Skip to Main Content
Lawyers in Edinburgh
Solicitors in Edinburgh
Family Solicitors/Lawyers in Edinburgh

Latest news and insights

24 September 2026 | Time to read: 4 mins

Grouse Licensing in Scotland: Key Changes from Autumn 2026

By Robert Scott-Dempster

New grouse licensing rules could reshape applications, licence areas and enforcement. Discover what the changes could mean for rural businesses.

23 September 2026 | Time to read: 5 mins

Awaab’s Law in Scotland: New Damp and Mould Rules for Landlords

By Stephen Gamba

Awaab's Law is bringing new responsibilities for Scottish landlords. Discover the key rules, deadlines and exceptions.

21 September 2026 | Time to read: 3 mins

Family Business Succession Planning

By Kathryn Johnston

Family business succession is changing. Discover how new IHT rules are prompting owners to rethink plans for the next generation.

17 September 2026 | Time to read: 6 mins

Six Things to Think About Before Expanding Your Rural Business

By Lorna Balfour

Before launching a new venture or expanding your rural business in a different direction, here are six key areas worth thinking about.

Data Protection Complaints: New Employer Obligations Explained

Article Employment Law for Employers
Published: 10 September 2026   |   Time to read: 3 mins

The Data (Use and Access) Act 2025 (the Act) places new obligations on employers in relation to data protection.  Importantly, the Act does not replace the UK GDPR or the Data Protection Act 2018. Instead, it introduces new obligations on data controllers (including, by definition, all employers) to ensure that they have an effective, formal complaints handling framework in place for the use of personal data.

For employers, the changes mean that concerns about how employee personal data is used can no longer be dealt with exclusively by the Information Commissioner’s Office (ICO). Employers must now have their own internal process for receiving, investigating and responding to complaints.

Common workplace issues that could qualify as a complaint under the Act include concerns about how background checks have been carried out and processed; retention and use of recruitment data; workplace monitoring or tracking software; unauthorised access to personnel files; and the length of time personal data is held for.

While Article 77 of the UK GDPR already gave individuals the right to complain to the ICO, there was previously no equivalent statutory right for employees and workers to raise data protection complaints directly with their employer. The new framework closes that gap by requiring employers to take initial responsibility for complaints and to deal with them in a structured and accountable way. The legislative intention here is to encourage concerns to be addressed internally and resolved at an organisational level before regulatory intervention from the ICO becomes necessary.

Employer Obligations

To comply with the Act, from 19 June 2026, employers must:

  • Give employees and workers a clear route to report or raise complaints about how their personal data is being processed.  The ICO’s guidance suggests that organisations can satisfy this obligation through various mechanisms including a dedicated email address, online forms, complaint portals, telephone reporting systems, or face-to-face arrangements;
  • Acknowledge complaints within 30 days, ensuring that individuals receive timely confirmation that their complaint is being considered;
  • Deal with complaints promptly and effectively, including carrying out appropriate investigations without undue delay and keeping individuals informed of progress; and
  • Communicate outcomes clearly, so complainers understand the result of their complaint and any steps taken by the organisation.

For employers already grappling with increasing numbers of data subject access requests (no doubt driven at least in part by AI), this is yet another compliance burden for them to face.

What practical steps should employers take?

We would encourage employers to:

  • Establish a dedicated route for data protection complaints to be submitted, acknowledged, investigated and resolved, if one does not already exist
  • Review and update employee privacy notices (or equivalent clauses in contracts of employment);
  • Review compliance training, to ensure that HR and management teams understand how to identify, escalate and handle complaints;
  • Review existing policies and procedures to ensure that complaint handling procedures align with existing grievance, whistleblowing, and DSAR processes; and
  • Embed appropriate accountability, record keeping and oversight.

The new requirements represent a shift towards greater organisational accountability for data protection concerns. Employers should ensure their existing processes enable them to receive, investigate and respond to complaints in a consistent and documented way.

Taken together, these steps will help employers comply with the new statutory requirements, reduce regulatory risk and maintain transparency and trust with their workforce.

 

Go Back

Our related services

To find out how we can help you with this topic or others, contact our expert teams or Fiona Cameron directly.

Subscribe

To receive regular updates like this one, you can sign up to our bulletins, and we will provide updates on the issues that matter to you.

Subscribe now

Get in touch

Contact us to find out how we can help you.

Get in touch

Lawyers in Edinburgh
Solicitors in Edinburgh
Family Solicitors/Lawyers in Edinburgh

Find a lawyer

If you are looking for a specific member of our team, you can search for them by their name here. You can also search for your regular contact by their area of expertise using the buttons below.

Visit the ‘Our People’ page for more ways to search if you can’t find who you’re looking for.