Introduction
This Policy explains how ASI handles complaints about the way it collects, uses, stores or shares personal data. The ASI is committed to handling personal data responsibly and in accordance with data protection law. If you believe that we have fallen short of that standard, this Policy explains how to raise a concern and what you can expect from us.
Legal basis
The Data (Use and Access) Act 2025 introduced a new legal duty for organisations to have a formal procedure for handling data protection complaints. This requirement is set out in section 164A of the Data Protection Act 2018. ASI is meeting this duty through this Policy. ASI’s Data Protection Officer (DPO) in conjunction with ASI’s Director of Legal, Ethics and Compliance is responsible for overseeing compliance with this Policy and with data protection law.
What is a data protection complaint?
A data protection complaint arises when you believe that ASI has not handled your personal data correctly. A person does not have to use the words ‘data protection complaint’ for us to treat their concern as one. Examples include:
- Using your personal data without a lawful basis.
- Sharing your data without authority or in breach of confidentiality.
- Retaining your data for longer than necessary.
- Failing to respond to a Subject Access Request within the required timeframe.
- Failing to correct inaccurate personal data when asked to do so.
- Failing to delete personal data when there is a legal duty to do so.
- Handling your data in a way that has caused you distress.
What is not a data protection complaint?
Some matters fall outside this Policy:
- A Data Subject Request – a request to access your personal data – is handled under a separate process. This includes a Data Subject Access Request.
- General compliance complaints – please check our website at www.adamsmithinternational.com which explains how to raise a concern.
Time limit for making a complaint
We will accept a data protection complaint made within 6 months of the event occurring, or within 6 months of the date on which you became aware of it. We will consider exercising discretion to accept complaints made outside this period where there is a good reason for the delay. If we decide not to accept a complaint, we will explain why and remind you of your right to complain to the Information Commission.
How to make a data protection complaint
You can make a complaint directly by:
- Using our online data protection complaint form available here. We encourage you to use this form if possible.
- Emailing the Data Protection Officer at dpo@adamsmithinternational.com or writing to them at our address (below).
- Using any of the routes identified on our website at www.adamsmithinternational.com.
- You can also raise a data protection complaint with any ASI employee, and they will make sure it reaches the Data Protection Officer.
All complaints are handled confidentially. We cannot investigate anonymous complaints as we need to be able to communicate the outcome to you. We therefore need your contact details.
Accessibility and reasonable adjustments
We want the complaints process to be accessible to everyone. We will make reasonable adjustments for individuals who need them under the Equality Act 2010. If you need us to communicate with you in a different format or need any other adjustment, please let us know when you make your complaint.
Making a complaint on behalf of someone else
ASI will review complaints which you make on behalf of someone else. We will require evidence of your authority to act for that other person.
How we deal with data protection complaints
Please tell us what your complaint is about and, if relevant, how it has affected you. The person dealing with your complaint will clarify any aspects they are unclear about, deal with the complaint on its merits with an open mind and consider all relevant information carefully.
We will always aim to respond within the timeframes set out below. The Data (Use and Access) Act 2025 requires that complaints are acknowledged within 30 days.
Stage 1 – Resolution
Your complaint will initially be handled by the Data Protection Officer, a senior member of their team or a nominated member of the Legal, Ethics and Compliance.
We will:
- Acknowledge your complaint promptly. Our aim is to acknowledge complaints within 5 working days wherever possible. However, there may be some circumstances in which we are unable to meet this and if this is the case we confirm that all acknowledgements will in any event within 30 days from our receipt of your complaint.
- Aim to provide a full response within 30 days of the date of acknowledgment. If we need more time, we will let you know as soon as we are aware ourselves.
When we notify you of an extension, we will also give you the contact details of the Information Commission. Our response will aim to address all the points you have raised and provide clear reasons for any decisions, referencing relevant law or good practice where appropriate.
If you are not satisfied with the Stage 1 outcome, you may ask for a Stage 2 review. You do not have to explain your reasons for requesting a review, but it will help us to deal with your case more quickly and effectively if you can tell us why the Stage 1 response was not acceptable and what you would like us to do.
We will contact you when we acknowledge your Stage 2 request to make sure we understand your outstanding concerns. You must request a Stage 2 review within 30 days of receiving our Stage 1 response.
Stage 2 – Review and Resolution
Stage 2 complaints are reviewed by either the Director of LEC (if they did not review your Stage 1 complaint) or a Director, who will not be the same person who handled your Stage 1 complaint. The review will focus on your continuing concerns, whether Stage 1 was conducted fairly and whether the conclusions were reasonable.
We will:
- Acknowledge your complaint promptly and in any event within 30 days from our receipt of your Stage 2 complaint. We may in that acknowledgement set out our understanding of your outstanding concerns and the outcome you are seeking.
- Aim to provide a full response within 30 days of the date of acknowledgment. If we need more time, we will let you know as soon as we are aware ourselves.
When we notify you of an extension, we will also give you the contact details of the Information Commission. Our response will aim to address all the points you have raised and provide clear reasons for any decisions, referencing relevant law or good practice where appropriate.
At the conclusion of Stage 2 we will write to you to confirm: the complaint stage; our understanding of the complaint; our decision; the reasons for that decision; details of any remedy we are offering; details of any outstanding actions; and how to escalate the matter to the Information Commission if you remain dissatisfied.
Please note that under the Data (Use and Access) Act 2025, the Information Commission will generally expect you to complete ASI’s internal complaints process before it will investigate.
How we respond to a data protection complaint
| Document version and date: | v1 June 2026 |
| Next review date: | December 2026 |
| Author: | LEC and IT and Cyber Security |
| Who does this policy apply to: | All ASI People |
We will endeavour to respond to all the points raised in your complaint. We will also tell you what to do next if you are not satisfied with the outcome. Any remedy we offer will reflect the impact on you because of what went wrong. We will always follow through on any remedy we propose. If a proposed remedy cannot be delivered, we will tell you why, offer any available alternative, and remind you of your right to complain to the Information Commission.
All complaints and the actions taken are documented in accordance with our record management obligations under data protection law.
For further information about how ASI processes your data please see ASI’s privacy notice which is available on ASI’s website here.
Click here to download the ASI Data Complaint Form.
|
Document version and date:
|
v1 June 2026
|
|
Next review date:
|
December 2026
|
|
Author:
|
LEC and IT and Cyber Security
|
|
Who does this policy apply to:
|
All ASI People
|