Data Governance Atlas

Anatomy of a data protection complaint

For both sides

A composed escalation letter taken apart paragraph by paragraph — what each part asserts, which provision it engages, and what it obliges the recipient to do.

NIST PF CM-P
ISO 27701 A.7.3.9
GDPR family Art 5(1)(c)Art 5(1)(d)Art 6(1)(f)Art 15Art 16Art 19Art 77

Most guidance addresses one side: how to complain, or how to handle complaints. This page does both at once, because they are the same analysis read from opposite ends.

The scenario and every quotation below are invented. They are a composite of patterns that recur constantly in this correspondence, written to illustrate the structure. No real dispute, organisation or person is described.

The scenario

A customer of an energy supplier is recorded under the wrong name and repeatedly addressed by it. They send a screenshot; a support agent replies that no such correspondence can be found. Separately, while resolving a billing dispute, the supplier passes the customer’s details to a debt collection agency on the basis that the agency handled the account — it did not. The customer makes a subject access request, which is answered, and the response shows both that the screenshot was received and that the disclosure happened. Three months pass with no substantive reply, and the customer escalates to the sector ombudsman and the regulator.


Paragraph by paragraph

“I am writing to notify you that I have escalated this matter to the ombudsman and the regulator.”

Asserting: the internal process is exhausted and the matter is now external.

Engages: the right to lodge a complaint with a supervisory authority, which exists independently of any contractual or sector route. The two run in parallel — the ombudsman decides the service dispute, the regulator assesses the data protection conduct.

For the DPO: this changes your position materially. You are no longer managing a customer complaint; you are creating the record a regulator may later read. Write everything after this point on the assumption it will be disclosed.


“It has been three months since my last correspondence, to which no response was provided.”

Asserting: unreasonable delay.

Engages: the obligation to respond without undue delay and in any event within one month, extendable by two for complex or numerous requests, with the extension notified inside the first month. A complaint is not automatically a rights request — but where it asserts a right, the clock is running.

For the DPO: silence is the most damaging fact in the letter. A regulator looks at the response record before it looks at the substance. An extension taken but never communicated is a separate failure from the delay itself.


“Your agent stated they were unable to locate any correspondence recording my name incorrectly.”

Asserting: inaccurate personal dataPersonal dataAny information relating to an identified or identifiable person: names, IDs, location, online identifiers, and combinations that single someone out., and a failure to investigate it properly.

Engages: the accuracy principle and the right to rectification. A name is personal data, and being wrong is exactly what accuracy addresses. “We could not find it” is not a rectification decision — it is an account of a failed search.

For the DPO: a search that fails to find evidence the requester already supplied is a records problem. When a subject access response later proves the evidence was held, it becomes a credibility problem. See rectification in practice.


“The response to my subject access request confirms the screenshot was received on [date].”

Asserting: the controllerControllerDecides why and how personal data is processed. Carries most of the duties — and the fines.’s own disclosure contradicts its earlier denial.

Engages: the right of access, used evidentially. This is the mechanic controllers underestimate most: an access request is routinely the evidence-gathering stage of a dispute.

For the DPO: treat every access request as potentially that. Not a reason to narrow the response — narrowing it is itself an infringement — but a reason to ensure the underlying records are accurate and that colleagues’ informal assertions match them.


“I dispute that this disclosure rested on legitimate interests. The necessity test is not met.”

Asserting: the lawful basis fails at the second limb.

Engages: legitimate interestsLegitimate interestsUpdate: DUAA 2025 introduced a \, which is not one test but three — a legitimate purpose, necessity, and a balance against the individual’s rights and reasonable expectations. The writer has separated them and attacked necessity independently of the balance.

For the DPO: answer all three limbs explicitly, or concede. A reply asserting “legitimate interests” without addressing necessity has not engaged with the complaint. See the legitimate interests assessment.


“The account was never referred for collection, so no third party needed to identify me to resolve it.”

Asserting: the disclosure was unnecessary because the purpose it served did not exist.

Engages: necessity, and data minimisation. Necessity is not “useful” or “how we normally do it” — it asks whether the purpose could reasonably be achieved less intrusively. If no referral was required, the sharing had no purpose to be necessary for.

For the DPO: the strongest limb, and the hardest to answer, because it is factual rather than legal. Establish whether the referral was actually required before you defend the disclosure.


“Your own records show the disclosure was made on the mistaken belief that the agency held the account.”

Asserting: the disclosure rested on an error, so the balance cannot save it.

Engages: accuracy and lawful basis together. An interest built on a mistaken belief carries little weight, because the weight depends on the purpose being real.

For the DPO: this is where accuracy and lawful basis stop being separate complaints. See disclosures to third parties.


“Any industry practice of routine referral does not supply a lawful basis for a specific disclosure.”

Asserting: common practice is not a lawful basis.

Engages: the basis requirement generally. Correct, and worth stating plainly: each instance of processing needs its own basis. An arrangement does not become lawful by being routine.

For the DPO: if your answer to “what was the basis” is “this is how the sector settles accounts”, you do not have a basis; you have a habit. Sector arrangements can support a legitimate interest, but they must still be assessed.


“You may wish to consider whether this meets the threshold for reporting to the regulator.”

Asserting: this may be a notifiable personal data breach.

Engages: the breach notificationBreach notificationThe duty to report qualifying security breaches to the regulator — 72 hours in GDPR-family laws — and often to affected people. duties. An unauthorised disclosure to a third party is capable of being a breach — the definition covers unauthorised disclosure, not only security incidents in the hacking sense.

For the DPO: assess it rather than dismissing it because nothing was attacked. See when to report yourself. A documented assessment concluding “not notifiable” is a good outcome; an absent assessment is not.


What the recipient should actually do

  1. Acknowledge in writing, immediately, with a named owner and a date.
  2. Reconstruct the timeline from your own records — receipt, searches, responses.
  3. Answer the rectification point separately from the disclosure point. Different rights, different remedies; merging them reads as evasion.
  4. Produce or write the legitimate interests assessment. If none existed at the time, say so — a retrospective one is not the same thing, and claiming otherwise is worse than the original gap.
  5. Assess the breach threshold and record the reasoning either way.
  6. Check the notification duty: if data was rectified, recipients of the incorrect version must be told unless impossible or disproportionate. Regularly missed.
  7. Answer every numbered point. Answering two of three and going quiet on the third is the most common failure in this correspondence.

What makes a letter like this hard to deflect

Worth naming, because it is the model to copy: each allegation tied to a specific provision; necessity and balance attacked separately rather than as one vague objection; facts stated before legal conclusions; the access request used as evidence rather than as a threat; and the remedy sought identified. Every paragraph asks a question that has an answer, which is precisely what makes a non-answer visible.

How this differs elsewhere

No departures recorded for this concept yet. That is not a finding. It means nobody has checked, not that the position is the same everywhere — see the coverage note on the governance index.

Where this connects

Sources

Never independently verified.