Data Protection Complaints Policy
Last Updated : 15 June 2026
1. PURPOSE
This Data Protection Complaints Policy is a specific policy which outlines how Brand Financial Training will handle any complaints related to personal data or privacy. Brand Financial Training is committed to protecting personal data and complying with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018. This policy explains how individuals can raise concerns regarding the processing of their personal data and how those concerns will be handled.
2. SCOPE
This policy applies to customers, website visitors, employees, contractors and suppliers.
3. WHAT CONSTITUTES A DATA PROTECTION COMPLAINT?
Examples of why you may wish to make a complaint to us could include;
- Personal information is inaccurate.
- A subject access request has not been handled appropriately.
- Marketing communications are being sent without consent.
- Data has been disclosed to the wrong person.
- Personal data has been retained longer than necessary.
- A data breach has occurred.
- An individual believes their GDPR rights have been infringed.
Any complaints regarding third-party providers will still be investigated by Brand Financial Training, even where data is hosted on third-party systems, to the best of our ability.
4. HOW TO MAKE A COMPLAINT
You can make a complaint by emailing
You must include:
- Your name
- Contact details
- Description of concern or nature of complaint
- Relevant dates
- Supporting evidence (if applicable)
Note that should you make a complaint to us via social media channels, you will be asked to provide us with alternative contact information so that we can assist you with your complaint.
5. COMPLAINT HANDLING PROCESS
Step 1 – Acknowledgement
We will aim to acknowledge your complaint within 5 working days, as long as the complaint is submitted via the correct channels above. Complaints sent via any other channels will be redirected to ensure we are able to investigate and respond to your complaint promptly.
Step 2 – Investigation
Your complaint will be investigated by the most appropriate manager available at the time. Investigations will include reviewing records, consent history, speaking to staff members, reviewing systems and procedures.
We may ask you to verify your identity before we can investigate your complaint and/or provide our response.
Step 3 – Response
A written response will given within 30 days, starting the day after the complaint is received. Should this date fall on a weekend, the next working day will be the response deadline.
6. OUTCOMES
Possible outcomes include:
- No breach identified
- Data corrected
- Data deleted
- Processes amended
- Staff retraining
- Apology issued
- ICO notification where appropriate
7. ESCALATION
If you remain dissatisfied with our response, you have the right to raise your concerns with the Information Commissioner’s Office (ICO).
8. RECORD KEEPING
Any complaints received are logged internally for reference, monitoring and review. All investigations are documented in writing and records will be retained.
9. RELATED POLICIES
Our privacy and cookies policies can be viewed on our policies page.







