The Information Commissioner’s Office (ICO) has announced that new legal requirements under the Data (Use and Access) Act 2025 (DUAA 2025) are now in force, requiring all organisations that handle personal data to provide a clear process for individuals to raise data protection complaints, acknowledge complaints within 30 days, investigate them appropriately, and communicate the outcome. The ICO stated that its focus is on supporting organisations to comply with the new requirements through guidance and practical examples covering common issues such as subject access requests, inaccurate personal data, and marketing concerns. Deputy Commissioner for Regulatory Policy at the ICO, Emily Keaney, said that effective complaints handling should become a routine part of good data protection practice, helping organisations resolve issues early, identify problems, and maintain customer trust. The ICO also noted that all remaining provisions of the DUAA 2025 are now in force following the completion of its 12-month commencement period and encouraged organisations to review and improve their complaints processes, highlighting that prompt and fair complaint handling can reduce the likelihood of issues escalating.