About this policy

This Data Protection Complaint Handling Policy (Policy) is effective from 19 June 2026. This Policy’s owner is the Data Protection Officer. Questions about this Policy should be directed to [email protected]

Data protection complaint handling policy

1 Privacy and scope

SUEZ in the UK has legal complaint handing obligations under both the UK GDPR and Part 3 of the Data Protection Act 2018. If an individual considers that we have breached data protection laws, they have the right to make a complaint directly to us, to the Information Commissioner's Office (ICO) or to pursue legal action. 


This Policy outlines our approach to handling data protection complaints. It applies to all employees, workers, contractors and third parties acting on our behalf. It covers complaints from any data subject or their authorised representative.

2. Guiding principles

We are committed to handling data protection complaints in line with our legal obligations and in an accessible, fair, transparent and timely manner. We will handle complaints confidentially and only share information where appropriate to investigate and resolve the complaint, as required or authorised by law or otherwise in accordance with our policies.

3. Roles and responsibilities

Our Data Protection Officer is responsible for co-ordinating how we handle data protection complaints. They will involve relevant business, HR, IT, security, risk or compliance and other teams as needed. 


All staff are responsible for recognising complaints and referring them to Data Protection Officer at [email protected] promptly as well as for providing supporting information and responding to requests from Data Protection Officer when asked.

4. Transparency

We will provide information about how to submit a data protection complaint. Using plain and clear language, we will explain:

  • Our data protection complaints process.
  • How individuals can make a data protection complaint.
  • How we will respond if we consider the complaint is not a data protection matter.
  • The available complaint channels.
  • The information we require to investigate a complaint.
  • What we do with that information and why (for example, investigations, establishing acts, complaint resolution).
  • How we handle complaints which might be sensitive in nature.
  • What individuals can expect from the process.
  • When individuals can expect to hear from us, including, status update communications such as acknowledgements, progress updates (where required) and outcomes.

5. Non-data protection complaints

Some complaints will include both data protection and non-data protection issues; we will handle the data protection aspects under this Policy and its associated procedures. Non-data protection issues will be addressed under the relevant customer complaints, HR, grievance, or other applicable procedure.

6. Complaints involving children or vulnerable individuals

Where we receive a complaint from, or on behalf of, a child or other vulnerable individual, we will consider additional safeguards and requirements to ensure our process is fair, transparent and accessible to the individuals concerned, having regard to age, understanding and any other relevant circumstances.

7. Complaint channels

People may submit a data protection complaint to us using any of the following options:

 

To expedite the complaint, we will encourage people to use our established complaint channels.

 

Where a complaint is made through social media or another insecure public channel, we will ask the complainant to continue the complaint through a more secure method to protect their data.

8. Requesting additional information

Some complaints may be easy to resolve; others may require further investigation. Where reasonably necessary to investigate a complaint, we may ask the complainant for additional information, including information to verify their identity or to clarify the scope of the complaint. We will only request information that is reasonable and proportionate in the circumstances and will not request more information than we require to identify the complainant or their representative.


Where a complaint is made on behalf of another individual, we may require evidence such as a power of attorney or signed letter of authority indicating that their representative is authorised to act on their behalf. We cannot progress complaints unless adequate proof of authority is provided. Where this is the case, we will explain it to the person who submitted the complaint.

9. Complaints to or about processors or partners

Where a complaint received by us relates to the processing of personal information by our service providers, we will ask these providers to provide us with details and information relevant to the complaint without undue delay and in accordance with any agreed and specified terms within our contract with the service provider.

 

Where a service provider receives a complaint about the processing of our personal data whether by them or us, they should forward this to us without undue delay. Service providers are under no obligation to handle complaints on our behalf unless this has been agreed between us and the relevant service provider(s) under a binding contract. Where applicable, we will ask service providers to handle such complaints in line with our policies and procedures.

10. Record keeping

We will keep appropriate records about each data protection complaint in our complaints register. Records include:

  • The date of receipt.
  • The acknowledgement.
  • Any relevant correspondence, conversations and documents.
  • The outcome of the complaint, including escalation, and any actions taken in response.

 

These records will be used to demonstrate compliance, for audit and monitoring purposes, training, to support consistent handling and to identify recurring issues, trends or areas for organisational improvements or remediation.

 

We will not retain personal data relating to complaints for longer than is necessary and will handle such records in accordance with our retention and data protection policies.

11. Acknowledgement and timeframes

We will acknowledge receipt of a complaint within 30 days of receipt.

 

For ongoing investigations, we will communicate this to individuals with an indication of our initial, anticipated timescales for resolving the complaint. We will continue to keep the complainant informed of our progress, including, where appropriate, the next steps, any further information required, and any expected timeframe for the next update, or outcome.

12. Investigations

We will take reasonable and proportionate steps necessary to investigate complaints fairly and in a timely manner.

It may take us longer to investigate and resolve complaints which are complex, serious or which relate to multiple data protection issues.

13. Outcomes and escalation

We will communicate the outcome of the complaint to the complainant without undue delay, explaining our findings, whether the complaint is upheld (in whole or in part), any action taken or proposed, and, where no action is taken, the reasons for that decision.

Once a decision has been issued, this decision is final. No further action will be taken and the complainant will be informed of this.

If the complainant is dissatisfied with the outcome of the complaint, we will inform them that they have the right to lodge a complaint with the ICO and, where appropriate, provide them with details of how to do this. They also have the right to complain to the ICO at any time and to lodge a claim before a competent court, irrespective of whether they have lodged a complaint with us using our complaints process.

14. Monitoring and audits

We will routinely monitor and audit our data protection complaint handling to ensure we can maintain performance levels in line with our legal obligations.

Complaint form

You can use this form if you wish to make a data protection complaint to us. This form should make it easier and quicker for you to provide us with the information we need to investigate your complaint efficiently.