Data Protection Complaint Policy
Purpose
This policy sets out how the London Borough of Havering receives, records, investigates and responds to Data Protection Complaints made by individuals, in line with our obligations section 103 of the Data Use and Access Act 2025.
The DUAA introduces a statutory right for individuals to complain directly to organisations about how their personal data has been handled, together with new duties on organisations to provide an accessible complaints route, acknowledge complaints within a set timeframe, and respond without undue delay.
This policy explains how those duties are met in practice.
Scope
This policy applies to all data protection complaints received from any individual, including residents, customers, employees, job applicants, suppliers, members of the public, and third parties acting on behalf of a data subjects.
What is a Data Protection Complaint?
A data protection complaint is any concern or dissatisfaction expressed by an individual relating to our processing of their personal data, including processing carried out by our nominated data processors.
A complaint does not need to reference specific legislation or use formal or legal language, and may be made verbally, in writing, or through any other channel, including social media.
Examples of matters that may constitute a data protection complaint include (but are not limited to) believing:
- we have mishandled your data
- we have shared your personal data inappropriately
- we have processed your data without a lawful basis
- we have used your data for purposes beyond what it was originally collected for
- a decision significantly affecting you was made using automated processing
What this policy does not cover
The following matters will not be investigated under this Data Protection Complaints Policy.
- Poor customer service or communication
- Council tax or parking enforcement disputes
- Staff rudeness
- Workplace disputes unrelated to personal data
- Subject Access Request complaints
These should instead be raised through our Corporate Complaints process.
Requests for information held by us should be raised via our Freedom of Information or SAR process.
Where another data controller, for example a school, processes your personal data, you will need to direct your concern to that organisation for them to investigate.
Where a data protection complaint has already been investigated and a final response issued, this should be directed to the Information Commissioner's Office, as set out in our final response to you.
How to make a complaint
You can submit a data protection complaint to the DPO by completing the online complaints form below.
You can also write to the DPO at Havering Town Hall, Main Road, Romford RM1 3BB.
It is preferable to raise complaints by email, as these can be assessed more quickly than complaints submitted by letter.
When raising your complaint, please include as much of the following information as possible to allow us to investigate effectively.
- Your full name and contact details
- Name of the officer, team, service, system or context involved
- Any relevant reference numbers (customer ID, case number)
- A clear description of what happened
- Which personal data is involved, if known
- The date or timeframe of the issue
- Any supporting evidence, such as screenshots, emails or system messages
- Copies of other relevant correspondence
- Whether you have raised the issue before and, if so, dates and details of responses already received
- Any previous escalation attempts
- What action or outcome you are seeking
Where a complaint is made by a third party on behalf of a data subject, we will verify that the third party is authorised to act on the individual's behalf before investigating, save where the individual lacks capacity or is a child assessed as not having sufficient competence to act for themselves.
Make a data protection complaint
Receipt and assessment
Complaints sent to the IG Team will be assessed and acknowledged within thirty days (30).
Acknowledgement will include:
- confirmation of receipt of the complaint
- assessment and confirmation that the complaint will be investigated under this policy
- expected timescales for investigation and whether the deadline needs to be extended by up to a further two months
- contact details for the Information Governance Team
- an internal reference number
If your complaint includes matters not covered by this policy, for example a SAR or a dispute with another Council service, that part of your request will be directed to the relevant team to process separately from your data protection complaint, in accordance with the Corporate Complaints Policy.
You will be informed if this happens.
If your complaint includes a request for compensation, the Information Governance Team will refer this to the appropriate team for consideration or forward this part of your complaint to the Council's Insurance Team, who will contact you separately about your request.
You will be informed if this happens.
Investigation
Investigation actions may include:
- reviewing relevant data and records
- requesting information from relevant staff or teams
- assessing compliance with legal requirements
- determining whether a breach or error occurred
- identifying remedial actions
Outcome
The outcome response will:
- summarise the complaint
- present the investigation findings
- specify whether the complaint is upheld, partially upheld, or not upheld
- detail actions taken or planned
- explain the individual's right to escalate to the Information Commissioner's Office (ICO) if they remain unsatisfied after completing the internal process
Closure
Once the outcome response is sent:
- the complaint records will be updated and closed
- all investigation records will be securely stored in line with the Council's Retention Schedule
- emerging themes or risks will be reviewed to support monitoring and improvement
Escalation to the ICO
If you are unhappy with our final response to your data protection complaint, you have the right to contact the ICO.
Email: icocasework@ico.org.uk
Website: ICO make a complaint
Telephone: 0303 123 1113 or 01625 545 745
Post: Information Commissioner's Office, Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF
For all other complaints, please use our Corporate Complaints process.
Treating our staff with dignity and respect
We are committed to providing excellent customer service to everyone who contacts us in a respectful, courteous and polite manner.
As an employer, we have a duty to safeguard the health and wellbeing of our staff.
We do not expect our staff to tolerate abusive, threatening, demeaning or offensive behaviour, either verbally or in writing, nor to deal with contact that, because of its frequency, places a strain on time and resources and causes undue stress for staff.
Where we identify unacceptable or vexatious behaviour, we may restrict contact under this policy. Unacceptable behaviour generally includes:
- behaviour or language that causes staff to feel significantly stressed, intimidated, threatened or abused, including foul, offensive, demeaning, inappropriate, racist, sexist or homophobic language, threats or acts of violence, derogatory remarks, rudeness, harassment, inflammatory statements or unsubstantiated allegations
- unreasonably persistent or vexatious contact that places excessive pressure on staff time and resources, such as repeatedly pursuing complaints that lack substance, fall outside the DPO's remit, or have already been fully investigated and concluded
- excessive demands during an investigation, for example frequent or persistent phone calls, sending numerous emails to multiple staff or to one staff member, or submitting lengthy correspondence every few days while expecting immediate, detailed responses
- submitting repeated issues or service complaints after the complaints process is complete, including minor changes to previous complaints to justify reopening matters. Such behaviour will not lead to acceptance of a new complaint
- refusing to accept the outcome of a data protection complaint, including repeatedly disputing the decision and declining the further escalation routes available
- insisting on processes that conflict with standard procedures or good practice
- refusing to accept documented evidence as factual
Roles and responsibilities
Data Protection Officer (DPO)
Has overall accountability for this policy and for the handling of data protection complaints across the Council.
Information Governance Team
Acts on behalf of the DPO to receive, assess, acknowledge, investigate and respond to data protection complaints, maintains the Complaints Register, refers unrelated matters to Corporate Complaints, relevant service teams, or the Insurance Team as appropriate.
Service teams / relevant officers
Support investigations by providing records and information promptly when requested; implement any remedial actions identified.
Corporate Complaints Team
Handles general service complaints that fall outside the scope of this policy.
Senior Management / Board
Reviews periodic reporting on complaint volumes, themes and outcomes; approves policy updates.
Record keeping
We will maintain a central Data Protection Complaints Register recording, for each complaint: the date received; the channel used; the nature of the complaint; the identity of the complainant (or confirmation of third-party authority); the date acknowledged; the steps taken to investigate; the outcome; any remedial action taken; and the date the complaint was closed.
Records will be retained in accordance with the Council's Retention Schedule and may be reviewed by senior management or provided to the ICO if a complaint is escalated.
Review
This policy will be reviewed at least annually, or sooner if there are material changes to data protection law, ICO guidance, or our internal processes.
- Review cycle of this information: Annually
- Version control: This is Version 1
- Next review date: June 2027