Alex is Sprintlaw’s co-founder and principal lawyer. Alex previously worked at a top-tier firm as a lawyer specialising in technology and media contracts, and founded a digital agency which he sold in 2015.
- Overview
Practical Steps And Common Mistakes
- 1. Assign ownership
- 2. Create a central logging system
- 3. Triage the issue properly
- 4. Investigate facts before replying
- 5. Respond clearly and in plain English
- 6. Link complaints to the rest of your privacy framework
- 7. Train staff on what counts as a privacy complaint
- 8. Keep records and review trends
- Common mistakes to avoid
FAQs
- Do small businesses in the UK need a privacy complaint handling procedure?
- Is a privacy complaint the same as a subject access request?
- Do we need to tell the ICO about every privacy complaint?
- How quickly should a business respond to a privacy complaint?
- What documents should sit alongside the procedure?
- Key Takeaways
A privacy complaint rarely arrives at a convenient time. It usually lands when a founder is already juggling customer issues, staff questions and day to day operations. The problem is that many businesses still treat privacy complaints as an informal customer service matter, reply too slowly, or send a defensive response before they have checked the facts. Those mistakes can turn a manageable issue into a bigger regulatory and reputational problem.
If your business collects customer details, uses marketing lists, runs an online store, manages staff records or relies on third party software, you need a clear privacy complaint handling procedure. This guide explains what that procedure should look like in the UK, when you are likely to need it, the practical steps to put in place, and the common gaps that catch startups and SMEs before they spend money on setup or sign new supplier contracts.
Overview
A privacy complaint handling procedure is your internal process for receiving, assessing, investigating and resolving concerns about how personal data is collected, used, stored, shared or deleted. In the UK, having a clear process helps you meet your accountability obligations under data protection law, respond consistently, and reduce the risk of complaints escalating to the Information Commissioner's Office.
- Decide who owns privacy complaints inside the business and who can approve responses.
- Create a simple intake process so complaints made by email, web form, phone or social media are captured in one place.
- Check whether the issue is a routine concern, a data subject rights request, a security incident, or a reportable personal data breach.
- Set internal response timeframes and keep a written record of the investigation and outcome.
- Review your privacy notice, staff training, contracts with processors and internal policies to fix the root cause.
What Privacy Complaint Handling Procedure Means For UK Businesses
For a UK business, a privacy complaint handling procedure means more than having a polite email template. It is a working process that shows your business can deal with data protection concerns in an organised, accountable and lawful way.
Under the UK GDPR and the Data Protection Act 2018, businesses that handle personal data need to be able to explain what they do with that data and respond when individuals raise concerns. A complaint may be informal at first. A customer might say they never agreed to marketing emails, an employee might question who can access HR files, or a client might ask why their details were shared with a third party. If your team does not know what to do next, the main risk is inconsistency, delay and avoidable escalation.
A proper privacy complaint handling procedure usually sits alongside your wider privacy compliance documents. That may include:
- your privacy notice
- internal data protection policy
- data retention policy
- data breach response plan
- staff confidentiality terms and employment contracts
- supplier and processor contracts
The procedure should be practical enough for frontline staff to use, but clear enough for management to review. A small business does not need layers of bureaucracy. It does need a repeatable system.
What counts as a privacy complaint?
A privacy complaint can cover a wide range of concerns. It is not limited to formal legal language or complaints labelled as a "data protection complaint".
Common examples include:
- a person says they keep receiving marketing after opting out
- a customer asks why your website collected more information than necessary
- an employee says their records were visible to unauthorised staff
- a client says your business disclosed personal data to another company without clear notice
- someone says you kept their data for too long or failed to delete it when asked
- a person complains that your privacy notice was unclear or misleading
Some of these issues may also overlap with statutory rights requests, such as requests for access, correction, erasure or objection. Your process should help staff identify when a complaint is really a rights request, or when it raises both issues at the same time.
Why written procedures matter
Written procedures matter because privacy complaints often test whether your actual business practices match your documents. If your privacy notice says one thing, your sales team says another, and your software supplier does something else, that gap will show up fast when someone complains.
A documented process also helps if the ICO later asks what happened. You may need to show:
- when the complaint was received
- who reviewed it
- what facts were checked
- whether any data breach assessment was carried out
- what response was sent
- what corrective action was taken
This is part of accountability. In plain English, it means being able to show your working, not just your final answer.
When This Issue Comes Up
This issue comes up earlier and more often than many founders expect. You do not need to be a large tech company to need a privacy complaint handling procedure.
Most startups and SMEs should think about this before they launch online, before they start collecting marketing leads, and before they sign contracts with software providers that process customer or employee data. It also becomes more pressing when the business grows, hires staff, adds new systems or expands into more targeted marketing.
Common trigger points for businesses
Privacy complaints often appear at predictable moments in a business lifecycle, such as:
- when you launch a website with contact forms, analytics tools and newsletter sign ups
- when you start selling online and process customer names, addresses, payment related information and delivery details
- when you run email or SMS campaigns and people challenge consent or unsubscribe handling
- when you use CCTV, access controls or monitoring tools in a workplace or shop
- when you hire staff and begin holding payroll, sickness and performance records
- when you outsource functions to accountants, IT providers, marketing agencies or customer support platforms
- when you receive notice of an error, misdirected email or unauthorised access incident
These are founder moments where privacy gets practical very quickly. A complaint may start with a frustrated email, but it can expose deeper issues in your systems, contracts or internal training.
Complaints can arrive through different channels
One common mistake is assuming a complaint only counts if it arrives through a formal complaints inbox. In reality, privacy concerns may come in through:
- customer support emails
- social media messages
- online reviews
- phone calls to sales or account managers
- staff reports to HR or line managers
- messages sent to your general company inbox
If those channels are not linked to a central process, your business may miss deadlines, lose context or send inconsistent replies.
Why the timing matters
The earlier you build the procedure, the easier it is to handle complaints calmly. Once a complaint escalates to the ICO, or a customer is threatening to walk away, you have less room to fix internal confusion.
This is also why privacy complaints should be considered before you print policies, before you commit to a new CRM, and before you spend money on setup for marketing systems that rely heavily on personal data.
Practical Steps And Common Mistakes
The best privacy complaint handling procedure is simple, documented and used in practice. Your aim is to help the business identify the issue quickly, investigate it properly, communicate clearly and fix any underlying problem.
1. Assign ownership
Someone needs to be responsible for privacy complaints. In a small business, that may be a founder, operations lead, office manager or compliance contact. In a larger organisation, it may sit with legal, compliance, IT security or a data protection lead.
Your procedure should state:
- who logs the complaint
- who investigates
- who decides whether legal advice is needed
- who approves the response
- who signs off on corrective action
The main mistake here is shared responsibility with no real owner. That usually leads to delay and finger pointing.
2. Create a central logging system
You need one place where all privacy complaints are recorded, even if they come through different channels. A small business may use a secure spreadsheet or ticketing system. A larger team may use a case management tool.
Your log should include:
- date received
- complainant details
- how the complaint was received
- summary of the issue
- systems or teams involved
- deadline for internal review
- outcome and action taken
Without a log, it becomes hard to show patterns. You may miss that the same issue has happened five times before.
3. Triage the issue properly
Not every privacy complaint is the same. Some are service complaints with a privacy angle. Some are formal rights requests. Some point to security failings. Some may amount to a personal data breach.
Your triage step should ask:
- what personal data is involved
- whose data is affected
- what the person is actually asking for
- whether there is any immediate containment step needed
- whether a statutory deadline applies
- whether the issue needs escalation to management, IT or external advisers
A common mistake is treating every complaint as routine customer service. That can be risky if the issue is actually a reportable breach or a rights request with a legal timeframe.
4. Investigate facts before replying
Your first response should acknowledge the concern and, where appropriate, explain that the matter is being reviewed. It should not guess, deflect or make promises before the facts are checked.
A proper investigation may involve:
- reviewing account activity and communications
- checking consent records or unsubscribe logs
- looking at internal access permissions
- speaking to the staff members involved
- reviewing processor activity and supplier contracts
- checking whether your privacy notice covered the relevant use of data
Founders often get caught here when they rely on assumptions from a team member who handled the account informally. A quick internal statement such as "we would never do that" is not an investigation.
5. Respond clearly and in plain English
Your final response should explain the outcome in clear terms. It should address the actual complaint, not just give a generic summary of your privacy policy or privacy notice.
Depending on the issue, your response may need to cover:
- what happened
- whether the business agrees there was an error
- what steps were taken to fix it
- what the person can expect next
- whether any request has been actioned, such as suppression from marketing or correction of records
- how to raise further concerns if they remain dissatisfied
The tone matters. A defensive reply can push a manageable issue towards a regulator or public complaint channel.
6. Link complaints to the rest of your privacy framework
A privacy complaint handling procedure should not sit in isolation. If the complaint shows your processes are weak, you may need to update other documents and systems.
That might include changes to:
- your privacy notice and website wording
- staff training materials
- customer terms or supplier contracts
- data processing terms with service providers
- access controls and internal permissions
- retention and deletion settings
This is where businesses often miss the bigger picture. They close the complaint but leave the root cause untouched.
7. Train staff on what counts as a privacy complaint
Staff do not need to memorise legislation, but they do need to recognise a privacy issue and know where to send it. Customer support, sales, HR and management teams should all understand the basics.
Training should cover:
- examples of common privacy complaints
- how to escalate concerns internally
- what not to say before the facts are checked
- how rights requests differ from general complaints
- when to involve IT or senior management
The common mistake is limiting privacy awareness to one person in the business. Complaints rarely stay neatly within one department.
8. Keep records and review trends
Each complaint is a data point. Over time, your log should show whether problems are isolated or systemic.
Reviewing trends can help you spot issues such as:
- marketing permissions not syncing properly between systems
- staff over-access to employee or customer records
- unclear wording in online forms
- supplier behaviour that falls outside agreed processing instructions
- confusion about retention periods
That review process is especially useful before you renew software subscriptions, before you sign a contract review with a marketing agency, or before you expand your sales activity.
Common mistakes to avoid
Most privacy complaint problems come from avoidable operational gaps rather than obscure legal points.
- Having no written procedure at all.
- Letting complaints sit in general inboxes without tracking.
- Replying before checking systems, logs and staff accounts.
- Failing to distinguish complaints from subject access requests or breach reports.
- Using a privacy notice that does not reflect actual business practice.
- Forgetting to review processor contracts and supplier responsibilities.
- Training only senior staff and leaving frontline teams unsure what to do.
- Closing the complaint without fixing the process that caused it.
If your business is growing quickly, sells online, uses contractors or stores a lot of customer data, these are sensible areas to tidy up before they become expensive distractions.
FAQs
Do small businesses in the UK need a privacy complaint handling procedure?
Yes. If your business handles personal data, even on a modest scale, you should have a clear internal process for dealing with privacy concerns. The procedure can be simple, but it should be written down and followed.
Is a privacy complaint the same as a subject access request?
No. A privacy complaint is a concern about how personal data has been handled. A subject access request is a specific legal request for access to personal data. Sometimes the same message contains both, so your team should know how to spot that.
Do we need to tell the ICO about every privacy complaint?
No. Not every complaint needs to be reported. Some issues can be resolved directly with the individual. However, if the complaint reveals a personal data breach, you may need to assess whether the breach is reportable to the ICO.
How quickly should a business respond to a privacy complaint?
There is not one universal deadline for every complaint, but businesses should respond promptly and without unnecessary delay. If the issue includes a formal rights request or breach assessment, specific legal timeframes may apply.
What documents should sit alongside the procedure?
Common supporting documents include a privacy notice, internal data protection policy, data retention policy, data breach response plan, staff confidentiality terms and relevant supplier or processor agreements.
Key Takeaways
- A privacy complaint handling procedure helps your business receive, assess, investigate and resolve data related concerns in a consistent way.
- In the UK, it supports accountability under data protection law and helps reduce the risk of complaints escalating to the ICO.
- Your procedure should cover ownership, logging, triage, investigation, response steps, record keeping and corrective action.
- Complaints often arise when businesses launch online, expand marketing, hire staff, adopt new software or outsource data processing activities.
- The most common mistakes are informal handling, poor record keeping, slow escalation, unclear privacy notices and failure to fix the root cause.
- Staff training and aligned contracts, policies and privacy documents make the procedure far more effective in practice.
If your business is dealing with privacy complaint handling procedure and wants help with privacy policies, data processing contracts, complaint response processes, and staff data protection documents, you can reach us on 08081347754 or team@sprintlaw.co.uk for a free, no-obligations chat.
Get your customer-facing terms right
What should your privacy and online terms cover?
If you collect customer data, sell online or run marketing campaigns, your public terms and privacy documents should match the real customer journey.







