Cost of Poor Data Quality

The Hidden Cost of Poor Data Quality: How One Error Can Cost Millions

You are having a great year, business is booming, and the future looks bright. Suddenly, you receive a notice from the local data protection board that your organization is in violation of a data protection act (GDPR, California CCPA, etc.). The potential fine could be $100,000 at the minimum!  How did this happen?

Cost of Poor Quality Data

The Dangers of Poor Data Quality

It is essential to recognize that data can pose unforeseen risks to your organization. Accordingly, understanding your obligations in safeguarding information is crucial, as inadequate data protection may result in significant consequences for your business operations.

Protecting the data you have has become imperative since 2016, when the EU enacted the GDPR (General Data Protection Regulation). Since GDPR was enacted, 144 countries have adopted similar regulations, covering approximately 82% of the world's population. In the US, there are currently 20 states that have some form of data protection, including several that have very strict regulations, for example, California, Colorado, Connecticut, and Virginia, among others.

No matter the size of your organization, you are at serious risk if your data is not properly governed.


Examples of Data Protection Fines

The following are examples of fines that have been handed out to businesses under GDPR and California’s Consumer Privacy Act (CCPA).

GDPR Fines – Large Organizations

Some of the larger fines were as follows:

  • Cambridge Analytica Data Breach: While Cambridge Analytica went insolvent over the data breach, Meta (Facebook) was fined €5 billion for its role in the scandal
  • Meta (Facebook): Since 2021, they have been fined over €1.8 billion for various violations
  • Amazon: Was fined €746 million for allegedly non-compliant cookie consent and ad targeting practices.

GDPR Fines – Small to Medium Organizations

In addition to these fines for larger companies, many smaller companies have also received considerable fines under GDPR, including the following:

  • Tax Return Limited: Fined €200,000 for sending millions of unsolicited text messages without consent. bridgepointconsulting.com
  • DM Design Bedrooms Limited: Fined €160,000 for making millions of unsolicited calls to subscribers
  • Lifestyle Marketing, Mother & Baby Limited: Fined €140,000 for reselling personal information without consent
  • Secure Home Systems:: Fined €80,000 for making unsolicited calls to numbers purchased from a third party without proper consent
  • Eldon Insurance Services Limited: Fined €60,000 for sending unsolicited emails without consent.

California’s Consumer Privacy Act (CCPA) Fines

The California Consumer Privacy Act (CCPA), like GDPR, is a comprehensive data regulation law with significant fines.

The following organizations have been fined in accordance with the CCPA.

  • Sephora: $1.2 Million Settlement (2022)
  • American Honda Motor Company: $632,500 Fine (2025)
  • Todd Snyder, Inc (clothing retailer):$345,178 Fine (2025)
  • National Public Data: $46,000 Fine.

Understanding data protection regulations around the world

Although fines and enforcement vary globally, most data regulations share several key provisions.

  1. Data Privacy and Protection
    • Safeguard personal data from unauthorized access, misuse, or breaches.
    • Often includes definitions of personal or sensitive data (for example, name, email, health data).

  2. Data Subject Rights
  3. Individuals typically have rights such as:
    • Access: Right to see what data is held about them.
    • Correction: Right to rectify inaccurate data.
    • Deletion ("Right to be forgotten"): Request the removal of their data.
    • Portability: Request their data in a usable format.

  4. Consent and Lawful Basis for Processing
  5. Data must be collected and processed with explicit consent or under a legitimate legal basis.

  6. Data Minimization
  7. Only collecting and processing the minimum amount of personal data necessary for a specific purpose.

A false sense of security - Core Elements of Data Privacy Governance

Although fines and enforcement vary globally, most data regulations share the following key provisions.

  1. Data Privacy and Protection
  2. Data Subject Rights
  3. Consent and Lawful Basis for Processing
  4. Data Minimization

Here are examples where an organization may think they comply with the key provisions but actually do not, and how to protect yourself from violating these regulations


Data Privacy and Protection

❌ False belief: “Our systems are secure, so we’re compliant.”

✅ Reality:

  • Security does not equal privacy. An organization might have strong technical defenses but still mishandle or misuse personal data (e.g., excessive data sharing).
  • Lack of role-based access controls may allow too many employees to access sensitive data.
  • No formal data classification or data inventory means they may not even know what data needs protecting.

⭐ Best Practices:

  • Encrypt data and enforce access controls.
  • Define what constitutes personal/sensitive data.
  • Maintain data protection policies and train staff accordingly.
  • Run regular audits and security checks.


Data Subject Rights

❌ False belief: “We don’t get many data requests, so we must be compliant.”

✅ Reality:

  • Being compliant isn’t just about responding to requests—it’s about being ready to respond.
  • Many companies lack documented processes or tools to handle subject access, deletion, or portability requests within legal timeframes.
  • Some fail to inform users of their rights at all, which is a compliance issue.

⭐ Best Practices:

  • Provide a self-service portal for data requests.
  • Automate handling of access, correction, deletion, and portability requests.
  • Log and track all request activities.
  • Set clear internal deadlines to meet legal timelines.


Consent and Lawful Basis

❌ False belief:  “Users clicked 'I agree,' so we have consent.”

✅ Reality:

  • Consent must be freely given, specific, informed, and unambiguous—not buried in fine print.
  • Pre-ticked boxes, vague language, or bundled consent (for example, combining consent for multiple purposes) are non-compliant.
  • Some data uses require a legal basis other than consent (for example, legitimate interest), and companies may misclassify this or fail to document it properly.

⭐ Best Practices:

  • Use clear, separate consent options for different uses.
  • Log consent details and updates.
  • Inform users of why and how their data is used.
  • Regularly review legal justifications for data processing.


Data Minimization

❌ False belief:  “More data helps us serve our customers better.”

✅ Reality:

  • Collecting extra data "just in case" violates data minimization.
  • Organizations often keep data long after it's no longer needed, increasing risk and violating retention rules.
  • Forms and surveys often ask for unnecessary information, unintentionally breaching this principle.

⭐ Best Practices:

  • Collect only essential data; remove optional fields where possible.
  • Audit and remove outdated or unused data.
  • Tag data for a purpose to ensure necessity.
  • Apply retention rules to delete data when no longer needed.

Additional Considerations for Maintaining Data Quality

Maintaining clean and high-quality data can reduce organizational costs and may reflect the return on investment of establishing a data governance and data quality program.

Below are several strategies for safeguarding your data and ensuring regulatory compliance.

  • Implementing a data governance program along with duplicate prevention tools like Paribus 365 Search and Detect will ensure high-quality data going forward. See our CRM Data Governance Best Practices articles for more details.
  • Using duplicate data cleaning tools like Paribus 365 Data Cleansing.
  • Performs regularly scheduled compliance checks to ensure readiness in case of an audit by a government regulator.

Read further information on how poor data quality is harming your business here.