Go to Wolters Kluwer VitalLaw.comGo to Wolters Kluwer VitalLaw.com
VitalLaw®
  • Find answers to your questions
  • Log in to access your subscriptions
In depth. On point.
In depth. On point.
  • Home
  • Legal Directory
  • Home
  • Legal Directory
In depth. On point.
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations
    • DOGE Copied ‘Entire Country’s’ Social Security Data to ‘High-Risk’ Database, Whistleblower Says
    • D. Idaho: Health Insurance administrator prevails over its accidental data breach victims
    • EU Establishes Emergency Fund for Major Cyber Incidents
    • Polish Bank Fined Over GDPR Violations
    • U.K.’s ICO Seeks Input on Data Protection Complaint Procedures
    • Wash. App.: Privacy Act claim against Seattle Children's Hospital over website tracking dismissed
  • Articles
  • Articles
  • Law Firms
  • Law Firms
  • Organizations
  • Organizations

    Cybersecurity Policy Report, U.K.’s ICO Seeks Input on Data Protection Complaint Procedures, (Aug 26, 2025)

    By Tony Foley

    The United Kingdom’s Information Commissioner’s Office (ICO) opened a consultation last week on proposed changes to the processes it uses in handling data protection complaints.

    The consultation comes after the announcement of a similar ...

    By Tony Foley

    The United Kingdom’s Information Commissioner’s Office (ICO) opened a consultation last week on proposed changes to the processes it uses in handling data protection complaints.

    The consultation comes after the announcement of a similar consultation on a requirement implemented under the Data (Use and Access) Act 2025 (DUAA) that organizations must have a process in place by June 2026 to handle data protection complaints (CPR, Aug. 21).

    This additional consultation, which runs through Oct. 31, involves ICO’s draft changes on complaint handling. The agency has developed a proposed framework to assess and determine the extent to which it is appropriate for the ICO to investigate each complaint, allowing it to focus on cases where it can have the most impact and improve compliance.

    ICO cited the precipitous rise in data protection complaints, from 37,721 complaints in 2023/2024 to 42,881 complaints in 2024/2025. If the current trends continue, ICO predicted that complaints could increase to somewhere between 45,000 to 55,000 in the coming year. Acknowledging the DUAA requirement that organizations have a complaint procedure in place, ICO said that once these provisions entered into force, it expected that more complaints would be resolved without ICO intervention. It added, however, that if individuals brought complaints to the ICO, the agency would provide the most effective services available given its limited resources.

    “We are proposing changes to our processes to better support people who have experienced harm and focus our resources on those cases where we can have the biggest impact,” the ICO said. “Organisations will also benefit from reduced routine engagement on lower-risk cases, enabling them to focus on the most significant concerns. Our goal is not just to manage demand, but to raise standards around customer experience and regulatory effectiveness.”

    Interested parties can provide feedback on the draft changes and proposed framework via a Citizen Space survey.

    News: InternationalLegislation DataPrivacy

    © 2026 CCH Incorporated and its affiliates and licensors. All rights reserved.

    • Manage Cookie Preferences
    • Privacy Statement
    • Terms of Use