Independent investigation and regulated complaints handling

Contested cases need someone with no stake in the outcome. I investigate misconduct, harassment and grievance allegations for education providers, and I build the complaints frameworks that regulators now require organisations to operate.

Fifteen years in higher education. Eight years of complaints, appeals and conduct casework to Office of the Independent Adjudicator standards.

What has changed, and when

  1. 19 June 2026Data protection complaints became a statutory dutySection 164A of the Data Protection Act 2018 requires every UK controller to operate a complaints process, acknowledge within 30 days and respond without undue delay. No size threshold. No sector exemption.
  2. 1 September 2026The OfS free speech complaints scheme openedStaff, applicants for academic posts and visiting speakers can now complain to the regulator. Students continue to use the OIA scheme.
  3. April 2027Free speech conditions of registration take effectRegistered providers in England face assessment against them. Complaints, disciplinary and speaker-event procedures need to be ready before, not after.

Independent investigations

Commissioned by education providers where internal handling would create a conflict of interest, where capacity is short, or where the allegation is serious enough that independence has to be visible.

Student conduct and disciplinary

Scoping allegations against your regulations, interviewing the parties and witnesses, testing the evidence, and producing a report a decision-maker can act on. I establish facts on the balance of probabilities. I do not decide the outcome, recommend sanction, or sit on the panel.

Code of student conduct · academic misconduct · disciplinary regulations

Harassment and sexual misconduct

Trauma-informed interviewing that minimises avoidable distress without lowering the standard of proof or the fairness owed to the responding party. Safeguarding interfaces, precautionary measures and criminal-process liaison handled explicitly rather than assumed.

OfS harassment and sexual misconduct condition · Equality Act 2010

Staff grievance and disciplinary

Where the allegation sits inside the reporting line, or involves someone senior enough that internal investigation would be challenged. Same methodology, same separation between finding facts and taking decisions.

Grievance · bullying · whistleblowing referrals

Complaints reviews and OIA readiness

Independent review of a complaint your own process has not resolved, or an audit of how your complaints and appeals procedure would stand up on external review. Findings come with the procedural and systemic issues observed along the way, not just the outcome.

OIA Good Practice Framework · QAA and the UK Quality Code

Data protection complaints

Since June 2026 every controller in the UK has had to run a complaints process that meets a statutory standard. Most organisations have privacy expertise. Far fewer have ever run a complaints function.

Readiness assessment

A structured gap assessment against the section 164A duty across five areas: accessibility of the route, whether staff recognise a complaint that does not use data protection language, handling and timeliness, signposting across notices and rights responses, and third-party and assurance arrangements. You get a scored position and a prioritised action list.

Typically one to two weeks

Procedure and framework build

A complaints procedure written to the statutory requirements and to how your organisation actually works: triage that separates complaints from rights requests and breach reports, proportionate investigation, scheduled progress updates, reasoned outcomes, and a register that evidences compliance if the Commissioner asks.

  • Procedure, correspondence templates and register specification
  • Privacy notice and rights-response signposting wording
  • Staff quick-reference for recognising a complaint

Any UK controller · no sector restriction

Caseworker training

Half-day and full-day sessions for the people who will handle the cases. Recognising a data protection complaint arriving through a non-standard route, setting proportionate investigation depth, writing an outcome the complainant can follow, and avoiding the delay that turns a defensible case into a regulatory one.

Front-line teams · DPO functions · complaints teams

Overflow and interim casework

Handling complaints directly where volume has outrun capacity, or where a case needs someone outside the team that did the processing complained about.

Interim · project · retained

How an investigation runs

Every instruction follows a published framework, which is shared with the commissioning provider and available to the parties on request. Nothing is investigated outside the agreed terms of reference.

  1. 01Scoping and independenceYou set out the allegation and the regulations. I confirm capacity and complete a conflict of interest and independence declaration before anything else happens.
  2. 02Terms of referenceThe questions to be answered, the regulations in scope, what is excluded, the timescale and who receives the report. Signed by both of us.
  3. 03NotificationParties are told in writing what is alleged, who is investigating, their right to be accompanied, the support available and the expected timescale.
  4. 04Evidence and interviewsDocumentary evidence indexed first where possible, then interviews. Records go back to each interviewee to check. Adverse evidence is put to the party it affects before any finding is made on it.
  5. 05ReportFindings of fact with reasons, traceable to indexed evidence, written so a decision-maker who has seen none of it can follow how each conclusion was reached.
  6. 06HandoverReport, bundle and index to the commissioning officer. I stay available to clarify the report, and take no part in the decision.

About

Compliance & Data Guard Services is the practice of Ransford Stanley, an independent investigator and regulated complaints specialist based in London.

Fifteen years in higher education, including eight leading complaints, appeals and conduct casework to Office of the Independent Adjudicator standards at the University of Plymouth, Canterbury Christ Church University, University College London and the University of East London. The work has consistently been the contested end: allegations involving special category data and safeguarding, appeals under external scrutiny, and the design of the policies and training that follow.

The second strand is data protection. Subject access request handling, information sharing governance, and the UK GDPR applied to decisions that are genuinely disputed rather than routine. That combination — someone who has run a regulated complaints function and understands data protection law — is what the section 164A duty now asks organisations to find.

Professional qualifications

  • Introduction to Alternative Dispute Resolution, Chartered Institute of Arbitrators
  • International Advanced Certificate in Regulatory Compliance (Merit), International Compliance Association
  • UK GDPR Data Protection Practitioner Certificate
  • CIPP/E, IAPP — in progress
  • CompTIA Security+ · ISC2 Certified in Cybersecurity
  • Associate Fellow of the Higher Education Academy

Education

  • PGCert International Student Advice and Support (Distinction), University of Nottingham
  • MA European Politics, Business and Law (Merit), University of Surrey
  • BA (Hons) Politics and International Relations (First Class), University of Westminster

Discuss an instruction

For investigations, tell me the nature of the allegation, the procedure it falls under and your timescale. For complaints work, tell me where you think the gap is. Initial conversations are free and confidential, and I will say if the work is not something I should take.

rstanley@compliancedataguardservices.com
07586 553272
linkedin.com/in/ransford8stan

Please do not send case papers or personal data about a third party in a first email. I will set up a secure route before anything of that kind is exchanged.