Features Hub

UK Data Protection Changes Are Arriving June 2026

Wed 17 Jun 2026

Chatbot icon displayed on a keyboard key, representing AI-powered digital assistants and conversational technology.”

Two important changes to UK data protection law come into force on 19 June 2026.

The first introduces a legal requirement for organisations to operate a formal complaints-handling process. The second raises expectations around how organisations explain the use of artificial intelligence when processing personal data.

The changes form part of the Data (Use and Access) Act 2025 and apply regardless of organisation size or sector.

“UK organisations face two clear, non-negotiable shifts in data protection requirements: a mandatory, formalised complaints process for all data controllers, and significantly higher expectations around transparency when AI is used to process personal data,” said Grant Foster, Partner and Risk Advisory Leader at Howden Risk Advisory. “These changes mark a decisive move by regulators to put accountability and clarity at the centre of data governance, with no exemptions by size or sector and a clear expectation that organisations handle concerns directly before they reach the ICO.”

Complaints Handling Becomes a Legal Obligation

One of the most immediate changes arrives through Section 103 of the Data (Use and Access) Act 2025.

From 19 June, all data controllers must provide individuals with a clear route to raise complaints about how their personal data is handled. Organisations will be required to acknowledge complaints within 30 days, investigate concerns appropriately, and communicate the outcome to the individual.

The right to escalate concerns to the Information Commissioner’s Office (ICO) remains unchanged. However, regulators are signalling that organisations should resolve complaints directly wherever possible before external intervention becomes necessary.

For many organisations, effective complaints handling has long been considered good practice. The difference now is that it becomes a legal requirement.

The change also has practical implications. Privacy notices will need to explain how complaints can be submitted, while organisations may need to consider how complaints are identified and managed across multiple communication channels, including email, web forms, customer service interactions, and social media platforms.

AI Transparency Requirements Come Under Scrutiny

Alongside complaints handling, the new rules place greater focus on transparency where AI is used to process personal data.

“At the same time, organisations must ensure their privacy notices plainly explain how and why AI is used, what data it touches, and how individuals can challenge or seek human review of decisions that affect them,” continued Foster. “For many, particularly across financial and professional services, this will require urgent review and updating of existing processes and disclosures, as regulators signal that vague or outdated approaches will no longer meet legal standards.”

The requirements build upon existing UK GDPR obligations, particularly those relating to transparency, fairness and individual rights under Articles 5(1) (a), 12 to 15, and 22.

In practice, organisations may need to provide clearer explanations of:

  • How AI systems are being used
  • What personal data is involved
  • Whether third-party AI providers are participating in processing activities
  • How individuals can seek clarification or human review of decisions

The direction of travel is clear. Organisations are expected to explain AI use in language that individuals can understand rather than relying on broad or highly technical descriptions.

Why Regulated Firms Should Pay Attention

The implications extend beyond data protection compliance alone.

For regulated sectors, particularly financial services, these developments increasingly overlap with wider obligations around consumer understanding and informed decision-making.

The Financial Conduct Authority’s Consumer Duty places significant emphasis on delivering good outcomes, acting in good faith and ensuring customers receive information they can understand and act upon.

As AI becomes more embedded within customer-facing processes, data governance and Consumer Duty requirements begin to intersect.

Being transparent about how personal data is used, including where AI systems are involved, supports broader expectations around customer understanding and informed decision-making. The FCA has repeatedly highlighted clear communication as a core component of good outcomes, making AI disclosures and privacy notices increasingly relevant beyond data protection teams alone.

The result is that privacy notices, complaints processes, and AI governance frameworks may increasingly serve multiple purposes. They support compliance with data protection law while also helping organisations demonstrate openness and accountability to customers and regulators.

For firms that treat these obligations as separate exercises, there is a risk of creating unnecessary complexity and duplication.

What Organisations Should Do Next

The changes arriving on 19 June are practical in nature, and the immediate priority for many organisations will be implementation.

On the complaints side, organisations should review whether a formal process already exists and whether it satisfies the new requirements. This includes ensuring complaints can be acknowledged within 30 days, that outcomes are communicated clearly and that privacy notices explain how concerns can be raised directly with the organisation.

On the AI side, organisations may need to map where AI tools are used across the business, identify what personal data those systems process, and assess whether existing privacy disclosures remain understandable to non-specialist audiences.

Just as importantly, employees need to understand both requirements. Staff should be able to recognise when a communication constitutes a data protection complaint and understand how the organisation describes its use of AI when handling personal data.

The changes may focus on complaint handling and transparency, but they also signal a broader direction of travel. Regulators increasingly expect organisations not only to process personal data lawfully, but to explain clearly how that data is used, how decisions are made and how concerns can be raised.

For organisations that have not reviewed their complaints procedures or AI disclosures recently, the implementation date provides a useful deadline for reassessing both.

Techerati thanks Grant Foster, Partner and Risk Advisory Leader at Howden Risk Advisory, for his insights on the upcoming changes to UK data protection law.

Tags:

AI Governance data protection GDPR ICO
Send us a correction Send us a news tip

Subscribe for News in Your Inbox