Auditen
contrarian

The high price of ignoring 'no'

Ten years of worrying about our perimeter, and every board meeting starts with that same dread. Someone brings up a catastrophic breach or some ransomware group leaking millions of records through a porous API, and that's why we throw money at encryption and SOCs. We think privacy is just a security problem.

It isn't.

Check the numbers from this week, and hôpital Privé de la Loire let over 727,000 patient records leak. The CNIL fined them €500,000, and it was a major failure of technical and organizational systems. Still, the penalty seems small for that much sensitive health data.

Then there is BBVA's Italian subsidiary. There was no breach here. No hackers broke in. They just ignored marketing opt out requests, and for this clerical slip, they paid €5.5 million.

The lesson is blunt: regulators are far more offended by a company that ignores a user's explicit "no" than one that fails to stop a sophisticated intruder.

A breach looks like you're incompetent, and ignoring an opt-out is different because it shows a lack of respect. When you ignore a request to stop marketing, you aren't failing at security, and you're violating Article 21 of the GDPR and the right to object. You're basically telling the regulator that selling your products matters more than an individual's legal autonomy.

Lots of firms talk about privacy by design. Most just bought a consent management platform and plugged it into a CRM that doesn't actually sync with the mailing list in real time. They built a facade.

People argue security is more important because breaches cause real harm like medical fraud or identity theft. But regulators see systemic disregard for rights as a choice. It's easier to forgive a missed patch than a policy of ignoring the unsubscribe button.

This puts CRM architects and procurement teams in a bad spot; they focus on big bang events and ignore the plumbing. If your marketing automation tool can't guarantee an absolute stop across all channels in the legal timeframe, your DPO is just performing theatre. The liability stays with you even if the vendor promised it was compliant.

The risk now falls on auditors who signed off on processes without testing one single opt-out request from end to end. They checked a policy document instead of the database; why do they do that?

We can keep buying expensive firewalls, and we can chase the ghost of another huge leak, like the 200 million records just hit via an API in Vietnam. But firms will keep paying millions for the privilege of being annoying until they treat rights requests as hard legal constraints instead of nuisances.

The real risk isn't the hacker who gets in. It's the customer you refuse to let out.

Sources

The reporting this piece was written from. Check the originals before relying on anything here.

  1. Health data breach: the CNIL fined Hôpital Privé de la Loire 500 000 EUR European Data Protection Board
  2. BBVA’s Italian arm faces €5.5m GDPR fine over failed marketing opt-out - MLex Data Privacy (Google News)
  3. Nasdaq puts Premium Catering (Nasdaq: PC) on notice over a missed financial report - Stock Titan Compliance Week (Google News)
  4. Vietnam APIS Breach: No Owner Claims 220M Records [2026] - tech-insider.org Data Privacy (Google News)
  5. Two Ransomware Groups Claim Attacks on Nationwide Home Healthcare Provider - The HIPAA Journal InfoSec Compliance (Google News)
  6. Failure to respect the rights of individuals: EUR 300,000 fine against EXTIA - CNIL Data Privacy (Google News)
  7. SEC and CFTC Extended Form PF 2024 Amendments Compliance to July 1, 2027: - HedgeCo.Net Compliance Week (Google News)
  8. Privacy Act reforms: what the second tranche means for businesses - hcamag.com Data Privacy (Google News)

How stories are selected and assessed