ICO enforcement makes headlines when it hits a household name, but the pattern behind most action against SMEs is far more mundane — and far more fixable. Here's what it means for how you keep your GDPR paperwork.
Enforcement actions get attention when they involve a well-known brand or a large fine. The pattern behind most ICO scrutiny of SMEs looks nothing like that — it's quieter, more procedural, and usually starts with a request for paperwork rather than a headline breach.
When the ICO opens an inquiry, the first requests are rarely about the underlying incident. They're about your records: your Record of Processing Activities (ROPA), your documented lawful basis for the processing involved, and evidence of how any consent was actually captured.
The pattern
Most enforcement outcomes for SMEs cite a failure to maintain accurate records or evidence a lawful basis — not a failure of the underlying security control itself.
Good practice that only exists as institutional knowledge is invisible to a regulator, an auditor, or a customer's due diligence team. If your lawful basis, your data flows, and your consent records aren't documented somewhere reviewable, you can't demonstrate compliance — even if your actual practice is sound.
These are exactly the records our GDPR evidence guide walks through building, in the order the ICO tends to ask for them.
Read the full guide
How to collect GDPR evidence
Fortify's free GDPR assessment maps your data protection gaps and gives you a prioritised starting point — in around 10 minutes.