Fined over data compliance: What should you do next?

Know the law

According to Rowlands, after the breach occurs and you learn about the violation and associated fines, the next step is one that involves your legal department. It's important to know not just the violation fines and the data breach that occurred but how it impacts the business in general.

"Make sure you know the law," he says. "It might be tempting to try to keep things quiet – or it might be just as tempting to want to inform everybody, in an attempt to look like the good guys. Before you do either of those things, make sure you know what the regulatory and contractual obligations are.

"It's very likely that there will be regulators to notify. You may need to involve law enforcement. It's probable that you have insurers to inform (you do have that policy in place, don't you...?). When you know all these things, move as fast as possible to notify those who are involved or, if you can't be certain, those who might be involved."

Fix the problems

After analysing the legal ramifications, companies should then move into a remediation phase – fixing the problems. This requires a security evaluation to determine what caused the breach and a thorough process of fixing the data breach problems in accordance with the regulations.

"Chances are you will also be instructed [as part of the compliance violation notice] to take proper measures to avoid a recurrence of the issue," says Redmon. "Demonstrate to the regulator that you're taking it seriously." Redmon adds that the fines can be higher if the same violation occurs again and the company did not take adequate measures to resolve the issue.

Work with the media

Another step to take once you have learned about a compliance fine is to notify the local media. Redmon says this is a matter of prioritisation. "You have to find out what laws have the shortest timeframes for reporting," he says. "Make sure you have an internal Public Relations person or contract with an outside PR firm to help coordinate both internal and external communication. You'll need help with explaining the incident to employees, preparing talking points in case they receive questions from the public, and also a point of contact for media inquiries."

"Remind the world that the best security in the world still may be compromised," he added. "Even a company using reasonable efforts to secure its data and environment is at risk. Communicate opening and plainly, but only after you have secured the facts and have a plan.

"Second, comply with disclosure requirements, demonstrating to regulators and the public that you've taken the matter seriously. Third, conduct a post-mortem review to determine what changes need to be made going forward in order to prevent a recurrence."

Of course, companies should also work with employees and educating them on the compliance violation and why it occurred. Due diligence means making sure everyone at the company understands what happened and how the problem will be resolved.

John Brandon
Contributor

John Brandon has covered gadgets and cars for the past 12 years having published over 12,000 articles and tested nearly 8,000 products. He's nothing if not prolific. Before starting his writing career, he led an Information Design practice at a large consumer electronics retailer in the US. His hobbies include deep sea exploration, complaining about the weather, and engineering a vast multiverse conspiracy.

Latest in Pro
Epson EcoTank ET-4850 next to a TechRadar badge that reads Big Savings
I found the best printer deal you won't see in the Amazon Spring Sale and it's got a massive $150 saving
Microsoft Copiot Studio deep reasoning and agent flows
Microsoft reveals OpenAI-powered Copilot AI agents to bosot your work research and data analysis
Group of people meeting
Inflexible work policies are pushing tech workers to quit
Data leak
Top home hardware firm data leak could see millions of customers affected
Representational image depecting cybersecurity protection
Third-party security issues could be the biggest threat facing your business
An image of network security icons for a network encircling a digital blue earth.
Why multi-CDNs are going to shake up 2025
Latest in News
Nintendo Music teaser art
Nintendo Music expands its library with songs from Kirby and the Forgotten Land and Tetris
An image of Pro-Ject's Flatten it closed and opened
Pro-Ject’s new vinyl flattener will fix any warped LPs you inadvertently buy on Record Store Day
The iPhone 16 Pro on a grey background
iPhone 17 Pro tipped to get 8K video recording – but I want these 3 video features instead
EA Sports F1 25 promotional image featuring drivers Oscar Piastri, Carlos Sainz and Oliver Bearman.
F1 25 has been officially announced, with this year's entry marking a return for Braking Point and a 'significant overhaul' for My Team mode
Garmin clippd integration
Garmin's golf watches just got a big software integration upgrade to help you improve your game
Robert Downey Jr reveals himself as Doctor Doom to a delighted crowd at San Diego Comic-Con 2024
Marvel is currently revealing the full cast for Avengers: Doomsday, and I think it's going to be a long-winded announcement