The ICO has contacted you
Receiving contact from the Information Commissioner's Office (ICO) means they are looking into your organisation's handling of personal data. This could be because of a complaint from an individual, concerns arising from a data breach you reported, or a proactive audit.
The ICO is the UK's data protection regulator. They have significant powers to investigate organisations and take enforcement action. How you respond matters.
Types of ICO investigation
The ICO may contact you for several reasons:
- Complaint investigation: An individual has complained about how you handle their data
- Breach investigation: Follow-up to a data breach you reported
- Compulsory audit: The ICO requires you to allow them to audit your practices
- Enforcement investigation: The ICO has identified potential serious breaches (most serious)
Immediate steps
- Note the deadline: ICO letters specify response deadlines. Request an extension before the deadline if needed.
- Gather documents: Collect processing records, policies, breach logs, and relevant correspondence.
- Involve the right people: Your DPO if you have one. Consider legal advice for serious investigations.
- Preserve records: Destroying or concealing documents is a criminal offence.
Your duty to cooperate
UK GDPR requires data controllers to cooperate with the ICO. This is not optional. The ICO has statutory powers to compel cooperation.
ICO powers
The ICO can:
- Require you to provide information and documents
- Enter and inspect your premises (with a warrant if necessary)
- Interview staff and officers
- Examine equipment and materials
- Access and copy records
Consequences of non-cooperation
Failing to cooperate can result in:
- Additional enforcement notices requiring cooperation
- Higher penalties if non-cooperation is treated as an aggravating factor
- Criminal prosecution for obstruction in serious cases
- Adverse inferences drawn from your failure to explain
What the ICO may ask for
The ICO may request: processing records, policies, privacy notices, processor contracts, breach logs, SAR logs, consent records, DPIAs, and training records.
For audits and serious investigations, ICO officers may visit your premises and interview staff. You may have legal representation present.
Possible outcomes
After investigation, the ICO may:
- Take no further action if there was no breach or a minor breach you addressed
- Make recommendations without formal enforcement
- Issue a reprimand (public record of infringement)
- Issue an enforcement notice requiring specific compliance steps (non-compliance is criminal)
- Issue a monetary penalty for serious infringements
Your rights during an investigation
While you must cooperate, you have procedural rights:
- Representations: Before enforcement, the ICO must issue a notice of intent allowing you to respond
- Appeal: You can appeal to the First-tier Tribunal within 28 days of a decision
- Legal advice: You can seek legal advice at any stage (strongly recommended for serious cases)
- Privilege: Communications with legal advisers may be protected, but routine business documents are not
After the investigation
Whether or not the ICO takes formal action, use the investigation as an opportunity to strengthen your data protection practices.
Review your data protection compliance
Comprehensive guidance on UK GDPR requirements, ICO registration, lawful bases, data subject rights, and breach notification.
Update your breach response procedures
Ensure you can detect, assess, and report data breaches within the 72-hour deadline.
Check your ICO registration
Verify your ICO registration is current and your details are up to date.
Record lessons learned and demonstrate improvement by keeping evidence of changes you have made.