Fines for data mismanagement could exceed $1 billion
Businesses that are careless with subject rights requests could face severe penalties


Financial penalties issued for mismanaging subject rights are set to rise above $1 billion worldwide in 2026, according to Gartner forecasts.
Researchers say the figure represents a tenfold increase from 2022’s levels.
In this context, subject rights requests (SRRs) are a set of legal rights that enable individuals to demand clarity – and occasionally request changes – regarding the use of their data.
Nader Henein, VP Analyst at Gartner, described the management of SRRs as a basic requirement for security and risk management leaders.
He said: “Data subject rights should not be treated exclusively as a legal requirement.
“To support positive customer sentiment, the organization’s privacy UX should be developed with the same care as any customer-facing service.”
Researchers also noted that data held on staff, regardless of employment status, was worthy of the same care as that given to customers. The report noted: “The highest cost per request is often attributed to employees’ SRRs rather than those coming from customers due to the complexity and the volume of data”.
Get the ITPro daily newsletter
Sign up today and you will receive a free copy of our Future Focus 2025 report - the leading guidance on AI, cybersecurity and other IT challenges as per 700+ senior executives
Automation is key to avoiding substantial fines, and sticking with a manual process for responding to SRRs is likely to increase the risk of an organization facing regulatory fines and possible reputational damage. Henein noted that demands around SRRs would not go away and said that adopting a zero-touch model would allow users to self-serve via a privacy portal.
RELATED RESOURCE
The state of email security 2023
Download this report to get the latest insights from 1,700 CISOs and other IT professionals as they present a realistic picture of the steps they are taking to protect their organizations from increasing threats
DOWNLOAD FOR FREE
The same portal should be transparent about the data being held and ensure users understand how it is used and by whom.
Organizations are faced with multiple potential costs from both regulators and attacks by threat actors.
The former have been adopting a stronger stance in recent years. For example, the EU has rolled out GDPR rules to give citizens more control over their data. Although SSRs are only part of the rules, penalties possible under the wider regulatory framework can be severe.
Meta has incurred more than €1 billion in fines alone from European regulators over a 12 month period over its GDPR violations.
The UK’s Information Commissioner’s Office (ICO) has similarly been increasing the fines it levies, with its current average of £14.7 million per year in fines representing a tenfold increase when compared to fines imposed in the 12 months prior to GDPR rules coming into effect.
The rise of generative AI has also resulted in lawmakers giving consideration to how data is used in training models, as well as a number of lawsuits leveled at AI vendors.
Organizations are also facing increasing costs from attacks. One recent report noted that public companies experience an average net income drop of 73% within the first year of a data breach’s disclosure.

Richard Speed is an expert in databases, DevOps and IT regulations and governance. He was previously a Staff Writer for ITPro, CloudPro and ChannelPro, before going freelance. He first joined Future in 2023 having worked as a reporter for The Register. He has also attended numerous domestic and international events, including Microsoft's Build and Ignite conferences and both US and EU KubeCons.
Prior to joining The Register, he spent a number of years working in IT in the pharmaceutical and financial sectors.
-
Bigger salaries, more burnout: Is the CISO role in crisis?
In-depth CISOs are more stressed than ever before – but why is this and what can be done?
By Kate O'Flaherty Published
-
Cheap cyber crime kits can be bought on the dark web for less than $25
News Research from NordVPN shows phishing kits are now widely available on the dark web and via messaging apps like Telegram, and are often selling for less than $25.
By Emma Woollacott Published
-
FCC orders telcos to sharpen up security after Salt Typhoon chaos
News The move follows a devastating attack on US telecoms infrastructure
By Solomon Klappholz Published
-
US eyes 'Cyber Trust Mark' to lock down IoT frailties, but experts worry it doesn’t go far enough
News The label is intended to build trust in internet-connected devices
By Solomon Klappholz Published
-
Why the UK's "outdated" cybersecurity legislation needs an urgent refresh
News The bipartisan coalition seeks to update the Computer Misuse Act
By Solomon Klappholz Published
-
Top data security trends
Whitepaper Must-have tools for your data security toolkit
By ITPro Published
-
Conquering technology risk in banking
Whitepaper Five ways leaders can transform technology risk into advantage
By ITPro Published
-
Advancing your risk management maturity
Whitepaper A roadmap to effective governance and increase resilience
By ITPro Published
-
Are you ready for NIS2?
WEBINAR Find out what you should be doing to prepare for the EU’s latest data protection regulation and UK equivalent with our free webinar
By ITPro Published
-
When banking works, the world works
Whitepaper Five ways automated processes can drive revenue and growth across your bank
By ITPro Published