Since 19 June 2026, every UK organisation has been legally required to operate a formal data protection complaints process. The duty comes from the Data (Use and Access) Act 2025 (DUAA), which inserts a new section 164A into the Data Protection Act 2018. There are no exemptions. One month in, many marketing teams have not noticed that it applies to them.
The ICO confirmed the timetable in February: most DUAA provisions took effect on 5 February 2026, with the complaints requirement following on 19 June.
What the duty requires
Under the new regime, set out in the ICO’s DUAA guidance for organisations, organisations must give people a clear and accessible way to submit a data protection complaint, acknowledge it within 30 days, then investigate and respond without undue delay. Records of complaints, investigation steps and outcomes should be kept, and the ICO may ask for them if a matter escalates. Privacy notices need updating to mention the right to complain directly to the organisation, alongside the existing right to complain to the ICO.
The structural change is the ordering. Individuals are now expected to raise complaints with the organisation first, before going to the regulator. That shifts early-stage accountability onto controllers. A complaint that reaches the ICO because it was never acknowledged is now a compliance failure in itself, not just poor customer service.
Why this lands on marketing first
Think about what a data protection complaint usually is in practice. I never consented to these emails. I unsubscribed and you kept sending. You have the wrong details for me. Why are you profiling me. These arrive through reply addresses, support inboxes and social channels, and they have historically been handled as customer service tickets.
From 19 June they are regulated complaints with a statutory clock. If your intake channels cannot recognise a data protection complaint when it arrives, the 30-day acknowledgement deadline starts running anyway. Marketing, customer support and compliance teams need a shared definition of what counts as a complaint and a route for getting it into the process.
The enforcement backdrop has changed too
The complaints duty is the last piece of a DUAA package that quietly rewired PECR enforcement in February. The maximum penalty for a PECR breach rose from £500,000 to £17.5 million or 4% of global annual turnover on 5 February 2026, in line with UK GDPR. The new cap applies to conduct after that date.
The ICO was already active under the old regime. In January it fined Allay Claims and ZMLUK a combined £225,000 for millions of unlawful marketing messages sent on vague and third-party consent. In June it fined KRA Consultancy £300,000 for a texting operation targeting people in financial difficulty. Both cases were decided under the £500,000 cap. Comparable conduct occurring after 5 February faces the new one.
Also live since February
Two more DUAA changes took effect on 5 February and are worth having on the record. The soft opt-in exemption now extends to charities, which can message existing supporters about fundraising and campaigning without UK GDPR-standard consent, provided the strict conditions are met. And consent is no longer required for certain low-risk cookies, including some first-party analytics and functionality cookies. Consent is still required for advertising, profiling and cross-site tracking, so cookie banners are not going anywhere for most senders.
What has not changed
The rules of compliant email marketing are the same, and the ICO’s Guide to PECR remains the reference. Consent where required, clear sender identification, a working unsubscribe, prompt opt-out processing, accurate suppression lists and records showing how consent was collected. The DUAA changed the consequences, not the rules.
What to do now
Check whether your organisation can actually receive, recognise and acknowledge a data protection complaint within 30 days, across every channel where one might arrive. Update privacy notices to reference the right to complain directly. Brief support and marketing teams on what counts as a complaint. Then review consent records and suppression processes with the new penalty cap in mind. The biggest work is behind the scenes, not in the emails themselves.







