New Module

DUAA Complaints — Handle Data Protection Complaints End to End

A complete complaints procedure out of the box — complaint intake, acknowledgement, investigation, SLA tracking and ICO escalation, all evidenced for the regulator.

Acknowledge, investigate and close every complaint within the statutory one-month window.

Privacy professional tracking a DUAA complaint through acknowledgement, investigation and SLA status in Privacy360

Everything the complaints duty demands, in one workflow

The UK Data (Use and Access) Act 2025 turns complaints handling into a formal obligation. The DUAA Complaints module operationalises it: one register, one workflow, one evidence trail. [TEAM REVIEW: confirm final statutory wording and citations before publication.]

Embeddable public complaint form

A secure, branded form the organisation can embed on any website in minutes, so complainants submit directly into the platform. Walk-in, email and postal complaints are logged into the same workflow alongside platform submissions.

Automatic acknowledgement

Every complainant receives an immediate, professional acknowledgement email with their complaint reference, satisfying the DUAA acknowledgement duty without manual work.

Structured triage and investigation

A guided status workflow — Received, Triage, Identity pending, Investigating, Awaiting complainant, Resolved, Rejected, Escalated to ICO — with valid state transitions enforced, so cases are always handled consistently.

Identity verification built in

Track whether identity verification is required, requested, provided, verified or failed, with full notes retained on the record.

SLA tracking and daily breach alerts

Every complaint carries a response deadline with on-track, due-soon and overdue indicators, plus a daily SLA-breach digest to the ops mailbox so nothing slips past the one-month window.

ICO escalation handling

Record the ICO escalation reference and timeline when a complaint is escalated, keeping the regulator's view and the internal record aligned.

Full audit trail and evidence

Every action, note, status change and communication is timestamped against the complaint, giving the organisation defensible evidence of its complaints procedure for the ICO.

Category analytics

Complaints are classified by category — DSAR mishandling, suspected breach, retention and erasure, inaccuracy, marketing and cookies, lawful basis, international transfers, automated decisions — so teams spot and fix systemic issues, not just individual cases.

How it works

  1. 1

    Capture every complaint in one place

    Embed the complaint form on your website, or route email and postal complaints into the same intake, so nothing sits in a personal inbox.

  2. 2

    Acknowledge automatically

    The complainant is acknowledged immediately with a reference number, meeting the acknowledgement duty on day one.

  3. 3

    Triage, verify and investigate

    Your team triages, verifies identity where needed and investigates, with the SLA countdown visible at every stage.

  4. 4

    Resolve or escalate with evidence

    Close the complaint, or escalate to the ICO with a complete, timestamped evidence file behind you.

What your team gets

One month

Statutory response window, tracked on every case

Zero

Manual acknowledgement emails to send

100%

Of complaints audit-ready from intake to closure

  • Complaints link to the underlying DSAR or breach record in the same platform
  • Category analytics expose systemic issues before the ICO does
  • The evidence file is complete before anyone asks for it

Works alongside DSAR Management, Breach Incident Management and Global Privacy Assessments in the Privacy360 platform.

Frequently asked questions

The UK Data (Use and Access) Act 2025 requires organisations to operate a data protection complaints procedure: acknowledge complaints, investigate them and respond within a defined statutory window, with a clear route for escalation to the ICO. The DUAA Complaints module gives you that procedure out of the box, with the evidence trail to show the ICO it is operating in practice. [TEAM REVIEW: confirm final statutory wording and citations before publication.]

Yes. The module provides a secure, branded embed form that can be added to any website in minutes. Complaints submitted through it land directly in the platform's intake, alongside complaints logged manually from walk-in, email or postal channels.

Every complaint carries a response deadline derived from its intake date. On-track, due-soon and overdue indicators are visible on each case and across the register, and a daily SLA-breach digest is sent to the operations mailbox so at-risk cases are escalated internally before the statutory window closes.

No. The embed form is public and unauthenticated. Complainants submit through the form and receive their acknowledgement and reference number by email, without creating an account or signing in.

Complaints often start as a DSAR gone wrong or a suspected breach. The module sits in the same platform as DSAR Requests and Breach Incident Management, so a complaint can reference the underlying request or incident, and category analytics reveal where upstream processes are generating complaints.

The DUAA complaints duty is already live. Get your procedure on record.

See the DUAA Complaints module running end to end — intake, automatic acknowledgement, investigation, SLA tracking and ICO escalation — and leave the demo with a complaints procedure you can evidence to the regulator from day one.

Live walkthrough of a complaint from first contact to closure — including the evidence file the ICO expects to see.

Privacy-first website: We do not use tracking cookies, advertising pixels, or third-party analytics on this site. Read our Privacy Notice.