Data Protection Act 2018

165Complaints by data subjects

This section has no associated Explanatory Notes

(1)Articles 57(1)(f) and (2) and 77 of the GDPR (data subject’s right to lodge a complaint) confer rights on data subjects to complain to the Commissioner if the data subject considers that, in connection with personal data relating to him or her, there is an infringement of the GDPR.

(2)A data subject may make a complaint to the Commissioner if the data subject considers that, in connection with personal data relating to him or her, there is an infringement of Part 3 or 4 of this Act.

(3)The Commissioner must facilitate the making of complaints under subsection (2) by taking steps such as providing a complaint form which can be completed electronically and by other means.

(4)If the Commissioner receives a complaint under subsection (2), the Commissioner must—

(a)take appropriate steps to respond to the complaint,

(b)inform the complainant of the outcome of the complaint,

(c)inform the complainant of the rights under section 166, and

(d)if asked to do so by the complainant, provide the complainant with further information about how to pursue the complaint.

(5)The reference in subsection (4)(a) to taking appropriate steps in response to a complaint includes—

(a)investigating the subject matter of the complaint, to the extent appropriate, and

(b)informing the complainant about progress on the complaint, including about whether further investigation or co-ordination with another supervisory authority or foreign designated authority is necessary.

(6)If the Commissioner receives a complaint relating to the infringement of a data subject’s rights under provisions adopted by a member State other than the United Kingdom pursuant to the Law Enforcement Directive, the Commissioner must—

(a)send the complaint to the relevant supervisory authority for the purposes of that Directive,

(b)inform the complainant that the Commissioner has done so, and

(c)if asked to do so by the complainant, provide the complainant with further information about how to pursue the complaint.

(7)In this section—

  • foreign designated authority” means an authority designated for the purposes of Article 13 of the Data Protection Convention by a party, other than the United Kingdom, which is bound by that Convention;

  • supervisory authority” means a supervisory authority for the purposes of Article 51 of the GDPR or Article 41 of the Law Enforcement Directive in a member State other than the United Kingdom.