Warburtons Limited GDPR Complaints Procedure (April 2026)
Overview Policy
The purpose of this Procedure is to:
- explain how individuals can raise concerns or complaints about how Warburtons processes their personal data.
- ensure complaints are handled fairly, transparently, consistently and within statutory timeframes.
- demonstrate compliance with UK GDPR, the Data Protection Act 2018 and ICO guidance.
Scope
This Procedure:
- applies to all GDPR-related complaints about the handling of personal data by Warburtons Limited, including concerns about:
- how personal data is collected, used, stored or shared;
- accuracy or security of personal data;
- handling of data subject rights (e.g. access, rectification, erasure);
- alleged breaches of the company’s Privacy Notice or Data Protection Policy.
- covers complaints from employees, former employees, job applicants, customers, consumers, suppliers and other individuals whose data is processed by the company.
What is a GDPR Complaint?
A GDPR complaint is any expression of dissatisfaction relating to:
- the lawfulness, fairness or transparency of personal data processing;
- failure to uphold an individual’s data protection rights;
- perceived misuse, loss or unauthorised disclosure of personal data.
This is distinct from:
- general commercial or service complaints; and
- formal Subject Access Requests (which follow a separate procedure).
How to Raise a GDPR Complaint
Individuals may submit a complaint:
- by email to gdpr@warburtons.co.uk; or
- in writing to the Company Secretary – Data Protection Queries (address as set out in the Privacy Notice).
The complaint should, where possible, include:
- the individual’s name and contact details;
- a description of the concern;
- any relevant dates, correspondence or supporting information.
(Complaints will not be rejected solely because information is missing)
Acknowledgement of Complaints
All GDPR complaints will be acknowledged promptly, normally within a few working days.
The acknowledgement will:
- confirm receipt;
- explain the next steps in the process;
- set out the expected response timeframe.
Investigation Process
Complaints are reviewed by the Head of Legal / GDPR Team in line with internal governance arrangements.
The investigation may involve:
- reviewing relevant systems, emails, policies or records;
- consulting internal teams or third-party processors where appropriate;
- assessing compliance with GDPR principles and internal policies.
Where clarification or additional information is required, the complainant will be contacted.
Response Times
An acknowledgement will normally be provided within a few days of receipt and a substantive response within 30 days of receipt.
Where the complaint is complex or requires further investigation, the individual will be informed of:
- the reason for the delay; and
- the revised response timeframe.
Outcome and Resolution
The response will:
- explain the findings of the investigation in clear, plain English;
- confirm whether the complaint is upheld, partially upheld or not upheld;
- set out any corrective actions taken (where appropriate), such as:
- data correction or deletion;
- changes to processes or controls;
- staff guidance or training.
Escalation to the ICO
If the individual remains dissatisfied after receiving the company’s response, they may raise their complaint with the Information Commissioner’s Office (ICO).
Contact details for the ICO will be provided in the response, consistent with the Privacy Notice.
Record Keeping
All GDPR complaints will be:
- logged centrally;
- retained in line with the Data Retention Policy; and
- used to identify trends, risks and training needs.
Roles and Responsibilities
- Employees: must promptly escalate any GDPR-related complaint to the GDPR Team.
- Head of Legal / GDPR Team: responsible for oversight, investigation, response and reporting.
- Senior Management: informed of material risks or systemic issues.
Review and Updates
This procedure will be reviewed periodically and updated as required to reflect:
- changes in law or ICO guidance;
- internal policy changes; or
- lessons learned from complaints or incidents.
Document Owner and Approval
Head of Legal and Company Secretary are the owners of this document and are responsible for ensuring that this procedure is reviewed in line with the review requirements of the GDPR.
Monitoring & Review
This policy is subject to review and revision in the light of changing circumstances and developments in employment legislation, to ensure continuing fairness, effectiveness and compliance with our legal obligations. Any significant changes will be notified to all employees.