The Data (Use and Access) Act 2025 (DUAA) introduced a significant change to the UK’s data protection framework which came into force on 19 June 2026.
While much of the commentary around the DUAA has focused on lawful bases for processing, cookies and automated decision-making, one of the most practical changes for law firms is the introduction of a statutory requirement to handle data protection complaints directly.
For the first time, individuals have an express legal right to raise data protection concerns with an organisation before escalating the matter to the Information Commissioner’s Office (ICO), and all controllers must have a suitable complaints process in place.
What Has Changed?
Prior to 19 June 2026, individuals could complain directly to the ICO if they believed an organisation had mishandled their personal data.
The DUAA has introduced a new statutory complaints framework requiring organisations to provide a mechanism for individuals to raise data protection complaints directly with them. The ICO expects organisations to be the first point of contact for such complaints and has issued guidance on how complaints should be handled.
The new requirements apply to all data controllers, regardless of size.
What Must Organisations Do?
Under the new regime, organisations must:
- provide a means for individuals to submit data protection complaints;
- acknowledge complaints within 30 days of receipt;
- take appropriate steps to investigate complaints without undue delay;
- keep complainants informed where investigations are ongoing; and
- communicate the outcome of the complaint without undue delay.
The ICO has also made clear that organisations should ensure complaints can be submitted through accessible channels and that staff understand how to recognise and escalate data protection complaints when they are received.
Why Does This Matter for Law Firms?
Firms should already have a complaints procedure in places that satisfies SRA requirements and complies with the expectations of the Legal Ombudsman.
However, a traditional complaints procedure may not adequately address data protection concerns.
For example, complaints relating to:
- confidentiality breaches;
- cyber incidents;
- personal data breaches;
- inappropriate disclosure of client information;
- marketing communications;
- subject access requests;
- retention of personal data; or
- wider information security concerns
may not currently be captured within the firm’s existing complaints framework.
As a result, firms should review whether their documentation expressly covers data protection and information security complaints and whether appropriate escalation routes exist internally.
Documents Firms Should Review
Many firms are focusing on updating their complaints procedure but overlooking other client-facing documentation.
Firms should consider reviewing:
Complaints Handling Procedure
The procedure should expressly include:
- data protection complaints;
- information security concerns;
- confidentiality complaints;
- the firm’s investigation process; and
- the individual’s right to escalate concerns to the ICO if dissatisfied.
Client Care Documentation
Client care letters and terms of business should explain how clients can raise data protection concerns and direct them to the firm’s complaints process.
Website Complaints Information
Complaints information on the firm’s website should be reviewed to ensure it reflects the new statutory requirements.
Privacy Notice
Privacy notices should explain how individuals can raise data protection complaints with the firm and when they may contact the ICO.
Final Response Letter Templates
Where a complaint relates to personal data, firms should ensure final response templates signpost individuals to the ICO and accurately explain their escalation rights.
Internal Policies and Training
Staff should understand that a data protection complaint may not arrive labelled as such. Complaints about confidentiality, cyber security, data breaches or information handling may all fall within the new requirements and should be routed appropriately.
Practical Steps for Compliance Teams
If your firm has not yet reviewed its documentation following the commencement of the DUAA complaints provisions, now is a good time to:
- Review your complaints procedure.
- Update client care documentation.
- Review website complaints information.
- Update privacy notices.
- Review complaint acknowledgement and final response templates.
- Update complaint registers and categorisation.
- Train staff on identifying and escalating data protection complaints.
- Record management approval of revised procedures and communications to staff.
Need Assistance?
We are helping law firms review and update their documentation to reflect the new DUAA requirements.
We can assist with reviewing and updating:
- Complaints Handling Procedures
- Client Care Letters and Terms of Business
- Website Complaints Information
- Privacy Notices
- Final Response Letter Templates
- Data Protection Policies
- Staff Guidance and Training Materials
If you would like assistance assessing whether your firm’s documentation is compliant with the new requirements, please get in touch.



