Data Protection Complaints Process
The Advantage Group International, Inc.
Prepared under the UK GDPR, Data Protection Act 2018, and the Data (Use and Access) Act 2025 (DUAA)
1. Purpose
This procedure sets out how The Advantage Group International, Inc. (AGI) handles complaints about how we handle personal data, in line with our obligations under the UK GDPR, the Data Protection Act 2018, and the Data (Use and Access) Act 2025 (DUAA).
It applies to any complaint from an individual (a “data subject”) about how we have processed their personal data — including complaints about our privacy practices, our response to a subject access request, or any other data protection matter.
2. How to Complain
People can complain to us in any of the following ways:
- Email: privacy@advantagegroup.com
- Post: Security, Privacy & Compliance team, The Advantage Group International, Inc, 40 University Avenue, Suite 903, Toronto, ON, M5J 1T1 Canada
- Verbally or otherwise to any member of staff — who will log it on the complainant’s behalf
We do not require complaints to be submitted in a particular format. A complaint can be as simple as “I don’t think you should have used my data in this way.”
This route will be clearly signposted in our privacy notice, on our website, and in any response we send to a subject access request.
3. Acknowledging a Complaint
We will acknowledge receipt of a complaint within 30 days of receiving it. The acknowledgement will:
- Confirm we’ve received the complaint
- Give the complainant a reference number, assigned in the format DP-YYMMDD-NNN (e.g. DP-260710-001)
- Provide an expected timeframe for our response
- Name a contact point for questions in the meantime
4. Investigating the Complaint
We will investigate every complaint without undue delay, proportionate to its complexity. This includes:
- Assigning the complaint to a trained member of staff
- Gathering relevant records, correspondence, and system logs
- Establishing whether our data handling met legal requirements and our own policies
- Identifying any corrective action needed
5. Keeping the Complainant Informed
If an investigation is going to take longer than expected, we will tell the complainant:
- That there is a delay
- The reason for it
- A revised timeframe
We will not leave a complainant waiting without an update.
6. Communicating the Outcome
Once the investigation is complete, we will write to the complainant with:
- A clear summary of what we found
- Whether we agree there was an issue, and if so, what we are doing about it
- Any changes to our practices as a result
- Their right to escalate the matter to the Information Commissioner’s Office (ICO) if unsatisfied, including the ICO’s contact details (ico.org.uk, 0303 123 1113)
7. Escalation to the ICO
Complainants have the right to complain directly to the ICO at any time — they do not have to complain to us first, and do not have to wait for us to finish investigating. We will make this clear in all our communications.
8. Record-Keeping
We will keep a record of every data protection complaint, saved in a folder with its reference number, including:
- Date received and acknowledged
- Nature of the complaint
- Investigation notes and outcome
- Date and content of final response
- Any remedial action taken
The Data Protection Complaints Log must be kept up to date at all times, with each complaint recorded on receipt and updated as it progresses through acknowledgement, investigation, and resolution.
Records will be retained in line with our retention schedule, and reviewed periodically to identify trends or recurring issues.
9. Staff Training
All staff who may receive or handle complaints will be trained to:
- Recognise when a query or grumble is in fact a data protection complaint
- Log it correctly and route it to the right person
- Understand the 30-day acknowledgement requirement
10. Related Documents
This procedure works alongside our:
- Privacy Notice(s) — updated to signpost this complaints route and the right to complain to the ICO
- Subject Access Request Procedure — SAR responses will reference this complaints route
- Data Protection Policy
Document control
|
Owner |
Director Security, Privacy & Compliance |
|
Version |
1.0 |
|
Last reviewed |
10 July 2026 |
|
Next review due |
10 January 2027 |
|
Approved by |
Director Security, Privacy & Compliance |
See How Benchmarking Strengthens Retailer-Supplier Relationships
Gain a clear, comparable view of partnership performance and identify the actions that drive measurable improvement.