The ICO's "Digital Bin" Complaints Row: What It Means for Every UK Data Controller
Five weeks after every UK organisation became legally required to run a proper, documented complaints process under DUAA, the regulator that will judge whether they did it right is itself being taken to task for allegedly doing the opposite.
The Good Law Project and Open Rights Group have threatened the ICO with legal action after accusing it of "brushing aside" thousands of data protection complaints from the public, describing the regulator's new approach to complaint triage and investigation as akin to a "digital bin" for the public's concerns. The row is not a side story. Read alongside the complaints obligations that came into force for every UK organisation on 19 June 2026, it reveals something every business, IT director and compliance lead needs to understand about where the real burden of proof now sits.
Key takeaways
The ICO published a new complaint triage framework on 5 February 2026 that prioritises complaints by assessed harm level.
The Good Law Project and Open Rights Group say the framework effectively "bins" complaints that do not show serious, demonstrable harm.
DUAA made it mandatory for every UK data controller to run a formal complaints process from 19 June 2026, with a 30-day acknowledgement deadline.
The combination means organisations cannot assume the ICO will catch a compliance failure. Self-policing through documented, certified processes is now the primary safeguard, not a backup to regulatory oversight.
A complaint that never reaches serious harm status and gets triaged away does not mean the underlying issue was fine. It means nobody investigated it.
What the ICO's new framework actually does
Under the framework published 5 February 2026, complaints are triaged based on the ICO's assessment of how harmful the alleged practice is, which the regulator said will help "focus our limited resources where we can make the biggest difference." Outside the level of harm, the ICO also considers the impact on vulnerable individuals, the number of people significantly affected, the relevance to the regulator's strategic priorities, and the general public interest in investigating.
In plain terms: a complaint that cannot demonstrate serious, ongoing, or widespread harm is unlikely to receive a substantive investigation. The ICO's own justification is resource-based. An ICO spokesperson said the regulator "must be strategic" in how it handles complaints, "focusing our finite resources on complaints where there is the greatest risk of harm and where our intervention can make the biggest impact," while stating it remains "committed to delivering proportionate and timely responses."
The Good Law Project sees this differently. Duncan McCann, the organisation's tech and data lead, said the framework makes clear the regulator was "never interested in protecting our data rights," adding: "The ICO has finally said the quiet part out loud. Unless you're facing serious and ongoing harm, the regulator will just chuck your complaint in a digital bin. This puts each and every one of us at risk from unscrupulous companies who are cavalier with our data." The organisation says that when it wrote to the ICO outlining these failings, the regulator maintained that its preliminary screening process legally counts as an "investigation" and that it has "exclusive discretion" over how it deploys its resources.

The contradiction sitting at the centre of this story
Here is what makes this row worth reading closely rather than scrolling past. The ICO's triage framework is itself the direct result of changes to UK data protection law ushered in by the DUAA, the same legislation that requires organisations to have a data protection complaints process in place by 19 June 2026.
The same piece of legislation that made it mandatory for your organisation to take every complaint seriously, log it, acknowledge it within 30 days and investigate it properly, also gave the regulator the framework it is now being accused of using to deprioritise most of what lands on its own desk. Businesses face a hard compliance deadline. The regulator built itself a discretion-based triage system. Whether or not the legal challenge succeeds, the optics alone tell every UK data controller something important about where accountability actually sits in 2026.
What this means in practice for your organisation
The instinct many organisations have when building a data protection compliance programme is to treat the ICO as the ultimate backstop. If something goes wrong internally, the reasoning goes, the regulator will catch it eventually. This row should unsettle that assumption.
You cannot rely on the ICO to catch every failure. If a complaint about how your organisation handled someone's data is triaged away because it does not meet the threshold of serious, demonstrable harm, that does not retroactively make your handling of that data compliant. It means nobody with regulatory authority looked closely at it. The obligation to have handled the data correctly in the first place never moved.
The burden of proof sits with you at the point of complaint, not at the point of regulatory escalation. Under the DUAA complaints regime, when someone raises a concern, whether about a marketing email, a subject access request, or what happened to their data on a device your organisation retired, you must investigate and respond within 30 days using your own records. If your own documentation cannot answer the question, the fact that the ICO might never see the complaint does not solve your problem. It just means the gap goes unnoticed for longer, until it does not.
Low-harm complaints that go uninvestigated by the ICO can still become high-harm complaints later. A complaint about uncertainty over data disposal, on its own, might not clear the ICO's harm threshold. But if that uncertainty is well-founded, and the data genuinely was mishandled, the consequences of that failure do not stay contained. They surface later, often in a form that does meet the threshold: a data breach, a fraud case traced back to a recovered device, a subject access request that reveals the organisation cannot account for what happened to specific records.
Why this matters specifically for IT asset disposal
This dynamic is particularly relevant to end-of-life IT disposal because it is exactly the kind of issue that tends to generate low-harm, easily dismissed complaints in isolation, right up until it does not.
A former employee emailing to ask what happened to their old laptop is, on its face, a low-severity concern. There is no demonstrated harm yet, just a question. Under the ICO's new framework, a complaint at that stage of concern, on its own and without evidence of actual harm, is a plausible candidate for the kind of triage the Good Law Project is challenging.
But the organisation cannot treat that as licence to respond vaguely. The DUAA complaints obligation still applies. And if the honest answer to "what happened to my data" is "we are not entirely sure," that uncertainty is the actual compliance failure, whether or not the ICO ever investigates it. The only way to close that gap permanently, rather than hoping it never gets tested, is to have the documentation already in hand: a serial-level Certificate of Destruction naming the specific device, the sanitisation standard applied, and a complete chain of custody. That evidence is what turns a low-harm enquiry into a closed, answered complaint, rather than an open question sitting in a queue somewhere waiting to become a bigger problem.
What to do regardless of how the legal challenge resolves
Three actions make sense whether the ICO's framework survives legal challenge unchanged or is forced to reform.
Do not build your compliance posture around the assumption of regulatory backstop. Treat every internal control, complaints process and documentation requirement as your organisation's actual first and only line of defence, because in practice, for many complaints, it now is.
Audit whether your organisation can answer a specific data disposal question today, not eventually. If a former employee, client or customer asked what happened to their data on a named device right now, could you produce a serial-level answer within your own records inside the 30-day DUAA deadline, or would you need to start investigating from scratch?
Treat certified documentation as risk management, not paperwork. A Certificate of Destruction is not overhead. It is the thing that converts an uncomfortable question into a five-minute, fully evidenced response, regardless of whether the ICO ever gets involved.
Retire your IT. Recover its value. Prove it is gone.
NanoSoft provides the serial-level Certificates of Destruction that let your organisation answer a data disposal complaint honestly and completely, without waiting to find out whether the ICO would have investigated it anyway. Every job is documented to a standard that holds up regardless of who is checking.
Contact NanoSoft: services@nanosoftltd.com | 0800 677 1344 | Unit 8 & 9 Maldon Trade Park, Heybridge, Maldon CM9 4LJ, UK
NanoSoft Team
Writer at Nanosoft - covering ITAD, data security, and sustainable technology lifecycle management.
Found this useful? Share it.



