Auditen
number of the day

The cost of a regulatory tax

Just over $21 billion.

That is the total amount foreign governments have extracted from US technology firms in fines to date. It is a staggering sum, the kind of figure that usually suggests a scorched-earth policy from regulators. However, if you look at the actual filings and the frequency of subsequent breaches, it looks less like enforcement and more like a subscription fee for ignoring the rules.

When a regulator announces a billion-dollar fine, the press release is written to sound like a victory for the public interest. They use words that suggest a fundamental shift in corporate behaviour. But the paperwork tells a different story. Most of these payments are processed as settled liabilities after years of litigation. The firms don't wake up and suddenly decide to respect data privacy; they simply adjust their legal reserves.

The logic is simple: if the profit generated by non-compliance exceeds the eventual settlement cost, the rule isn’t a barrier—it’s a line item in the budget.

We see the result of this calculation every week. While billions are being paid out in the aggregate, the actual security remains porous. Trezor recently leaked the details of 13,689 customers, including names and home addresses. Meanwhile, French taxpayer data has been compromised in a cyber heist. Even the Metropolitan Police managed to leak sensitive information regarding survivors of abuse.

One might argue that these fines eventually force a structural overhaul of how data is handled. That would be the comforting view. But if a structural overhaul were actually happening, we wouldn't see the same patterns of negligence repeated across different sectors. A fine is a lagging indicator; it tells you what went wrong three years ago, not what is being fixed today.

The real victims here aren't just the people whose data is leaked. The second-order effect falls on the auditors and risk managers who have to sign off on these provisions. When a company carries a multi-billion dollar liability for potential regulatory action, it creates a headache for whoever is certifying the balance sheet. They have to guess the appetite of a foreign regulator, which is far less predictable than any GAAP standard.

It turns the auditor into a gambler. They aren't auditing compliance; they are estimating the cost of future failures.

The SEC has tried a different tack this week by ordering capital market operators to freeze the assets of nine individuals linked to terrorism financing. That is an actual enforcement action—a direct, surgical strike on assets rather than a broad fine that gets absorbed into a corporate treasury. It requires specific filings and immediate freezes, leaving very little room for "budgeting" the penalty.

Until data regulators move away from the "big fine" model and toward the "freeze and stop" model, we can expect those figures to keep climbing. We will see more billions paid and more thousands of records leaked.

One wonders at what point a fine becomes so large that it stops being a penalty and starts being an admission that the regulator has given up on actually changing the behaviour. I'll be watching the next round of US tech provisions to see if the numbers start to plateau.

Sources

The reporting this piece was written from. Check the originals before relying on anything here.

  1. SEC Advances Tokenized Stock Exemption Allowing 24/7 Trading - The Defiant Compliance Week (Google News)
  2. Cyber Heist: French Taxpayer Data Breach - Devdiscourse Data Privacy (Google News)
  3. SEC Orders Capital Market Operators to Freeze Assets of 9 Alleged Terrorism Financiers - freedomonline.com.ng Compliance Week (Google News)
  4. Foreign Fines Tracker: Governments Have Extracted $21.7 Billion and Counting From US Tech Firms - Information Technology and Innovation Foundation Data Privacy (Google News)
  5. Plum Acquisition Corp. III (PLMJF) details Marcum LLP resignation and control weakness note - Stock Titan PCAOB
  6. SEC launches FRAU: A new era in accounting enforcement | United States | Global law firm - Norton Rose Fulbright Compliance Week (Google News)
  7. Met Police apologises for data breach involving alleged Al Fayed victims - BBC Data Privacy (Google News)
  8. Trezor Data Breach Exposes 13,689 Customers: Names, Phone Numbers and Home Addresses Leaked - Cryptonews.net InfoSec Compliance (Google News)

How stories are selected and assessed