One item in the Data (Use and Access) Amendment is to place into law a requirement that has been ICO best practice for some time, to have a formal complaints procedure.
Complaints might be generated from:
- the effect of a data breach upon a data subject
- your response to a Data Subject Access or other rights request
- the reasonableness of your retention policy
- any profiling that a data subject has been a part of
- any other data protection relation matter
The law now requires that you give data subjects a way of raising data protection complaints, acknowledge each complaint within 30 days of receipt, investigate and take appropriate action, and advise the complainant of the outcome without undue delay.
If we can help you to draft a data protection complaints policy, just let us know.