Auditen
number of the day

Quarterly Fines are the Only Real KPI

€225 million.

That is the total for GDPR fines in the second quarter of 2026. It’s a staggering figure, not because of the amount itself, but because of what it says about the gap between "compliance" and reality.

I've spent half my career as the one asking the questions and the other half being the one answering them. On both sides, I’ve noticed a recurring obsession with the word "mature." When a CISO or a Compliance Officer tells me their program is mature, my internal alarm goes off. In audit-speak, "mature" usually means we've written enough policies to bore an assessor into submission and we have a folder full of screenshots that were all taken in the same week in March.

The €225 million spent by companies in Q2 suggests that "maturity," as defined by checkboxes, isn't stopping the bleeding.

Here is the problem with the way most firms approach evidence. They treat an audit like a court case where they are the defense attorney, trying to prove they did something right once. I judge every control by a different standard: what would you show the assessor on a Tuesday?

Not a curated evidence pack. Not a slide deck prepared three weeks ago. I mean a random Tuesday in November when the system is lagging and the person who knows how the legacy database works is on vacation. If you can't produce the log or the approval trail in ten minutes, the control doesn't exist. It's just a wish.

We see this disconnect vividly with SOC 2 reports. Look at tl;dv. They had their certification, yet just over 180,000 meeting records leaked because of a vendor failure. A SOC 2 is a snapshot; it’s a photograph of a room that was clean for one hour on one day. It isn't a guarantee that the doors are locked today.

The strongest objection I hear from boards is that they've invested millions into these frameworks to mitigate risk. They argue that following the framework *is* the mitigation.

It isn’t. The framework is the map, not the journey. You can have a perfectly mapped-out route and still drive the car off a cliff because you weren't looking at the road. When Medusa ransomware hits north of 500 critical infrastructure organizations, they aren't hacking "frameworks." They are hacking unpatched servers and poorly managed credentials—the very things that often get glossed over in a "mature" program because the policy says the patching is "handled by the IT team."

The second-order effect here hits the insurers. When GDPR fines hit these levels, underwriters stop trusting certificates. They're starting to realize that a SOC 2 or an ISO cert is just a piece of paper that tells them the company knows how to hire an auditor, not necessarily how to secure data. We'll see premiums spike for firms that can't prove operational effectiveness in real-time.

Then you have the outliers, like the board of Mukumu Girls school paying a fine of roughly Ksh 300,000. It's a drop in the bucket compared to the European totals, but it proves the same point: regulators are looking for the failure of the actual process, not the existence of the policy.

If you want to know if your program is actually mature, stop looking at your certification date. Ask your team to produce evidence for a random sample of three changes made last Thursday. If they start talking about "gathering the documents," you aren't mature; you're just lucky you haven't been audited lately.

I’ll be watching the Q3 fine totals. If that number doesn't drop, it means the industry has finally admitted that its current version of compliance is just an expensive way to document a failure.

Sources

The reporting this piece was written from. Check the originals before relying on anything here.

  1. PLDT Inc. (PHI) to amend 2025 Form 20-F after material control weakness and pulled audit opinions - Stock Titan PCAOB
  2. SEC charges former execs of auto subprime lender giant Tricolor with fraud, falsifying loan documents - Compliance Week Compliance Week (Google News)
  3. tl;dv Leaked 181,874 Meeting Records: SOC 2 and the Vendor Problem - Machine Brief InfoSec Compliance (Google News)
  4. SEC lays groundwork for crypto issuers to raise flexible capital with new rules proposal - | Governance Intelligence Compliance Week (Google News)
  5. Medusa Ransomware Group Has Attacked 500+ Critical Infrastructure Orgs - The HIPAA Journal InfoSec Compliance (Google News)
  6. Nasdaq warns SAGTEC Global (Nasdaq: SAGT) over sub-$1 shares, with delisting risk - Stock Titan Compliance Week (Google News)
  7. Utah governor says he’s ‘deeply troubled’ by Flock cameras, calls for review to protect privacy - Utah News Dispatch Data Privacy (Google News)
  8. EHang (EH) replaces PwC as 2026 auditor, names new audit firm - Stock Titan Compliance Week (Google News)

How stories are selected and assessed