Data Protection Complaints

Any individual, including a client, former client, prospective client, employee, volunteer, trustee, contractor or other data subject, who has concerns about the way in which SELC has collected, used, disclosed, retained, secured or otherwise processed their personal data may submit a complaint under this procedure.

Scope

This procedure applies only to complaints relating to data protection matters. Complaints concerning service quality, legal advice or professional conduct should be handled through the general complaints procedure. Where a complaint contains both data protection and service-related elements, the relevant procedures may run in parallel.

Accessibility and Support

SELC is committed to ensuring that data protection complaints are accessible to all individuals.

Complaints may be made:

  • In writing.
  • By email.
  • By telephone.
  • Through an authorised representative.
  • With appropriate support from an advocate, interpreter, support worker or other representative.

Reasonable adjustments will be made wherever practicable to assist individuals experiencing disability, language, literacy, digital exclusion or other barriers to making a complaint.

There is no charge for making a complaint.

Informal Resolution

Where appropriate, SELC may seek to resolve concerns informally before commencing a formal investigation.

Examples may include:

  • Providing clarification regarding processing activities.
  • Correcting inaccurate personal data.
  • Explaining a decision relating to a data subject rights request.
  • Providing information that was not previously available.

Where a concern is resolved informally, a record must still be retained on the complaints register for monitoring and governance purposes.

How to Make a Complaint

Complaints should be directed to the Data Protection Lead (currently the Operations Manager) using the info@selc.org.uk email address.

The complaint should include, where possible:

  • The complainant’s name and contact details.
  • Details of the concern.
  • Relevant dates or correspondence.
  • Any steps already taken.
  • The outcome sought.

Anonymous complaints may be considered where sufficient information has been provided to allow investigation.

Logging and Acknowledgement

All complaints must be recorded in the Data Protection Complaints Register immediately upon receipt.

The register must record:

  • Complaint reference number.
  • Date received.
  • Complainant details.
  • Nature of the complaint.
  • Investigating officer.
  • Key actions taken.
  • Outcome.
  • Corrective actions implemented.
  • Date closed.

Complaints must be acknowledged within two working days of receipt.

The acknowledgement shall:

  • Confirm receipt.
  • Provide a reference number.
  • Identify the person handling the complaint.
  • State the expected response date.
  • Inform the complainant of their right to complain to the Information Commissioner’s Office (ICO).

Triage and Risk Assessment

A preliminary assessment must be carried out within two working days to determine:

  • Whether the matter falls within the scope of this procedure.
  • Whether a Data Subject Rights request is involved.
  • Whether a personal data breach may have occurred.
  • Whether safeguarding concerns are present.
  • Whether urgent remedial action is required.
  • Whether any conflict of interest exists.

Where ongoing risk to personal data, safeguarding concerns or significant compliance failures are identified, the complaint must be escalated immediately.

Investigation

The Data Protection Lead, or another suitably independent manager appointed for the purpose, shall conduct a fair and proportionate investigation.

The investigation may include:

  • Reviewing relevant files and records.
  • Reviewing applicable policies and procedures.
  • Consulting relevant staff members.
  • Reviewing data protection compliance requirements.
  • Assessing whether any remedial action is required.

The investigator must maintain written records of all significant investigative actions and conclusions.

Where a staff member is the subject of a complaint, they must be given an opportunity to respond.

Conflicts of Interest

Any person with a personal involvement in, or conflict relating to, a complaint must not investigate that complaint.

Where the complaint concerns the Data protection lead or a member of senior management:

  • The matter shall be referred to the Managing Director/Senior Solicitor.
  • Where independence cannot reasonably be achieved internally, an external investigator may be appointed.
  • Trustees may provide oversight where appropriate.

Personal Data Breaches

Where a complaint identifies or suggests a personal data breach, the Data Breach Procedure must be activated immediately.

Investigation of the complaint must not delay:

  • Breach containment measures.
  • Risk assessment.
  • ICO notification requirements.
  • Notification of affected individuals where required by law.

All such matters must be recorded on the Data Breach Register.

Safeguarding Concerns

Where a complaint identifies a safeguarding concern involving a child, young person or adult at risk, the matter must be immediately referred to the Designated Safeguarding Lead.

Safeguarding action shall proceed independently of, and in parallel with, the complaints investigation.

Response Times

SELC aims to meet the following service standards:

Stage Target
Acknowledgement 2 working days
Initial triage 2 working days
Final response 20 working days

 

Where a complaint is particularly complex, the response period may be extended.

The complainant must be informed:

  • Why an extension is necessary.
  • The revised response date.
  • Their continuing right to complain to the ICO.

Outcomes

Complaints will normally be categorised as:

  • Upheld.
  • Partially Upheld.
  • Not Upheld.
  • Resolved Informally.
  • Withdrawn.

The outcome letter shall include:

  • A summary of the complaint.
  • Details of the investigation undertaken.
  • Findings.
  • Any corrective actions identified.
  • Information about escalation rights.

Corrective Actions and Organisational Learning

Where a complaint identifies failures or weaknesses, SELC will implement appropriate corrective action.

This may include:

  • Rectifying, erasing or restricting personal data.
  • Issuing an apology.
  • Providing information previously omitted.
  • Staff training.
  • Process improvements.
  • Policy revisions.
  • Technical security improvements.

Serious or systemic failures shall be subject to root-cause analysis and tracked until all corrective actions are completed.

Record Retention

Data protection complaint records shall be retained for seven years following closure of the complaint, or longer where litigation, regulatory investigation or safeguarding matters require extended retention.

Access shall be restricted to authorised personnel only.

Contact us

For further information about our complaints process, please get in touch with us.

Southern England Law Centre
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.