknowledgeWithin 5 working daysWithin 30 days, section 164A(3)
First substantive updateWithin 14 daysPart of keeping the person informed, 164A(5)
Outcome for a simple complaintWithin 30 daysWithout undue delay, 164A(4)
Outcome for a complex complaintWithin 60 days with updatesWithout undue delay, 164A(4)

What to do when the complaint is also a subject access request

This happens often. Someone complains about your handling of their data and asks for a copy of it. Run both tracks: the SAR to its own one-month statutory deadline, and the complaint to section 164A. Do not let the SAR swallow the complaint, and remember your SAR response must now include the section 164A signposting wording.

Where small organisations trip up

  • One inbox nobody owns during annual leave.
  • Complaints handled verbally with nothing written down, so there is no record and no receipt date.
  • A response that argues with the complainant instead of answering the complaint.
  • No ICO signposting, which reads as an attempt to keep the person in-house.
  • Records spread across personal mailboxes, so the file cannot be reconstructed six months later.

Prove you met the duty, not just that you meant to

The work in section 164A is operational: spotting the complaint, dating it, acknowledging it within 30 days, keeping the person informed and recording the outcome. PrivacyComplaints does that part for small organisations.

Related guides

Acknowledge in 30 days and prove it.

Log complaints