Auditen
number of the day

Does €225 Million Buy Compliance?

The number for this week is €225 million.

That is the total sum of GDPR fines handed out in the second quarter of 2026. To a press officer at a data protection authority, it looks like a victory. It's a figure designed to look formidable on a slide deck in Brussels, suggesting that the "strict" nature of the regime is finally biting.

From a regulatory desk perspective, however, one has to ask who actually paid those fines and whether the money changed any actual behaviour.

Large firms generally treat these penalties as a cost of doing business. They don't see a fine as a failure of ethics or a breach of law; they see it as an operational expense that was slightly underestimated in the annual budget. If a company makes several billion euros from a data-hungry business model, a few million euros in fines is simply the price of the lease on their database.

The paperwork tells a different story than the press releases.

While regulators celebrate the total figure, the actual impact on security remains negligible. We see this in the gap between certification and reality. Take tl;dv, which recently leaked north of 180,000 meeting records because of a vendor failure. They had their SOC 2 certification. On paper, they were compliant. In practice, the data walked out the door.

Then there is Medusa. This ransomware group has hit over 500 critical infrastructure organisations. These are not small shops; these are entities that are required to follow strict frameworks and maintain rigorous controls.

The argument from the regulators is that high fines create a deterrent effect. They claim that the threat of a massive penalty forces boards to prioritise security.

This is where the logic fails. A fine is a lagging indicator. It arrives years after the breach, following an eternity of appeals and administrative hearings. For a CISO, a fine three years from now is far less frightening than a ransomware attack today. The deterrent isn't the regulator; it's the attacker.

The second-order effect here is the growth of "compliance theatre". When the penalty for being *caught* without a process is higher than the risk of actually *having* a breach, firms invest in the appearance of security. They buy the certificates and file the reports to ensure that if a breach happens, they can point to their paperwork and argue for a reduced fine.

They aren't buying security. They are buying an insurance policy against regulatory wrath.

The auditors are complicit here. They sign off on the controls because the controls exist on paper. The auditor checks that there is a password policy; they don't necessarily check if the admin password is still "Admin123" across five hundred servers.

We can see this fragility in other corners of the market too. Look at PLDT, which now has to amend its 20-F filing after audit opinions were pulled due to material control weaknesses. It's a classic case of the paperwork finally catching up with the reality of the internal controls.

If we want to know if GDPR is actually working, we shouldn't look at the total amount of fines collected in a quarter. We should look at whether those fines are actually causing firms to change their architecture.

Currently, they aren't. They're just getting better at filing the forms.

I suspect that as long as regulators prioritise "total fine amounts" over systemic architectural audits, we will continue to see these eight-figure sums alongside six-figure leaks. The fines are high enough to look impressive, but not high enough to make a trillion-dollar industry actually stop leaking data.

One wonders how many more hundreds of thousands of records need to leak before the regulator stops counting the money and starts counting the holes in the fence.

Sources

The reporting this piece was written from. Check the originals before relying on anything here.

  1. PLDT Inc. (PHI) to amend 2025 Form 20-F after material control weakness and pulled audit opinions - Stock Titan PCAOB
  2. SEC charges former execs of auto subprime lender giant Tricolor with fraud, falsifying loan documents - Compliance Week Compliance Week (Google News)
  3. tl;dv Leaked 181,874 Meeting Records: SOC 2 and the Vendor Problem - Machine Brief InfoSec Compliance (Google News)
  4. SEC lays groundwork for crypto issuers to raise flexible capital with new rules proposal - | Governance Intelligence Compliance Week (Google News)
  5. Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs - The HIPAA Journal InfoSec Compliance (Google News)
  6. Nasdaq warns SAGTEC Global (Nasdaq: SAGT) over sub-$1 shares, with delisting risk - Stock Titan Compliance Week (Google News)
  7. Utah governor says he’s ‘deeply troubled’ by Flock cameras, calls for review to protect privacy - Utah News Dispatch Data Privacy (Google News)
  8. EHang (EH) replaces PwC as 2026 auditor, names new audit firm - Stock Titan Compliance Week (Google News)

How stories are selected and assessed