Data protection framework
How we handle data protection complaints
This page explains how we handle data protection complaints, including how we assess them. We list the main sections below:
- How do we check if we can handle a complaint?
- How do we determine the extent to which we will investigate a complaint?
- What happens if we decide to look into a complaint in more detail?
- What happens if we don’t need to look into a complaint in more detail?
- What happens if the complainant disagrees with our outcome?
- How do we use the information we collect from complaints?
- What do we do with this information?
- How do we use this information to decide when to act?
- What happens if we decide to act?
- What happens if we decide not to act?
- What does this mean for people who complain to us?
- What does this mean for the organisations that people complain about?
If people are concerned about how an organisation has handled their personal information, they can come to us at the ICO for help.
The law requires us to:
- investigate a data protection complaint to the extent appropriate; and
- inform the person making the complaint (the complainant) of the outcome.
We assess each complaint individually and decide the extent of our involvement using the criteria set out below. Triaging complaints and handling them based on their individual circumstances allows us to:
- focus on the most serious data protection issues;
- provide timely outcomes; and
- support organisations to comply with their data protection obligations.
This means we record some complaints for information purposes only, without further investigation. However, every complaint helps us to:
- identify trends;
- spot emerging risks; and
- inform our wider regulatory work.
We’ve designed this framework, including the criteria for when we look into a complaint, to:
- be transparent about how and why we make decisions;
- give us structure and support when we consider the different types of complaints we receive; and
- help us to be as consistent as possible, while giving us the flexibility to use our judgement.
We ask people to use our complaint form as it prompts them to provide us with the information we need.
If complainants use other methods to submit their complaint, it is important that they provide as much relevant information as possible, particularly about any harm experienced. If we don’t receive all the information we need, we may record the complaint for information purposes only.
When considering a complaint, we review the details provided to determine the appropriate extent of our involvement. This can range from a light-touch review to carrying out more detailed enquiries, depending on the circumstances and in accordance with our published criteria. This is different from deciding to open an investigation, where we send a case opening letter to an organisation to notify them.
How do we check if we can handle a complaint?
Before bringing a complaint to us, we recommend that people give the organisation a chance to put things right. People and organisations can resolve many data protection concerns quickly and easily by doing this.
When we receive a complaint, we check that it relates to how an organisation has handled personal information. In some cases, another regulator may be better placed to handle a complaint where the issues overlap with their responsibilities. Our role means we don’t handle complaints that:
- aren’t about data protection issues;
- should have gone to another organisation or regulator for them to deal with because the complaint is about an area they cover; or
- are solely about an organisation’s customer service. If a complaint is about both an organisation’s customer service and a data protection issue, we handle the data protection aspect of the complaint.
How do we determine the extent to which we will investigate a complaint?
We examine each complaint carefully and use the criteria below to decide whether we can provide an outcome at this stage or need to look into it in more detail.
Due to the range of complaints we receive, this requires a degree of judgement, so we use the following criteria to help us remain as consistent as possible.
Criteria for triaging complaints
What we’ll consider to help us decide if we need to look into a complaint in more detail:
-
Has the data protection issue caused, or is it likely to cause, anyone a high level of harm?
See harm in complaints for more information.
-
Has the data protection issue significantly affected anyone, including people who need extra support to protect themselves, or is it likely to?
For example, where the issue involves children, or people who may find it harder to understand risks or take action themselves.
-
Has the data protection issue had a significant adverse impact on a substantial number of people, or is it likely to?
For example, where a policy or practice has negatively affected many people.
-
Will looking into the data protection complaint in more detail help us to significantly improve data protection rights or the way the organisation uses personal information?
For example, where there could be changes to the organisation’s policies or practices that would benefit many people if we intervene.
-
Do people have to provide their personal information to the organisation?
For example, where people have to provide their information to get essential services they need and there isn’t a practical alternative.
-
Does the data protection issue relate to our strategic priorities?
For example, where the complaint concerns an area we have decided to focus on in our regulatory work.
-
Is making enquiries in the public interest?
For example, does it raise a new or high-profile data protection issue?
- Do we already know about the data protection issue?
What we’ll consider to help us decide if we don’t need to look into a complaint in more detail:
-
Do we already know about the data protection issue?
For example, where we’ve already been told about the issue and it is being addressed.
-
Is the organisation currently taking steps to respond to the complaint? Do those steps seem adequate?
For example, where the organisation is actively looking into the complaint and appears to be taking appropriate action.
-
Do we think the organisation has complied with data protection law?
For example, where we think the information provided in the complaint suggests the organisation has done what the law requires.
-
Has the organisation already addressed the data protection issue and taken appropriate action?
For example, where the organisation has fixed the problem and put measures in place to prevent it happening again.
This list is not exhaustive. We will review the criteria periodically.
What happens if we decide to look into a complaint in more detail?
If, based on the criteria above and our judgement, we need to investigate further before providing an outcome, we allocate the complaint to a case officer. The case officer:
- weighs up the facts of what’s happened, fairly and impartially;
- asks the complainant and the organisation for further information, if they think they need it; and
- provides an outcome.
There are a number of possible outcomes for a complaint:
- We log the complaint but may only keep a record of it at this stage. Information like this can help us learn more about the way an organisation handles personal information and information rights requests.
- We may tell the complainant that it appears the organisation has complied with data protection law.
- We may tell the organisation to do more work to help resolve the complaint or explain their position more clearly to the complainant. This could mean getting the organisation to provide them with their information or correct any inaccuracies.
- We may recommend that the organisation improves how it handles personal information. For example, we might ask them to review their policies or procedures, guidance or standards.
- We may take regulatory action, although we are not able to do so for each individual complaint, and it would not be proportionate for us to do so. It is important that we focus our resources on cases where we can have the biggest impact. However, the information we gather from complaints does help us to identify broader issues with an organisation’s compliance and inform our regulatory interventions.
What happens if we don’t need to look into a complaint in more detail?
We may conclude, based on the above criteria and our judgement, that we don’t need to obtain further information or contact the organisation. We may instead decide to record the complaint for information purposes.
What happens if the complainant disagrees with our outcome?
If the complainant disagrees with the outcome of their complaint, they can ask us for a review.
To support their request, they can provide additional information, including further details about the harm they or others experienced or any circumstances that may be relevant to their case.
A reviewing officer looks at how we’ve handled the complaint and writes to the complainant explaining what they’ve found out within 30 calendar days.
Organisations can also complain to us if they disagree with the outcome of a complaint.
How do we use the information we collect from complaints?

Every complaint is important. The complaints we receive help us understand the issues that people experience when organisations use their personal information. Alongside other information we hold, we use this valuable insight to inform our wider regulatory work.
We consider the individual circumstances of each complaint and provide an outcome to the person who has contacted us.
We’ve always used information from complaints, enquiries and other sources to identify patterns, emerging issues and areas where organisations may need additional support, guidance or regulatory attention. The threshold approach helps us do this in a more consistent and structured way. It identifies organisations that receive higher volumes of complaints, allowing us to carry out a focused review of the available information.
What do we do with this information?
We record all the data protection complaints we receive about each organisation. We monitor whether the number of complaints about them reaches a certain amount within a certain time. We call this the threshold.
The current threshold is 12 complaints within one month. We’ve set this based on our experience of the types and volumes of complaints we receive. We review it quarterly.
We receive a substantial number of complaints about some organisations which means they may reach the threshold. This doesn’t necessarily mean that they haven’t complied with data protection law.
If the number of complaints about an organisation reaches the threshold, we carry out a short, focused review of the available information we have about them to understand why. This could include looking for any patterns within their complaints, such as complaints about the same issues. We look at the complaints we’ve received alongside other information we already hold.
We share information we gather from complaints with relevant teams within the ICO to support our wider regulatory work.
How do we use this information to decide when to act?
Reaching the threshold doesn’t automatically mean we’ll take regulatory action.
We use the information to decide if we need to take any further action or contact the organisation. We take into account:
- the data protection issues;
- how serious they are; and
- the context.
If we believe there is little evidence of a wider data protection issue within the organisation, we may not act further.
We only take further action when an organisation reaches the threshold if doing so is consistent with our regulatory approach and priorities.
What happens if we decide to act?
If we take further action, examples of what we may do are:
- contact the organisation about the complaints;
- give them guidance;
- highlight areas where they need to improve;
- monitor them; or
- where appropriate, refer them for further regulatory interventions.
We’ll review the organisation every six months for at least two years to see if the number of complaints about them reaches the threshold again. If it does, we’ll look to see if the complaints are about similar issues.
What happens if we decide not to act?
If we consider we don’t need to act at this time, we’ll record our decision. We’ll look at this again every six months for at least two years to see if anything changes. This will include:
- whether the number of complaints about the organisation reaches the threshold again; and
- if so, why.
What does this mean for people who complain to us?
When people complain to us:
- we investigate their complaint appropriately;
- they receive an outcome for their complaint; and
- their complaint helps to:
- protect personal information and information rights more widely; and
- improve standards so organisations use personal information more safely.
If an organisation reaches the threshold, we don’t reopen cases that we closed and recorded for information purposes.
If we need to do something further, we may contact the organisation about the types of data protection issues people have complained about.
What does this mean for the organisations that people complain about?
The number of complaints we receive about an organisation is relevant when we decide whether to act further.
If organisations handle the complaints they receive well, this can reduce the number of complaints made to us about them. This could mean we’re less likely to become involved.
We don’t want organisations to feel they should contact us to find out:
- if we’ve received complaints about them; or
- whether they’ve reached the threshold.
We will contact them about complaints if we need to.
If organisations wish to know how many complaints we’ve received about them, they can obtain details from the complaints data sets we publish on our website.