The true impact of GDPR fines
The impact that a significant GDPR fine can have on a firm’s bottom line can be devastating, even for some of the world’s biggest companies. In the case of a firm that commits the most egregious violations, as listed above, the effect of a fine totaling up to four percent of annual revenue can cause the company’s profit numbers to go from black to red in an instant.
Gavin Millard, EMEA technical director of the data security firm Tenable, told InfoSecurity Magazine that the firms with the highest revenues face the possibility of the highest fines, as “the larger the revenue, the larger the risk, and the larger the fines”.
(Gavin Millard of Tenable on GDPR fines)
As an example of what these firms could face, an article in Digital Guardian examined what the impact would have been if GDPR had been in effect during the 2015 data breach of Hilton Hotels. In November 2017, the New York Attorney General’s Office fined Hilton $700,000 for a breach involving data from 350,000 customers, an average of $2 per record. Under GDPR, the fine could have been as high as $420 million.