Defence before the SIC in data protection investigations
When the Superintendence of Industry and Commerce requests information, forwards a complaint or issues formal charges, deadlines are running and every document filed shapes the discussion that follows. We take on the company's technical defence: reconstruction of the facts, responses to requests, replies to charges, evidence and appeals. We do not promise outcomes; we offer an orderly case and a position sustained from start to finish.
Where these matters usually start
Almost no file starts with news of a formal investigation. It starts with something quieter, and what is done in those first days shapes everything after.
- A complaint from someone who never got an answer to their query or claim.
- An information request addressed to the company, sometimes without explaining where it comes from.
- An own-initiative action triggered by press coverage, a reported incident or a sector review.
- A report from a competitor, a former employee or a dissatisfied consumer.
- An on-site inspection, with collection of documents and access to systems.
First: rebuild the internal file
A defence is built on what the company can prove, not on what it remembers. So the work starts inward, and it often reveals that the problem was not the one everyone assumed.
- The authorisation of the individual involved: how it was obtained, where it is recorded and which purposes it covered.
- The processing policy and notice in force on the date of the events, not today's versions.
- The trail of the request that triggered the complaint: when it arrived, who handled it and what was answered.
- The contracts with the processors involved and the allocation of responsibility they set.
- The security measures actually applied, and evidence that they existed before the event.
What we do at each stage
- First response. We confirm the date of service and the applicable deadline, define the real scope of what is being asked and stop information from going out before we know what it says.
- Answering requests. We respond to what was asked, with complete information and in the form the authority will read it.
- Inspections. We attend, monitor what is collected and how it is recorded, and place the appropriate observations on record.
- Reply to charges. We answer the statement of objections, contest the allegations fact by fact and request the evidence supporting the company's position.
- Evidence and submissions. We take the evidence admitted, challenge the authority's evidence and file closing submissions.
- Appeals. We file the available appeals against the decision and assess the route before the administrative courts.
Controller and processor: who answers for what
Many of these files involve more than one company: the one that decided about the data and the one that handled it on the other's behalf. Pointing at each other without contractual support worsens both positions. We review what the contracts say, what instructions existed and what can be evidenced, and build a position consistent with what the company signed and with what it did.
When the right move is to correct
Not every file is defended the same way. Where the internal review shows there was a real failure, the conversation changes: correct quickly, record the correction and present it to the authority for what it is. We say so plainly, with the consequences on the table, rather than maintaining a position the file will not support.
What the client receives
- A map of the file: what is under investigation, at what stage, which deadlines are running and what scenarios exist.
- The responses, replies to charges, evidence requests and submissions filed on their behalf.
- Attendance at inspections and at any procedural steps taken.
- The internal file put in order, with the compliance evidence located and usable.
- The appeals against the decision and an opinion on whether to take the matter to the administrative courts.
Typical situations we handle
- A company served with a complaint from a customer who asked for deletion and got no answer.
- An information request about commercial messaging or the use of a purchased database.
- A proceeding opened after the company itself reported a security incident.
- An investigation where controller and processor disagree about who was responsible for what.
Let's solve your legal matter
Every case starts with an honest conversation. Book 30 minutes, no commitment.
Schedule an urgent consultation →