Skip to content

Complaint Handling

What is Complaint Handling?

Processes for receiving, investigating, and resolving complaints from data subjects about the handling of their personal information.

Privacy and Data Protection

Each of these is named in at least one of the same controls as complaint handling. The number is how many controls name both.

What the standards actually require on complaint handling

Requirements naming complaint handling across 6 standards, quoted from the control text.

Organisation has processes for receiving and addressing privacy-related inquiries and complaints from data subjects.

PMF-ME.2 · Complaint Handling

The applicant has procedures to receive, investigate and respond to privacy-related complaints.

CBPR-PR-41 · Complaint handling procedures

Provide a channel for subscribers to lodge personal data complaints and respond within reasonable time.

SD134-16 · Complaint Handling

Handling of complaints and reports (including via the Spam Reporting Centre) as part of the CRTC enforcement regime and a documented compliance program.

CASL-19 · Complaint Handling

Provide mechanisms for handling complaints about infringements of the code by adherents.

RDCOC-COM-01 · Complaint Handling

Online platforms shall provide recipients (and notifiers) access, for at least six months following a moderation decision, to an effective internal complaint-handling system allowing electronic and free-of-charge lodging of complaints, with decisions taken und...

DSA-Art.20 · Internal complaint-handling system

Questions people ask about complaint handling

What is Complaint Handling?
Processes for receiving, investigating, and resolving complaints from data subjects about the handling of their personal information.
Why is Complaint Handling important for compliance?
Complaint Handling is a key concept in Privacy and Data Protection. Understanding complaint handling helps organizations meet regulatory requirements, reduce risk, and demonstrate due diligence during audits. Our compliance platform maps 686 frameworks with 311K cross-framework control mappings.
Which compliance frameworks address Complaint Handling?
Complaint Handling appears in the requirement text of AICPA Privacy Management Framework (PMF), APEC Cross-Border Privacy Rules (CBPR) System, Cambodia Sub-Decree on Personal Data Protection (Sub-Decree No. 134), Canada's Anti-Spam Legislation (CASL), Code of Conduct on Data Protection for Research (GDPR Article 40). Across these standards we have identified 6 controls that name it directly, each linked to the control text on the compliance platform.
Where can I learn more about Complaint Handling?
Explore our compliance framework pages to see how complaint handling applies across different standards and regulations. Our implementation guides provide step-by-step guidance, and the compliance platform offers AI-powered analysis of how this concept maps across 686 frameworks.

See how Complaint Handling applies across compliance frameworks

Our platform maps 686 frameworks with 311K cross-framework control mappings. Explore how this concept is addressed across standards.

Written and maintained by Gerard Blokdyk, The Art of Service.