BITO

Why retailers must get ahead of new data complaint rules

New rules for handling data protection complaints are set to come into force in June 2026, creating more than just another compliance exercise for data controllers, such as retailers. 

Commercial solicitor Ashleigh Dibb from Forbes Solicitors explains why retailers should review and rethink their complaints processes.

Customer-friendly complaints 

New rules, introduced through the Data (Use and Access) Act 2025 (DUAA), will require all organisations acting as data controllers to provide clearer, more accessible routes for customers to raise concerns about how their personal data is used. This is a significant moment for retailers, which increasingly value customer insight for driving sales, building loyalty and informing product innovation.   

Retailers are, arguably, at the forefront of collecting and utilising personal information. Customer data has long provided a backbone for loyalty schemes and cards that have since been replicated across many different sectors. Data has enabled promotional offers to become increasingly personalised, creating new opportunities for cross-selling and upselling that grow basket sizes and introduce shoppers to new categories. However, with the growing value of personal information comes greater exposure to risk. 

Customers are seemingly more aware than ever of how their data is collected and used. At the same time, regulatory expectations continue to rise. The DUAA reforms are designed to simplify aspects of the UK’s data regime, while maintaining high standards, and place a sharper focus on how businesses respond when things go wrong.

From 19 June 2026, customers will have a clearer statutory route to challenge how their data is handled, and regulators expect customer complaints to be dealt with quickly, transparently and effectively.

As pioneers in collecting and handling personal information, retailers may understandably think they are already well-positioned for the new rules. This could prove a risky approach, and retailers should not assume that their existing customer service or complaints processes will automatically meet new requirements. 

Complacency may well impede compliance, proving costly. Breaches of individuals’ data protection rights under the new DUAA rules could expose businesses to substantial regulatory penalties. Depending on the nature and seriousness of the infringement, the Information Commissioner’s Office (ICO) has the power to issue fines of up to £17.5 million or 4% of a retailer’s total global annual turnover, whichever is the highest, for the most serious breaches.

Faster, more transparent resolution

Under the new rules, retailers must ensure customers can easily submit data-related complaints through accessible and appropriate channels. This could include email, online forms, phone support or messaging platforms, particularly those channels and formats that are already used during customer communications. The key requirement is visibility and ease of use. If a customer cannot easily find or understand how to make a complaint, a retailer may well be deemed to be falling short of regulatory requirements.

The DUAA also introduces expectations around responsiveness and transparency. Complaints must be acknowledged within 30 days, investigated without undue delay, and customers kept informed throughout the process. Clear outcomes must be provided, along with routes for escalation if a customer is not satisfied.

For retailers handling large volumes of customer interaction, from online orders and returns to in-store transactions and delivery services, this can create an operational challenge. But it also presents an opportunity. A well-managed complaints process can reinforce trust at a time when customer loyalty is increasingly fragile and competition is intense.

Documentation will be key

While the new legislation does not explicitly require a standalone data complaints policy, documentation will play a critical role in demonstrating compliance. Retailers should consider how data complaints are currently captured and tracked across different parts of the organisation. 

In practice, data-related concerns can arise in a wide range of everyday interactions, including:

  • Delivery errors linked to incorrect address data
  • Marketing communications sent without proper consent
  • Loyalty scheme or account issues
  • Returns, refunds or customer service disputes involving personal information

Without clear and consistent documentation, it becomes difficult to evidence how decisions were made or whether complaints were handled appropriately.

Updating privacy notices is also essential. Customers should be clearly informed about how their data is used and how they can raise concerns. Crucially, these notices must align with real-world processes, or retailers risk creating gaps between policy and practice.

The supply chain factor

For retailers, data use rarely sits within a single organisation. E-commerce platforms, delivery partners, payment providers and marketing agencies all play a role in processing customer information. This makes third-party relationships a critical area of risk under the new DUAA regime.

Retailers are best placed to review supplier agreements to ensure partners are required to promptly notify them of any data-related complaints and provide support in resolving issues. Without these safeguards, businesses may struggle to meet regulatory expectations, especially when complaints span multiple parties in the customer journey.

A moment to rethink and reset

The DUAA reforms are designed, in part, to encourage complaints to be resolved directly between customers and organisations, before escalating to the ICO. This shifts the emphasis firmly onto the internal processes of data controllers.

To support compliance, retailers may well want to check existing complaint channels and question whether these are clear, accessible and easy to use. How user-friendly are they? It can also be beneficial to speak with teams internally to determine their understanding of complaint procedures. Do they have full clarity of processes, roles and responsibilities? Are escalation routes clear? And, how are complaints recorded and evidenced? This could include a review of the process for documenting decision-making during the management and resolution of complaints. 

Clear procedures, accessible reporting channels, well-trained staff and consistent record-keeping will be essential to meeting the new data protection obligations.

Dorotape