Auditen
framework watch

The Cost of Doing Business in Q2

The regulators have stopped asking nicely.

For years, GDPR compliance has been treated as a paperwork exercise: appoint a Data Protection Officer, draft a privacy policy that no one reads, and keep a register of processing activities. If you had the folders in the right place, you were generally safe from the heaviest hammers. That era ended around the second quarter of this year.

The numbers are quite plain. GDPR fines hit just over €220 million in Q2 2026 alone. This isn't a slow creep; it's a sprint toward actual enforcement. While the press releases from national authorities usually talk about "protecting the fundamental rights of citizens", the ledger tells a different story. The regulators have found their appetite for revenue.

The implication here is that having a policy is no longer a shield against a fine. We’ve moved from a period of "formal compliance" to one of "demonstrable effectiveness". If your internal records say you encrypt data at rest, but a breach reveals the files were sitting in plain text on an unsecured bucket, the regulator won't care that you have a signed policy document dated January 2024. They will fine you for the gap between the paperwork and the practice.

Some would argue that these figures are skewed by a few massive penalties against Big Tech. It’s easy to dismiss €200 million when it’s carved out of a trillion-dollar balance sheet.

That argument ignores the smaller, quieter kills. Take the Data Protection Office's order for the board of Mukumu Girls school to pay roughly 300,000 Kenyan shillings over a privacy breach. It is a modest sum in absolute terms, but it's a significant signal. When a secondary school finds itself on the wrong side of a data protection ruling, it means the regulator is no longer just hunting whales. They're fishing in every pond.

The paperwork requirement remains the same—Article 33 still demands notification within 72 hours—but the scrutiny applied to those notifications has sharpened. A late filing is now almost an invitation for a full audit of your entire data estate.

This creates a nasty second-order effect for cyber insurers. Underwriters are not in the habit of paying out when "gross negligence" or "wilful failure to adhere to stated policies" is on the table. If a firm claims it's GDPR compliant to lower its premium, but the regulator finds it was merely pretending through a series of checklists, the insurer may well walk away from the claim.

The firms most exposed aren't actually the ones with no policies; they're the ones with perfect policies and lazy implementations. They've built a paper fortress that looks imposing until the first gust of wind hits it.

One wonders how many DPOs are currently staring at their registers, wondering which "administrative" error is about to cost their board several million euros. I suspect quite a few.

Sources

The reporting this piece was written from. Check the originals before relying on anything here.

  1. PLDT Inc. (PHI) to amend 2025 Form 20-F after material control weakness and pulled audit opinions - Stock Titan PCAOB
  2. SEC charges former execs of auto subprime lender giant Tricolor with fraud, falsifying loan documents - Compliance Week Compliance Week (Google News)
  3. tl;dv Leaked 181,874 Meeting Records: SOC 2 and the Vendor Problem - Machine Brief InfoSec Compliance (Google News)
  4. SEC lays groundwork for crypto issuers to raise flexible capital with new rules proposal - | Governance Intelligence Compliance Week (Google News)
  5. Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs - The HIPAA Journal InfoSec Compliance (Google News)
  6. Nasdaq warns SAGTEC Global (Nasdaq: SAGT) over sub-$1 shares, with delisting risk - Stock Titan Compliance Week (Google News)
  7. Utah governor says he’s ‘deeply troubled’ by Flock cameras, calls for review to protect privacy - Utah News Dispatch Data Privacy (Google News)
  8. EHang (EH) replaces PwC as 2026 auditor, names new audit firm - Stock Titan Compliance Week (Google News)

How stories are selected and assessed