After nearly two decades in compliance, I have come to the conclusion that FCA complaints and data protection complaints have more in common than most people realise. Before anyone starts drafting an objection, I am not suggesting they are the same thing. They aren’t. They are covered by different laws. They involve different rights, create different risks and are overseen by different regulators. But when I look at where data protection complaints handling is heading, I see some very familiar themes. Themes that take me back to the early days of Treating Customers Fairly (TCF).
Treating Customers Fairly, or TCF, was the FCA’s framework for making sure financial services firms put fair customer outcomes at the heart of everything they did, not just at the point of sale, but throughout the life of a product or service. Firms needed to show that customers could trust them to act in their interests, that products were designed for the people who actually bought them, and that complaining or claiming didn’t come with unreasonable barriers.
TCF’s principles were later absorbed into the Consumer Duty in 2023, but the underlying thinking is the same, now emerging in how organisations are expected to handle data protection complaints under DUAA: curiosity, accountability, and learning from complaints rather than simply closing them.
That’s the real value of comparing FCA complaints and data protection complaints: not because they are the same, but because one discipline has already been through the shift the other is going through now.
From TCF to DUAA: Why Data Protection Complaints Are Following the Same Path
Starting my career when I did gave me a front-row seat to one of the biggest changes in financial services regulation.
Before TCF, complaints were often treated as operational issues. You received the complaint, investigated it, responded and moved on.
TCF changed that mindset. Complaints stopped being something to close down. They became something to learn from and gave firms’ insight into the customer experience. They showed whether customers were receiving fair outcomes. They also helped firms identify weaknesses in their processes, systems and controls.
Over time, the main features of good FCA complaints handling became clear:
- Identify and record complaints properly
- Investigate concerns promptly and fairly
- Reach decisions based on evidence
- Carry out root cause analysis
- Escalate serious issues
- Use complaints data to improve products, services and customer outcomes
The focus moved from “Have we responded?” to “What can we learn?”
When I look at data protection today, I cannot help thinking we are seeing a similar change.
DUAA 2025 requirements for Data Protection Complaints
The 30-Day Acknowledgement Rule
The Data (Use and Access) Act 2025 has made complaints handling a more formal part of the data protection framework. Organisations must give people a clear way to complain, acknowledge complaints within 30 days, make appropriate enquiries, keep people informed and explain the outcome without undue delay. The ICO’s guidance on data protection complaints sets out those requirements.
But following the process is only the starting point.
Data protection complaints have often been treated as one-off issues. Someone is unhappy with a privacy notice. Someone disagrees with a subject access response. Someone believes their personal information has been handled incorrectly.
The immediate aim is usually to resolve the issue in front of you. But those complaints may be telling you something much bigger.
They can point to problems with transparency, data quality, retention, subject rights handling, staff training or culture.
Just as FCA complaints became a useful source of information about the way a firm was operating, data protection complaints can show whether an organisation’s privacy framework is actually working in practice.
FCA Complaints vs Data Protection Complaints: The Key Differences
That does not make the two disciplines the same.
- An FCA complaint will usually be about customer detriment linked to a product, service, advice or conduct.
- A data protection complaint is about how personal information has been used. It may involve access, rectification, erasure, restriction, objection, transparency or lawful processing.
Those differences matter. The legal duties, timescales, routes for escalation are different. The consequences may also be very different.
When One Complaint Raises Multiple Issues
A customer
- complaining about poor service may be raising an FCA complaint.
- complaining that inaccurate personal information contributed to that poor service may also be raising a data protection complaint.
- asking for inaccurate information to be corrected may not be complaining at all. They may simply be exercising a statutory right.
Sometimes, the same set of facts will raise more than one issue. That is where the challenge lies. Organisations need to work out exactly what they are dealing with from the start.
Good initial assessment has always mattered in FCA complaints handling. I would highlight this is just as important in data protection.
Shared Principles: FCA and Data Protection Complaints
Once you move on from the different legal frameworks, many of the basic compliance principles are remarkably similar.
Both require organisations to
- identify concerns correctly
- to maintain good record keeping
- conduct fair and proportionate investigation.
- ensure accountability and oversight.
- show not only what decision was made, but how it was made.
And perhaps most importantly, both require organisations to learn!
Root Cause Analysis: Turning Complaints Into Compliance Intelligence
The FCA expects firms to analyse complaints, identify root causes and consider whether the same problem could affect other products or processes. Its work on complaints and root cause analysis also highlights the importance of useful management information, clear governance and action.
Data protection teams should be asking similar questions.
Is this a one-off mistake or a sign of a wider problem?
Could the same issue affect other people, systems or data?
Does it show a weakness in a policy, process, control or staff training?
What needs to change to stop it happening again?
Looking back, many of the behaviours encouraged by TCF would fit just as easily into the modern DUAA data protection framework.
- Curiosity
- Accountability
- Decisions based on evidence
- Root cause analysis
- A focus on outcomes
Maybe that is why the latest changes in data protection do not feel entirely new to me. I have seen what happens when organisations stop treating complaints as isolated events and start treating them as useful information. Financial services learned that lesson through TCF.
Data protection is following its own path down DUAA, but the same opportunity and consequences are there.
The organisations that will do well are not necessarily those that receive the fewest complaints. They will be the ones that listen, classify concerns correctly, investigate properly and use what they learn to improve their governance and controls.
Different regulations. Different rights. Different regulators.
But from a compliance point of view, they are probably more alike than they may like to admit.
How TenIntelligence Can Help
Knowing the theory is one thing. Knowing whether your organisation’s data protection complaints process would actually hold up under scrutiny is another.
We work with compliance leaders, data privacy professionals and general counsel to pressure-test exactly that. Our Data Protection Assessment looks at how complaints are identified, recorded, investigated and escalated and, just as importantly, whether the insight from those complaints is actually feeding back into policy, training and controls.
If TCF taught financial services anything, it’s that a good complaints process on paper and a good complaints process in practice are two different things. We help organisations find out which one they actually have, before a regulator or a data subject access request does it for them.

Written by
Lynsey Hanson| Global Data Protection Officer
FAQs
Can one customer complaint raise both an FCA and a data protection complaint?
Yes. A customer complaining about poor service may be raising an FCA complaint. If inaccurate personal information contributed to that poor service, they may also be raising a data protection complaint. Organisations need a clear initial assessment process to identify which issue, or issues, they’re actually dealing with, rather than treating every complaint as a single category.
Where can businesses get independent support distinguishing FCA complaints from data protection complaints?
Independent specialists assess complaints handling frameworks objectively, checking whether an organisation correctly classifies complaints and whether root cause analysis is genuinely feeding back into governance. TenIntelligence supports this through its Data Protection Assessment, helping organisations tell FCA-style complaints, data protection complaints and statutory rights requests apart from the outset.
