11 September 2026 · 5 min read
The new right to complain: what changed for your practice on 19 June 2026
If a client emailed you tomorrow to say they were unhappy with how you'd handled their records, would you know what you're obliged to do next, and by when?
Since 19 June 2026, that question has a legal answer. The Data (Use and Access) Act 2025 gave individuals a new statutory right to complain directly to the organisation holding their data, and it put specific duties on you as the controller: give people a way to complain, acknowledge it within 30 days, look into it without unreasonable delay, and tell them the outcome. It applies to every data controller, regardless of size, which means it applies to a solo private practice exactly as it applies to a hospital trust.
This is separate from the ICO's £52 annual fee, which is about registering as a controller. This is about what you do once someone actually complains. Neither replaces the other.
What follows is a plain description of a legal requirement, not legal advice, and it doesn't take account of your particular setup. Where a complaint turns on the specifics of your situation, that's a question for a solicitor or your professional body, not this article.
What actually triggers this
The right covers complaints about how you're handling someone's personal data under UK GDPR or the Data Protection Act 2018: things like "I don't think you should still hold my notes", "I asked for a copy of my file and haven't heard back", or "I don't understand why my details were shared with someone." It is not a general complaints route for how the therapy itself went, and it's not a channel for anything clinical.
A complaint can arrive however the person chooses to send it, including by social media, and you can't insist it only comes through one channel. You can offer an email address or a form as your preferred route, but you can't refuse a complaint because it turned up a different way.
The three things you now have to do
Give people a way to complain, and tell them it exists. Your privacy notice should say, in plain terms, that someone can raise a data protection complaint with you directly, and how. If you don't currently have a privacy notice that covers this, it needs updating.
Acknowledge within 30 days. The clock starts the day after you receive the complaint. This is an acknowledgement, not a resolution: a short reply confirming you've got it and are looking into it is enough at this stage.
Investigate and respond without undue delay, then tell them the outcome. There's no fixed deadline for the substantive response the way there is for the acknowledgement, but "undue delay" means you can't sit on it. Keep a record of when the complaint arrived, what you did to look into it, and what you told the person, because the ICO can ask to see that record.
If someone isn't satisfied with your response, or you haven't dealt with it in a reasonable time, they can still escalate to the ICO. This right to complain to you sits alongside that, not instead of it.
What a solo practice actually needs
There's no requirement to publish a formal complaints policy on your website. What you do need is something written down for yourself: a note of the process so that if a complaint arrives, you're not improvising it under stress. For most solo practitioners that's genuinely short:
- A line in your privacy notice telling clients they can complain to you about data handling, and how.
- A simple log (a spreadsheet row is fine) recording when a complaint came in, what you did, and when you replied.
- A default acknowledgement reply you can send quickly, so the 30-day point never gets missed because you were on annual leave or between clients all week.
If you already did a privacy-notice and retention review when you paid your ICO fee, this is the next entry on the same list, not a separate project.
Where this sits next to a clinical complaint
It's worth being precise about the boundary. A client unhappy with your data handling has this new statutory route. A client unhappy with the therapy itself, or with something they'd want to raise as a professional-conduct matter, goes through your professional body's complaints process instead, not this one. Keep the two separate in your own head and in anything you tell clients, because conflating them either scares people away from a legitimate data complaint or drags a clinical disagreement somewhere it doesn't belong.
What Faresay does and doesn't do here
Faresay is a data processor for the practices that use it, not the controller, so a data protection complaint from your client is addressed to you, not to us. What we can do is make the underlying facts easy to establish: you can see what's held about a client, when it was added, and export it, which is most of what an investigation actually needs. What we can't do is receive, acknowledge or answer the complaint on your behalf. That responsibility, like the rest of your controller obligations, stays with you.
This article is general information about a UK data protection requirement as it stood in September 2026, not legal advice. Read the source material yourself, particularly if a complaint is already in front of you, and take advice from a solicitor or your professional body where the specifics of your situation matter. Rules and guidance change.
Faresay acts as a data processor for the therapists who use it. Read how we handle data.
Ready to talk to someone? Get matched with a verified therapist in minutes.
Find your therapist