Auditen
framework watch

GDPR Fines Hit €225 Million in Second Quarter

The numbers for the second quarter are out, and they're ugly. Just under €225 million in GDPR fines were handed down across the board. Most people will look at that figure and assume the regulators are just hunting whales—the big tech firms with bottomless pockets.

They're wrong.

Look at the fine levied against the board of Mukumu Girls school. They were ordered to pay roughly 300,000 shillings for a privacy breach. It isn't a massive sum in global terms, but it signals a shift in enforcement appetite. The regulator is no longer just interested in the systemic failures of Silicon Valley; they're now knocking on the doors of small-scale operators who thought they were under the radar.

This is where I get suspicious. Whenever I sit across from a CISO or a Compliance Officer, they love to tell me their program is "mature." In my experience, "mature" is usually code for "we have a very expensive folder of PDFs that no one has opened since 2023."

I judge every control by a simple standard: what would you show the assessor on a Tuesday?

If your answer involves showing me a policy document that says "we protect data," you've already failed. I don't want to see the rulebook; I want to see the evidence that the rule was actually followed last Tuesday at 2 PM. I want the access logs, the timestamped approval for the data export, and the proof that the deleted records are actually gone from the backups.

Some will argue that smaller organizations can't maintain the same level of evidentiary rigor as a Fortune 500 company. They'll say it's a disproportionate burden.

That's a convenient excuse, but it doesn't stop the fine. The regulator doesn't care if your internal process is "basically working." They care if you can prove it. If you can't produce the artifact, the control didn't happen. It's that simple.

The second-order effect here isn't just for the firms getting fined; it's for the consultants who sold them their "compliance-in-a-box" packages. There are plenty of shops out there selling a version of maturity that consists of templates and quarterly checklists. When these firms start facing fines like the Mukumu Girls board, they won't blame their own lack of rigor first—they'll blame the consultants who told them they were "compliant."

We're seeing a move away from paper-based compliance toward operational reality. If you've spent the last two years trusting a dashboard that tells you your risk is green without ever sampling the raw logs, you're exposed.

The question to ask yourself this week isn't whether you have a DPO or a privacy policy. It's whether you can actually produce a clean audit trail for a random data request from six months ago without having to spend three days "cleaning up" the files first.

I suspect we'll see the number of these smaller fines climb north of a dozen this quarter alone.

Sources

The reporting this piece was written from. Check the originals before relying on anything here.

  1. PLDT Inc. (PHI) to amend 2025 Form 20-F after material control weakness and pulled audit opinions - Stock Titan PCAOB
  2. SEC charges former execs of auto subprime lender giant Tricolor with fraud, falsifying loan documents - Compliance Week Compliance Week (Google News)
  3. tl;dv Leaked 181,874 Meeting Records: SOC 2 and the Vendor Problem - Machine Brief InfoSec Compliance (Google News)
  4. SEC lays groundwork for crypto issuers to raise flexible capital with new rules proposal - | Governance Intelligence Compliance Week (Google News)
  5. Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs - The HIPAA Journal InfoSec Compliance (Google News)
  6. Nasdaq warns SAGTEC Global (Nasdaq: SAGT) over sub-$1 shares, with delisting risk - Stock Titan Compliance Week (Google News)
  7. Utah governor says he’s ‘deeply troubled’ by Flock cameras, calls for review to protect privacy - Utah News Dispatch Data Privacy (Google News)
  8. EHang (EH) replaces PwC as 2026 auditor, names new audit firm - Stock Titan Compliance Week (Google News)

How stories are selected and assessed