Data (Use and Access) Act 2025: New complaints obligations and what they mean for your retail business
The Data (Use and Access) Act 2025 (DUAA) has brought sweeping changes to how businesses handle personal data.
For retailers - who collect and process significant volumes of customer data through loyalty schemes, online accounts, delivery services, and targeted marketing - these changes are particularly important. Many of the updates work alongside existing data protection legislation, amending both the UK General Data Protection Regulations (UK GDPR) and the Data Protection Act 2018.
The changes have been introduced in phases, with the most recent, and arguably most significant, tranche of provisions coming into force on 19 June 2026. These introduce new requirements around complaints handling, including obligations on data controllers to: (i) make it easy for customers to raise data protection complaints, (ii) acknowledge complaints within a set timeframe, and (iii) take appropriate steps to investigate and respond.
What has changed?
Before these changes, UK GDPR gave individuals the right to lodge complaints with the Information Commissioner's Office (ICO), but there was no corresponding obligation on businesses to operate an internal complaints process. DUAA addresses this gap by creating a new right for individuals to complain directly to the data controller.
In a retail context, data protection complaints are likely to arise from a wide range of circumstances, including: customers questioning how their purchase history or browsing data has been used for profiling or targeted advertising; concerns about the sharing of personal data with third-party delivery partners or marketing agencies; or dissatisfaction with how a Subject Access Request (SAR) was handled following a customer service dispute.
The ICO has confirmed that simply exercising a data protection right does not automatically amount to a data protection complaint. For example, if a customer submits a SAR alongside a complaint about an incorrect order, the SAR itself would not be treated as a data protection complaint. However, if the complaint relates to how the complainant's personal data has been handled or the customer later raises a concern about the way the SAR was dealt with or how their personal data was handled during the order process - for instance, whether their delivery address was shared inappropriately - this would be a relevant complaint. Where there is any doubt, the ICO recommends that clarifying with the individual whether their concern relates to data protection.
What does your organisation need to do?
The first step is to put in place a documented process and policy for handling data protection complaints. Retailers should also consider providing extra training to customer service teams, store managers, and anyone else likely to be the first point of contact for such complaints, so they understand the new statutory requirements set out below.
Provide a clear mechanism for customers to complain
Retailers must give customers a clear way to raise a data protection complaint. There is no set format for this – it could be an online complaint form, a dedicated email address, or a telephone number. However, even where a formal complaints process exists, retailers must accept complaints in any form.
This is particularly important for retailers, who are likely to receive complaints through a range of channels including social media platforms such as Instagram, X (formerly Twitter), and Facebook — channels that many customers instinctively turn to when raising concerns about brands. Retailers should make sure they have robust process for handling complaints received through these channels. Where a complaint is made via a public post, it is not appropriate to address it publicly – instead, the individual should be directed to a private channel, for example by asking them to send a direct message or contact the customer services team directly.
Acknowledge complaints within 30 days
Much like the process for a SAR, any complaint about a breach of UK data protection legislation must be acknowledged within 30 days, starting the day after it is received. This does not mean the complaint must be fully resolved within that timeframe – rather, the retailer must contact the individual making the claim to confirm receipt and confirm the matter is being looked into.
Given the volume of customer interactions large retailers handle, it is important to make sure that data protection complaints are clearly separated from general customer service complaints in any case management or CRM system, so that the 30-day acknowledgement deadline is not missed.
Take appropriate steps to respond - without undue delay
Appropriate steps might include investigating whether customer data was processed in line with the retailer's privacy policy, consulting with the relevant internal team (such as the e-commerce, loyalty, or marketing team), or reviewing transactional records to assess whether personal data was handled appropriately. Unlike SARs, for complaints involving third-party processors, such as delivery couriers, payment processors, or email marketing providers, retailers will need to liaise with those third parties as part of the investigation.
Unlike SARs, there is no set timeline for responding to a complaint (aside from the 30-day acknowledgment period), although the individual should be kept informed of progress and any expected timelines. The requirement to act without undue delay means each complaint should take the time reasonably needed to investigate and resolve it properly – no longer, but equally no less.
Reporting
DUAA has also created a mechanism for the Secretary of State to introduce regulations requiring data controllers to report the number of data protection complaints they have received.
While these regulations have not yet been introduced, they are likely to follow in time. Retailers should start keeping a central log of all complaints now, including ongoing correspondence and any supporting evidence. This will also be useful in the event that the ICO makes a request to see complaints records, and may help retailers spot recurring data protection issues - for example, patterns in complaints linked to a particular loyalty programme, marketing campaign, or third-party supplier.
Practical steps for retailers
Moving forward, retailers should consider the following steps to make sure they comply with the new DUAA obligations:
- Designate a specific individual or team, such as a Data Protection Officer or dedicated compliance function, to oversee the data protection complaints process, ensuring accountability and consistency across all channels (in-store, online, and social media).
- Set internal target timelines for the resolving complaints (for example, aiming to resolve straightforward complaints within 60 days), to demonstrate that complaints are being handled without undue delay.
- Update privacy policies and cookie notices to tell customers about their right to complain directly to the retailer, and provide this information at the point of data collection- for example, at checkout, during loyalty scheme sign-up, or when obtaining consent for marketing communications.
- Review contracts with third-party processors who process personal data on the behalf, including delivery partners, payment providers, and marketing agencies, to make sure appropriate data protection complaints handling obligations are included, and that those parties will cooperate promptly in any investigation.
- Ensure that all social media channels are monitored regularly for data protection complaints, and deactivate any inactive brand accounts to prevent complaints from being missed.
- Provide targeted training to customer-facing staff - including in-store teams, contact centre agents, and social media managers - so that data protection complaints are identified and escalated correctly, rather than being handled solely as general customer service issues.
For further information, please contact Philip James or Richard Edwards-Earl.
Retail law roundup, July 2026: Contents
- CMA v Emma Matrazen case update: Reference pricing key takeaways for retailers
- Children in the digital environment: The advertising rules you should be aware of
- Data (Use and Access) Act 2025: New complaints obligations and what they mean for your retail business
- England to ban energy drink sales to under-16s
- VAT on package deals: What the KFC meal deal case means for your business
- Watching the workforce: What employers need to know about the new workplace monitoring consultation
- Star players, big stakes: Why the ASA is showing gambling ads the red card
Contact
Philip James
Partner
philip.james@brownejacobson.com
+44 (0)330 045 1022
Richard Edwards-Earl
Associate
richard.edwards-earl@brownejacobson.com
+44 (0)330 045 1049