On this page
- Purpose
- Scope
- Legal Basis
- What is a data protection complaint?
- What is not a data protection complaint?
- Receiving a data protection complaint
- Time limit for bringing a complaint
- Acknowledgement
- Investigation and response timescale
- Roles and responsibilities
- Complaint outcomes
- Remedies and corrective action
- Escalation to the Information Commissioner’s Office
- Record keeping
- Learning and reporting
- Policy Review
1. Purpose
This policy explains how Bradford Children and Families Trust (the Trust) receives, investigates and responds to complaints about the way it collects, uses, stores, shares, retains, discloses or otherwise handles personal data.
It supports compliance with the UK General Data Protection Regulation, the Data Protection Act 2018, and the Data (Use and Access) Act 2025.
Individuals have the right to complain directly to the Trust if they believe their personal data has been handled in a way that infringes data protection legislation. The Trust aims to resolve complaints fairly, lawfully, promptly and transparently, and to use complaints to improve information governance practice.
2. Scope
2.1 Who the policy applies to
This policy applies to all BCFT employees and any authorised agents working on behalf of BCFT, including temporary or agency staff, elected officials, volunteers, secondees and third-party contractors.
For the benefit of doubt this policy will refer to all individuals within scope of the policy as ‘Officers’. Officers who are found to knowingly or recklessly infringe this policy may face disciplinary action in accordance with BCFT’s disciplinary policies and procedures.
2.2 What the policy applies to
- all personal data processed by the Trust;
- complaints from data subjects or their authorised representatives;
- complaints relating to data subject rights requests, including Subject Access Requests;
- complaints about data handling, including security, sharing, retention, accuracy, or misuse;
This policy operates alongside the Trust’s corporate complaints procedure and statutory complaints processes. Where complaints include both data protection and service issues, the Trust will triage and manage each element under the appropriate process. In such cases, complainants will receive separate responses for each element, issued under the relevant procedure.
3. Legal basis
The Data (Use and Access) Act 2025 introduced a statutory right for individuals to complain to a data controller (section 164A, Data Protection Act 2018).
The Trust will:
- provide accessible ways to make complaints;
- acknowledge complaints within statutory timescales;
- investigate and respond without undue delay;
- keep the complainants informed;
- communicate outcomes clearly.
Individuals are encouraged to raise concerns with the Trust in the first instance so that issues can be resolved before escalation to the Information Commissioner’s Office (ICO).
4. What is a data protection complaint?
A data protection complaint is an expression of dissatisfaction where an individual believes the Trust has failed to comply with data protection law or has mishandled their personal data.
This may include concerns about:
- unlawful or unfair processing;
- inappropriate data sharing or disclosure;
- security failures or breaches;
- excessive retention;
- inaccurate data;
- poor handling of Subject Access Request or other rights;
- lack of transparency;
- distress caused by data handling.
5. What is not a data protection complaint?
This policy does not normally apply to::
- Freedom of Information Act 2000 or Environmental Information Regulations 2004 requests;
- General service complaints;
- statutory children’s social care complaint;
- employee grievances.
Where appropriate, complaints will be redirected to the relevant process.
6. Receiving a data protection complaint
A data protection complaint can be made:
By email:
dpo@bradfordcft.org.uk
By post:
Information Governance Team
Bradford Children and Families Trust
Sir Henry Mitchell House
4 Manchester Road
Bradford
BD5 0QL
Verbally:
A complaint may be made verbally to any Trust employee. The employee must record the complaint and forward it to the Information Governance Team without delay.
Electronically:
A data protection complaint can be submitted by completing the online complaint form available on the Trust’s website.
Complainants should provide:
- their name and contact details;
- details of the issue;
- relevant dates and service area (if known);
- the outcome sought;
The Trust may request further information to support the investigation.
Where necessary, identity and authority checks may be undertaken.
7. Time limit for bringing a complaint
Complaints should normally be made within two months of the last meaningful contact.
The Trust may consider complaints outside these timescales where it is reasonable to do so.
8. Acknowledgement
Complaints will be acknowledged within 5 working days.
The acknowledgement will normally:
- confirm receipt of the complaint;
- provide a reference number;
- set out the process and timescale for handling the complaint;
- ask for clarification and ID if required.
9. Investigation and response timescale
9.1 Non-Complex Requests
For non-complex requests the Trust will investigate and respond without undue delay and will aim to provide a full response within 30 working days.
Where the Trust cannot provide a full response within 30 working days, it will inform the complainant before the deadline expires, explain the reason for the delay, provide a progress update and give a revised response date.
Final responses will normally be issued by the Information Governance Team. The Data Protection Officer will be consulted or will approve responses in complex or high-risk cases, as defined within this policy.
9.2 Complex Requests
Timescales may be extended where complaints are complex, involve multiple services, or require legal, safeguarding or third-party consideration. Where this happens, the complainant will be informed and given a revised response date.
Investigations will consider compliance with key data protection principles, including lawfulness, fairness, transparency, data minimisation, accuracy, retention and security.
Where a complaint is particularly complex, the response period may be extended by up to two further months.
10. Roles and responsibilities
10.1 Information Governance Team
The Information Governance Team is responsible for:
- logging and acknowledging complaints;
- triaging and coordinating investigations;
- overseeing and quality assuring investigations undertaken by service areas;
- liaising with service areas;
- drafting responses;
- approving and issuing final responses to complainants;
- maintaining records.
10.2 Data Protection Officer
The Data Protection Officer is responsible for:
- oversight of compliance;
- advising on complex or high-risk matters;
- reviewing serious complaints;
- identifying trends, learning, and reporting risks;
- Reviewing and approving responses to complex, high-risk, or serious complaints.
10.3 Service areas
Responsible for:
- undertaking investigations into the matters relevant to their service area;
- cooperating with investigations;
- preserving and providing relevant records;
- ensuring the accuracy and completeness of information provided for complaint responses, under the oversight of the Information Asset Owner (IAO);
- implement corrective actions.
10.3 All colleagues
Responsible for:
- identifying complaints;
- reporting promptly to the Information Governance team;
- complete relevant training.
11. Complaint outcomes
The Trust’s response will include:
- a summary of the complaint;
- what was investigated;
- the decision (upheld, partially upheld or not upheld);
- whether the complaint is upheld, partially upheld or not upheld;
- reasons for the decision;
- any action taken or proposed;
- guidance on escalation to the ICO.
The response will normally constitute the Trust’s final position.
12. Remedies and corrective action
Where appropriate, the Trust may:
- apologise;
- correct or update data;
- completing any outstanding requests;
- review processes or controls;
- improving privacy information;
- strengthen security measures;
- providing guidance or training;
- update policies or procedures
Where a complaint identifies a potential personal data breach, this will be assessed in line with the Trust’s breach reporting process, including consideration of ICO notification where required.
13. Escalation to the Information Commissioner’s Office
If the complainant remains dissatisfied after the Trust’s final response, they may complain to the Information Commissioner’s Office. This right will be clearly communicated in the Trust’s final response, together with details of how to contact the ICO.
14. Record keeping
The Trust will keep records of:
- complaints received;
- investigations and evidence
- correspondence;
- outcome and actions;
- learning and improvements.
Records will be retained securely in line with the Trust’s retention schedule.
15. Learning and reporting
The Data Protection Officer and Information Governance Team will monitor complaints to identify:
- trends and recurring issues;
- areas requiring improvement;
- training needs;
- systemic risks.
Learning will be reported through appropriate governance arrangements.
Policy Review
This policy will be reviewed annually, or sooner if there are changes to legislation, ICO guidance, regulatory expectations or Trust processes.
Version: 1.0
Date: 31/05/2026