Most small organisations that have thought about GDPR at all have thought about one scenario: someone asks what data is held on them, and there's a month to answer. That's a subject access request, and it's been the whole mental model for years. The Data (Use and Access) Act 2025 — now largely in force — adds a second, separate scenario that doesn't fit that model at all, and it's one a lot of small organisations haven't noticed yet: a standalone duty to handle complaints about data handling, with its own process and its own clock.

The distinction matters because a complaint isn't a data request wearing a different hat. Someone asking "what do you hold on me" wants a copy of their data. Someone complaining is saying something was done wrong with it — kept too long, shared without basis, inaccurate and never corrected, whatever the specific gripe. A small organisation that only ever built a process for the first kind of message now has a gap for the second, and the law no longer treats that gap as someone else's problem to notice.

A complaint needs somewhere to land and a clock that starts on arrival

Under the new duty, an organisation doesn't get to wait and see whether a complaint needs a considered response — a complaint about data handling must now be acknowledged within 30 days, then investigated proportionately and taken through to an outcome without undue delay, whether or not the organisation has a documented process for it. The ICO recommends that a complainant try the organisation first, and most do, but that's encouragement rather than a legal precondition — the complainant can go straight to the ICO at any time, in parallel or instead of raising it internally. For an organisation with no defined complaints route, that means an ordinary email sitting unanswered in a shared inbox for a fortnight isn't a contained, first-stage conversation with time to spare — it's already running against a statutory clock, and the person who sent it was never obliged to wait before going to the regulator anyway.

None of this requires anything elaborate. It requires knowing, before the first one arrives, who reads it, how quickly it gets acknowledged, and what "properly considered" looks like for an organisation of this size — written down once, rather than improvised under the mild panic of an actual complaint landing for the first time.

The subject access request clock now has an explicit pause button

The same wave of changes also puts a longstanding grey area onto a firmer footing: an organisation that genuinely needs to ask a requester for clarification before it can answer a subject access request properly is now able to pause the one-month response clock while it waits for that reply, rather than relying on it being tolerated in practice. That's a real practical help for anyone who's ever received a subject access request too vague to action and wasn't sure whether asking a clarifying question first was safe — it now explicitly is, provided the clarification is genuinely needed rather than a stalling tactic.

Between the two, the shape of what's expected has moved in the same direction: less "wait and see what a message turns out to be," more "know in advance which lane it belongs in, and what the clock does in each one." That's a small piece of documentation, not a department — but it's the piece that turns an unfamiliar message into a routine one instead of a fire.

That's also the instinct behind the assessment tooling built under this roof: not assuming a small organisation needs the same machinery as a large regulated one, but making sure the machinery it does have matches the obligations that actually apply to it — priced accordingly, rather than as an afterthought bolted onto something built for a different scale of problem.