Data protection complaint route: controller → ICO → tribunal
Escalation route for UK GDPR breaches: DSAR ignored, erasure refused, unlawful processing, data breach.
When to use this route
An organisation has breached your data protection rights — refused a DSAR, declined erasure, processed your data unlawfully, or failed to notify you of a breach.
When NOT to use this route
If you want compensation for distress only — that's a civil claim under s.168 DPA 2018 (County Court). The ICO does not award compensation.
Prerequisites
- • You have asked the controller to fix the issue and given them a reasonable time
Evidence to gather
- • Original rights request
- • Controller's response (or proof of non-response)
- • Evidence of the unlawful processing
- • Evidence of distress / harm (for compensation claims)
Route map
- Stage 1
Complain to the controller
The ICO requires you to give the controller a chance to respond first. Quote UK GDPR Articles and DPA 2018 sections.
Controller has 1 month to respond (extendable by 2 months for complex) - Stage 2
ICO complaint
Submit online with all correspondence attached.
- Stage 3
ICO assessment and outcome
ICO assesses and either takes no action, issues a reprimand, an enforcement notice, or a monetary penalty.
- Stage 4
First-tier Tribunal appeal
If you disagree with the ICO outcome — or if the controller appeals an enforcement / penalty notice — the matter goes to the General Regulatory Chamber (Information Rights).
28 days from the ICO noticeForum: first tier tribunal - Stage 5
County Court damages claim (parallel)
For compensation for distress, issue under s.168 DPA 2018. Quantum guided by Lloyd v Google and Vidal-Hall principles.
Final remedies
- • ICO enforcement notice or reprimand
- • Monetary penalty (up to £17.5m or 4% global turnover) — payable to ICO, not to you
- • Court damages for distress
- • Court order requiring rectification or erasure
Official sources
Frequently asked questions
- Do I have to contact the company before complaining to the ICO?
- Before contacting the Information Commissioner’s Office (ICO), you must first ask the organisation (the controller) to resolve the issue. You should give them a reasonable time to respond, which is typically one month, though this can be extended by two months for complex requests. The ICO requires this initial step to allow the controller a chance to address the breach or explain their actions.
- What happens if I disagree with the ICO’s decision on my complaint?
- If you disagree with the ICO’s decision, or if the controller appeals an enforcement or penalty notice, the matter can be taken to the First-tier Tribunal, specifically the General Regulatory Chamber (Information Rights). You must submit this appeal within 28 days of receiving the ICO’s notice. This is the formal route for challenging the regulator’s assessment or outcome.
- What evidence do I need to provide when making an ICO complaint?
- You should gather your original rights request, the controller’s response (or proof they did not respond), and evidence of the unlawful processing. If you are also pursuing a claim for compensation for distress, you should include evidence of that harm. Submitting these documents with your online complaint helps the ICO assess the situation and determine the appropriate enforcement action.
- What actions can the ICO take against an organisation that breaches data protection rules?
- The ICO can take several actions after assessing a complaint. These include taking no action, issuing a reprimand, issuing an enforcement notice, or imposing a monetary penalty. Monetary penalties can be up to £17.5m or 4% of global turnover, but these are payable to the ICO, not to the individual complainant. The ICO does not order the controller to pay you directly for distress.