01732 759725 magazine 33 what someone can do if they want a human to review an outcome. That last point matters, particularly in pensions, insurance and risk advisory. Where AI supports assessments or decisions that have a real impact on clients or scheme members, people have the right to object, request a human review and challenge the result. The ICO is also explicit about language. Technical jargon and legalistic phrasing do not meet the standard. If a client reads your AI disclosure and cannot understand what it means for them, it needs rewriting. AI adoption has accelerated quickly. Privacy notices have not always kept pace. If yours predates the AI tools now embedded in your operations, it almost certainly needs to be looked at. What to do now Do not wait for the next review. On the complaints side, check whether there is a formal process in place. If there is, test it against the new requirements, particularly the 30-day acknowledgement window and whether your privacy notice clearly tells people they can come to the organisation directly. If there is not a process, build one. Regarding AI, map where AI tools are used across your organisation and what personal data they involve. Read the privacy notice as if you were a client seeing it for the first time. If it would not make sense to them, rewrite it. In either case, make sure people know what to do. Staff need to be able to recognise a data protection complaint when it comes in and understand what your AI disclosures actually say. https://www.howdengroup.com/ uk-en/risk-advisory Complaints must be acknowledged within 30 days. Organisations must investigate and respond without unnecessary delay, keep the person informed throughout and tell them the outcome, including their right to escalate to the ICO if they remain unhappy. Their privacy notice must make clear that individuals can complain directly to them. One detail worth noting: complaints must be accepted however they come in, including via social media. That has practical implications for how your teams recognise and log them day to day. This is a meaningful shift. Previously, individuals could go straight to the ICO with a data protection concern. Under the new framework, they are expected to come to you first. That puts the responsibility on organisations to handle complaints properly before they escalate to the regulator. Telling people about AI is already a legal requirement The ICO has been clear on this for some time. If AI is being used to process personal data and your privacy notice does not say so clearly, you risk breaching your transparency and accountability obligations under UK GDPR Articles 5(1)(a), 12 to 15 and 22. The standard expected is not a vague line buried in your terms and conditions. Your privacy notice needs to explain, in plain English, where AI is used and why, what personal data it touches, whether that data is shared with third-party AI platforms and whether it is used to train or improve AI systems. It also needs to cover how AI influences decisions that affect individuals and On 19 June 2026, regulators took a decisive step to put accountability and clarity at the centre of data governance with the introduction of two new data protection requirements, with no exemptions by size or sector. The first requires every data controller to have a formal process for handling data protection complaints, with the clear expectation that organisations handle concerns directly before they reach the ICO. The second raises the bar on how clearly people are told when AI is involved in processing their personal information by ensuring that privacy notices plainly explain how and why AI is used, what data it touches and how individuals can challenge or seek human review of decisions that affect them. For many, particularly across financial and professional services, this will require urgent review and updating of existing processes and disclosures, as regulators signal that vague or outdated approaches will no longer meet legal standards. If either of these is not already on your radar, the time to act is now. A complaints process is no longer optional Until now, handling data protection complaints well was considered good practice. On 19 June, it became a legal requirement under Section 103 of the Data (Use and Access) Act 2025. The ICO has confirmed there are no exemptions. Every organisation that processes personal data must have a formal complaints process in place, regardless of size or sector. Organisations need to give people a clear way to raise a complaint, whether that is by email, phone, an online form or post. On 19 June 2026, two changes to UK data protection law came into force. Both carry real compliance obligations and neither has an exemption, warns Grant Foster, Partner and Risk Advisory Leader at Howden Risk Advisory Are you compliant with the new data protection rules? DATA PROTECTION Grant Foster
RkJQdWJsaXNoZXIy NDUxNDM=