ICO publishes recognised legitimate interests and complaints handling guidance

21/08/2025 | ICO

The Information Commissioner's Office (ICO) has published draft guidance on two new areas and launched consultations to inform the final versions. This follows the implementation of the first provisions of the Data (Use and Access) Act 2025 (DUA Act), which took effect on 19-20 August.

The guidance on recognised legitimate interests is intended to help organisations use the recognised legitimate interest lawful basis in compliance with the UK General Data Protection Regulation (GDPR) and the Data Protection Act 2018 (DPA18). This guidance clarifies what the new lawful basis entails, defines what constitutes a recognised legitimate interest, and outlines when and by whom it can be used. In addition, it addresses specific types of data processing, including children's data, special category data, and criminal offence data. It also covers important topics such as data sharing, automated decision-making, and the five recognised legitimate interest conditions. 

The recognised legitimate interests consultation closes on 30 October 2025.

The guidance on data protection complaints explains the new legal requirement for organisations to have a process in place for handling data protection complaints from anyone unhappy with how their personal data has been processed. Such complaints can include subject access and other rights requests, or if a personal data breach has impacted them. The guidance explains how to set up a complaints process from putting in place a complaints form through to providing an outcome and reviewing lessons learned. It also covers receiving complaints from or on behalf of children. 

The complaints handling consultation closes on 19 October 2025.


Training Announcement: Freevacy offers a range of independent data protection qualifications from IAPP and BCS. Our certified courses are available at foundation and practitioner levels and cover multiple legal jurisdictions, data protection operations management, and the implementation of complex privacy solutions in technical environments. Find out more.

Read Full Story
ICO website

What is this page?

You are reading a summary article on the Privacy Newsfeed, a free resource for DPOs and other professionals with privacy or data protection responsibilities helping them stay informed of industry news all in one place. The information here is a brief snippet relating to a single piece of original content or several articles about a common topic or thread. The main contributor is listed in the top left-hand corner, just beneath the article title.

The Privacy Newsfeed monitors over 300 global publications, of which more than 6,250 summary articles have been posted to the online archive dating back to the beginning of 2020. A weekly roundup is available by email every Friday.