New Data Protection Complaints Rules: What VCSE Organisations Need to Know

06/08/2026

From 19 June 2026, new requirements under the Data (Use and Access) Act 2025 mean that all organisations handling personal data, including charities and other VCSE organisations, must have a clear process for managing data protection complaints. Organisations must provide a straightforward route for individuals to make complaints, acknowledge them within 30 days, investigate concerns without undue delay, keep complainants informed, and communicate the outcome.

Why does this matter for charities?

Charities can hold a significant amount of personal data, including information about beneficiaries, volunteers, donors, staff, supporters and service users. In many cases, this information may be particularly sensitive.

While many organisations already have a general complaints procedure, the new requirements introduce a specific obligation to handle data protection complaints through a defined process. The aim is to help individuals resolve issues directly with organisations before involving the ICO.

For VCSE organisations, effective complaints handling is not just about compliance. It can also help strengthen trust, demonstrate accountability, and identify weaknesses in processes before they become more serious data protection incidents.

What should organisations do now?

The ICO recommends that organisations review their existing arrangements and ensure staff understand how to recognise and respond to data protection complaints.

A good starting point is to:

  • Publish a clear, accessible data protection complaints procedure.
  • Provide an easy way for people to raise concerns.
  • Ensure staff and volunteers know how to identify and escalate complaints.
  • Keep records of complaints and actions taken.
  • Review privacy notices and policies to make sure complaint routes are clearly signposted

For many charities, these changes can be incorporated into existing complaints and governance processes rather than requiring a completely new system

The new requirements apply regardless of organisational size. Many smaller charities may not currently have a formal process for handling data protection complaints, making now a good time to review policies and procedures. The ICO has emphasised that its guidance is intended to support organisations of all sizes, particularly smaller organisations that may have fewer dedicated compliance resources.

Further information and practical guidance are available from the ICO’s Guidance on Preparing for Data Protection Complaints.