Complaints
NHRIs should address complaints in a prompt and fair manner. Doing so will help maintain trust with
stakeholders and organisational reputation generally as well as preventing unnecessary legal and
regulatory actions with their associated costs.
Steps for Handling a Data Privacy Complaint
•
Acknowledge the complaint promptly: send an acknowledgement to the individual as soon as the
complaint is received. Provide contact details of the person responsible for handling the matter,
along with a timeline for when the complainant can expect a full response.
•
Verify the identity of the complainant: check the complaint comes from the person whose personal
data is involved. Use secure methods, such as confirming personal details that are already on file
or requesting additional identification if necessary.
•
Investigate: review the details of the complaint, including the nature of the alleged privacy breach,
when it occurred, and what personal data is affected.
•
Involve the relevant staff: if the complaint relates to specific departments (e.g., fundraising,
volunteer management), involve the appropriate staff in the investigation to gain a full
understanding of the issue.
•
Take corrective action (if needed): if the issue involves inaccurate or outdated information, rectify the
data. If the individual’s data was handled improperly, address the issue so it doesn’t happen again.
•
Offer redress: in cases where the NHRI has mishandled personal information, consider offering
compensation and an apology.
•
Communicate the outcome: provide the individual with a full and detailed response within a
reasonable timeframe (typically within one month under GDPR). If the issue is complex, inform them
of any delays and reasons for the delay. Clearly explain the results of the investigation, the steps
taken, and any corrective measures implemented. If the NHRI cannot fully meet the complainant’s
request (e.g., legal reasons prevent the deletion of certain data), explain the rationale.
•
Report a data breach: If the complaint reveals a data breach, you may need to follow data breach
reporting obligations in the relevant country.
•
Keep a record of the complaint: document all complaints and how they were handled. This record
can be useful in case of future audits or investigations by regulatory bodies.
•
Improve internal processes: use complaints as opportunities to improve your organisation’s data
handling procedures. Identify if the complaint reveals gaps in staff training, policies
* (!) Don’t store data in a location which poses a risk to an HRD
I f an NHRI is handling personal information of HRDs at risk of harm from the authorities of particular
countries, the data should not be stored in those countries. That means, if you are using third party
cloud platforms or storage providers, you need to understand the physical location of the servers.
Remember that police and other government agencies in most countries can use their legal
powers to compel companies, including cloud service providers, to provide access to data they
deem necessary for criminal and other investigations. It is up to the provider the extent to which
they comply with such requests and the NHRI may not have much influence over the cloud
provider’s decision. This is sometimes referred to as ‘data sovereignty risk’ meaning there is
a risk governments can exert legal authority over data because its physical location is within
their jurisdiction.
Data Protection Guidelines for NHRIs Toolkit
16