ICO Complaint Journey
From data protection breach to ICO investigation outcome and any onward appeal to the First-tier Tribunal.
Who Uses This Journey
Data subjects whose UK GDPR rights have been breached (e.g. DSAR refused, data inaccurately processed, marketing without consent) and whose initial complaint to the controller has not been resolved.
Stage-by-Stage Timeline
Complain to the controller first
The ICO requires (in most cases) that you give the controller a chance to respond. Send a written complaint stating the breach and what you want the controller to do.
Submit ICO complaint
Online form at ico.org.uk/make-a-complaint. Provide copies of correspondence, the alleged breach, and what you want.
- Original DSAR or rights request
- Controller's response (or lack of it)
- Screenshots of unlawful processing
- Marketing communications received
ICO assessment
Caseworker reviews. May ask both sides for further information. Less serious complaints may receive a 'no further action' decision with general guidance.
ICO outcome
Possible outcomes: no further action; reprimand; enforcement notice; monetary penalty notice (up to £17.5m or 4% of global turnover); referral to prosecution.
- No further action
- Reprimand letter
- Enforcement notice
- Monetary penalty (rare for individuals)
Appeal (if applicable)
An enforcement notice or penalty notice can be appealed to the First-tier Tribunal (General Regulatory Chamber, Information Rights). Data subjects can also separately claim damages for distress in the County Court under s.168 DPA 2018.
- Tribunal upholds, varies, or quashes the notice