Skip to main content
Back to Legal
10 Last updated: August 2026

Data Protection Complaints Policy

Quick Summary

Handling data protection complaints is a core accountability obligation. UrbanChain must provide clear routes for individuals to raise concerns about how their personal data is handled, acknowledge complaints promptly, investigate without undue delay, and communicate outcomes transparently. This policy establishes a structured, auditable framework to ensure complaints are managed fairly, consistently, and in line with regulatory expectations.

1. Who is covered by this policy

This policy applies to all individuals who process personal data on behalf of UrbanChain, including employees, contractors, temporary staff, partner organisations and third parties with access to UrbanChain systems or data.

2. Why do we need this policy

This policy ensures that UrbanChain can:

  • demonstrate accountability to regulators;
  • handle complaints consistently and fairly; and
  • reduce regulatory risk by resolving issues before escalation to a regulator.

Failing to maintain a robust complaints process can increase the risk of unresolved data protection concerns, regulatory scrutiny and damage to our organisation's reputation. Without a formal mechanism for handling complaints, individuals may feel their concerns are not taken seriously, which could lead to the issue being escalated to a regulator. In addition, the absence of a complaints process may make it difficult for an organisation to identify systemic issues and evidence compliance with its obligations, more generally.

3. Policy principles you should be aware of

UrbanChain adopts the following principles when handling data protection complaints:

  • Accessibility: Individuals must be able to complain using any reasonable channel.
  • Fairness: Complaints must be assessed objectively and without bias.
  • Timeliness: Action must be taken without undue delay.
  • Transparency: Individuals must be informed about progress and outcomes.
  • Accountability: Decisions and actions must be recorded and justifiable.
  • Proportionality: Investigations must be appropriate to the risk and impact.

4. How we aim to comply with the principles

4.1 Receiving complaints

UrbanChain accepts data protection complaints through multiple channels, including:

  • email;
  • an online form;
  • telephone;
  • post;
  • in person; and
  • social media (with redirection to secure channels).

Complaints do not need to reference legislation or use formal language. Any expression of dissatisfaction about personal data handling may qualify.

To submit a data protection complaint, please contact our Data Protection Officer at DPO@urbanchain.co.uk.

4.2 Acknowledging complaints

  • Complaints must be acknowledged as soon as possible and within 30 calendar days.
  • The timeframe begins the day after receipt.
  • If the deadline falls on a non-working day, the next working day applies.

Acknowledgement should:

  • confirm receipt;
  • outline next steps; and
  • provide a point of contact.

Where identity verification or clarification is requested early, a separate acknowledgement is not required.

4.3 Identifying and clarifying complaints

Where ambiguity exists, UrbanChain will:

  • seek clarification promptly;
  • confirm whether the matter relates to data protection; and
  • identify the desired outcome.

Not all complaints that include data rights are data protection complaints. For example, a service complaint bundled with a deletion request remains primarily a service issue. Misclassification here is a common operational error that distorts reporting and response priorities.

4.4 Investigation Process

All data protection complaints must be investigated in a structured, fair and proportionate manner. Investigations must:

  • assess all relevant facts thoroughly, objectively and without bias;
  • involve appropriate staff, including subject matter experts where necessary (e.g. IT, HR, safeguarding, or legal);
  • compare the details of the complaint with internal records, systems and correspondence; and
  • consider applicable internal policies, procedures, contractual obligations and legal requirements.

Investigations must begin immediately upon receipt of the complaint, and not be delayed pending formal acknowledgement.

Each complaint must have a nominated investigation lead responsible for coordinating and overseeing the process. The investigation lead will take ownership of the complaint from receipt to outcome, ensure the scope of the investigation is clearly defined at an early stage, identify and engage relevant stakeholders and departments, and act as the primary internal point of contact for the complaint.

Relevant staff must be consulted as part of the investigation. This may include:

  • individuals directly involved in the handling of the data;
  • system or asset owners; and
  • managers responsible for the relevant process.

Staff should be asked to provide factual accounts and supporting information. The investigation lead must ensure that responses are considered critically and not accepted at face value where inconsistencies arise.

A clear audit trail must be maintained throughout the investigation, including:

  • key decisions and rationale;
  • evidence reviewed;
  • communications with staff and the complainant; and
  • any deviations from standard process and the reasons for them.

This record must be sufficient to demonstrate accountability and withstand internal or external scrutiny.

4.5 Timeframes and delays

UrbanChain must investigate complaints without undue delay.

Factors influencing investigation time include:

  • complexity;
  • scale;
  • potential harm; and
  • availability of information.

To support efficient investigations, the following internal target timelines apply as best practice benchmarks:

  • Logging and triage: within 1–2 working days of receipt
  • Acknowledgement: within 3–5 working days (and always within the 30-day legal maximum)
  • Initial assessment and scoping: within 5 working days
  • Substantive investigation underway: immediately after triage, with no avoidable gap
  • Progress update to complainant: within 10–15 working days where the matter remains open
  • Outcome provided: within 20–30 calendar days for standard complaints

For complex, large-scale, or high-risk complaints, timelines may extend where justified. In such cases, UrbanChain will:

  • prioritise based on risk and potential harm;
  • document reasons for any delay; and
  • provide clear, revised timeframes to the complainant.

These timelines are intended to promote prompt handling. They must not be treated as default waiting periods. Where a complaint can be progressed or resolved more quickly, it must be.

4.6 Communication and updates

UrbanChain must:

  • keep complainants informed of progress;
  • explain delays where they arise; and
  • provide expected completion timeframes.

Communication should prioritise clarity over volume. Excessive procedural updates without substance can obscure rather than inform.

4.7 Outcome and resolution

Upon completion, UrbanChain must:

  • provide a clear outcome;
  • explain findings and reasoning;
  • describe any remedial actions; and
  • address each complaint point where relevant.

Even where UrbanChain concludes that it has complied with data protection law, the response must provide a clear and reasoned explanation. Simply stating that compliance has been met, without supporting detail, is unlikely to be sufficient under scrutiny.

Complainants should also be informed of their right to escalate to a regulator.

5. Who is responsible

  • Senior Managers: overall accountability and oversight.
  • Primary Security Contact: advice, monitoring, and escalation.
  • Line Managers: ensuring staff awareness and appropriate handling.
  • All Staff: recognising and escalating complaints appropriately.

6. Why you need to comply with this policy

Handling complaints about personal data is a core element of responsible data governance in any jurisdiction. Organisations that deal with complaints effectively are better able to identify risks early, correct mistakes, and demonstrate accountability to individuals, regulators, and partners. A clear and responsive complaints process helps to:

  • build trust with individuals whose data is being processed;
  • reduce the likelihood of escalation to regulators or legal claims;
  • surface systemic issues in data handling practices; and
  • strengthen overall data protection and information governance frameworks.

Ignoring or minimising complaints tends to have the opposite effect. Concerns harden into disputes, small issues become systemic failures, and the organisation loses the opportunity to resolve matters on its own terms.

7. Definitions

Term Definition
Asset Owners Information system owners responsible for assessing compliance and ensuring their systems comply with this Access Control policy.
Chief Executive Officer, CEO Has overall accountability and responsibility for information security within UrbanChain on a day-to-day basis.
Data Champions Senior owners within the business entrusted with promoting good data governance and data management within their own department and cross-company. A list of all the Data Champions is available in the UrbanChain app.
Everyone Includes all UrbanChain employees as well as all temporary staff, contractors, consultants and any third party with whom special arrangements have been made e.g. confidentiality and Non-disclosure Agreements.
Information Any information, data or record irrespective of format, collected, generated or used by a UrbanChain system or process. Examples include: electronic communications, emails, digital recordings such as Call Centre Telephone conversations and CCTV, hard copy (paper) files, photographs, maps, plans, process documentation (code, scripts, etc.) and technical drawings.
Information Classification Assigning a piece of information to a particular category based on its content.
Information Security The ability to protect the confidentiality, integrity and availability of information held by UrbanChain, including any subcontractors and suppliers, from unauthorised use, disclosure, modification, damage or destruction, be it accidental or malicious.
Information System Information in any media type, hardware, software, supporting networks, processes and human resources that support its acquisition, processing, storage and communication.
Personal data Personal data is information which relates to an individual, who can be identified either directly by that information or in combination with other information held by UrbanChain. It is information about an individual whether their name is used or not, so long as it is clear that it is about that particular individual.
Primary Security Contact Individual responsible for providing oversight of related policies and procedures and overall data protection compliance program.
Privileged User A privileged user is a user who has an elevated level of access to a network, computer system or application and is authorised to perform functions that standard users are not authorised to perform. This includes a "standard user" with approved elevated privileges that allows equivalent access to that of a privileged user.
Processing 'Processing' means any operation or set of operations performed upon personal data or sets of personal data, whether or not by automated means, such as collection, recording, organisation, structuring, storage, adaptation or alteration, retrieval, consultation, use, disclosure by transmission, dissemination or otherwise making available, alignment or combination, restriction, erasure or destruction.
Risk Committee UrbanChain forum where information security matters are discussed and activities related to information security are coordinated.
Secure A term used in this document to define the requirement to manage information in a manner so as to minimise the risk of a Security Incident occurring through unauthorised disclosure or access to controlled information.
Senior Owners / Managers Senior leaders (such as heads of departments) in the company who own the overall accountability for data protection. They are the accountability group for data protection, information security and associated risks and sit on regular Risk Committee meetings.
Special category personal data Types of personal data that is sensitive and requires additional protection under the law. These include data revealing: racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, data concerning health, sexual orientation or sex life, genetic or biometric data (such as fingerprint or retinal scan data).
The Business / The Company UrbanChain, classified as a Private Limited Firm.