Skip to content

Data Protection Complaints Process

The Advantage Group International, Inc.

Prepared under the UK GDPR, Data Protection Act 2018, and the Data (Use and Access) Act 2025 (DUAA)

1. Purpose

This procedure sets out how The Advantage Group International, Inc. (AGI) handles complaints about how we handle personal data, in line with our obligations under the UK GDPR, the Data Protection Act 2018, and the Data (Use and Access) Act 2025 (DUAA).

It applies to any complaint from an individual (a “data subject”) about how we have processed their personal data — including complaints about our privacy practices, our response to a subject access request, or any other data protection matter.

2. How to Complain

People can complain to us in any of the following ways:

  • Email: privacy@advantagegroup.com
  • Post: Security, Privacy & Compliance team, The Advantage Group International, Inc, 40 University Avenue, Suite 903, Toronto, ON, M5J 1T1 Canada
  • Verbally or otherwise to any member of staff — who will log it on the complainant’s behalf

We do not require complaints to be submitted in a particular format. A complaint can be as simple as “I don’t think you should have used my data in this way.”

This route will be clearly signposted in our privacy notice, on our website, and in any response we send to a subject access request.

3. Acknowledging a Complaint

We will acknowledge receipt of a complaint within 30 days of receiving it. The acknowledgement will:

  • Confirm we’ve received the complaint
  • Give the complainant a reference number, assigned in the format DP-YYMMDD-NNN (e.g. DP-260710-001)
  • Provide an expected timeframe for our response
  • Name a contact point for questions in the meantime

4. Investigating the Complaint

We will investigate every complaint without undue delay, proportionate to its complexity. This includes:

  • Assigning the complaint to a trained member of staff
  • Gathering relevant records, correspondence, and system logs
  • Establishing whether our data handling met legal requirements and our own policies
  • Identifying any corrective action needed

5. Keeping the Complainant Informed

If an investigation is going to take longer than expected, we will tell the complainant:

  • That there is a delay
  • The reason for it
  • A revised timeframe

We will not leave a complainant waiting without an update.

6. Communicating the Outcome

Once the investigation is complete, we will write to the complainant with:

  • A clear summary of what we found
  • Whether we agree there was an issue, and if so, what we are doing about it
  • Any changes to our practices as a result
  • Their right to escalate the matter to the Information Commissioner’s Office (ICO) if unsatisfied, including the ICO’s contact details (ico.org.uk, 0303 123 1113)

7. Escalation to the ICO

Complainants have the right to complain directly to the ICO at any time — they do not have to complain to us first, and do not have to wait for us to finish investigating. We will make this clear in all our communications.

8. Record-Keeping

We will keep a record of every data protection complaint, saved in a folder with its reference number, including:

  • Date received and acknowledged
  • Nature of the complaint
  • Investigation notes and outcome
  • Date and content of final response
  • Any remedial action taken

The Data Protection Complaints Log must be kept up to date at all times, with each complaint recorded on receipt and updated as it progresses through acknowledgement, investigation, and resolution.

Records will be retained in line with our retention schedule, and reviewed periodically to identify trends or recurring issues.

9. Staff Training

All staff who may receive or handle complaints will be trained to:

  • Recognise when a query or grumble is in fact a data protection complaint
  • Log it correctly and route it to the right person
  • Understand the 30-day acknowledgement requirement

10. Related Documents

This procedure works alongside our:

  • Privacy Notice(s) — updated to signpost this complaints route and the right to complain to the ICO
  • Subject Access Request Procedure — SAR responses will reference this complaints route
  • Data Protection Policy

Document control

Owner

Director Security, Privacy & Compliance

Version

1.0

Last reviewed

10 July 2026

Next review due

10 January 2027

Approved by

Director Security, Privacy & Compliance

 

See How Benchmarking Strengthens Retailer-Supplier Relationships

Gain a clear, comparable view of partnership performance and identify the actions that drive measurable improvement.