Guide · Data & Privacy

Complaining to the ICO

How to present a focused ICO complaint with the request, response, disputed issues and supporting records.

The ICO can assess data-protection handling and regulatory compliance, but it is not a general compensation ombudsman.

The Information Commissioner’s Office is the UK regulator for data protection and information rights. You can complain about matters such as mishandled SARs, inaccurate data, unlawful processing, security failures and other data-protection concerns.

The ICO will usually expect you to have raised the issue with the organisation first. The strongest complaint is focused, evidenced and clear about what remains unresolved.

Key points

  • Provide the original request/complaint and the organisation’s response.
  • Identify the specific unresolved data-protection issues.
  • The ICO can assess compliance and use regulatory powers, but it does not simply award consumer compensation in the way an ombudsman may.
  • Court remedies remain separate.

What to send

Send a short chronology, the key correspondence, a schedule of unresolved issues and supporting documents. Avoid expecting an ICO case officer to find the issue inside hundreds of unindexed pages.

What the ICO may consider

The ICO can consider whether the controller complied with rights requests, principles and other requirements. Its regulatory response can range from advice and casework outcomes to formal enforcement depending on seriousness and wider factors.

What the ICO does not decide

The ICO does not determine every contractual dispute or whether a debt is legally owed. If the complaint is fundamentally about service, credit affordability or contract formation, another body may be needed even if data accuracy is also involved.

In practice

  • Frame the ICO complaint around information-rights law.
  • Show exactly what you asked the controller to fix and how it responded.
  • Run sector complaint routes in parallel where they address a different issue.

Evidence worth keeping

Original request or data-protection issue
Complaint to the organisation
Acknowledgement and final response
Short issue schedule
Key supporting documents only
Any evidence of continuing harm or unresolved processing

Know what to do with the outcome.

If the ICO gives an outcome you disagree with, read the route and deadline stated in the correspondence. The ICO currently says that a complaint about its data-protection decision making should normally be raised for case review within three months. Separately, individuals may be able to enforce data-protection rights through the courts; legal advice is sensible before litigating.

Useful framing.

“The unresolved issue is [x]. I asked the controller to [y] on [date]. It refused/failed to address the point because [brief reason]. The attached documents A–C show [facts]. I ask the ICO to consider whether the controller complied with [right/principle].”

Build a small evidence pack around the alleged breach.

  • A short chronology with the key dates.
  • The original rights request or complaint.
  • The organisation’s acknowledgement and substantive response.
  • The exact personal data/document showing the problem.
  • Any evidence contradicting the organisation’s factual position.
  • A short statement of what remains unresolved and what outcome you sought.

Avoid burying the central issue in hundreds of pages without explanation. Refer to attachments by name/date and map them to numbered complaint points.

Give the organisation a focused chance to resolve the data issue first.

Current ICO public guidance recommends first making a data-protection complaint to the organisation and allowing it the opportunity to resolve the matter. Since 19 June 2026 the organisation has express legal duties around receiving, acknowledging, investigating and concluding data-protection complaints. You can approach the ICO at any point, but a completed internal record often makes the unresolved issue much clearer.

The ICO is a regulator, not a general compensation tribunal.

The ICO can consider whether an organisation appears to have complied with data-protection law and can use regulatory powers where appropriate. Its complaint process is not the same as a civil damages claim and it does not simply calculate compensation for distress or inconvenience. If your goal includes compensation, correction of a contractual outcome or another non-data remedy, identify the separate route as well.