DUAA June 19: Your Loyalty Scheme, Customer Email List and CCTV Are Now a Legal Liability

DUAA June 19: Your Loyalty Scheme, Email List and CCTV Are Now a Legal Liability
From 19 June 2026, every UK organisation that handles personal data must operate a formal data protection complaints procedure. For retailers, that turns three everyday assets — your loyalty scheme, your customer email list and your CCTV — into areas the regulator can now act on far more directly.
The change comes from the Data (Use and Access) Act 2025 (DUAA). This guide explains the new complaints duty, why retail data practices are squarely in scope, and the short list of things to put in place before the deadline.
Table of Contents
- What Changes on 19 June 2026
- The New Complaints Procedure Duty
- Loyalty Schemes, Email Lists and CCTV
- What Non-Compliance Costs
- Your Retail Compliance Checklist
- Frequently Asked Questions
- Key Takeaways
What Changes on 19 June 2026
The DUAA updates and extends UK data protection law. One of its most practical provisions requires data controllers to give individuals a clear route to complain about how their personal data is handled, to acknowledge those complaints within 30 days, and to respond without undue delay. The duty takes effect on 19 June 2026 and applies to businesses of every size — there is no small-retailer exemption.
In short: if you hold customer data, you must have a documented complaints procedure, and you must be able to show you actually follow it.
The New Complaints Procedure Duty
A compliant procedure has a few moving parts: a published way for customers to raise a data concern (an email address or form), a facility to log and track complaints, an acknowledgement within 30 days, and a substantive response. The Information Commissioner's Office (ICO) can ask to see this process — and can act if complaints are ignored.
For most retailers this is not onerous, but it does need to exist on paper and in practice. A privacy policy alone is not enough; the new duty is specifically about handling complaints.
Loyalty Schemes, Email Lists and CCTV
Three retail staples attract the most data complaints, and all three are now firmly in scope:
- Loyalty schemes collect rich profiles of purchase history and contact details. Customers increasingly ask what is held and how it is used — and now have a formal channel to complain if they are unhappy.
- Email marketing lists remain governed by PECR consent rules. Sending marketing without valid consent is a common source of complaints, and the DUAA aligns penalties with GDPR levels.
- CCTV captures customers and staff. You must justify it, signpost it, and be able to handle access requests and complaints about it.
What Non-Compliance Costs
The DUAA brings PECR penalties into line with UK GDPR. That means the ICO can issue fines of up to £17.5 million or 4% of global annual turnover, whichever is higher, for serious breaches. In practice, smaller retailers are more likely to face enforcement notices and reputational damage than headline fines — but the ceiling, and the regulator's appetite, have both risen.
Your Retail Compliance Checklist
- Publish a data complaints procedure with a named contact or email and a clear promise to acknowledge within 30 days.
- Create a simple log to record complaints, dates and outcomes — your evidence that the process works.
- Review loyalty-scheme privacy information: what you collect, why, and how customers can object or withdraw.
- Check email marketing consent is valid and recorded for every contact you message.
- Audit your CCTV: signage, retention period, and a process for footage requests.
- Brief your team so a data complaint in store is escalated, not ignored.
Frequently Asked Questions
Does this apply to a small independent shop? Yes. The complaints duty applies to all data controllers, regardless of size. The effort should be proportionate to your data, but the obligation is universal.
Isn't a privacy policy enough? No. A privacy policy explains what you do with data; the new duty is specifically about giving customers a route to complain and handling those complaints within set timescales.
What if we use a third party for our loyalty scheme or email? You remain responsible as the data controller. Check your provider supports the complaints and consent requirements, but the legal duty stays with you.
Key Takeaways
- From 19 June 2026, all UK retailers must run a formal data complaints procedure under the DUAA.
- Loyalty schemes, marketing email lists and CCTV are the highest-risk areas.
- Penalties now reach GDPR levels — up to £17.5m or 4% of turnover.
- The fix is quick: publish a procedure, log complaints, and review consent and CCTV.
Stay ahead of UK regulations
ComplianceAlert monitors HSE, HMRC, ICO, CQC and more — and alerts you in plain English before changes cost you.
Try ComplianceAlert free for 7 days →7-day free trial · No card needed · Free for 7 days · Cancel anytime
Have a question?
Talk to us about how ComplianceAlert can help your business. We reply within one business day.
Or call Alice free: 📞 Free call — +44 23 9433 0468 · hello@compliancealert.co.uk
Related articles
July 1 Double Compliance Hit: Steel Tariffs AND Unfair Dismissal Rights Land Together for UK Construction
Two Laws Just Changed Retail Forever — Most Shop Owners Haven't Heard of Either
No Cap, No Limit: What the Removal of the Unfair Dismissal Compensation Cap Means for UK Employers