After a complaint to your data protection authority: what actually happens
A complaint to a data protection authority is the start of a process, not a verdict. Most SMBs imagine the worst; the actual workflow is a letter, a response, and usually a closure, provided the response is well-prepared.
A complaint to a supervisory authority is the start of a regulatory conversation, not a verdict. Most SMB owners who have never received one imagine FBI-style raids; the actual experience is a letter on official letterhead with a list of documents requested and a deadline to respond. The outcome depends heavily on what the response contains.
The arrival
Supervisory authorities (CNIL in France, BfDI / state DPAs in Germany, Garante in Italy, AEPD in Spain, ICO in the UK, etc.) receive complaints through public web forms. A complaint is screened by the authority’s intake team. If it meets the threshold of a credible allegation against an identifiable controller, it is forwarded to the controller.
The forwarding is typically a letter or registered email containing:
- The complaint reference number.
- A summary of the allegation (often quoting the complainant’s text).
- The specific GDPR / ePrivacy / national-law articles the authority believes may apply.
- A list of information requested from the controller.
- A response deadline, typically 21 days (CNIL), 30 days (most DPAs), up to 60 days (large or complex matters).
The letter is not an accusation. It is a fact-finding step. The tone in most EU DPA letters is neutral and procedural.
What gets asked for
A typical first-letter information request includes:
- The lawful basis under Article 6 the controller relies on for the processing in question.
- A copy of the privacy policy and any consent records.
- Where applicable, evidence of consent (timestamps, CMP logs).
- The retention period for the relevant data category.
- The data processing agreement with any subprocessors involved.
- Any transfer mechanism (DPF certification, SCCs, etc.) relied on for international transfers.
- The internal procedure for responding to data subject rights requests.
For accessibility complaints under the EAA or national accessibility law, the equivalent list is: WCAG conformance evidence, the accessibility statement, the remediation roadmap, and the date of the last audit. A Veracly report slots into the first and the last of those. It is not the evidence package, and an earlier version of this post claimed it was — which is exactly the kind of overclaim this site spends its time criticising in overlay vendors.
The reason is not modesty, it is arithmetic. Roughly a third of WCAG success criteria are machine-testable at all; Veracly’s own manual-criteria list names 29 criteria that no automated pass can decide, and scores them neutrally rather than pretending otherwise. Keyboard traversal is never exercised, so no keyboard-trap or focus-order finding can exist. PDFs are never scanned. There is no screen-reader emulation and no authenticated-area testing. A conformance claim resting only on an automated scan is one a regulator can take apart with a single follow-up question. What the report evidences is the automated layer, the date it ran, and that the site is monitored rather than assumed compliant. The manual audit that completes the picture is separate work, and if the complaint is about accessibility you should assume the authority expects it.
How to respond
Five principles consistently predict good outcomes:
- Respond on time. The deadline is real. Late responses can result in escalation regardless of substance. If you need an extension, ask explicitly before the deadline, most authorities grant a short extension on a reasonable request.
- Respond factually. Answer each question with documentation attached, not narrative. Authorities read hundreds of complaints; clear evidence is faster to process than careful prose.
- Be specific about remediation. If a finding is correct, acknowledge it and describe what you have already changed. “We fixed the banner parity issue on 12 May 2026, here is the deploy log” is a much better answer than “We dispute the characterization.”
- Don’t over-share. Provide the information requested, not everything the controller has. Volunteering additional processing details that were not asked about expands the scope of inquiry.
- Get a lawyer if there is doubt. First letter on a clear, cooperative case is generally manageable in-house. Special-category data, cross-border issues, or any allegation of intentional violation needs counsel.
The escalation path
If the first response is unsatisfactory, or the complaint is severe enough at intake, the authority can escalate to a formal investigation. This typically involves:
- A follow-up letter with more specific document requests.
- Possibly an on-site visit (rare for SMBs in the EU, more common for large controllers and US contexts).
- A draft decision shared with the controller for comment.
- A final decision, possibly with a fine and remediation order.
- An appeal window, typically 30 to 60 days to the relevant administrative court.
For most SMB cases the process closes at step 1 with a warning, or at step 4 with a remediation order. Fines for SMB respondents are typically calibrated to size, CNIL has been explicit that they apply Article 83’s proportionality framework, and SMB fines in the four- and low-five-figure range are common; the seven-and-eight-figure headline fines target controllers with global revenue.
The patterns that lead to fines
Across published EU DPA decisions against SMB respondents, the patterns that correlate with fines (versus warnings or remediation orders) are consistent:
- Failure to respond at all. The single largest predictor of an escalated outcome.
- Repeat violation. A controller previously warned for the same issue is treated more sternly than a first-time finding.
- Special-category data. Health, biometric, racial, religious, union, or sexual-orientation data raises the severity by one tier in most authorities’ internal frameworks.
- Children’s data. Special weight under GDPR Article 8 and CNIL’s 2021 guidelines on under-15 processing.
- Intentional or knowing violation. Evidence the controller knew the processing was problematic and continued. Internal communications surfaced in document production frequently determine the difference between a warning and a fine.
- Cross-border violations. Where the one-stop-shop engages, Article 56 designates the lead supervisory authority and Article 60 governs the cooperation procedure that follows. Get the direction right: this route is slower, not faster. Cross-border cases have historically sat in the Article 60 process for years, which is precisely why Regulation (EU) 2025/2518, applicable from 1 January 2026, imposes binding procedural deadlines on them. Cross-border exposure raises severity because more authorities are watching and the eventual decision carries across the EU — not because anything moves quickly.
What having a signed Veracly report does
A signed, timestamped Veracly report is a piece of evidence that does several things in a complaint response:
- Establishes when the controller last audited the relevant processing, the regulator wants to see that compliance is monitored, not assumed.
- Provides an independent third-party assessment, distinct from self-certification.
- Carries a verifiable signature, so the authority can confirm the PDF is the one issued and has not been edited. One practical caveat: the verify URL has a limited validity window — the integrity block printed in the PDF itself states 30 days from issue. If you are attaching a report to a complaint response, say when it was issued, and re-issue a current one rather than sending a regulator a link that will be dead when they click it.
- Maps findings to specific regulation articles, which is exactly the format the authority’s legal team is operating in.
None of this is a defense to a substantive violation. But it shifts the conversation from “does the controller take this seriously” to “here is the evidence of monitoring, here are the findings as of [date], here is the remediation status.” That framing matters.
Practical recommendation
Treat the response window as a project. Open a folder for the complaint, file every piece of correspondence with the authority, file every piece of internal investigation, file your Veracly reports for the relevant period. Respond on the deadline, with attachments, in the format the authority requested. Follow up to confirm receipt. Most first-time SMB complaints close at this stage.
See also: How to verify a Veracly report is authentic · Sharing a Veracly report with regulators
Common questions
How do most SMB complaints arrive?
By mail or by registered email from the supervisory authority, with a complaint reference number and a response deadline (typically 21 to 30 days). They are factual and procedural, not accusatory. The cover letter usually summarizes the complaint and lists the specific information the authority requests.
What is the typical outcome?
For a first-time SMB complaint with a cooperative response, the most common outcome by a very wide margin is closure with no fine, often with an instruction to remediate. The published French counts give a sense of scale: in 2023 the CNIL received 16,433 complaints, and across all of its enforcement activity that year it issued 168 formal notices (mises en demeure) and 42 sanctions. Do not turn those into a percentage — the enforcement figures cover the CNIL's whole caseload, including controls it opened on its own initiative, so they are counts drawn from different populations rather than an outcome rate for complaints. The CNIL also publishes no breakdown by respondent size, so nobody can honestly give you an SMB-specific split.
Do I need a lawyer immediately?
For most first-time SMB complaints, no. The response is a procedural letter providing the requested information. A lawyer becomes valuable if the complaint alleges special-category data processing, cross-border violations, or repeat violations, or if the regulator escalates to a formal investigation.
See where your site stands.
Run a free Veracly scan and get a multi-jurisdiction report, EAA, GDPR, ADA, UK Equality Act, AODA, with copy-paste developer fixes.
Run a free scan