Skip to main content
Category: Data Subject Rights

Right to Lodge a Complaint

Also known as: Right to Complain to a Supervisory Authority, Right to File a Complaint
Simply put

The right to lodge a complaint generally refers to a person's ability to formally register a grievance with an official body when they believe their rights have been infringed or that they have been treated unlawfully. In the data protection context, this typically means an individual can raise concerns with a designated authority rather than being limited to complaining only to the organization involved. The precise scope, forum, and procedure vary considerably by jurisdiction and by the type of complaint.

Formal definition

In general usage, to 'lodge a complaint' means to register a formal charge or statement with a competent body asserting that something has been done wrongly or is unsatisfactory. As a data subject right, this concept typically empowers an individual to submit such a complaint to a designated authority, and the specific authority, eligibility criteria, filing procedure, and available outcomes are determined by the applicable legal instrument and jurisdiction. Note that the evidence provided here consists of general-language definitions and non-data-protection complaint processes (for example, a state civil rights body and a state consumer-protection body); it does not establish the article-level requirements, competent authorities, remedies, or procedural rules under any specific privacy regime such as the EU GDPR, UK GDPR, or CCPA/CPRA, and treatment of this right differs across those regimes. This entry is limited to the general meaning of the term and does not cover enforcement mechanics, timelines, appeal rights, cross-border complaint handling, or the relationship between complaining to a supervisory authority and pursuing a judicial remedy, none of which are substantiated by the supplied evidence.

Why it matters

The right to lodge a complaint is a cornerstone of accountability in most rights-based frameworks: it gives individuals a route to challenge treatment they believe is unlawful or unsatisfactory through an official body, rather than being confined to raising concerns only with the organization they believe wronged them. In the data protection context, this typically means a person who suspects mishandling of their information can escalate the matter to a designated authority. The practical value of the right lies in that external forum, which is generally independent of the party being complained about.

The evidence available here illustrates the general shape of complaint mechanisms through non-privacy examples, such as a state civil rights body that evaluates discrimination complaints and decides whether to open an investigation, and a state consumer-protection body that receives complaints about deceptive business practices. These examples show a common pattern: an individual registers a formal statement, and a competent body then assesses whether to act. They do not, however, establish the specific procedures, competent authorities, or remedies applicable under any particular privacy regime.

Because the scope, forum, and outcome of a complaint vary considerably by jurisdiction and by the type of grievance, organizations and individuals should treat the right as context-dependent. The general concept is well established, but its data protection specifics, including who the competent authority is, what eligibility rules apply, and what remedies follow, depend on the applicable legal instrument and are not settled by general-language definitions or by unrelated complaint processes.

Who it's relevant to

Data subjects and individuals
Individuals who believe their rights have been infringed benefit from understanding that a complaint can generally be raised with a designated external authority, not only with the organization involved. The specific authority, eligibility, and procedure depend on the applicable jurisdiction and are not established by the general evidence here.
Data protection officers and privacy leads
Those responsible for handling data subject rights should be aware that individuals may escalate grievances to an external body. Because the competent authority and procedural rules vary by legal instrument, DPOs should confirm the applicable regime rather than assume a uniform complaint process across jurisdictions.
Compliance and information governance teams
Governance functions charged with demonstrable accountability should recognize that external complaint routes can trigger evaluation or investigation by a competent body. The evidence here describes the general pattern; teams should map the specific authorities, timelines, and remedies that apply under their governing regime, none of which are substantiated by the supplied evidence.
Legal counsel
Advisers assessing an individual's options should note that the general right to lodge a complaint is distinct from, and this entry does not address, the relationship between complaining to a supervisory authority and pursuing a judicial remedy, nor appeal rights or cross-border handling, which are determined by the applicable jurisdiction.

Inside Right to Lodge a Complaint

Right to Lodge a Complaint with a Supervisory Authority
Under the EU GDPR, a data subject generally has the right to lodge a complaint with a supervisory authority if they consider that the processing of their personal data infringes the Regulation. The UK GDPR provides an analogous right, with the relevant supervisory authority being the UK regulator rather than an EU one. Treatment differs across regimes and is not universal.
Choice of Supervisory Authority
Under the EU GDPR, a data subject may typically lodge a complaint with the supervisory authority in the Member State of their habitual residence, place of work, or place of the alleged infringement. This entry does not cover the internal cooperation or lead authority mechanics between supervisory authorities in cross-border cases.
Relationship to Judicial Remedies
The right to lodge a complaint is generally described as being without prejudice to other administrative or judicial remedies available to the data subject. The specifics of those separate remedies, including any right to compensation, are out of scope for this entry.
Controller and Processor Accountability
While the right sits with the data subject, controllers and processors bear the obligations that a complaint may allege were breached. A controller is typically the primary point of accountability for responding to a supervisory authority, though a processor may have direct obligations depending on the circumstances. Demonstrable evidence of compliance, not stated intent, is generally what an authority will assess.
Distinction from Internal Complaints and DSAR Handling
A complaint to a supervisory authority is external to the organization and directed at a regulator. It is distinct from an internal grievance to the organization or from the exercise of other data subject rights such as access or erasure, which follow their own procedures.

Common questions

Answers to the questions practitioners most commonly ask about Right to Lodge a Complaint.

Does lodging a complaint with a supervisory authority replace the right to a judicial remedy?
No. Under the EU GDPR and UK GDPR, the right to lodge a complaint with a supervisory authority is generally distinct from, and does not displace, the right to an effective judicial remedy. A data subject can typically pursue both avenues, and lodging a complaint does not waive the ability to seek redress through the courts. The precise interaction between administrative and judicial routes depends on jurisdiction and national procedural law, which is outside the scope of this entry.
Is a data subject required to complain to the organization first before approaching a supervisory authority?
Generally, no. In most jurisdictions applying the EU or UK GDPR, a data subject may lodge a complaint directly with a supervisory authority without first exhausting the controller's internal complaints process. That said, some authorities encourage or operationally prefer that individuals raise the matter with the organization first, and practice varies by regime. This does not create a binding legal precondition unless national law provides otherwise, which this entry does not detail.
Which supervisory authority should we direct a complainant to when we operate across multiple EU Member States?
A data subject may generally lodge a complaint with the supervisory authority in the Member State of their habitual residence, place of work, or the place of the alleged infringement. Organizations typically should not restrict complainants to a single authority of the organization's choosing. Where a matter has cross-border elements, cooperation mechanisms between authorities may apply, but the mechanics of lead authority designation and cooperation procedures are outside the scope of this entry.
What should our privacy notice say about the right to lodge a complaint?
Transparency information provided to data subjects should typically inform them of their right to lodge a complaint with a supervisory authority. As a practical matter, organizations often identify the relevant authority and provide contact or reference details, while making clear the individual may approach the authority of their residence, workplace, or the place of the alleged infringement. The exact content requirements derive from the applicable transparency obligations and are not fully enumerated in this entry.
How should we handle an inbound notification that a data subject has complained to a supervisory authority?
Organizations generally should route such notifications to the accountable function, such as the data protection officer or privacy team, preserve relevant records, and prepare to cooperate with the authority's inquiries. Under governance and accountability principles, the ability to demonstrate cooperation and produce supporting evidence matters more than stated intent. This entry does not cover the specific timelines, enforcement procedures, or potential penalties that a given authority may apply.
Should our internal complaints procedure be treated as a substitute for the statutory right to complain?
No. An internal complaints or grievance mechanism can support responsiveness and demonstrate accountability, but it does not replace or limit a data subject's statutory right to lodge a complaint with a supervisory authority. Organizations should design internal processes to complement, not obstruct, access to that external right, and should avoid language suggesting the individual must use the internal route exclusively. Retention rules for complaint records and cross-jurisdiction procedural differences are outside the scope of this entry.

Common misconceptions

Lodging a complaint with a supervisory authority automatically results in a fine against the organization.
The right allows a data subject to raise a concern with a regulator, but it does not determine any outcome. Whether enforcement action, corrective measures, or penalties follow depends on the authority's assessment, the jurisdiction, and the facts. This entry does not cover enforcement mechanics or penalty amounts, and no specific figures should be assumed.
A data subject must first complain to the organization before approaching a supervisory authority.
Under the EU and UK GDPR the right to lodge a complaint with a supervisory authority is generally available directly and is not conditioned on exhausting an internal complaint process. Organizations may offer internal channels, but that is distinct from and does not override the statutory right.
The right to lodge a complaint is a universal, identically framed right across all data protection regimes.
The framing described here originates in the EU GDPR, with an analogous provision in the UK GDPR. Other frameworks such as the CCPA and CPRA, HIPAA, ISO/IEC 27701, or the NIST Privacy Framework address individual recourse differently or not at all, and the mechanics should not be treated as interchangeable.

Best practices

Maintain a documented, tested process for receiving and responding to inquiries from a supervisory authority, and ensure the responsible controller function is clearly identified so accountability is not ambiguous.
Provide clear, accessible privacy information that informs data subjects of their right to lodge a complaint with the relevant supervisory authority, and identify the applicable authority for the regime in question rather than assuming a single universal regulator.
Keep demonstrable evidence of compliance, such as records of processing decisions and handling of data subject requests, since a supervisory authority will generally assess evidence rather than stated intent.
Offer an internal complaint or contact channel as a good-practice complement, while making clear it does not replace or precondition the data subject's direct right to approach a supervisory authority.
Where processing is cross-border, seek specialist advice on which supervisory authority applies, as the choice-of-authority and cooperation mechanics are nuanced and outside the scope of a general definition.
Confirm the treatment of individual recourse for each applicable regime separately, since provisions under the EU GDPR, UK GDPR, and other frameworks differ and should not be conflated.