Privacy Complaints

Purpose and Scope

This procedure establishes a clear and accessible process for handling complaints related to the processing of personal data and privacy matters. It applies globally across all our operations and entities at The Access Group.

The procedure enables individuals to raise concerns about how their personal data has been handled, ensures transparent investigation processes, and supports our commitment to accountability and continuous improvement in privacy practices.

This procedure applies to complaints from individuals (or their authorised representatives) regarding the processing of their personal data. It does not apply to complaints from organisations, such as our business customers. If you are a business customer with concerns about data processing, contractual matters, or service issues, please see the Customer Success Portal for how to make a complaint.

Nothing in this procedure limits or affects an individual's statutory rights, including the right to lodge a complaint with a relevant supervisory authority, and we will continue to comply with our obligations under applicable data protection law.

We may, where lawful to do so, update and or deviate from this procedure at our sole discretion, where deemed necessary.

Definitions

Complaint: Any expression of dissatisfaction relating to the processing of personal data or privacy practices, whether justified or not.

Complainant: Any individual (data subject) who submits a complaint regarding the processing of their personal data.

Personal Data: Any information relating to an identified or identifiable individual.

Processing: Any operation performed on personal data, including collection, storage, use, disclosure, or deletion.

Supervisory Authority: The relevant data protection regulatory body in the applicable jurisdiction (e.g., Information Commissioner's Office in the UK, CNIL in France, state attorneys general in relevant US states).

Submitting a complaint

3.1 How to Submit

Individuals may submit a complaint through any channel, but our preference is via the following online form.

While English is our preferred language for the purpose of complaints - complaints may be submitted in any language commonly used in the regions where we operate. We will arrange translation services where necessary.

3.2 Information to Include

To help us investigate effectively, complainants should provide:

  • Full name and contact details
  • Description of the complaint and which privacy rights or practices are of concern
  • Details of any relevant dates, interactions, or transactions
  • Any supporting documentation or evidence
  • Preferred outcome or resolution sought
  • Any previous attempts to resolve the matter

If a complaint is submitted on behalf of another person, proof of authority to act (such as written authorisation or power of attorney) must be provided.

Complaint handling process

4.1 Receipt and Acknowledgment

Upon receipt of a complaint:

  • We aim to acknowledge receipt within 14 business days
  • The acknowledgment will include a unique reference number for tracking purposes
  • We will confirm our understanding of the complaint and outline the next steps
  • We will provide contact details for the case handler

4.2 Initial Assessment

The Privacy Team will conduct an initial assessment to: 

  • Verify the identity of the complainant (where necessary)
  • Clarify any unclear aspects of the complaint
  • Determine the appropriate response pathway
  • Identify any urgent action required

If the complaint relates to a potential data breach, our Data Breach Response Procedure will be initiated concurrently.

4.3 Investigation

A thorough investigation will be conducted, which may include:

  • Reviewing relevant documentation, records, and systems
  • Interviewing relevant staff members
  • Consulting with technical teams or external advisors as needed
  • Examining our policies, procedures, and compliance measures
  • Requesting additional information from the complainant if necessary

The investigation will be conducted objectively and impartially. The Privacy Team will maintain independence in their assessment.

4.4 Resolution and Response

Following the investigation, we will provide a written response that includes:

  • A summary of the complaint and investigation findings
  • Our decision on whether the complaint is upheld, partially upheld, or not upheld
  • Explanation of the reasons for our decision
  • Details of any remedial actions taken or to be taken
  • Information about the right to escalate to a supervisory authority
  • Information about our internal escalation process (if applicable)

Possible outcomes may include:

  • An apology or expression of regret, where we consider it appropriate (which does not constitute an admission of legal liability or fault)
  • Correction, deletion, or restriction of personal data
  • Changes to policies, procedures, or systems
  • Staff training or disciplinary action
  • Enhanced monitoring or controls

Timeframes

We are committed to handling complaints promptly, our aim is to:

  • Acknowledgment: Within 14 business days of receipt
  • Resolution: Within 30 calendar days from receipt of all necessary information
  • Complex Cases: Where additional time is required, we will inform the complainant within the initial 30-day period, explaining the reasons for the delay and providing an expected resolution date. Extensions will not normally exceed an additional 30 days.

We will keep complainants informed of progress throughout the process, particularly in complex or lengthy investigations.

Escalation

Individuals have the right to lodge a complaint with the relevant supervisory authority at any time, regardless of whether they have used our internal complaints procedure. We will not require individuals to exhaust internal processes before escalating externally.

Relevant supervisory authorities include:

  • UK: Information Commissioner's Office (ICO) - www.ico.org.uk
  • EU/EEA: The supervisory authority in the member state of the individual's habitual residence, place of work, or place of alleged infringement
  • Other Jurisdictions: The relevant data protection or privacy regulator in the applicable territory

We will provide information about the relevant supervisory authority in our response to complaints.

Confidentiality and record keeping

All complaints will be handled with appropriate confidentiality:

  • Information will only be shared with those who need to know for investigation purposes
  • Information will be securely stored in accordance with our retention policy (6 years from closure)

We maintain records of all complaints, including:

  • Nature and details of the complaint
  • Investigation steps taken
  • Outcome and actions implemented
  • Lessons learned and improvements made

These records are used to demonstrate accountability, identify trends, and drive continuous improvement in our privacy practices.

Vexatious or repeated complaints

We handle all complaints seriously and respectfully. However, in cases where complaints are manifestly unfounded, excessive, or repeatedly made without new grounds, we may decline to respond, having provided clear explanation of our reasons

Any such decision will be carefully documented and will respect the individual's right to escalate to a supervisory authority.

Training and awareness

Staff members involved in handling complaints will receive appropriate training on:

  • Data protection principles and individual rights
  • This complaints procedure and associated processes
  • Investigation techniques and impartial decision-making
  • Effective communication with complainants

All employees will be made aware of this procedure and understand their role in supporting an effective complaints process.

Monitoring and continuous improvement

The Privacy Team will:

  • Monitor complaint trends and root causes
  • Report regularly to senior management and governance committees
  • Analyze complaints to identify systemic issues
  • Recommend and implement improvements to policies, procedures, and systems
  • Review this procedure annually and update as needed.

Complaints data will be used constructively to enhance our privacy practices and prevent recurrence of issues.

Accessibility

We are committed to making our complaints process accessible to all individuals. This includes:

  • Providing information in clear, plain language
  • Making this procedure available in multiple languages upon request
  • Offering alternative formats (large print, audio, braille) where needed
  • Providing reasonable accommodations for individuals with disabilities
  • Ensuring our complaint channels are accessible to users with different technical capabilities

Publication and availability

This procedure is made available to all individuals through:

  • Our privacy notice and website
  • Employee SharePoint Site
  • Upon request to the Privacy Team
  • Our Customer Success Portal

Contact information

For any questions about this procedure or to submit a complaint, please submit it via this form.

  • Document Version: 1.0 
  • Effective Date: 12 March 2026
  • Classification: Public
  • Review Date: 12 March 2027
  • Owner: Global Data Protection Officer