Series
Blogs
UK Pensions – Dealing with data protection complaints
UK Pensions – Dealing with data protection complaints
15 May 2026
Series
Blogs
15 May 2026
Author: Claire Collier
From 19 June 2026, trustees need to meet new requirements to have a data protection complaints process under the Data Use and Access Act 2025.
Trustees can choose to retain their current internal dispute resolution procedure (IDRP) and create a separate complaint process and complaint form specifically for complaints relating to data protection, or incorporate the data protection complaints process into their existing IDRP.
However, trustees should be aware that different requirements apply under the new data protection complaints regime as compared to the existing IDRP regime, and each have different escalation routes (one to the Information Commissioner’s Office and one to the Pensions Ombudsman). If trustees decide to incorporate the data protection complaints process into their existing IDRP, they will need to ensure the requirements outlined below in relation to data protection complaints are met.
From 19 June, new requirements will apply in relation to complaints about data protection. This could include complaints about the way trustees have responded to a subject access request, the security measures trustees have used to store personal information, or how trustees have collected or used personal information.
Data protection law requires trustees to:
There may be cases where a data protection complaint forms part of a wider complaint about other issues relating to the pension scheme. If trustees can provide an outcome to the data protection complaint sooner than the other issues, trustees must do this, as waiting to deal with all the issues at once without justification could cause an undue delay.
We recommend that trustees take the following steps before 19 June:
For more information, please speak to your usual Linklaters contact.