24 February 2026

Information Commissioners Office (ICO) Complaints Consultation Outcome

By Jess Pembroke, Director of Information Law Services

The ICO has just published a summary of the feedback it has received on its proposed transformation about how it handles data protection complaints. And while the regulator’s goal is to create a more strategic, risk-based model, organisations may feel the impact just as strongly as the public[1].

So, what’s changing and what should organisations be doing now to prepare? Three key areas of change are:

1. Complaint Handling Now Comes with Statutory Obligations

Under the Data (Use and Access) Act 2025 (DUAA), organisations must now meet new statutory requirements for how they handle data protection concerns. Although this is a legislative change rather than an ICO driven policy shift, it aligns closely with the regulator’s long-standing expectation that organisations should resolve complaints “at source” wherever possible. The intention is clear: individuals should receive meaningful, timely outcomes directly from the organisation, rather than defaulting to the ICO as their first point of contact.

By keeping responsibility on organisations, the DUAA supports the ICO’s broader goal of early resolution, ensuring that organisations have the first opportunity to “put things right” before a matter escalates. This shift also allows the ICO to focus its finite resources on complaints involving serious harm, high risk processing, or systemic non-compliance, rather than investigating every individual grievance.

The ICO is now explicitly encouraging the public to raise concerns with the organisation first; something that has long been general practice but is now reinforced through statutory obligations and a clearer regulatory expectation.

Every organisation will need to:

  • Implement and maintain a formal, documented complaints process
  • Take “appropriate steps” to investigate and respond to every complaint
  • Provide complainants with a clear, accessible outcome
  • Retain evidence of decisions and rationale
  • Demonstrate independence and impartiality in how the complaint was reviewed

2. The ICO’s “Threshold Approach”: A New Kind of Oversight

From late 2026, the ICO will begin tracking all complaints it receives about each organisation even those it chooses not to investigate.

For organisations, this means reputation with the ICO will increasingly be shaped by complaint patterns, not just individual incidents.

The ICO currently plans to apply the same threshold to every organisation, regardless of its size or sector which some raised concerns about in the consultation including “treating all organisations the same could result in a greater burden on smaller organisations that may have fewer resources”[2]

3. A Sharper Regulatory Focus on “Serious Harm”

The ICO’s new model directs regulatory attention where it can have the greatest impact.

This means:

  • High harm or high-risk complaints will be prioritised‑harm or high‑risk complaints will be prioritised
  • Lower risk complaints may be logged but not investigated
  • Patterns of harm or systemic failures will attract regulatory scrutiny

The ICO won’t stop recording low‑risk complaints it will simply stop intervening. That means organisations must be prepared to resolve far more issues internally, while knowing the ICO is still monitoring complaint volumes and trends.

Complex complaints increasingly require skills beyond data protection expertise. People are using AI to generate extensive, technical questions and often expect rights that data protection legislation doesn’t provide. This can create frustration and misunderstanding and it places new demands on data protection staff.

Organisations should ensure they have in place the following:

  • Clear, plain English explanations of rights and limitations‑English explanations of rights and limitations
  • Transparent communication and timely updates on a complaints progress
  • Accessible processes accessibility for all users, including vulnerable individuals
  • Retain evidence of decisions and the rationale behind them

Need help with a data protection complaint https://naomikorn.com/data-protection-help-desk/or complex data subject access https://naomikorn.com/outsourced-data-subject-access-requests-dsars/? Contact us to learn about our services.


[1] Summary of responses to the ICO consultation on draft changes to how we handle data protection | ICO

[2] The proposed ‘threshold approach’ | ICO

Recent News

Back to News

Discover more from Naomi Korn Associates

Subscribe now to keep reading and get access to the full archive.

Continue reading