In-force UK duty. Detailed handling depends on the complaint and applicable law.
What happened
The ICO’s 23 June 2026 announcement confirms new requirements for organisations handling personal information. People need a clear route to complain. Organisations must acknowledge complaints within 30 days, investigate appropriately and communicate the outcome. The acknowledgement deadline is not a universal deadline for resolving every complaint.
Source: ICO — original source ↗
What it means for your website
Start with the journey a real person takes: find the privacy policy, locate the contact route and explain a concern. Then follow the message internally. Who sees it when the usual contact is away? Who can investigate a tracking problem or an incorrect customer record? Your website and your internal arrangements need to join up. A scanner can look for visible complaint information, but cannot see whether your staff actually respond. GDPRFix keeps those two questions separate. Consider testing your workflow internally with a clearly marked exercise rather than sending fake complaints to other organisations.
Three useful next steps
- Publish a clear privacy complaint route.
- Name the person responsible and their cover.
- Track acknowledgements, investigation and the final response.
Sources & context
Official sources consulted on 1 October 2026. A regulator’s announcement records its findings at that time; it is not proof of payment or the outcome of every later appeal.
ICO — original sourceOur practical suggestions are GDPRFix commentary. A public website scan cannot establish your full legal position. For advice on a specific obligation or enforcement matter, use a suitably qualified adviser.