ICO outlines its criteria for triaging data protection complaints
Published: 28/07/2026
| ICO
The Information Commissioner's Office (ICO) has provided further clarification on how its new data protection complaints-handling framework works. The framework, launched in February, is intended to move away from the previous "casework lottery" by prioritising high-value cases in which the ICO can have the most significant impact.
In practice, this means the ICO no longer treats all data protection complaints in the same way. The recent clarification outlines how the ICO decides which complaints to investigate further and which ones to archive after an initial review, indicating that no further action will be taken.
Under the new framework, the ICO prioritises detailed investigations where data protection issues cause high levels of harm, significantly affect vulnerable groups such as children, or impact a substantial number of individuals. Priority is also given to cases that advance data protection rights, align with the regulator's strategic priorities, raise high-profile public-interest matters, or where individuals must provide personal data to certain organisations.
In contrast, the ICO will refrain from further investigation if the issue is already known and being addressed, or if it deems the organisation has complied with data protection laws. Complaints will also be archived if the organisation is taking adequate corrective measures or has already implemented appropriate safeguards to prevent recurrence.
The ICO noted the list is not exhaustive and that the criteria will be subject to periodic review.
If you want to know the statistics concerning the number of complaints that are archived after triage with 'no further action' required, a disclosure by the ICO under the Freedom of Information Act 2000 (FOIA) confirmed that between 9 February and 8 May 2026, the ICO received 22,052 complaints, of which 10,974 (49%) recorded such an outcome.
While only following up on 1 in 2 complaints may seem disproportionate, it's worth noting that not every complaint is actionable, and the ICO will undoubtedly receive a high volume of low-quality complaints, many of which will be AI-generated. It is also only fair to mention that over the past 12 months, the number of complaints received surged to 76,743, an 81% increase from the 42,315 complaints in the previous year.
What do you think... should the ICO follow up on every complaint?
Training announcement: Freevacy provides comprehensive training for new and existing practitioners on the changes introduced by the DUA Act to the UK General Data Protection Regulation (GDPR), the Data Protection Act 2018 (DPA18), and the Privacy and Electronic Communications Regulations 2003 (PEC-Regulations). Our courses are always up to date and provide a forum for learning and discussing how to ensure your data protection processes remain compliant. Find out more.
What is this page?
You are reading a summary article on the Privacy Newsfeed, a free resource for DPOs and other professionals with privacy or data protection responsibilities helping them stay informed of industry news all in one place. The information here is a brief snippet relating to a single piece of original content or several articles about a common topic or thread. The main contributor is listed in the top left-hand corner, just beneath the article title.
The Privacy Newsfeed monitors over 300 global publications, of which more than 3,250 summary articles have been posted to the online archive dating back to the beginning of 2020. A weekly roundup is available by email every Friday.