AILegalDocsAI.co.uk
← Legal guides
23 Sep 2026 · updated 25 Sep 2026Data protection complaint guide

Data protection complaint and ICO escalation

How to structure a UK data-protection complaint, preserve the response record and escalate an unresolved complaint to the Information Commissioner's Office.

This practical guide organises “data protection complaint after an unsatisfactory controller response information commissioner office”: outcome, chronology, evidence, remedy, deadline, filing and service.

Outcome and recipient

Define the result, correct recipient, procedural stage and reference. Separate the requested remedy from the dispute narrative.

Chronology

List events, service, payments and replies by date. Connect every material date to a reliable record.

Evidence

Match each important fact with a contract, invoice, email, decision, photograph, account record or proof of service.

Remedy and deadline

State a measurable amount, action, document or correction and a realistic response date. Remove inconsistent requests.

Procedure

Check venue, form, signature, fee, copies, filing and service. Keep a complete copy and evidence of submission.

Quality control

Verify names, addresses, references, dates, amounts and exhibits. Separate established facts from argument and unresolved points.

Checklist

  • recipient and reference
  • chronology and deadlines
  • requested outcome
  • evidence and attachments
  • signature, fee, filing and service

Start with the organisation first

In most cases, give the organisation that handled the personal information a fair opportunity to put the problem right before escalating it to the Information Commissioner’s Office. Make clear that you are raising a data-protection complaint, identify the relevant account or reference, describe what happened in a short factual summary and state the outcome you want. Keep a copy of the complaint and evidence showing when it was sent.

You do not need to fill the complaint with legal terminology. A specific description of the processing problem is usually more useful. Identify the information involved, the important dates and the decision or action that is disputed. If the wider dispute also concerns customer service, employment, a contract or another non-data-protection issue, separate those matters so the privacy complaint can be considered on its own facts.

Separate the complaint from a rights request

A data-protection complaint can overlap with a subject access request or another individual-rights request, but they are not the same procedural step. Keep them separately identifiable. For a subject access request, record what information was requested, what was supplied, what appears to be missing and any explanation for redactions or refusal. Current ICO guidance states that a subject access request generally must be dealt with without undue delay and at the latest within one calendar month, subject to the rules on identity, clarification and permitted extensions.

For a complaint, preserve the organisation’s acknowledgement and substantive response separately. ICO guidance published in 2026 states that an organisation receiving a data-protection complaint must acknowledge receipt within 30 days. It should then take appropriate steps to investigate, keep the complainant informed and provide a final response without unnecessary or unjustifiable delay.

Build a chronology and evidence index

Prepare a short chronology before drafting. Record each important event, its date, the document that proves it and why it matters. Useful entries can include the original collection or disclosure of information, a privacy notice, a rights request, acknowledgement, identity or clarification request, partial disclosure, redactions, refusal reasons, follow-up correspondence and the final response.

Attach only the evidence needed to understand the unresolved points. Keep the originals. Give documents descriptive names and use the same order in the evidence index and the attachment bundle. If a date is uncertain, identify it as uncertain instead of presenting an estimate as established fact.

When to escalate to the ICO

If the organisation has had an opportunity to address the data-protection issue and the outcome remains unsatisfactory, prepare the ICO escalation around the unresolved points rather than starting the story again from the beginning. State what you asked the organisation to do, what it decided, which points remain disputed and where the evidence for each point can be found.

Current ICO public guidance recommends raising the complaint with the ICO within three months of the last meaningful contact with the organisation about the issue. Record that date in the file. Do not confuse an ICO complaint with a court limitation period or another procedural deadline; if litigation is contemplated, check those time limits separately.

Prepare a concise ICO bundle

Start with a one-page chronology and a numbered list of unresolved issues. Then include the original complaint to the organisation, its acknowledgement, its final response, the important intermediate correspondence and the key documents that demonstrate the handling problem. For a subject access dispute, a schedule showing what was requested, what was provided, what was redacted and what remains missing can be more useful than a large unsorted email archive.

Keep the requested regulatory outcome separate from any claim for compensation or other private remedy. The ICO considers data-protection complaints and decides what regulatory response is appropriate; it does not act as the complainant’s legal representative and its public guidance explains that it cannot award compensation. Court remedies, if relevant, require a separate assessment.

Quality control before submission

Check names, addresses, references, dates and attachment labels. Make sure each factual assertion is traceable to a document or clearly identified as your understanding. Remove duplicate attachments and material that is not relevant to the data-protection issue. If screenshots are used, preserve enough context to identify the service, date and relevant action.

Finally, compare the requested outcome with each numbered complaint point. If the request is for correction, identify the information to correct. If it concerns a subject access response, identify the categories still missing or the redactions that remain unexplained. If it concerns disclosure or security, identify the information affected, the event and the evidence showing why the organisation’s response remains inadequate.

Practical escalation checklist

  • give the organisation a reasonable opportunity to address the privacy issue;
  • keep proof of the original complaint and its acknowledgement;
  • separate complaints from subject access and other rights requests;
  • prepare a dated chronology tied to evidence;
  • list unresolved issues individually;
  • retain the final response and meaningful follow-up correspondence;
  • prepare a short indexed evidence bundle;
  • record the date of the last meaningful contact;
  • check separately for any court or tribunal deadlines;
  • verify current ICO guidance before relying on a draft.

Official sources

This material is informational. Check current law, official instructions, jurisdiction and deadlines for the particular matter.

Start