What is section 164A of the Data Protection Act 2018?

Section 164A of the Data Protection Act 2018 requires every controller to accept data protection complaints from the people whose data it holds, acknowledge each complaint within 30 days, and respond without undue delay. It came into force on 19 June 2026.

The short answer

Section 164A is the statutory data protection complaints duty for the UK. It was inserted into the Data Protection Act 2018 by section 103 of the Data (Use and Access) Act 2025, alongside a new section 164B. It applies to complaints received on or after 19 June 2026.

Before 19 June 2026 there was no direct statutory obligation on a UK controller to run a complaints process. People had a right to complain to the regulator under Article 77 of the UK GDPR, and good practice said you should handle complaints yourself, but that was practice rather than law. Section 164A changes that. Complaint handling is now a legal duty with a hard deadline attached to one part of it.

Section 164A subsection by subsection

The section is short. Below is each subsection, the legal text, and what it means for an organisation that has to run this in practice.

164A(1): the right to complain to you

A data subject may make a complaint to a controller if the data subject considers that there is an infringement of the UK GDPR or Part 3 of this Act in connection with personal data relating to the data subject.
Data Protection Act 2018, section 164A(1)

In plain English: Anyone whose personal data you hold can bring a complaint straight to you if they think you have got something wrong. The test is what they consider, not whether they are right. A complaint that turns out to be unfounded is still a complaint you have to handle.

Two things follow. First, the complaint has to relate to that person's own personal data. A general objection to your business model is not a section 164A complaint. Second, the reference to Part 3 of the DPA 2018 brings in law enforcement processing, so the duty is not limited to UK GDPR processing.

164A(2): facilitating complaints

The controller must facilitate the making of complaints under subsection (1) by taking steps such as providing a complaint form which can be completed electronically and by other means.
Data Protection Act 2018, section 164A(2)

In plain English: You have to make complaining easy. A form is given as an example of how to do it, not as a fixed requirement. What is not optional is an accessible route: people must be able to reach you electronically and by another means, such as post or telephone.

164A(3): the 30-day acknowledgement

The controller must acknowledge receipt of the complaint before the end of the period of 30 days beginning when the complaint is received.
Data Protection Act 2018, section 164A(3)

In plain English: This is the only fixed deadline in the section. The clock starts when the complaint reaches you, not when someone in your organisation recognises it as a complaint. It is an acknowledgement deadline, not a deadline to investigate or resolve.

164A(4): responding and informing the outcome

The controller must, without undue delay, take appropriate steps to respond to the complaint and inform the data subject of the outcome of the complaint.
Data Protection Act 2018, section 164A(4)

In plain English: You have to actually deal with the complaint and then tell the person what you decided. There is no fixed number of days. Undue delay is judged against the circumstances of the complaint and the nature of your organisation.

164A(5): what appropriate steps include

The steps referred to in subsection (4) include making enquiries into the subject matter of the complaint and keeping the data subject informed about the progress of the complaint.
Data Protection Act 2018, section 164A(5)

In plain English: Two named expectations: investigate, and keep the person updated while you do it. Silence for three months followed by a decision letter is not compliant even if the decision is right.

The four duties in one table

DutySubsectionTimingEvidence to keep
Facilitate complaints164A(2)ContinuousPublished route, form, policy page, contact address
Acknowledge receipt164A(3)Within 30 days of receiptDate received, date acknowledged, copy of the acknowledgement
Take appropriate steps and respond164A(4) and (5)Without undue delayEnquiry notes, progress updates, internal decisions
Inform of the outcome164A(4)Without undue delayOutcome letter or email, date sent, ICO signposting

Who has to do this

Every controller. There is no exemption by size, sector or turnover. A sole trader with a customer list is a controller. So is a village cricket club, a primary school, a charity with two staff and a national retailer. See who section 164A applies to for how this works for processors and joint controllers.

What counts as a complaint

The definition is broad: any expression of dissatisfaction about how you have handled that person's own personal data. It does not have to arrive on your form, use the word complaint, or cite a legal provision. Phone, email, post, social media and in person all count. That breadth is the operational problem, because complaints arrive in ordinary inboxes and get treated as ordinary messages. Read what counts as a complaint.

What changed for the regulator route

On 19 June 2026 Article 77 of the UK GDPR was omitted. The right to complain to the Information Commissioner now sits in section 165(2) of the DPA 2018. People can still go straight to the ICO and do not have to come to you first, although the ICO says it will usually ask them to raise the matter with the organisation first. Section 164A does not create a gate you can hide behind. See section 164A vs ICO complaints.

The new signposting duties

The same reforms amended Articles 12, 13, 14 and 15 of the UK GDPR. You must tell people about the section 164A right to complain to you in your privacy notices and in your responses to subject access requests. Two short paragraphs handle it. Copy them from privacy notice wording for section 164A.

Reporting under section 164B

Section 164B gives the Secretary of State power to make regulations requiring controllers to tell the Commissioner how many complaints they receive. No such regulations are in force, so there is no reporting duty today. The practical response is to keep records in a countable form so that a future return is a query rather than a project. See section 164B reporting.

What good compliance looks like

  1. A published complaints route that works electronically and by another means.
  2. A single place where every complaint is logged with the date it was received.
  3. An acknowledgement that goes out well inside 30 days, with a reference and a realistic timescale.
  4. Notes of the enquiries you made and the updates you sent.
  5. An outcome message that answers the complaint and signposts the ICO.
  6. A record you could produce if the ICO asked what happened.

Prove you met the duty, not just that you meant to

The work in section 164A is operational: spotting the complaint, dating it, acknowledging it within 30 days, keeping the person informed and recording the outcome. PrivacyComplaints does that part for small organisations.

Related guides

Acknowledge in 30 days and prove it.

Log complaints