The 19 June 2026 ushered in the latest set of regulatory changes under the Data (Use and Access) Act 2025. If you are a data controller, now is the time to understand what these updates mean for your organisation, writes Jason Mcleod
Whilst organisations acting as data controllers have always been required, under data protection law, to provide accessible mechanisms for individuals (data subjects) to exercise their rights and raise concerns about personal data processing, the new regulations now make this process a mandatory requirement. All organisations, no matter their size, must have a formal process in place where an individual can raise a data protection complaint directly with them, should they believe their personal data has been processed in breach of data protection legislation. Organisations must now ensure that they:
- Have a clear process for receiving complaints;
- Make it easy for individuals to complain;
- Tell people about their right to complain;
- Acknowledge complaints within the statutory time limit;
- Investigate and respond without undue delay.
Key actions to take include, reviewing current arrangements with data processors to check that any contracts contain the appropriate provisions on complaints handling. Alongside this, DSAR response wording and privacy notices should be updated to mirror an individuals’ new right to complain. It would also be worth bearing in mind whether any staff training may be required, providing employees with a better understanding of how to recognise and handle data protection complaints should they arise.
Please do not hesitate to get in touch should you require any assistance with reviewing your current arrangements, need more information about the Data (Use and Access) Act 2025 or preparing completely new regimes. We are always happy to help!
This article was originally published on: 22 July 2026



