Shifting burden of regulatory investigation visual

Regulatory investigations are changing: While regulators retain extensive investigative powers, they increasingly rely on organisations to locate, assess and produce the information on which investigations depend. This article examines what is driving this development, the challenges it creates, and how organisations can strengthen their readiness to respond effectively when an investigation arises.

Why more of the work is shifting to companies

Regulators have a broad range of enforcement tools at their disposal. In the first half of 2026, European competition authorities carried out around thirty unannounced inspections of businesses (“dawn raids”)[1]. Regulators also issue Requests for Information (RFIs), requiring companies to provide targeted data sets, documents or communications to support the assessment of specific issues under investigation.

In practice, the distinction between these two instruments is becoming less clear-cut. Regulators have extensive powers, but increasingly depend on the companies to exercise them effectively. Not long ago, an investigation mainly affected email environments and shared network drives. Today, its scope is broader, extending to virtually every digital environment in which organisations create, share and retain information. Only the organisation itself knows where its data is located, which systems are in use, how the data is structured, and what technical or legal limitations may apply.

This does not make an investigation a joint project: cooperation is an obligation, not a choice. It does, however, shift the focus to a different question. The issue is no longer simply whether the regulator will gain access to the relevant data, but how that access will be organized, managed and determined.

That shift creates both practical challenges and legal risks. A company that provides information too broadly may disclose more than necessary, potentially including legally privileged material or information outside the scope of the request. A company that provides too little, responds too late, or follows a process that cannot be reproduced may face allegations of incomplete cooperation or the provision of incorrect information, together with the associated sanctions.

The result is that companies increasingly need to be prepared not only to provide information, but also to understand their own data environment, make defensible decisions about what is in scope, and demonstrate how those decisions were reached.

1. Data is everywhere

The volume of corporate information has grown exponentially in recent years, and that information is spread across an ever-increasing number of systems and communication channels. Whereas relevant information could previously be found largely in email archives on a company’s own servers, it is now distributed across a wide landscape of applications and cloud environments. Communications take place through email, Teams, Slack and WhatsApp; documents are stored in SharePoint and cloud storage; and relevant information may also sit in project management tools, specialist applications, backups and systems run by third-party providers. Data may be held by a cloud provider, external service provider or parent company, creating practical questions about access, contractual rights, data transfers and timing.

Data is also increasingly stored across borders. Where a local subsidiary once kept its files on its own servers, multinationals now typically operate centrally managed IT environments: mailboxes and documents are hosted by the parent company or a cloud provider, often in another jurisdiction, and are accessed from many countries at once. This raises legal questions of its own, such as whether data held by a foreign parent falls within the scope of an investigation into a local entity, how data protection rules affect transfers, and whether foreign laws prevent disclosure.

The consequence is clear: more data means more work, and much of it falling to the company itself. This applies both to regulatory requests for information and to investigations following a dawn raid. Before documents can be reviewed, the company must establish where relevant information is located, which data sources need to be investigated, and how this process can be conducted in a defensible manner. That requires knowledge that only the company possesses, an understanding of its own systems, people and data. Responding to an RFI or conducting a parallel investigation has therefore become a complex data and information exercise, one that demands time, expertise and preparation. Successfully managing such exercises requires companies to understand their own data environment before an investigation begins.

2. Legal privilege has become more complex

The identification and exclusion of privileged documents has become one of the most complex and labour-intensive aspects of investigations. Across Europe, organisations are generally given the opportunity to identify privileged material themselves. Under the European Commission’s current practice, the undertaking may review the data selected by inspectors to raise claims of legal professional privilege or concerns relating to special categories of personal data[2]. Determining what is privileged, however, is rarely straightforward. Organisations therefore need to know which lawyers they have communicated with, which documents were created for the purpose of legal advice, and where that information is stored. In response to an RFI, they must also collect, filter, and assess the data themselves, often under tight deadlines. As data volumes grow, this exercise is becoming increasingly demanding. Confidential business information and sensitive personal data add a further layer of complexity, which falls outside the scope of this article.

The seizure of bulk data raises a broader European question: How should authorities handle bulk data once it has been copied, while ensuring adequate protection of privileged information? In the Netherlands, this debate has been running for years. In its preliminary ruling of 12 March 2024, the Dutch Supreme Court underscored the importance of adequate safeguards: investigators should, in principle, not review potentially privileged information, and privilege claims should be assessed independently[3]. Although that ruling concerned criminal investigations, its impact extends to regulators: in 2024, the Netherlands Authority for Consumers and Markets (ACM) revised its procedure for handling privileged material, stating that it had aligned it with the Supreme Court’s criteria where possible[4]. The debate surfaced in the last months over a legislative proposal that would transfer the assessment of potentially privileged information in large data sets from the examining magistrate to the Public Prosecution Service. The government points to practical problems and growing backlogs, while the Netherlands Bar Association argues that the proposal conflicts with recently adopted legislation and Supreme Court case law[5]. At EU level, the same question is being discussed, as regulators seek more efficient access to large volumes of data while stakeholders call for stronger protection of legal privilege.

Regardless of how these debates are resolved, the practical reality remains unchanged: organisations must be able to identify privileged material quickly and accurately across increasingly large and complex data sets. How they handle privileged information is therefore becoming ever more important. This concerns not only the legal assessment of individual documents, but also a defensible process for identifying, reviewing and protecting privileged communications. A robust process can help organisations protect legitimate privilege claims while demonstrating that information has been handled appropriately and consistently.

3. Generative AI helps, but requires oversight

Beyond the assessment of privileged information, investigations place increasing emphasis on how information is collected, selected and reviewed. Regulators, courts and opposing parties need to know not only what information has been provided, but also how it was produced. Organisations must be able to demonstrate that their approach is consistent, reproducible and explainable.

Fortunately, generative AI is now being used increasingly in investigations and eDiscovery. It makes it possible to analyse large volumes of documents quickly, identify patterns, summarise content and rapidly locate relevant information. In internal investigations, this can deliver substantial efficiency gains.

Although regulators are becoming more open to the use of AI, the position is more nuanced when responding to regulatory requests. Speed is not the only consideration. If generative AI is used to select documents, the basis for those decisions must later be justifiable. This requires an explainable process: which data was reviewed, which instructions the model was given, which decisions it made, and how the results were checked. Not all AI tools used within law firms are suitable for this. Many are designed for drafting, legal research or summarising, rather than for reviewing and producing large data sets in a way that can be documented and defended for afterwards. Specialised eDiscovery platforms with built-in generative AI record key steps and allow results to be validated through sampling.

Where generative AI can be used in consultation with the regulator, the focus shifts to how its use is agreed and demonstrated. Early engagement is key: discuss the approach, agree on the validation methodology and establish what documentation will be provided. Even then, the approach remains hybrid, with human review and quality controls remaining an essential part of the process.

What companies can do now

Investigations by regulators and law enforcement agencies often arise unexpectedly and rarely at a convenient time. This is precisely why it is important to be prepared for the way in which such investigations are conducted today.

The first step is to understand the organisation’s own information landscape. Many organisations have a broad idea of where their data is located, but have limited visibility of all systems, communication channels, cloud environments, and third-party providers that may hold relevant information. That overview is essential when it is necessary to determine quickly which data falls within the scope of a request and how it can be collected and reviewed.

It is also worth deciding how privileged information will be handled in advance. This should not wait until a regulator requests data, but form part of the organisation’s regular information governance and investigation preparedness.

Equally important is a clear response plan. When a regulator arrives, there is little time to think about responsibilities, decision-making, or lines of communication. Organisations that have identified in advance who needs to be involved can respond faster and ensure that key decisions are made consistently and documented from the outset.

Preparation does not mean predicting exactly what an investigation will look like. It means putting the basic structures in place before they are needed: knowing where relevant information is held, understanding how privileged material will be identified and protected, and ensuring that roles and responsibilities are clear. These measures can make the difference between an organisation that is simply reacting to an investigation and one that can respond in a structured and defensible way.

Authors

Mr. Mathieu van Ravenstein, Partner.

Ms. Michelle Hagoort, Cyber and eDiscovery Specialist.


[1] White & Case LLP, ‘Dawn Raid Analysis Quarterly’ (Q2 2026 edition)

[2] European Commission, Explanatory note on Commission inspections pursuant to Article 20(4) of Council Regulation (EC) No 1/2003 (revised March 2024), para. 17.

[3] HR 12 March 2024, ECLI:NL:HR:2024:375

[4] Autoriteit Consument & Markt, ACM Werkwijze geheimhoudingsprivilege advocaat 2024 (18 July 2024)

[5] The Netherlands Bar Association, ‘NOvA: Trek voorgestelde wijziging verschoningsrecht uit Tweede aanvullingswet Strafvordering in’ (10 September 2026)