
A major shift in data protection law is now in effect, and it directly impacts how you manage your workers. On 19 June 2026, a new statutory right came into force under the Data (Use and Access) Act 2025.
Workers can now raise data protection complaints directly with you, their employer. Your business is legally required to handle these concerns internally before they escalate to regulators, such as the ICO (Information Commissioners Office).
What triggers a complaint?
Employees do not need to use official legal terms or even use the word "complaint." A simple, informal comment triggers your legal obligations.
Examples of phrases that now count as official complaints include:
"I don't think you should be using my information in that way."
"Why are you sharing my contact details with that contractor?"
"I'm not comfortable with how you track my hours on that app."
The ICO recommends that if you are unsure whether your employee is making a complaint that you should ask them to clarify what is meant by what they have said.
Your legal obligations
If a worker raises a concern about their personal data, your business must meet four specific requirements:
Provide a clear pathway.
Give workers a designated way to submit data complaints.
Acknowledge within 30 days.
Confirm receipt of the complaint within 30 days.
Act without delay.
Take immediate, appropriate steps to investigate the issue and keep your worker informed.
Record your actions and report the outcome.
Inform the worker of your final decision without undue delay.
Failure to meet these steps is a direct breach of data protection law.
Why it matters
Previously, most worker data disputes went straight to the ICO. Now, the burden of initial resolution sits firmly on your shoulders.
Employers often handle sensitive worker data, including:
Seasonal worker passports and visas
CCTV footage
Vehicle and machinery GPS tracking data
Biometric clock-in systems.
You must have an internal system to receive, investigate, and resolve data concerns. The ICO has published official guidance to help employers set up these systems.
See How to deal with data protection complaints | ICO
The legislation does not require you to have a formal complaints policy, but the ICO recommend having one as a way to demonstrate compliance with the accountability and transparency requirements under GDPR.
The ICO have extensive powers to take action for a breach of the UK GDPR or DPA 2018 which includes assessment notices, warnings, reprimands, enforcement notices and penalty notices (administrative fines). For serious breaches of the data protection principles, ICO have the power to issue fines of up to £17.5 million or 4% of your annual worldwide turnover, whichever is higher.
How we can help
Our team of Employment advisers can provide advice, guidance and support with the aim of reducing the risk of you finding yourself defending a claim. Contact us on the Employment Service Helpline 0370 840 0234.
More from NFU Employment Service:
Not yet an NFU Employment Service member? Join today and take advantage of a host of guidance to support you navigating the complex world of employment law.
You'll also receive access to a wide range of member benefits – with discounts ranging from cars to health insurance.
For more information, call us on 0370 840 0234 or email us at [email protected]
