Compliance

The New Data-Complaints Rule Is Here: What the DUAA Means for Your Documents

Published 24 June 2026

The DUAA complaints rule, frequently asked questions

What is the Data (Use and Access) Act 2025 (DUAA)?

The DUAA is the UK's new data law. It received Royal Assent in June 2025 and amends, rather than replaces, the UK GDPR, the Data Protection Act 2018 and PECR. Its data-protection provisions have been commencing in stages through 2026, refining areas such as legitimate interests, automated decision-making, and how organisations must handle data-protection complaints.

What do I have to do by 19 June 2026?

From 19 June 2026 every organisation that processes personal data must have a clear way for people to make a data-protection complaint, must acknowledge a complaint within 30 days, and must respond without undue delay. In practice that means a published complaints procedure, an easy route to complain (such as an online form), assigned responsibility, and a log that records each complaint and how it was handled.

Does the data-complaints rule apply to small businesses?

Yes. The statutory complaints-handling requirement applies to all organisations that process personal data, with no exemption for small businesses or charities. The scale of your process can be proportionate to your size, but you still need a documented procedure and a record that you followed it.

How quickly must I acknowledge a data complaint?

You must acknowledge a data-protection complaint within 30 days of receiving it, and then investigate and respond without undue delay. Keeping a timestamped record of when each complaint was received, acknowledged, investigated and closed is the simplest way to evidence that you met the deadline.

How can software help me comply?

A document and workflow platform can turn the rule into a repeatable process: capture each complaint, route it to the right person, enforce the 30-day acknowledgement, and keep an immutable, timestamped audit trail of every step. DocFlow does exactly this, so you can prove compliance rather than just assert it.

Make the 30-day deadline automatic

See how DocFlow captures every data-protection complaint, enforces the acknowledgement deadline and keeps an audit-ready trail of every step.