When will data protection complaints pique the ICO’s interest?
Twelve complaints by individuals to ICO about your organisation within a month of each other is the magic number which could trigger unwelcome attention.
This threshold has been revealed as the ICO publishes a framework for how complaints are triaged, managed and recorded. The criteria the ICO uses also provides useful insight into nature of issues the regulator is likely to take more seriously. This in turn gives organisations a way to assess how likely their activities are to elicit regulatory scrutiny, should a complaint be raised.
Now that all organisations are legally required to have a data protection complaints process, it’s hoped the ICO will be less swamped and can therefore become more effective in its complaint handling. Most complainants will be expected to go through the relevant organisation’s complaints process first, before the ICO will assess.
Complaint assessment criteria
The ICO says each individual complaint it receives will be assessed with a focus on the most serious data protection issues, and it will support organisations to comply with their obligations. Even if no future action is taken, records of complaints will be kept, to help identify trends, spot emerging risks and inform wider work.
The following criteria are used by the ICO to determine whether they should investigate a complaint further.
⏹ Level of harm
Has the data protection issue raised caused or is likely to cause anyone a high level of harm? The ICO uses three levels of harm; low, moderate and high.
Low level of harm
The ICO gives an example of an organisation responding two days late to an employee DSAR and omitting some key information. The organisation apologises and provides the missing information. The regulator says this would be classed as low harm, but could become moderate or high if the employee is prevented from acting on some important information in sufficient time or misses a deadline for claiming compensation.
Moderate level of harm
The ICO would class a small company accidentally sending an internal email to a wider distribution list than intended, which included detail of how junior member of staff is underperforming, as moderate harm. This could rise to high if the information was shared outside the company, or reduce down to low if shared with a relevant small group of colleagues.
High level of harm
An example given of high is a school sending an email to all parents and mistakenly attaching a document containing sensitive information about a child, including medical details. This could drop down to moderate harm if the email is only sent to a small relevant group and quickly contained.
You can read other examples in the ICO’s Harm in Complaints.
⏹ Children / other vulnerable people
The ICO will take into consideration the type of people affected or likely to be affected by an issue, with a focus on children and vulnerable adults.
⏹ Volume
Where an issue has had or is likely to have a significant adverse impact on a substantial number of people, the ICO may be more inclined to look into it in more detail.
⏹ Essential services
The regulator may be minded to investigate a complaint in circumstances where people have no choice but to share their personal details with an organisation; a service they had to use with no realistic alternative.
⏹ AI, biometrics and online tracking
Weight will be added to any complaints which relate to the ICO’s strategic priorities.
Alongside the above, the ICO will factor in areas where it feel it can have the most meaningful impact. For example where;
⏹ intervention will help improve data protection rights or the way an organisation is using person information
⏹ changes to policies or practices would benefit many people if they intervened
⏹ an issue raised is new or high profile and regulatory scrutiny would be in the public interest.
What happens if the ICO investigates?
Should the ICO decide they need to investigate further, a designated case officer will ‘weigh up the facts of what’s happened, fairly and impartially’. Where necessary they will ask the complainant and the organisation for more information. Based on this they will provide an outcome. Possible outcomes include:
⏹ The complaint is only logged at this stage
⏹ The complainant is told the organisation appears to have complied with the law
⏹ The organisation is asked to do more to resolve the complaint
⏹ The organisation is given recommendations on how to improve its practices
⏹ Regulatory action such as a reprimand or fine.
Monitoring complaints about each organisation
The ICO says: “We record all the data protection complaints we receive about each organisation. We monitor whether the number of complaints about them reaches a certain amount within a certain time. We call this the threshold.”
This threshold is set at twelve complaints within one month, but this will be kept under review. If you hit the threshold, the ICO will carry out a short, focused review of available information to try and understand why, to establish any patterns.
They may decide to contact organisations about the types of issues people have complained about, or they may take no further action at this stage. But even if no further action is taken the organisation will remain on the ICO’s radar with a review every six months for at least two years to see if anything changes.
Organisations and their complaint handling
The message is clear from the ICO; if organisations handle complaints they receive well, this will reduce the number of complaints to the ICO and mean the regulatory intervention is less likely.
I think some organisations and individuals would welcome more proactive reassurance. Data Subject Access Requests is a good example, as they’ve always made up a significant proportion of all complaints to the ICO, and no doubt still will.
If someone believes an organisation has not handled a DSAR properly, an internal complaints process may not persuade them otherwise. They may still raise a complaint with the ICO but will remain a statistic unless eleven other people complain about the same organisation in the same month. Will this leave the organisation uncertain as to the robustness of their approach, and the individual wondering why they bothered complaining?