Data Protection Complaints Procedure
Data Protection Complaints Procedure
1. Purpose
This procedure defines how Fenn receives, acknowledges, investigates, and responds to data protection complaints from individuals. It implements the statutory complaints duty introduced by Section 164A of the Data Protection Act 2018 (inserted by the Data (Use and Access) Act 2025), which requires controllers to maintain a process for handling complaints and to facilitate individuals in raising them.
2. Application
This procedure applies to all data protection complaints received by Fenn, whether from employees, customers, or any other individual whose personal data Fenn processes as a controller. It covers complaints about any aspect of how Fenn has handled personal data, including collection, storage, use, disclosure, retention, and responses to rights requests.
Where Fenn acts as a processor for customer data, complaints about the processing of that data should be directed to the customer (the controller). Fenn assists the controller in responding to such complaints in accordance with the Data Processing Agreement.
3. What Is a Data Protection Complaint
A data protection complaint is any expression of dissatisfaction from an individual about how their personal data has been handled where the individual believes Fenn has not complied with data protection law. A complaint does not need to use legal terms or cite specific legislation to qualify.
Examples include complaints about how Fenn has responded to a subject access request or other rights request, the security measures used to protect personal data, how personal data was collected or used, how long personal data has been retained, or the accuracy of personal data held.
Complaints about Fenn’s products or services that do not concern the handling of personal data are not data protection complaints and are handled through Fenn’s general support channels.
4. How to Complain
Individuals may submit a data protection complaint to Fenn by emailing privacy@fennagritech.io. Fenn accepts complaints regardless of how they are submitted, including by email, letter, or through any other channel through which the individual contacts Fenn. If a complaint is received through a channel other than the privacy address, all employees and contractors are responsible for routing it to the Head of Security without delay. The complaint route is published on the Fenn trust center and referenced in Fenn’s privacy communications.
5. Handling a Complaint
5.1 Acknowledgment
Fenn acknowledges receipt of every data protection complaint within 30 days. The acknowledgment confirms that the complaint has been received, identifies the Head of Security as the contact for the complaint, and provides an indication of what the individual can expect next.
5.2 Investigation and Response
The Head of Security takes appropriate steps to investigate the complaint without undue delay. This includes reviewing the relevant processing activity, consulting the applicable policy or procedure, and determining whether Fenn’s handling of the personal data complied with data protection law.
If the investigation reveals a personal data breach, the Incident Response Plan is activated immediately regardless of the complaint’s progress.
Fenn keeps the individual informed of the progress of their complaint where the investigation takes longer than expected.
5.3 Outcome
Fenn communicates the outcome of the complaint to the individual without undue delay. The outcome explains what steps were taken to investigate the complaint, any actions taken or to be taken as a result, and the individual’s right to complain to the Information Commissioner’s Office if they are not satisfied with the outcome.
5.4 Escalation to the ICO
If the individual is not satisfied with Fenn’s response, they may lodge a complaint with the Information Commissioner’s Office under Section 165 of the Data Protection Act 2018. Fenn provides the ICO’s contact details in every outcome communication.
5.5 Conflicts of Interest
Where a complaint concerns a decision made by the Head of Security, the complaint is escalated to the CTO, who assumes responsibility for the investigation and response.
6. Record-Keeping
Fenn records each data protection complaint, including the date received, the nature of the complaint, the steps taken to investigate, the outcome, and any actions taken. Complaint records are retained for six years from complaint closure, aligned with the Limitation Act 1980 six-year claim window, as recorded in the Data Retention Policy.
7. Review
This procedure is reviewed annually, and after any significant change to data protection law or the ICO’s complaints guidance.
8. Related Documents
- FENN-POL-002: Information Security Policy
- FENN-POL-004: Data Retention Policy
- FENN-PLN-001: Incident Response Plan
- FENN-SCP-001: Scope and Context
- Data Processing Agreement
9. Revision History
| Version | Date | Author | Description |
|---|---|---|---|
| 1.0 | 2026-08-25 | Jack Lowe, Head of Security | Initial version. Implements the statutory data protection complaints duty under Section 164A of the Data Protection Act 2018. |