On 23 June 2026 at 1:00 PM BST, a significant requirement of the UK Data (Use and Access) Act (DUAA) came into force — and many organisations were still not fully prepared.
For the first time, controllers will need to have a formal and operational complaints procedure in place.
This marks a shift from accountability on paper to accountability in practice — and the gap between the two is often where risk sits.
During the session, we unpacked:
➡️ What the DUAA complaints requirement means and why it matters
➡️ How organisations are preparing their processes for the new requirement
➡️ Where compliance gaps typically arise and how to close them
➡️ How to operationalise complaints handling through workflows, governance and clear accountability
➡️ Real practitioner insights on managing complaints at scale
🎙️ Speakers
- Steve Wright — Founder & CEO, PICCASO (Moderator)
- Barry Gibbon — Group Head of Privacy & Data Protection, Cantor Fitzgerald
- Charlie Gretton — National Account Executive, Dastra
- Janine McKelvey — General Counsel, Privacy & Ethics Officer, BT
Organisations without a clear complaints process, acknowledgement mechanism or governance framework in place may already be creating unnecessary compliance risk.
If you are a DPO, compliance lead or privacy professional working through what the DUAA complaints mean for your organisation, this session is designed for you.