DUAA Complaints — Handle Data Protection Complaints End to End
A complete complaints procedure out of the box — complaint intake, acknowledgement, investigation, SLA tracking and ICO escalation, all evidenced for the regulator.
Acknowledge, investigate and close every complaint within the statutory one-month window.

Everything the complaints duty demands, in one workflow
The UK Data (Use and Access) Act 2025 turns complaints handling into a formal obligation. The DUAA Complaints module operationalises it: one register, one workflow, one evidence trail. [TEAM REVIEW: confirm final statutory wording and citations before publication.]
Embeddable public complaint form
A secure, branded form the organisation can embed on any website in minutes, so complainants submit directly into the platform. Walk-in, email and postal complaints are logged into the same workflow alongside platform submissions.
Automatic acknowledgement
Every complainant receives an immediate, professional acknowledgement email with their complaint reference, satisfying the DUAA acknowledgement duty without manual work.
Structured triage and investigation
A guided status workflow — Received, Triage, Identity pending, Investigating, Awaiting complainant, Resolved, Rejected, Escalated to ICO — with valid state transitions enforced, so cases are always handled consistently.
Identity verification built in
Track whether identity verification is required, requested, provided, verified or failed, with full notes retained on the record.
SLA tracking and daily breach alerts
Every complaint carries a response deadline with on-track, due-soon and overdue indicators, plus a daily SLA-breach digest to the ops mailbox so nothing slips past the one-month window.
ICO escalation handling
Record the ICO escalation reference and timeline when a complaint is escalated, keeping the regulator's view and the internal record aligned.
Full audit trail and evidence
Every action, note, status change and communication is timestamped against the complaint, giving the organisation defensible evidence of its complaints procedure for the ICO.
Category analytics
Complaints are classified by category — DSAR mishandling, suspected breach, retention and erasure, inaccuracy, marketing and cookies, lawful basis, international transfers, automated decisions — so teams spot and fix systemic issues, not just individual cases.
How it works
- 1
Capture every complaint in one place
Embed the complaint form on your website, or route email and postal complaints into the same intake, so nothing sits in a personal inbox.
- 2
Acknowledge automatically
The complainant is acknowledged immediately with a reference number, meeting the acknowledgement duty on day one.
- 3
Triage, verify and investigate
Your team triages, verifies identity where needed and investigates, with the SLA countdown visible at every stage.
- 4
Resolve or escalate with evidence
Close the complaint, or escalate to the ICO with a complete, timestamped evidence file behind you.
What your team gets
One month
Statutory response window, tracked on every case
Zero
Manual acknowledgement emails to send
100%
Of complaints audit-ready from intake to closure
- Complaints link to the underlying DSAR or breach record in the same platform
- Category analytics expose systemic issues before the ICO does
- The evidence file is complete before anyone asks for it
Works alongside DSAR Management, Breach Incident Management and Global Privacy Assessments in the Privacy360 platform.
Frequently asked questions
The DUAA complaints duty is already live. Get your procedure on record.
See the DUAA Complaints module running end to end — intake, automatic acknowledgement, investigation, SLA tracking and ICO escalation — and leave the demo with a complaints procedure you can evidence to the regulator from day one.
Live walkthrough of a complaint from first contact to closure — including the evidence file the ICO expects to see.
Complaints handling guides
Practical articles from Formiti's Global DPO team on running this work well.