Your privacy inbox needs a process

The UK complaints duty is in force. A contact email alone is not enough.

By GDPRFix · Published · 2 min read
AI-assisted reporting and commentary · Official sources linked below.
Source / announcement date: 23 June 2026

In-force UK duty. Detailed handling depends on the complaint and applicable law.

What happened

The ICO’s 23 June 2026 announcement confirms new requirements for organisations handling personal information. People need a clear route to complain. Organisations must acknowledge complaints within 30 days, investigate appropriately and communicate the outcome. The acknowledgement deadline is not a universal deadline for resolving every complaint.

Source: ICO — original source ↗

What it means for your website

Start with the journey a real person takes: find the privacy policy, locate the contact route and explain a concern. Then follow the message internally. Who sees it when the usual contact is away? Who can investigate a tracking problem or an incorrect customer record? Your website and your internal arrangements need to join up. A scanner can look for visible complaint information, but cannot see whether your staff actually respond. GDPRFix keeps those two questions separate. Consider testing your workflow internally with a clearly marked exercise rather than sending fake complaints to other organisations.

Three useful next steps

  1. Publish a clear privacy complaint route.
  2. Name the person responsible and their cover.
  3. Track acknowledgements, investigation and the final response.

Sources & context

Official sources consulted on 1 October 2026. A regulator’s announcement records its findings at that time; it is not proof of payment or the outcome of every later appeal.

ICO — original source

Our practical suggestions are GDPRFix commentary. A public website scan cannot establish your full legal position. For advice on a specific obligation or enforcement matter, use a suitably qualified adviser.

Keep reading