Auditen
sector watch

Your P&L is Not a Buffer for Bad Privacy

Coupang just handed us a masterclass in why "compliance" and "controls" aren't the same thing. When a privacy fine triggers an operating loss of north of $580 million, you aren't looking at a regulatory hiccup. You're looking at a material failure of internal control that hit the balance sheet with the force of a freight train.

For years, I’ve watched firms treat privacy as a legal function. The lawyers write a policy, the DPO signs off on a spreadsheet, and everyone decides they’re safe. It's classic control theatre. They confuse the existence of a policy with the operation of a control. In my early SOX days, back around 2004, I saw this constantly with access management; firms thought having an "Acceptable Use Policy" signed by employees was a control. It wasn't. It was a piece of paper. The actual control was whether someone had actually revoked the permissions of the guy who quit three months ago.

The Coupang disaster proves that privacy has finally migrated from the legal department to the risk committee. If a single fine can wipe out your profitability for a quarter, that isn't a "privacy issue." It's a financial reporting risk.

We see this concentrating now in high-volume data sectors: e-commerce and telecoms. The pressure is mounting. Look at the telecom sector, where potential privacy breach fines are now floating around 10 percent of total revenue. Do the math on that for a Tier 1 carrier. That isn't a cost of doing business; it's an existential threat to dividends.

The common defense from the C-suite is usually some variation of: "Our frameworks are aligned with global standards." I can't stand that phrasing. Alignment isn't a control. A framework is just a map; it doesn't tell you if your actual data deletion process actually deletes the data or if it just moves it to a different folder that another admin can still access.

The real question I ask during an audit is simple: What does this cost you at year-end?

If your privacy "controls" are just a series of vendor questionnaires and signed PDFs, the cost is exactly what Coupang paid. You've built a facade. When the regulator stops asking for the policy and starts asking for the evidence of execution (the actual logs showing the data was purged or the specific logic used to handle consent), the theatre ends.

Now, consider the second-order effects. The shockwaves from these massive fines don't stay within one company. They hit the insurers first. Cyber insurance providers are tired of paying out for "unforeseen" breaches that were actually caused by a total lack of basic data hygiene. Expect premiums to spike specifically for firms that can't prove their controls are designed to prevent the *type* of failure that cost Coupang half a billion dollars.

Then there are the auditors. If a firm’s external auditors signed off on an "effective" control environment while the company was ignoring basic privacy mandates, those audit firms are now in the crosshairs. We're moving toward a world where the auditor might be held liable for not flagging a privacy gap as a material weakness in financial controls.

Some will argue that these fines are outliers, that most companies won't see a half-billion dollar hit. That’s a dangerous gamble. You don't design your brakes based on the assumption that you'll never hit a wall; you design them so that when you do, you survive.

If your privacy strategy is based on "not getting caught" or "hoping for a settlement," you aren't managing risk. You're just waiting for the bill.

Watch the California Delete Act enforcement closely over the next few months. It’s a litmus test for automation. If a data broker has to process thousands of deletion requests manually, they will fail. They'll miss one, or two, or a hundred. That failure isn't a technical glitch; it's a design flaw.

I'll change my mind when I see a company treat a privacy gap with the same urgency as a hole in their revenue recognition process. Until then, keep your spreadsheets. The regulators aren't reading them.