Skip to content

What the Data (Use and Access) Act 2025 means for employers 

Tue 7th Jul 2026

When employees have concerns about how their personal data is being handled, most raise them with their employer first. The Data (Use and Access) Act 2025, which brought new provisions into force on 19th June 2026, takes that practical reality and builds a formal legal framework around it, one that every employer now needs to understand. 

What the Act does is formalise the way employers must respond to those concerns. Employers have always been able to resolve data protection complaints informally, and many will continue to do so. What has changed is that organisations must now have a structured, compliant complaints process available, and must be able to demonstrate that concerns have been properly handled. For employers who have relied on ad hoc responses in the past, that represents a meaningful shift. 

What has changed 

The new framework introduces a statutory right for individuals to raise data protection complaints directly with the organisation holding their data. That right covers not just current employees but also workers, former employees, job applicants and others whose personal data the organisation processes. It sits alongside the existing route to the Information Commissioner’s Office, the UK’s data protection regulator, which remains available. The changes are introduced through a new section 164A of the Data Protection Act 2018, and they sit alongside related amendments to the UK GDPR which affect how organisations respond to data subject rights requests and what information must appear in privacy notices. 

The new regime is not creating behaviour that did not previously exist. What it is doing is imposing a degree of formality and structure on employer responses that was not previously required by law. Complaints handling will now be a visible and auditable part of how organisations demonstrate accountability under data protection law. 

What employers are now required to do 

The legislation sets out a framework of obligations rather than a prescriptive step-by-step procedure. Employers must facilitate the making of complaints through accessible means, which might include an electronic complaint form, an email address, a telephone line or a way for individuals to raise concerns in person. The Act does not mandate any single channel, but it does require that at least one accessible route exists and that individuals can easily find and use it. That accessibility requirement must be reflected in your organisation’s privacy notice, which must now explicitly inform individuals of their right to complain to you directly as well as their continuing right to approach the ICO. 

Once a complaint is received, it must be acknowledged within 30 days. That is a hard statutory requirement under section 164A of the Data Protection Act 2018. Employers must then take appropriate steps to investigate the complaint and keep the individual informed of progress and outcome without undue delay. Records of complaints and how they were handled must be maintained. 

It is worth noting that the concept of a data protection complaint under this framework is deliberately broad. Concerns about subject access requests, how long data is retained, what legal basis is being relied upon for processing, marketing communications, or security incidents can all give rise to a complaint. An employee does not need to use the phrase “data protection complaint” for it to fall within scope. If someone raises a concern about how their personal data has been handled, through whatever channel, employers need to be in a position to recognise it and deal with it accordingly. 

The steps employers should take 

The first priority is reviewing and updating your privacy notice. It needs to explain clearly that individuals have the right to raise a data protection complaint with your organisation, set out how they can do so, and confirm that the right to complain to the ICO also remains available. 

Beyond the privacy notice, employers need a documented complaints handling process. This does not need to be complex, but it does need to exist in writing, be consistently applied and be capable of standing up to scrutiny if challenged. It should cover how complaints are received and routed, how they are assessed and investigated, what timelines apply, how outcomes are communicated and how records are kept. 

Relevant staff also need to understand what is expected of them. HR teams, line managers, legal and compliance functions and any data protection officer should all know what constitutes a data protection complaint, how it should be escalated and what timelines apply. In practice, many employee concerns will reach a line manager before they reach HR, and managers should be equipped to recognise when a workplace issue is also engaging data protection rights. A grievance, a disciplinary process, a sickness absence query or a concern about monitoring at work can all involve personal data, and the line between an employment matter and a data protection complaint is not always obvious. 

That overlap is worth thinking about more broadly. Data protection complaints in the employment context rarely arise in isolation. They frequently surface alongside other HR processes, and employers should consider how their complaints handling arrangements interact with existing grievance and disciplinary procedures, and ensure that responsibilities are clearly allocated where matters overlap. 

If your organisation uses third party processors, whether that is a payroll provider, an occupational health service or any other supplier that handles employee data on your behalf, it is also worth reviewing those contractual arrangements. Where a complaint relates to data processed by a third party, you as the controller remain responsible for investigating it. Your contracts need to ensure that processors will cooperate with you when that situation arises. 

A broader shift in accountability 

The new complaints framework is part of a wider direction of travel in UK data protection regulation, one which places increasing weight on demonstrable accountability. It is no longer sufficient to have good intentions around data protection. Organisations are expected to be able to show, if challenged, how they handle concerns when they arise, with a clear process, an audit trail and evidence of appropriate outcomes. 

For most employers, the investment required to meet these obligations is relatively modest. Updating your privacy notice, documenting a complaints process and ensuring the right people understand their responsibilities need not be a significant undertaking. The risk of not doing so is greater than it might initially appear. A failure to handle a complaint appropriately is itself capable of attracting regulatory scrutiny, and an employer who cannot demonstrate that basic processes are in place is in a much weaker position if a complaint is subsequently escalated to the ICO. 

If you have not yet reviewed your data protection complaints arrangements, now is the time to do so. Coodes’ employment team can advise on what good practice looks like in your organisation and help you put processes in place that meet the new legal requirements. 

About the Author: Steph Marsh is the Head of the Employment Law team at Coodes Solicitors. She has extensive experience in supporting both employers and employees on contentious and non-contentious matters, particularly surrounding discrimination issues, redundancy situations and data protection law. 

Get in touch: steph.marsh@coodes.co.uk  01579 324 017 

Tue 7th Jul 2026
A photo of Steph Marsh

Steph Marsh

Head of Employment

Related Services & sectors

Get in touch

Call us on 0800 328 3282, or complete the form below and we’ll get back to you as soon as possible.

This field is for validation purposes and should be left unchanged.
Name(Required)

Search News & Events

Popular

Image for Changes to Paternity Leave in April 2024: What do you need to know?

Changes to Paternity Leave in April 2024: What do you need to know?

As of 6th April 2024, paternity leave will be changing to reflect a shifting attitude…

Image for Suspecting a Power of Attorney of financial abuse: what can you do?

Suspecting a Power of Attorney of financial abuse: what can you do?

What steps should you take if you suspect someone is committing financial abuse as a…

chambers ranked in, uk, 2025, codes
winner! clinical negligence team of the year
The law society Children Law logo
The law society Clinical negligence logo
The law society Conveyancing logo
The law society criminal litigation logo
The law society family law advanced logo
The law society family law logo
The law society mental health advanced logo
The Law Society's Accredited conveyancing quality scheme
The Law Society's Lexel Practice Management Standard logo
A logo for accredited personal injury
association of personal injury lawyers. apil. accredited practice

Portfolio Builder

Select the legal expertise that you would like to download or add to the portfolio

Download    Add to portfolio   
Portfolio
Title Type CV Email

Remove All

Download


Click here to share this shortlist.
(It will expire after 30 days.)