Home / Blogs / Ask the Expert: Employee Data Protection Complaints: Would You Recognise One?

Ask the Expert: Employee Data Protection Complaints: Would You Recognise One?

Ask the expert blog-Julie

An employee tells their manager: “I don’t understand why you shared that information about me with everybody.”

Another says: “I’ve already told you that information on my file is wrong.”

And another asks: “Why are you still keeping that information about me?”

Would you recognise any of those comments as a potential data protection complaint?

Changes introduced under the Data (Use and Access) Act 2025 mean organisations now have specific legal duties when someone complains about how their personal information has been handled. Since 19 June 2026, organisations must have a process for dealing with data protection complaints, acknowledge complaints within 30 days and take appropriate steps to investigate them without undue delay.

For employers, however, one challenge may be recognising that a complaint has been made in the first place.

So, this month I sat down with our lovely Julie, one of our expert HR consultants, to talk about what the changes mean in practice, what managers should be listening out for and what employers need to do when an employee raises concerns about their personal information.

Angela: Let’s start at the beginning. What exactly is a data protection complaint?

Julie: Put simply, a data protection complaint is when someone believes an organisation hasn’t complied with data protection law in how it has handled their personal information.

In an employment setting, that could involve how you’ve collected an employee’s personal information, what you’ve used it for, where you’ve stored it, who you’ve shared it with, whether it’s accurate, how long you’ve kept it or how securely you’ve protected it.

It could also be a complaint about how you’ve dealt with a Subject Access Request or another data protection rights request.

The important point is that the employee doesn’t have to know the law. They don’t have to mention UK GDPR or say, “I’m making a data protection complaint”. We need to listen to what they are actually telling us.

Angela: So what has changed for employers?

Julie: Many employers will not realise that since 19th June 2026, organisations have had specific legal obligations around how they deal with data protection complaints.

You must give people a way of making a data protection complaint directly to your organisation. When you receive one, you must acknowledge it within 30 days.

You must also take appropriate steps to investigate the complaint without undue delay, keep the person informed about progress and, once you’ve completed your investigation, tell them the outcome without undue delay.

There isn’t an exemption because you’re a small employer. If you’re processing people’s personal information – and every employer is – this is something you need to be aware of.

Angela: Does an employee, as a matter of fact, have to tell us that they’re making a data protection complaint?

Julie: No, and this is probably the biggest practical message for employers.

Don’t become too focused on labels.

Imagine an employee emails their manager and says: “I’m really unhappy that details of my sickness absence were shared with the whole management team. I told you that in confidence and I don’t understand why everyone needed to know.”

They haven’t mentioned GDPR. They haven’t referred to the Data (Use and Access) Act. They haven’t filled in a complaints form.

But they’re clearly raising a concern about how their personal information has been handled.

Angela: What other things should managers be listening out for?

Julie: There are lots of examples which could come up in completely ordinary workplace conversations.

An employee might say: “Why has my home address been given to someone else?”

Or: “That information on my personnel file isn’t correct, and I’ve already asked for it to be changed.”

Perhaps: “Why can everybody see my absence information?”

Or: “Why are you still holding information about something that happened years ago?”

Someone might question why information about a disciplinary or grievance matter has been shared, why particular CCTV footage has been accessed, who has seen information contained in an occupational health report or why certain emails or records about them are still being retained.

None of those examples necessarily arrive looking like a formal data protection complaint. That’s why awareness amongst managers is so important.

Angela: Does that mean every complaint an employee makes is potentially a data protection complaint?

Julie: No. We need to distinguish between an employee being unhappy about something at work and an employee complaining about how their personal information has been handled.

For example, an employee saying: “I don’t agree with the disciplinary warning I’ve been given.”

isn’t, by itself, making a data protection complaint. That’s an employment matter which might need to be dealt with through the disciplinary appeal process.

But imagine they say: “I don’t agree with the warning I’ve been given, and I’m really concerned that details of my disciplinary hearing have been emailed to managers who had nothing to do with it.”

Now we have two separate issues.

One may be an employment issue, and the other may be a data protection complaint. We shouldn’t assume that dealing with one automatically deals with the other.

If you’re genuinely not sure what the employee is complaining about, ask them to clarify.

Angela: Are we seeing more of these complaints in practice?

Julie: We are seeing more employees raising questions about their personal information and exercising their data protection rights, and technology,  particularly with the advent of AI, is playing a part in that.

Information about employment rights and data protection is much more accessible than it once was. An employee can now describe what’s happened with an AI tool and, within seconds, get information about Subject Access Requests, UK GDPR, and data protection complaints, along with a draft letter or email to send to their employer.

That isn’t necessarily a bad thing. Employees are entitled to understand and exercise their rights. But it does mean that employers may receive more formal-looking requests and complaints, sometimes containing quite technical or legal language.

The important thing is not to be distracted by how the complaint has been written. A very polished five-page letter quoting legislation doesn’t necessarily mean that something has gone wrong, just as an informal comment to a manager doesn’t mean there isn’t a genuine data protection issue.

In both cases, come back to the substance: what is the employee concerned about, what personal information is involved, and what do we need to investigate or respond to?

Angela: Can employers use AI to help them respond?

Julie: AI can certainly be a useful tool, but this is one area where employers need to be particularly careful.

If you’re dealing with a data protection complaint, the information you’re working with could include names, emails, HR records, sickness information, disciplinary matters or other sensitive personal information. You shouldn’t copy an employee’s complaint or personal information into a public AI tool without considering your data protection obligations and your organisation’s rules on AI use.

AI might help with structure or general information, but it shouldn’t replace a proper investigation into what happened. Ultimately, the employer remains responsible for the response and for how the employee’s personal information is handled.

Angela: What about a Subject Access Request? Is that automatically a complaint?

Julie: No, and this is another important distinction.

A Subject Access Request – or SAR – is someone exercising their right to obtain their personal information. That doesn’t automatically mean they’re complaining about the way you’ve handled their data.

Equally, someone could make a SAR and a data protection complaint at the same time.

For example, an employee might say: “I want copies of all the emails discussing my sickness absence, and I also want to know why details about my medical condition were shared with my colleagues.”

We would need to review both elements carefully. The request for information may be a SAR, while the concern about their medical information being shared may amount to a data protection complaint.

They are separate issues with their own requirements, so it’s important to identify exactly what you’ve received.

Angela: The 30-day rule sounds important. Does that mean employers have 30 days to investigate and resolve the complaint?

Julie: No. The 30-day requirement relates to acknowledging receipt of the complaint.

But I wouldn’t encourage employers to think, “Great, I’ve got 30 days before I need to do anything.”

Your obligation to investigate starts when you receive the complaint. You need to take appropriate steps without undue delay and, if the investigation will take time, keep the employee informed about progress.

Once you’ve finished investigating, you then need to explain the outcome without undue delay.

From a practical HR perspective, my advice would be to acknowledge the complaint promptly and start dealing with it. The fact that the law gives you up to 30 days to acknowledge it shouldn’t become your target response time.

Angela: In reality, what should an employer do when they realise they’ve received a data protection complaint?

Julie: Firstly, make sure it gets to the right person within the business.

You should record when the complaint was received, what the employee is concerned about and what information or processing they’re challenging.

Then you need to investigate.

Depending on the complaint, that could involve speaking to the manager involved, reviewing emails, checking who had access to particular information, looking at the employee’s HR records, checking what your privacy information says or establishing why information was collected, retained or shared.

The investigation needs to be appropriate and proportionate to the complaint, but you also need an audit trail showing what you considered, what you found and what you did about it.

That’s why having a simple complaints tracker can be so useful.

Angela: What records should employers keep?

Julie: This is an area where I’d encourage employers to be quite methodical.

You should be able to show when you received the complaint, when and how you acknowledged it, what enquiries you made, any relevant conversations or documents, what you concluded and what action you took as a result.

It is also useful to record the reasons behind your decisions.

If you’re receiving several complaints about similar issues, keeping good records can also help you spot a wider problem. Perhaps managers are sharing too much employee information, access permissions need reviewing, or your retention practices aren’t working as they should.

A complaints tracker isn’t simply about demonstrating compliance. Used properly, it can help you spot patterns and improve how personal information is handled across the business.

Angela: What if, after investigating, we think we’ve essentially made a mistake?

Julie: Then put it right. Mistakes happen, but own it!

The purpose of investigating isn’t to prove that the employer was right. It’s to establish what happened.

Depending on the circumstances, that might mean correcting inaccurate information, changing who has access to particular records, addressing how information has been shared, reviewing a process, or reminding managers about confidentiality and data protection.

You should then explain the outcome clearly to the employee, including what you’ve done to resolve the issue and, where appropriate, what action you’ve taken as a result.

And don’t forget to look at what you can learn from it. One complaint might highlight a weakness that could affect other employees too.

Angela: Do all our managers now need to become data protection experts?

Julie: Thankfully, no!

But they do need enough awareness to recognise when something should be escalated.

I wouldn’t expect a line manager to determine whether there has technically been a breach of UK GDPR. What I would want them to recognise is that when an employee starts questioning what information you hold about them, why you have it, how you’re using it, who you’ve shared it with, whether it’s accurate, how secure it is or why you’re still keeping it, they shouldn’t simply dismiss that as somebody having a moan.

They need to know who to pass it to.

Sometimes that first conversation will be the difference between a concern being identified and dealt with promptly and it becoming a much bigger issue later.

Angela: What should employers be doing now?

Julie: This is a good opportunity to look at your data protection arrangements as a whole. I suggest checking that you have a process for dealing with data protection complaints.

Review your privacy information and existing data protection policies. Do employees know how they can make a complaint? Who receives it? Who investigates it? How will it be recorded? Who is responsible for keeping the employee updated? And how will you make sure managers recognise a potential complaint if it comes through them first?

I’d also review your Subject Access Request procedures because, as we’ve discussed, complaints and rights requests can sometimes arrive together.

Most importantly, make sure a practical process sits behind your paperwork. A beautifully drafted policy isn’t much help if the manager who receives the complaint doesn’t recognise what they’ve been given.

Final thoughts from Julie

The biggest message I would give employers is: don’t wait for the words “data protection complaint”.

Listen to what the employee is really telling you.

“Why did you share that?”

“Who has seen this?”

“Why are you keeping that information?”

“That information about me is wrong.”

“I’ve already asked you to change this.”

Those are the sorts of comments that should make you stop and consider whether a data protection issue needs to be dealt with properly.

Recognising a potential employee data protection complaint early allows you to understand the concern, investigate it and, where necessary, put something right before the issue escalates.

For employers, now is a good time to review your data protection policies and procedures to make sure they reflect the new requirements. That includes looking at your Fair Processing Notice, Subject Access Request procedures and, importantly, how you will recognise, record, investigate and respond to data protection complaints in practice.

At HR:4UK, we have updated our HR policies, guidance and supporting processes to reflect the changes, including introducing a Data Protection Complaints Tracker to help employers keep an appropriate record of complaints and how they have been handled.

If you’re an HR:4UK client, these updated resources will be available to support you. If you’re not currently a client and would like support reviewing your data protection procedures or understanding how the new data protection complaint requirements affect your business, please get in touch with the HR:4UK team.

Angela Clay

A qualified employment law solicitor and our managing director, Angela has unparalleled legal expertise and decades of experience and knowledge to draw from. She’s a passionate speaker and writer that loves to keep employers updated with upcoming changes to legislation, and is a regular guest speaker on BBC Leicester Radio.

Want more practical HR insights?