Voice AI and the DUAA Data Protection Complaints Duty
In short
From 19 June 2026, the Data (Use and Access) Act 2025 requires every controller to handle data protection complaints, acknowledging each within 30 days and responding without undue delay. Dilr Voice is enterprise voice AI that detects a complaint on the call, starts the statutory clock, and keeps the audit trail section 164A demands.
DE
Dilr.ai EngineeringEngineering team
Published Aug 26, 2026Read 12 min
A caller tells your voice AI line that they never agreed to be recorded, that the transcript of their last call is wrong, or that they want to know why an automated system made a decision about their account. Until this year, how you handled that moment was a matter of good manners and internal policy. From 19 June 2026 it is a statutory duty. The Data (Use and Access) Act 2025 inserted a new right for individuals to complain directly to the organisation that holds their data, and a matching obligation on that organisation to receive the complaint, acknowledge it inside a fixed window, and respond.
This matters for voice AI specifically because the technology has moved from pilot to production across the economy. McKinsey's State of AI puts 88% of organisations using AI in some form and 33% running it in production. A voice agent that answers thousands of calls a month is a processing operation at scale, and every one of those calls is a moment where a data protection complaint can be raised. The complaint no longer waits for a letter. It arrives mid-conversation, and the acknowledgement clock starts whether or not anyone at your organisation has read a word of it.
This guide is shipped by the team behind Dilr Voice, enterprise voice AI built for regulated deployments. Or see DATS, our five-stage AI consulting system for placing AI inside compliant processes.
What is the DUAA data protection complaints duty?
The DUAA data protection complaints duty is a statutory obligation, in force from 19 June 2026, that lets any individual complain directly to a controller, and requires that controller to acknowledge the complaint within 30 days and respond without undue delay. It sits in a new section 164A of the Data Protection Act 2018. For a voice AI line, it makes complaint handling a controlled process with a clock.
Before this change, an unhappy individual could complain to the Information Commissioner's Office but had no statutory route into the organisation itself. The DUAA closes that gap. Section 164A gives the data subject a right to raise the complaint with the controller first, and the ICO expects the controller to resolve most complaints at that level before they ever reach the regulator. The duty applies to the whole of your data estate, and a voice AI line is simply one part of it that happens to generate complaints in real time.
Does the complaints duty apply to your voice AI deployment?
Yes. Section 164A binds every controller processing personal data under the UK GDPR or Part 3 of the Data Protection Act 2018, with no carve-out for sector or size. The ICO is explicit that "there are no exemptions to this." If your voice AI line records calls, transcribes them, or makes or informs decisions about the people who ring in, you are a controller for that data and the duty applies to you.
This is the single most important thing to understand about the new regime, and it is where it differs from the complaint rules many enterprises already know. Financial services firms have handled complaints under the FCA's DISP rules for years, and we cover that separate regime in our guide to voice AI complaints handling under DISP and the Ombudsman. But DISP binds FCA-regulated firms only, runs on an eight-week clock, and escalates to the Financial Ombudsman. The section 164A duty binds you even if you have never been within a mile of the FCA, runs on a 30-day acknowledgement clock, and escalates to the ICO. The regime is not who you are regulated by. It is that you hold someone's data.
What must a voice AI line do when a caller complains?
Section 164A sets four obligations. The controller must facilitate the making of complaints, for example by providing a complaint form. It must acknowledge receipt within 30 days. It must, without undue delay, take appropriate steps to respond. And it must inform the complainant of the outcome. For a voice AI deployment, that means the line has to recognise a complaint when it hears one, capture it, and route it into a process that meets each step on time.
The acknowledgement window is the hard edge. The statute is unambiguous on timing:
"the controller must acknowledge receipt of the complaint within the period of 30 days beginning when the complaint is received."
That wording, from section 164A(3), is the clause your operating model has to guarantee. A missed acknowledgement is not a soft failure. It is a breach of a statutory duty that the ICO can act on. The commencement rules narrow the timing rather than the scope: under the transitional provision, the acknowledgement and response duties apply only to complaints received on or after 19 June 2026, so every complaint your live line takes now falls inside the regime. The workflow below is the minimum a compliant voice AI line has to support, and each step maps directly to a subsection of section 164A.
What section 164A requires when a complaint landsThe four statutory steps in DPA 2018 section 164A, from the moment a caller raises a complaint.
In practice, the facilitation step is where most voice AI lines are unprepared. A caller who says "I want to make a complaint about how you are using my recording" has, in law, started this process, even if they never touch a form. The line has to detect that intent, confirm it back, and log the complaint with a timestamp so the 30-day clock is anchored to a real moment rather than to whenever a human happened to notice.
How is this different from a subject access request or an FCA complaint?
The complaints duty is a distinct statutory route with its own trigger and clock. A subject access request under UK GDPR Article 15 asks for the requester's own personal data on a one-month deadline, as our guide to subject access requests for call recordings explains. A section 164A complaint is not a request for data. It alleges the controller has infringed the law, and it can concern an unlawful recording, an inaccurate transcript or an automated decision.
Keeping these apart matters because they route differently inside a voice AI operation. A caller can, in one conversation, exercise several rights at once: ask for their data, object to processing, and complain about how the line handled them. The right to object under Article 21 and the complaints duty are separate obligations with separate clocks, as our guide to the right to object explains. A well-designed line tags each intent separately rather than collapsing them into a single "escalate to a human" bucket, because each one carries its own statutory deadline. The DUAA also reshaped automated decision-making rules at the same time, which we set out in our guide to automated decision-making under Article 22A.
What happens if the caller escalates to the ICO?
If the complainant is not satisfied with how the controller handles the complaint, they can escalate to the Information Commissioner under section 165 of the Data Protection Act 2018, and if the ICO does not progress it, seek a tribunal order under section 166. The controller-first duty is designed to keep most complaints out of that chain by resolving them at source, and the scale of the problem the regulator is trying to relieve is visible in its own numbers.
The ICO received 42,315 data protection complaints in 2024/25, up from 39,721 the year before, and issued 36,196 outcome decisions, according to its annual report. More telling is the backlog: open complaint cases rose 72% in a single year, from 9,168 to 15,810. A regulator carrying that load cannot be the first responder for every grievance, which is exactly why the DUAA pushes the initial duty onto controllers.
Data protection complaints reaching the ICOComplaints received and open at year end, showing the backlog the controller-first duty is meant to relieve. Source: ICO Annual Report 2024/25
The escalation ladder is worth mapping because a voice AI line that resolves complaints well at the first rung keeps them off the second and third. The controller stage is the one you control, and it is the one the new duty makes non-negotiable.
The data protection complaints escalation ladderWhere a complaint goes if it is not resolved, from the controller through to the tribunal.
How do you build a voice AI line that meets the complaints duty?
You build the duty into the call flow, not onto it later. The line needs three capabilities: it must recognise complaint intent in natural speech, capture the complaint with a reliable timestamp, and route it into a tracked process that fires the 30-day acknowledgement and records the outcome. Each is an engineering decision, not a policy statement, and getting them right separates a line that meets section 164A from one that misses acknowledgements it never knew it received.
Detection is the foundation. A caller rarely says "I am making a formal complaint." They say the recording is wrong, that nobody asked their permission, or that they want the AI to stop. Your intent model has to map that language to a complaint category and confirm it, so the caller knows they have been heard and your logs know the clock has started. This is the same discipline that underpins how we place any AI system inside a live operation, and it is the core of our AI operating model consulting. Signposting matters too: your privacy notice and transparency approach should tell people how to complain, because facilitation under section 164A(2) starts before the call, not during it.
The same discipline underpins our AI execution office, a fixed-scope retainer that runs governed AI in production and owns the operational duties that come with it, including complaint handling.
Once a complaint is captured, it has to leave the call and enter a system that will not lose it. That means a ticket with the timestamp, the caller's identity where known, the category, and a due date for acknowledgement. A voice AI line that hands complaints to the same queue as ordinary enquiries will miss the clock, because ordinary enquiries do not carry a 30-day statutory deadline. Treat the complaint as a distinct object from the moment it is detected.
What records should you keep to prove compliance?
You keep enough of an audit trail to demonstrate, for any complaint, that you acknowledged it inside 30 days and told the complainant the outcome. UK GDPR accountability means the burden is on the controller to show compliance, not on the regulator to prove a breach. For a voice AI deployment that means logging the moment of detection, the acknowledgement, the steps taken to investigate, and the final response, each with a timestamp and each linked to the underlying call.
There is a forward-looking reason to keep clean numbers as well. The DUAA also inserted section 164B, which gives the Secretary of State a power to require controllers to report the number of complaints they receive to the Commissioner in specified periods. The power is a reporting switch the government can turn on by regulations, and an organisation that already counts and categorises its section 164A complaints will be ready if it does. The same records that protect you in an individual dispute are the ones a future reporting duty would ask for, so building the counter now is cheap insurance. If you want that counter and the wider complaint duty owned as a running operation rather than a policy on a shelf, that is what our AI execution office is built to do.
What is the best voice AI setup for the complaints duty in 2026?
The best setup depends on how much of the compliance workflow you need the platform to own. Self-serve voice AI builders such as Vapi, Retell AI and Synthflow give you fast, flexible call flows, and a capable team can wire complaint detection, ticketing and the 30-day clock into them. If you have that engineering capacity in house, they are a strong choice. That is a genuine scenario where a self-serve platform wins.
Where a managed platform earns its place is when you want the complaints duty handled as a designed compliance capability rather than a feature you integrate. PolyAI and Dilr Voice sit at the managed end, built for regulated deployments where the acknowledgement clock, the audit trail and the escalation routing are part of the product rather than a project. For enterprises in banking, health and the public sector, where a missed section 164A acknowledgement is a regulatory event, that difference is usually decisive. The honest test is your own risk tolerance and team: if a missed deadline is an inconvenience, build it yourself; if it is a headline, buy the managed capability. Our view on placing AI where the risk actually sits is set out in our approach and across the DATS methodology.
Does the complaints duty replace the right to complain to the ICO?
No. The section 164A duty is a first step, not a replacement. An individual can still complain to the Information Commissioner under section 165, and seek a tribunal order under section 166 if the ICO does not progress it. The duty is designed to resolve most complaints at controller level, but it does not remove anyone's right to escalate. A voice AI line should make the internal route easy so fewer complaints reach the regulator.
Is 30 days the deadline to resolve a complaint?
No. The 30-day window in section 164A(3) is the deadline to acknowledge receipt, not to resolve the complaint. The resolution obligation is to respond and inform the complainant of the outcome "without undue delay," which is a separate, less precise standard. A voice AI operation should treat the 30-day acknowledgement as a hard, automated deadline and the substantive response as a tracked task, because conflating the two is how organisations either miss the acknowledgement or rush an inadequate response.
Written by the Dilr.ai engineering team, practitioners who ship enterprise AI in production. Follow us on LinkedIn for shipping notes, or subscribe via the RSS feed.
voice AI data protection complaints dutyDUAA complaints dutysection 164A Data Protection Actdata protection complaints voice AI redditbest voice AI compliance platform 2026UK GDPR complaints handlingDilr Voice compliance
Questions this article answers
What is the DUAA data protection complaints duty?
The DUAA data protection complaints duty is a statutory obligation, in force from 19 June 2026, that lets any individual complain directly to a controller, and requires that controller to acknowledge the complaint within 30 days and respond without undue delay. It sits in a new section 164A of the Data Protection Act 2018. For a voice AI line, it makes complaint handling a controlled process with a clock.
Does the complaints duty apply to your voice AI deployment?
Yes. Section 164A binds every controller processing personal data under the UK GDPR or Part 3 of the Data Protection Act 2018, with no carve-out for sector or size. The ICO is explicit that "there are no exemptions to this." If your voice AI line records calls, transcribes them, or makes or informs decisions about the people who ring in, you are a controller for that data and the duty applies to you.
What must a voice AI line do when a caller complains?
Section 164A sets four obligations. The controller must facilitate the making of complaints, for example by providing a complaint form. It must acknowledge receipt within 30 days. It must, without undue delay, take appropriate steps to respond. And it must inform the complainant of the outcome. For a voice AI deployment, that means the line has to recognise a complaint when it hears one, capture it, and route it into a process that meets each step on time.
How is this different from a subject access request or an FCA complaint?
The complaints duty is a distinct statutory route with its own trigger and clock. A subject access request under UK GDPR Article 15 asks for the requester's own personal data on a one-month deadline, as our guide to subject access requests for call recordings explains. A section 164A complaint is not a request for data. It alleges the controller has infringed the law, and it can concern an unlawful recording, an inaccurate transcript or an automated decision.
What happens if the caller escalates to the ICO?
If the complainant is not satisfied with how the controller handles the complaint, they can escalate to the Information Commissioner under section 165 of the Data Protection Act 2018, and if the ICO does not progress it, seek a tribunal order under section 166. The controller-first duty is designed to keep most complaints out of that chain by resolving them at source, and the scale of the problem the regulator is trying to relieve is visible in its own numbers.
How do you build a voice AI line that meets the complaints duty?
You build the duty into the call flow, not onto it later. The line needs three capabilities: it must recognise complaint intent in natural speech, capture the complaint with a reliable timestamp, and route it into a tracked process that fires the 30-day acknowledgement and records the outcome. Each is an engineering decision, not a policy statement, and getting them right separates a line that meets section 164A from one that misses acknowledgements it never knew it received.
What records should you keep to prove compliance?
You keep enough of an audit trail to demonstrate, for any complaint, that you acknowledged it inside 30 days and told the complainant the outcome. UK GDPR accountability means the burden is on the controller to show compliance, not on the regulator to prove a breach. For a voice AI deployment that means logging the moment of detection, the acknowledgement, the steps taken to investigate, and the final response, each with a timestamp and each linked to the underlying call.
What is the best voice AI setup for the complaints duty in 2026?
The best setup depends on how much of the compliance workflow you need the platform to own. Self-serve voice AI builders such as Vapi, Retell AI and Synthflow give you fast, flexible call flows, and a capable team can wire complaint detection, ticketing and the 30-day clock into them. If you have that engineering capacity in house, they are a strong choice. That is a genuine scenario where a self-serve platform wins.
DE
Dilr.ai Engineering
Engineering team
Compliance
Deploy voice AI without failing an audit
Dilr Voice ships per-country TCPA and GDPR rules, and the UK AI compliance changelog tracks ICO, FCA, and EU AI Act changes as they land.