Small business owners exploring local grant funding for website costs
Data protection is not just something for big companies, banks or national brands to worry about. If your business collects personal information through your website, you have responsibilities under UK data protection law. 
 
This can include names, phone numbers, email addresses, enquiry form details, order information, booking details, payment information, staff data, customer records and more. 
 
Under the Data (Use and Access) Act 2025, new rules on data protection complaints came into force on 19 June 2026. The Information Commissioner’s Office, known as the ICO, has confirmed that all organisations handling personal data must now have a clear process for dealing with data protection complaints. This includes giving people a clear way to complain, acknowledging complaints within 30 days, investigating them properly and telling the person the outcome. 
 
So, has your website been updated? Has your current website company made you aware of this? And if a customer wanted to raise a data protection complaint with you today, would they know how to do it? 

What has changed? 

The new rules mean your business must make it easier for people to complain if they believe you have not handled their personal information properly. 
 
The ICO says organisations must now: 
 
Give people a way to make a data protection complaint directly to them. 
Acknowledge receipt of the complaint within 30 days. 
Take appropriate steps to respond without undue delay, including making enquiries and keeping the person informed. 
Tell the person the outcome without undue delay. 
 
This does not mean every business needs a complicated complaints system. For many small businesses, it may be enough to update your privacy policy, add clear wording to your website and make sure your team knows what to do if a complaint comes in. 
 
However, doing nothing is risky. 

What is a data protection complaint? 

A data protection complaint is when someone tells you they do not think you have handled their personal information correctly. 
 
This could be about: 
 
How you used their data. 
How long you kept their data. 
Whether you shared their data. 
A missing or unclear privacy policy. 
A poor response to a Subject Access Request, also known as a SAR. 
Unwanted marketing emails or messages. 
Concerns after a data breach. 
Incorrect customer, patient, client or employee records. 
 
The ICO tells the public that they may be able to complain using a website complaints page, complaint form, email address, phone call or another clear route. It also advises people to check an organisation’s privacy policy or website for the complaints process. 
 
That is why your website matters. 
 
If your privacy policy is out of date, if you have no clear route for data protection complaints, or if your team does not know where these messages should go, a simple concern can quickly become a bigger problem. 

What should your website include? 

Your website should make it clear how people can raise a data protection complaint with your business. 
 
This might include: 
 
A clear section in your privacy policy. 
A dedicated data protection complaints email address. 
A contact form option for data protection complaints. 
A simple explanation of what information someone should include. 
A note explaining that complaints will be acknowledged within 30 days. 
Details of how you will investigate and respond. 
A clear route to contact the ICO if the person remains unhappy. 
 
The ICO says you do not have to create a completely separate tool if your existing complaints process can be adapted, but you must still be able to meet your legal obligations. It also says that having a clear process can improve trust and may lead to fewer complaints being escalated to the ICO. 

Why does this matter for your business? 

Most businesses do not get into trouble because they set out to do something wrong. Problems often happen because nobody noticed that something needed updating. 
 
A website form is added. 
A privacy policy is left untouched for years. 
A customer asks for their data and nobody knows who should reply. 
A complaint goes to a general inbox and gets missed. 
A member of staff leaves and nobody checks where data protection emails are going. 
 
These are simple mistakes, but they can create serious issues. 
 
The ICO has said that resolving complaints quickly and fairly can prevent issues from escalating, protect customer trust and reduce the chance of regulatory involvement. It also says the sectors where data protection complaints are most common include healthcare, financial services, technology and retail. 
 
In other words, this is not just a legal issue. It is a trust issue. 
 
If a customer cannot see how you handle their personal information, will they feel confident sending an enquiry? If a client finds your privacy policy is out of date, will that make them question other parts of your business? If your competitor has clearer, more professional website information, who looks more credible? 

What are the risks of ignoring it? 

The ICO has the power to issue fines for data protection failures. The maximum fine under UK GDPR and the Data Protection Act 2018 can be £17.5 million or 4% of annual worldwide turnover, whichever is higher, depending on the type of infringement. 
 
For most small businesses, the more likely risk is not a huge fine on day one. The bigger everyday risks are: 
 
Losing customer trust. 
Making a complaint worse by handling it badly. 
Having complaints escalated to the ICO. 
Wasting time trying to fix issues under pressure. 
Looking unprofessional compared with competitors. 
Creating problems during tenders, audits or due diligence. 
 
You may also need to pay an annual data protection fee to the ICO unless you are exempt. The ICO says organisations that process personal information are required to pay this fee unless exempt, and failure to pay can lead to penalties. 

Are some industries at higher risk? 

Yes. Any business that handles personal data should take this seriously, but some sectors need to be especially careful. 
 
If you work in finance, insurance, accountancy, healthcare, care, legal services, recruitment, e-commerce or any regulated sector, you may handle more sensitive or detailed personal information. 
 
For example, accountants may hold tax records, payroll data, addresses, National Insurance numbers and financial information. Financial advisers and insurance firms may collect identity documents, bank details, health information, family details and information about vulnerable customers. Healthcare and care providers may handle special category data, which the ICO says needs more protection because it is sensitive. 
 
Regulated financial firms also need to think about how data protection connects with wider regulatory expectations. The FCA and ICO have published joint expectations on areas such as vulnerability-related customer data, and the two regulators have a framework for cooperation and information sharing. 
 
This does not mean every small business needs to panic. It does mean your website, privacy wording and internal process should match the type of data you collect. 

If your web company has not told you, where does the responsibility lie? 

Legally, the responsibility sits with your business. The ICO’s guidance on accountability says you are responsible for complying with UK GDPR and must be able to show the steps you have taken. 
 
If you are the data controller, the ICO says you are responsible for ensuring your processing complies with UK GDPR, including processing carried out by others on your behalf. 
 
However, your website is often the place where important data protection information is shown. It is where your privacy policy lives. It is where people complete enquiry forms. It is where complaints routes, contact details and customer notices are displayed. 
 
That is why your website partner should be paying attention. 
 
A good website company should not leave your site untouched for years. It should help you keep important website information up to date, especially when changes affect most business websites. 
 

How it’seeze helps 

One of the benefits of being with it’seeze is that your website is not simply built and forgotten. 
 
As part of the ongoing service, it’seeze monitors important website-related updates and helps keep client websites current. This includes changes such as privacy wording, website compliance requirements, accessibility expectations, security improvements and other updates that could affect how your website performs or protects your business. 
 
That does not replace formal legal advice where your business needs it, but it does mean you are not left on your own to spot every change. 
 
For many clients, this is one of the biggest reasons they choose it’seeze. You get a professional website, ongoing support and a team that keeps an eye on the details that many businesses simply do not have time to follow. 
 

Is your website up to date? 

If your website has not been reviewed for a while, now is a good time to check it. 
 
Ask yourself: 
 
Does your website explain how someone can make a data protection complaint? 
Does your privacy policy reflect the latest requirements? 
Do your forms collect only the information you need? 
Would your team know what to do if a data complaint arrived today? 
Has your current website provider made you aware of this change? 
 
If the answer is no, it may be time to review your website support. 
 
Your website should help protect your business, build trust and make it easier for customers to deal with you. With the new data protection complaints requirements now in force, keeping your website updated is not just good practice. It is part of running a responsible, professional business. 
 
Share this post: