If you’ve made a data protection complaint to the Information Commissioner’s Office (ICO) and you’re not happy with how it’s been handled, it helps to know exactly what the regulator has to do and what your options are if you want to take things further.
The recent First-tier Tribunal decision in Andrzej Witold Kuczys v The Information Commissioner is a useful reminder that the ICO complaints process has limits and so does the Tribunal’s power to intervene when someone is unhappy with the ICO’s response.
The case concerned complaints about CCTV, the opening or handling of correspondence, alleged disclosure or sharing of personal data and the response to a Data Subject Access Request. The applicant had complained to the ICO, received a case outcome, challenged that outcome and then applied to the Tribunal under section 166 of the Data Protection Act 2018. The Tribunal struck out the application. In plain terms, it found that section 166 is not a general appeal route against the ICO’s decision and it cannot be used simply because a data subject disagrees with the ICO’s view of the complaint.
When can you complain to the ICO about a data protection issue?
A data subject can complain when they believe an organisation has infringed their data protection rights. That may include a failure to respond properly to a subject access request, processing personal data without a lawful basis, refusing to erase or rectify data where the law requires it, disclosing information to the wrong person or failing to keep personal data secure.
In many cases, the sensible first step is to complain to the organisation itself. The ICO’s public guidance explains that organisations must now have a process for handling data protection complaints and should acknowledge, investigate and communicate an outcome. That matters because a well-prepared complaint to the organisation can narrow the issues, preserve evidence and sometimes resolve the matter without the need for regulatory or court action.
In Kuczys, the applicant had raised concerns with the controller and then complained to the ICO about, among other things, CCTV footage and the handling of his DSAR. That was the correct type of subject matter for a data protection complaint. The difficulty was not that he had no right to complain. The difficulty came later, when he tried to use the Tribunal process to challenge the substance of the ICO’s decision.
What must the ICO do when it receives a complaint?
The ICO is not required to investigate every complaint in the way a court would deal with a legal claim. Its role is regulatory. It must take appropriate steps to respond to a complaint, keep the complainant informed of progress and provide an outcome. What is “appropriate” will depend on the complaint, the evidence, the seriousness of the alleged breach and the ICO’s regulatory judgment.
The judgment shows how this often works in practice. The ICO reviewed the information provided, corresponded with the controller, identified some concerns about the DSAR response, gave advice to the controller and later confirmed that it was satisfied that the controller had explained the relevant processing activities and lawful bases. The applicant disagreed, but the Tribunal treated the key question as whether the ICO had failed procedurally, not whether the Tribunal would have reached a different view on the merits.
If the ICO does not investigate, what steps can be taken?
If the ICO has not responded, has not provided an update or has not told the complainant the outcome within the relevant time, section 166 of the Data Protection Act 2018 may allow an application to the First-tier Tribunal. The Tribunal can order the ICO to take appropriate steps to respond or to provide information about progress or outcome within a specified period.
That is a narrow but useful power. It is designed to deal with procedural inactivity, delay or failure to update. It is not designed to make the ICO carry out a wider investigation just because the complainant wants one and it is not a route to ask the Tribunal to decide whether the original controller breached data protection law.
In Kuczys, the applicant sought an order requiring the Commissioner to take appropriate steps to respond to each point raised in his complaint. The problem was that the ICO had already provided an outcome, corresponded with the controller, dealt with further points and completed a review. On those facts, there was nothing left for the Tribunal to “progress” under section 166.
When is a Tribunal application not appropriate?
A Tribunal application under section 166 is unlikely to be appropriate where the ICO has already responded to the complaint and the real issue is disagreement with the outcome. That is the central lesson from Kuczys. The Tribunal does not conduct a rehearing of the data protection complaint. It does not decide whether the controller did or did not breach the UK GDPR. It does not substitute its own regulatory judgment for that of the ICO.
This can feel frustrating for complainants. A person may have genuine concerns about their personal data and may believe the ICO has placed too much weight on the controller’s explanation. However, a section 166 application is not the right vehicle for that kind of challenge. If the complaint is really about the quality, depth or correctness of the ICO’s reasoning, specialist advice is needed before issuing Tribunal proceedings, because an application that falls outside the statutory power may be struck out at an early stage.
What other options do you have?
The most suitable next step depends on what the individual wants to achieve. If the aim is to obtain personal data, correct inaccurate data, stop unlawful processing, secure deletion of data or recover compensation, the answer may not be a Tribunal application against the ICO. It may be a direct claim or application against the organisation that controls the data.
For example, section 167 of the Data Protection Act 2018 gives the court power, in appropriate cases, to order a controller or processor to comply with a data subject’s rights. Section 168 deals with compensation for damage suffered because of a data protection infringement. Depending on the facts, a claim may also involve misuse of private information, breach of confidence, negligence, harassment or other privacy-related causes of action. These routes are very different from asking the Tribunal to direct the ICO to progress a complaint.
Judicial review may also be considered in rare cases where the focus is the lawfulness of the ICO’s own decision-making process. That is not the same as appealing the ICO’s view simply because the complainant considers it wrong. Judicial review is technical, time-sensitive and risk-sensitive, so it should not be treated as a routine next step.
Practical lessons from Kuczys for data subjects
The decision is not a sign that ICO complaints are pointless. In fact, this is a relatively rare example of where the ICO has taken some steps in respect of a complaint by a single individual. They can therefore be valuable, particularly where a controller has ignored a request, failed to explain its lawful basis, mishandled a DSAR or created wider regulatory concerns. But the complaint should be approached with a clear strategy from the start.
Before complaining, it is usually sensible to identify the specific data protection right engaged, gather the correspondence and evidence, explain what outcome is being sought and consider whether the real objective is regulatory involvement, disclosure of data, correction of data, deletion of data, injunctive relief or compensation. Those objectives may point to different legal routes.
How can we help?
Kevin Modiri is a Partner in our expert Dispute Resolution team, specialising in civil disputes, insolvency, inheritance disputes, data breach claims and defamation claims.
If you want to discuss the above subject, please do not hesitate to contact Kevin or another member of the team in Derby, Leicester, or Nottingham on 0800 024 1976 or via our online enquiry form.
Contact us