The Data (Use and Access) Act 2025 (the Act) places new obligations on employers in relation to data protection. Importantly, the Act does not replace the UK GDPR or the Data Protection Act 2018. Instead, it introduces new obligations on data controllers (including, by definition, all employers) to ensure that they have an effective, formal complaints handling framework in place for the use of personal data.
For employers, the changes mean that concerns about how employee personal data is used can no longer be dealt with exclusively by the Information Commissioner’s Office (ICO). Employers must now have their own internal process for receiving, investigating and responding to complaints.
Common workplace issues that could qualify as a complaint under the Act include concerns about how background checks have been carried out and processed; retention and use of recruitment data; workplace monitoring or tracking software; unauthorised access to personnel files; and the length of time personal data is held for.
While Article 77 of the UK GDPR already gave individuals the right to complain to the ICO, there was previously no equivalent statutory right for employees and workers to raise data protection complaints directly with their employer. The new framework closes that gap by requiring employers to take initial responsibility for complaints and to deal with them in a structured and accountable way. The legislative intention here is to encourage concerns to be addressed internally and resolved at an organisational level before regulatory intervention from the ICO becomes necessary.
Employer Obligations
To comply with the Act, from 19 June 2026, employers must:
- Give employees and workers a clear route to report or raise complaints about how their personal data is being processed. The ICO’s guidance suggests that organisations can satisfy this obligation through various mechanisms including a dedicated email address, online forms, complaint portals, telephone reporting systems, or face-to-face arrangements;
- Acknowledge complaints within 30 days, ensuring that individuals receive timely confirmation that their complaint is being considered;
- Deal with complaints promptly and effectively, including carrying out appropriate investigations without undue delay and keeping individuals informed of progress; and
- Communicate outcomes clearly, so complainers understand the result of their complaint and any steps taken by the organisation.
For employers already grappling with increasing numbers of data subject access requests (no doubt driven at least in part by AI), this is yet another compliance burden for them to face.
What practical steps should employers take?
We would encourage employers to:
- Establish a dedicated route for data protection complaints to be submitted, acknowledged, investigated and resolved, if one does not already exist
- Review and update employee privacy notices (or equivalent clauses in contracts of employment);
- Review compliance training, to ensure that HR and management teams understand how to identify, escalate and handle complaints;
- Review existing policies and procedures to ensure that complaint handling procedures align with existing grievance, whistleblowing, and DSAR processes; and
- Embed appropriate accountability, record keeping and oversight.
The new requirements represent a shift towards greater organisational accountability for data protection concerns. Employers should ensure their existing processes enable them to receive, investigate and respond to complaints in a consistent and documented way.
Taken together, these steps will help employers comply with the new statutory requirements, reduce regulatory risk and maintain transparency and trust with their workforce.