Regulators are generally more concerned with whether a business appears organised, cooperative and in control than whether it replies within hours.
A measured, coordinated response is usually more effective than an immediate one.
True story:
An employee mistakenly sent a job offer to the wrong individual. The offer letter contained various personal data, such as name, address, title of the offered role and salary information. The employee felt terrible and raised the error with their manager, who confirmed it was a data breach. The employee quickly asked the wrongful recipient to delete the letter. The employee then took their mea culpa a step further and took it upon themselves to inform the data protection regulator (this was outside of the UK) of the “data breach”. Senior management then got to hear about the issue…through a formal letter from the regulator requesting details of the recent data breach.
![]()
For many SMEs, receiving an email or letter from the Information Commissioner’s Office (ICO) or any other regulator triggers something not too far distant from mild panic. The instinctive reaction is often to respond immediately. In reality, the first few days are usually better spent organising the response rather than sending one.
But, regulatory contact does not automatically mean enforcement action, wrongdoing, or an impending fine. In practice, many ICO enquiries are simply:
- follow-up on a complaint
- routine information gathering
- clarification of how an organisation operates
- early-stage supervisory engagement
For example, the ICO continues to grapple with the rapid adoption of AI, assessing how AI is already being used (and how widespread use is), assessing whether personal data rights are being respected and using the current regulatory framework to provide guard rails where needed.
An initially straightforward enquiry can quickly become more complex and more time consuming – not necessarily because of the underlying issue, but as a result of the impression conveyed during those critical early stages.
Reply first assess later pitfall
A typical internal chain of events looks something like this:
- The initial recipient was not the correct “home” for the correspondence and so the correspondence is rapidly shared with anyone potentially relevant.
- Someone (anyone!) tries to be proactive and replies quickly to appear cooperative.
- Assumptions are made or a position is taken before facts are checked.
- Different teams provide inconsistent inputs.
- More information is shared than necessary.
- After the excitement of the initial response has subsided, the true picture emerges and further information needs to be provided, further questions are raised and corrections or clarifications are required.
The intention is good—be responsive, be helpful. But speed without structure creates avoidable risk.
Regulators are busy. Very busy. Their teams tend to prioritise accuracy, clarity and cooperation over immediate replies. A rushed response that later needs supplementing and correcting undermines credibility far more than a short, well-managed delay.
A practical framework: PAUSE before you respond
A simple way to approach any regulatory enquiry is to apply a structured pause. Not delay for its own sake, but a short, controlled pause to ensure the response is right. Even relatively routine enquiries can consume significant management time if handled reactively.
P: Preserve the correspondence
Maintain a clear record of all communications from and with the regulator and all related internal communications. Seek legal advice as to whether privilege may be relevant to any documents/communications.
Before starting to formulate any response, start with the basics: what exactly is the regulator asking?
Check:
- the deadline (and whether it is flexible)
- the scope of the request
- whether specific documents or explanations are required
- any reference to statutory powers
It’s common for SMEs to respond to what they think the regulator is asking (or perhaps even responding to what they would prefer the regulator to be asking…), rather than actually dealing with the request head on. If the deadline is on the short side, a polite holding response with a request for extension is often better than rushing to provide an incomplete substantive response. Just make sure that any request for extension is made in good time!
A: Assess the issue internally
Before drafting anything externally, establish the internal position.
Ask:
- what actually happened?
- who is involved?
- what systems or data are affected?
- what documentation exists?
This stage is often where the real work sits. A well-coordinated internal fact-finding exercise will significantly improve the quality—and confidence—of the eventual response. Have clear escalation processes set up to ensure that the right people are brought together quickly as soon as possible.
U: Understand the context
Not all enquiries carry the same weight.
For example, if receiving an ICO enquiry, look for indicators such as:
- references to complaints or data subjects
- formal notices or statutory wording
- repeated or escalating questions
- requests framed as mandatory
The tone of correspondence may appear informal even where the underlying issue is more serious. Understanding where you are on that spectrum helps calibrate your response.
S: Shape the response carefully
Once the facts are clear, focus on how you present them.
An effective response is:
- factual and evidence-based
- clear and concise
- aligned across internal stakeholders
- proportionate to the question asked
Avoid:
- speculation or guesswork
- defensive language
- volunteering additional issues unnecessarily
- overly selling a position
A considered response signals credibility. A good measure of tone is to imagine the response being read out in court.
E: Escalate where appropriate
Some situations justify external support.
Consider the need for external support early, particularly if:
- there is a personal data breach or potential breach;
- senior management actions are involved;
- there is cross-border element to an enquiry;
- insurers need to be notified;
- the issue could expand beyond its initial scope.
Early, targeted advice often prevents a relatively contained issue from becoming more complex.
Conversely, investing time to develop internal processes will also reduce the need for external support for more routine enquiries.
Why rushing creates bigger problems
The risks of moving too quickly are often underestimated. A premature response can:
- introduce inconsistencies that need correcting later
- disclose information that widens the scope of enquiry
- undermine internal alignment
- weaken your position if the matter escalates
By contrast, a short, structured pause allows you to respond with confidence and control.
What the regulator is really looking for
In many cases, a regulator may not require perfection at the outset. How an organisation demonstrates its handling of a situation matters more.
Positive indicators typically include:
- clear ownership of the issue;
- organised and accessible records (in relation to the ICO, key documents to have available will include the record of processing activity or “ROPA” detailing how personal data is used across the business, data protection policies, any relevant data protection impact assessments and a record of technical and organisational security measures);
- a clear explanation of what happened;
- evidence of remediation or mitigation; and
- steps being taken to prevent recurrence.
Demonstrating a thoughtful, structured approach can materially influence how an enquiry progresses.
Final thought
Any contact with a regulator should of course be taken seriously. But remember that the first response should be the right one, rather than the fastest one.
And as usual, involve your legal support sooner rather than later. Early legal input is rarely about escalating the issue. More often, it helps organisations respond calmly, consistently and strategically from the outset.

Written by Laura Perkins
Principal at My Inhouse Lawyer
One of our values (Growth) is, in many ways, all about cultivating a growth mindset. We are passionate about learning, improving and evolving. We learn from each other, use the best know-how tools in the market and constantly look for ways to simplify. Lawskool is our way of sharing with you. It isn’t intended to be legal advice, rather to enlighten you to make smart business decisions day to day with the benefit of some of our insight. We hope you enjoy the experience. There are some really good ideas and tips coming from some of the best inhouse lawyers. Easy to read and practical. If there’s something you’d like us to write about or some feedback you wish to share, feel free to drop us a note. Equally, if it’s legal advice you’re after, then just give us a call on 0207 939 3959.
Want to know more ? Book a discovery call
How it works
1
You
It starts with a conversation about you. What you want and the experience you’re looking for
2
Us
We design something that works for you whether it’s monthly, flex, solo, multi-team or includes legal tech
3
Together
We use Workplans to map out the work to be done and when. We are responsive and transparent
Like to know more? Book a discovery call
Freedom to choose & change
MONTHLY
A responsive inhouse experience delivered via a rolling monthly engagement that can be scaled up or down by you. Monthly Workplans capture scope, timings and budget for transparency and control
FLEX
A more reactive yet still responsive inhouse experience for legal and compliance needs as they arise. Our Workplans capture scope, timings and budget putting you in control
PROJECT
For those one-off projects such as M&A or compliance yet delivered the My Inhouse Lawyer way. We agree scope, timings and budget before each piece of work begins
Ready to get started? Book a discovery call
How we can help