Companies already spend heavily on GRC, Big Legal, and Big 4 assessments — yet still have no defense when things go wrong. Executives still can't answer three questions: What are we legally accountable for? Where are we exposed? What actions are required?
Executives are liable under laws that are never translated into their specific responsibilities. No existing Risk Management, GRC, or Privacy tool maps legal obligations to individual roles, or operationalizes the legal tests used by courts that bring the massive fines post-event.
Leadership cannot see where governance obligations are unmet until after a breach or investigation. By then, the damage is done.
Existing tools track compliance controls and tasks, but do not tell executives what actions they must take to satisfy duty-of-care requirements.
When scrutiny comes, companies cannot produce either record the law expects — proof the decision was reasonable, or proof the obligation was actually met. GRC logs activity; it cannot show judgment or verify implementation.
$21B+
in cyber, privacy & AI enforcement — addressed by Defensible Governance
$1.2B+
in fines tied to harm to minors — addressed by Minors Safety & Child Welfare
Compliance activity alone no longer answers the question regulators are asking. Enforcement now turns on governance judgment, not audit activity.
GDPR, EU AI Act, SEC Cyber Rules, NIS2, DORA, and 20+ state privacy laws now all require evidence of proportionate, reasonable decision-making — and proof the required measures were actually implemented, not just controls.
Uber CSO criminally convicted. SolarWinds CISO personally named. Drizly CEO personally bound for 10 years. D&O insurance increasingly excludes coverage for "gross negligence." The protection leaders assume they have is narrower than it used to be.
Marriott's fine was substantially reduced on appeal. Citi was fined $536M across two related enforcement actions. Documentation of judgment, not just the underlying incident, shaped both outcomes.
The standard has shifted.
From: "Did you comply?" → To: "Can you prove your leadership took reasonable care — and that the obligation was actually met?"
| Company | $ Amount | Primary Transgression | Governance Failure Characterization |
|---|---|---|---|
| Google (Texas AG) | $1.375B | Location tracking, biometric data collection, and Incognito-mode tracking | Unreasonable practices; failure to safeguard users from foreseeable privacy harm; deceptive governance |
| Meta Platforms | $3.5B–$4.1B+ | Illegal cross-border transfers; biometric collection; children's data misuse; transparency failures | Systemic governance failure; inadequate safeguards; unreasonable reliance on invalid transfer mechanisms |
| Amazon | $877M | GDPR violations in ad-tech and data processing | Failure to implement appropriate technical & organizational measures (Art. 25, 32 GDPR) = Requires defining and applying risk-based thresholds to demonstrate the standard of reasonable and appropriate care |
| Equifax | $575M–$700M | Failure to patch known vulnerability; massive consumer data breach | Negligence; failure to meet reasonable security standards; foreseeable harm ignored |
| Epic Games | $520M | COPPA violations; dark patterns tied to data use | Failure to protect children; unreasonable data and product governance |
| T-Mobile | $500M | Repeated breaches; inadequate access controls | Failure of reasonable security; governance breakdown despite prior warnings |
| Google (Incognito class action) | $0 cash to class plaintiffs valued noncash relief (data deletion, disclosure changes) at $5B–$7.8B; $217.6M in fees requested, Google argued for ≤$40M | Continued tracking users in Incognito/private-browsing mode | Court certified an injunctive-relief class only, no damages class; deceptive disclosure of tracking practices |
| Google (Web & App Activity jury verdict) | $425.7M | Continued data collection after users disabled Web & App Activity setting | Jury found unreasonable disregard of user-disabled privacy controls |
| Meta (Texas) | $1.4B (incl. above) | Facial recognition without consent | Per-se statutory negligence; failure to govern biometric risk |
| TikTok (EU) | $370M | Children's data mishandling | Failure to implement heightened safeguards for vulnerable populations |
| Citi (aggregate) | $536M | Data breach controls; internal risk governance failures | Failure to secure financial data; inadequate internal controls = governance failure |
| Uber (EU) | $324M | Unlawful international data transfers | Unreasonable safeguards; failure to assess transfer risk post-Schrems II |
| Home Depot | $200M+ | Payment card breach | Failure to segment networks and monitor foreseeable attack vectors |
| Capital One | $190M+ | Cloud misconfiguration; access control failure | Failure of reasonable cloud governance and risk assessment |
| Twitter / X | $150M | Misuse of security data for advertising | Deceptive governance; misuse of data entrusted for security purposes |
| Anthem | $115M | Healthcare data breach | Failure to safeguard sensitive health data; foreseeable harm |
| Oracle | $115M | Improper data collection and sale | Inadequate data governance; unreasonable secondary use of personal data |
| Zoom | $85M | Security failures ('Zoombombing') | Failure to design for reasonable security under foreseeable misuse |
| OPM | $63M | Federal employee data breach | Failure to meet baseline government security standards |
| Plaid | $58M | Excessive data collection beyond consumer consent | Unreasonable data minimization and access governance |
| Blackbaud | $49.5M | Ransomware + misrepresentation of risk | Failure to implement reasonable ransomware defenses; governance misstatements |
| Morgan Stanley | $35M | Unencrypted data disposal | Failure of basic data lifecycle governance |
$21B+ in enforcement penaltiesIn every case, governance failure was the common factor — the exposure Defensible Governance is built to address.