The pipeline, in the regulator's own numbers
Once a year, the UK's data protection regulator publishes an account of itself. The most recent one covers 2024/25, and read end to end it describes a pipeline.
Into the wide end went 42,315 data protection complaints from the public, up from 39,721 the year before. The overwhelming majority of the decisions that came back were advice and recommendations: guidance on information handling, suggestions for the organisation, a view on whether it likely complied. Out of the narrow end came 43 concluded UK GDPR investigations for the entire year, down from 285 the year before. Two of them ended in fines. Enforcement notices, the order that legally compels a company to change what it is doing: zero.
The pipeline, in numbers
Every figure is the regulator's own, from its 2024/25 annual report.
The queue tells the same story from inside. The regulator gives itself 90 days to respond to a complaint. In 2023/24, about one complaint in seven missed that window. In 2024/25 it was seven in ten, and the pile of open complaints grew from just over nine thousand to nearly sixteen thousand. Of the data breaches organisations were required to report, three per cent prompted an investigation, half the rate of the year before.
The queue, in numbers
The year before, the missed-window figure was 15%.
One academic analysis of the report described the result as a picture of "little formal regulation of data protection". We do not have a kinder reading to offer. This is not a scandal, and nobody needed to do anything wrong to produce it. It is arithmetic: a small public body, a caseload in the tens of thousands, and a legal regime whose enforcement was always going to be rationed. But it is the arithmetic behind a sentence people say to each other constantly, in forums and comment sections and consumer advice columns, as if it ended the conversation: report them to the ICO.
What a complaint actually buys
Follow one complaint through that pipeline and the shape becomes personal. You write up what happened. You attach your correspondence. You wait, most likely past the window the regulator set for itself. What comes back, when it comes, is most often advice: a letter to you, perhaps a letter to the company, a note on a file. The company's version of events is heard. Nobody enters a server room. Nobody audits a database. In the ordinary case, whether the company actually did what it claimed, deleted what it said it deleted, stopped what it said it stopped, is exactly as unverified after the complaint as before it.
We have written before about the request that gets thirteen million refusals and no replies, and about brokers who simply do not answer the requests the law entitles you to send. The complaint route sits above all of that as the thing you are supposed to do next. The numbers say the next step is, in the ordinary case, a slower version of the first one: a claim goes in, a written response may come out, and nothing is inspected.
That is not a reason to never file one. A complaint is on the record, it is dated, and regulators build their picture of an industry partly from the pile. It is a reason to file one the way you would file any other document: for the record it creates, not the rescue it suggests.
The same funnel, everywhere we looked
It would be convenient if this were a story about one under-resourced British office. It is not. Read any data protection regulator's account of itself and the same funnel appears; countries differ only in which stage quietly absorbs the volume.
California's privacy agency has taken in 12,546 complaints since its portal opened in mid-2023, a number its own enforcement chief says is more than doubling year on year and has not plateaued. Against that: hundreds of open investigations, a stated policy of "ruthless prioritization", and, across the state's two enforcers, thirteen substantive enforcement actions in the six years the law has been enforceable. Exactly one of them has ever been publicly traced to a consumer complaint.
Ireland hosts the regulator that answers for most of the world's largest platforms. Its 2025 closed with ten final decisions against 3,385 complaints, and its own statistics say 83 per cent of concluded cross-border complaints end in "amicable resolution", an outcome negotiated with the company that produces no decision at all. The headline fines are mostly still paper: 530 million euros imposed in 2025, and 125,000 collected, the rest suspended behind appeals.
France is the counterexample that proves the funnel rather than the exception to it. Its regulator runs the busiest sanctions desk in Europe, 83 fines in a single year. It still received 20,150 complaints and carried out 323 inspections. Canada's federal regulator cannot issue a fine at all; its own complaint guide says so in one sentence. Australia's can, and in the entire history of its Privacy Act it has brought penalty proceedings four times, with one penalty ordered by a court, in late 2025.
The funnel, elsewhere
Every figure is the regulator's own, from its latest annual report or public board record.
And almost nobody publishes a clock. The ICO at least sets itself 90 days and reports missing it. Ireland's service charter explicitly excludes complaints from its response window. California's regulation obliges the agency to tell you what action it has taken, if any, with no deadline attached. The only queue we could measure belongs to the one regulator that publishes a clock.
Notice, too, what even the rare fine buys the person who complained: nothing, directly. A penalty, when it lands, is paid to the state. Ireland's regulator remits what it collects to the central exchequer, and no pipeline in any of these countries routes a euro or a dollar to the individual whose complaint began it. Nor does a fine recall the data: whatever was copied, shared or shipped across borders before the ruling is already wherever it went, and nothing calls it back. If anything is ever to come to you, compensation, a correction, a settlement of your own, it comes through your own case, and a case runs on evidence.
The exception is the point
Every so often, the machine does turn all the way over. A regulator picks one company, goes inside, and publishes what it finds. When Spain's data protection authority did that to a face-scanning verification vendor, the postmortem contradicted the comfortable version at almost every point: the "just authentication" framing rejected, the retention longer than implied, the consent boxes pre-ticked. We wrote about what that ruling revealed, and the pattern holds beyond one company: when an audit actually happens, the gap between what was claimed and what was kept is where the findings live.
Hold both facts at once. Investigations are the rare exception. And when they happen, they have a habit of proving that the claims made to individuals in the meantime did not survive inspection. Deletions that were not deletions. Anonymisation that identified. Retention that outlived every promise about it.
That combination has a precise consequence for you. The years between a company's claim and any postmortem are exactly the years you were being told everything was handled. The only artifact that survives those years on your side is paper: what you asked, when you asked it, and what they said back, dated, in your own inbox.
Receipts appreciate
If enforcement were fast and routine, keeping your own record would be a courtesy. Because enforcement is rationed, the record is the whole game. A company's written claim that your data was deleted costs them one email today, and it costs them considerably more on the day an audit, a breach disclosure or a court filing shows the category of data they told people was gone. On that day the question stops being your word against a corporation's process, and becomes their own dated words against their own conduct.
Nobody can put that day in a calendar, and that is precisely why the move is not to wait for it. The stakes underneath are rising even where enforcement is not: retained data is worth more than it has ever been, AI training has found a new use for every archive, and when a reckoning does arrive for a company, through a regulator, a breach or a courtroom, it always arrives about the past, about what was kept and what was claimed years before. Whoever kept dated answers from those years has evidence. Whoever did not has a memory. A complaint filed years later cannot recover what was said at the time. The replies you kept are the only record of it.
And a receipt is not only a bet on that day. It pays on the day it arrives. You know where you stand with a company instead of assuming. The question stops living in the back of your head. Whatever they do next has a dated baseline it can be measured against. None of this asks for vigilance, a second job, or learning to fight a regulator's queue. See what they hold, limit what they can do with it, delete what can go, and bank the answer. Minutes per company, once, and the record compounds on its own.
So the order of operations we hold to is unchanged, and the regulators' own reports are the strongest argument for it we have published yet. Ask the company directly, because the company is the party legally answerable to you and the only one whose reply lands in your inbox. Keep what comes back, because nothing about it can be checked from the outside and its value is precisely that it was said. Know what lawfully stays, so the request asks for what a request can get. And treat the complaint route as what the numbers show it is: a filing cabinet with a long queue, there when you want your objection on someone else's record too, never the plan. The plan is your own record. Start your record →
They keep records about you. The regulator's report is the reason you keep records about them.