The Data (Use and Access) Act

Data protection complaints are no longer confined to customers or consumers. Increasingly, employers are finding themselves dealing with complaints from job applicants, employees and former employees about how their personal data has been collected, used, shared, retained or disclosed.

While many organisations have well established grievance and disciplinary procedures, far fewer have a dedicated process for handling data protection complaints arising in the employment context. That gap can create significant legal and practical risks.

From 19 June 2026, all organisations are required to manage data protection complaints under the Data (Use and Access) Act 2025. Under section 103, complaints must be acknowledged, and data controllers must facilitate the making of complaints by taking steps such as providing a complaint form that can be submitted electronically and by other means.

The growing intersection of employment law and data protection

Modern employment relationships generate vast quantities of personal data. From recruitment records and right to work documentation to absence management, occupational health reports, disciplinary records and employee monitoring data, employers routinely process highly sensitive information.

As employee awareness of data protection rights continues to increase, HR teams are seeing a growing number of complaints such as:

  • Allegations that personal information has been shared without authority.
  • Concerns about excessive retention of HR records.
  • Complaints regarding employee monitoring practices.
  • Challenges to the handling of health or occupational health data.
  • Dissatisfaction with responses to subject access requests.
  • Concerns about automated decision making during recruitment.

Importantly, a complaint does not need to mention “data protection” or “UK GDPR” or any specific legal right to qualify as a data protection complaint. If the substance of the concern relates to how personal data has been collected, used, disclosed, retained or secured, employers should treat it as a potential data protection complaint.

In practice, complaints may arrive through email, letters, telephone calls, internal messaging systems, social media platforms or face to face conversations. Where there is uncertainty, organisations should adopt a cautious approach and escalate the matter for assessment rather than risk overlooking a complaint that engages statutory obligations.

Not every HR complaint is a data protection complaint

One of the most common mistakes employers make is treating all complaints involving personal data as standard HR matters.

An employee may raise concerns about disclosure of personal information as part of a grievance. Equally, an employee may attempt to use a data protection complaint to challenge the outcome of a disciplinary process.

The two issues must be separated and managed through the appropriate channels.

Employers should ensure that:

  • Employment related concerns continue through the relevant HR procedure.
  • Data protection concerns are assessed separately.
  • Subject access requests are managed under the organisation’s data subject access request process.
  • Appropriate records are maintained for each process.

Where a communication contains both a complaint and a data subject rights request, such as a subject access request, organisations should treat it as both. However, each process should be tracked separately to ensure that the relevant legal obligations and deadlines are met. Failing to distinguish between these issues can lead to missed deadlines, procedural errors and increased legal exposure.

Why a formal complaint procedure matters

A structured complaint handling process provides consistency and accountability.

An effective procedure should enable employers to:

  • Identify potential data protection complaints quickly.
  • Escalate serious concerns to the Data Protection Officer (DPO) or appropriate decision maker.
  • Distinguish between data protection issues and wider employment disputes.
  • Investigate complaints fairly and independently.
  • Maintain clear audit trails.
  • Demonstrate compliance to the Information Commissioner’s Office (ICO) if challenged.

Complaints should be recorded consistently and include details such as the complainant’s contact details, the nature of the concern, the category of complaint, whether special category data is involved and whether third-party individuals are referenced. This helps organisations identify recurring issues, manage risk and improve wider compliance practices.

Particular risks in employment related complaints

Employment-related data protection complaints frequently involve special category data, including health information, trade union membership and diversity monitoring data.

Employers should be particularly alert to situations involving:

Ongoing disciplinary or grievance proceedings

Where a complaint is raised during active HR proceedings, there is a risk that the complaint process could be used to obtain information that would not otherwise be available within those proceedings.

Investigations should therefore be conducted independently and carefully coordinated with HR and legal teams.

Third party employee data

Many HR records contain information about other employees, including witness statements, investigation notes and disciplinary records.

Before disclosing information to a complainant, employers must carefully consider the rights and privacy of other individuals whose data may be contained within those records.

Occupational health and medical information

Health data attracts enhanced protection under UK data protection legislation.

Employers should ensure that any investigation involving medical information is conducted under an appropriate lawful basis and special category condition, with access restricted to those who genuinely need to see the information.

Employee monitoring and automated decision making

Complaints concerning workplace monitoring technologies, recruitment screening tools and automated decision making processes are becoming increasingly common. These complaints often require careful consideration of transparency obligations, lawful bases for processing and fairness requirements.

Timing matters

Under the Data (Use and Access) Act 2025, organisations are required to acknowledge complaints within 30 calendar days with day 1 being the day after receipt. Employers should therefore ensure that complaint handling procedures include clear acknowledgement processes and timescales.

Complaints should be logged as soon as they are identified, even where further information or identity verification may still be required. Delays can significantly increase the likelihood of escalation to the ICO and may undermine an employer’s position if litigation subsequently arises.

Where a complaint reveals a possible personal data breach, employers should immediately consider whether their data breach response procedures need to be activated. In some circumstances, personal data breaches must be reported to the ICO within 72 hours of the organisation becoming aware of the breach.

Employers should also ensure that outcome communications are clear, reasoned and proportionate. The response should confirm whether the complaint is upheld, partially upheld or not upheld, explain the reasons for that decision, identify any remedial action that has been or will be taken and explain the individual’s right to escalate the matter to the ICO if they remain dissatisfied. Where the complaint overlaps with an HR process, the response should clearly distinguish the data protection outcome from any separate employment related issue.

Lessons for employers

As workplace data processing becomes increasingly complex, employee data protection complaints are likely to become more common.

Employers should consider whether they currently have:

  • A dedicated data protection complaint procedure.
  • Clear escalation routes to the DPO or legal team.
  • Defined responsibilities between HR and data protection functions.
  • Processes for handling complaints involving special category data.
  • Training for managers and HR personnel on recognising data protection complaints.

Organisations that invest in robust complaint handling processes are better placed to resolve issues early, reduce regulatory risk and maintain trust with their workforce.

Final thoughts

Data protection complaints should not be viewed as purely compliance issues. In many cases they arise directly from workplace disputes and can become intertwined with grievances, disciplinary proceedings and employment tribunal claims.

For employers, having a clear and defensible process for managing these complaints is now an essential part of good employment law and HR practice. A structured approach not only helps demonstrate compliance with data protection obligations but also supports fairer and more effective workplace relations.

STAY INFORMED