Fines & orders
Laws can authorize monetary penalties, corrective action, or limits on data processing.
THE BUSINESS OWNER’S FIELD GUIDE
Know which rules may apply, what’s at stake, and where to start. A practical overview of data security and privacy for your business.
Sources checked September 23, 2026 · U.S. focus, with Illinois and EU coverage
This is an educational overview, not legal advice or a complete compliance determination. Requirements, exemptions, and deadlines vary. Use the official sources and qualified legal or compliance advice for your situation. A security scan alone does not establish compliance.
UNDERSTAND THE DIFFERENCE
Dollar amounts below have context. A statutory maximum, a lawsuit’s damages, and a payment-provider fee are different things.
Laws can authorize monetary penalties, corrective action, or limits on data processing.
Some laws allow people to sue. Available damages and legal fees depend on the statute and facts.
Payment agreements and customer or government contracts can carry their own requirements.
SOC 2, ISO 27001, and NIST serve different purposes. They are not universal legal clearance.
EXPLORE 11 COMMON TOPICS
Open a topic for coverage, practical requirements, possible consequences, and official sources. Categories help you browse; they do not determine whether a law applies.
11 topics · Select a heading to read more
Covered health plans, clearinghouses, qualifying healthcare providers, and their business associates. A dental or medical office may be covered; handling any health-related data does not automatically make every business subject to HIPAA.
HIPAA civil penalties depend on the violation and level of culpability; amounts are adjusted for inflation. HHS announced a $1.5 million civil penalty against Warby Parker in February 2025. That is an enforcement example, not a standard fine or a maximum for every case.
Risk analysis, remediation records, policies, training records, agreements, and incident documentation.
Financial institutions under FTC jurisdiction, including many tax preparers, mortgage brokers, and auto dealers that arrange financing. Coverage depends on business activities; other financial regulators have their own requirements.
FTC enforcement can require security improvements and independent oversight. Monetary exposure depends on the legal authority and conduct; there is no single universal “Safeguards Rule fine” for every business.
Security program, risk assessment, vendor reviews, testing results, and leadership reports. Certain breaches involving at least 500 consumers require FTC notice within 30 days of discovery.
Merchants and service providers that store, process, or transmit payment card data, or can affect its security. Small transaction volume does not automatically exempt a merchant.
PCI DSS is an industry standard, not a government fine schedule. Payment brands define noncompliance penalties; your acquiring bank or processor can explain your contractual exposure. PCI SSC does not publish one universal monthly fine for all merchants.
Applicable assessment and attestation, scan results, service-provider compliance evidence, and remediation records. Outsourcing payment processing can reduce scope but does not remove all responsibilities.
Qualifying for-profit businesses doing business in California. Thresholds include over $26.625 million in prior-year gross revenue; annually buying, selling, or sharing data of at least 100,000 California residents or households; or deriving at least 50% of revenue from selling or sharing residents’ personal information. Exemptions need separate review.
Effective January 1, 2025, administrative fines can reach $2,663 per violation, or $7,988 for intentional violations and specified violations involving consumers known to be under 16. These are maximums, not automatic charges. A limited private right of action also exists for certain security breaches.
Data inventory, notices, request logs, vendor agreements, retention rules, and evidence of security controls.
Organizations established in the EU, plus certain organizations outside it that offer goods or services to people in the EU or monitor their behavior there. Merely having a website accessible from Europe is not the whole test.
For specified serious infringements, the ceiling is €20 million or 4% of the preceding year’s worldwide annual turnover, whichever is higher. The lower tier is €10 million or 2%, also whichever is higher. Actual fines are case-specific; authorities can also restrict processing.
Processing records, lawful-basis decisions, contracts, risk assessments, and rights-request and incident logs. UK GDPR is a separate regime.
Data collectors handling covered personal information about Illinois residents. Similar duties may apply under other states’ laws based on where affected people live.
A PIPA violation is an unlawful practice under Illinois consumer-protection law. Exposure depends on the facts and enforcement provisions, rather than one automatic dollar amount for every breach.
Security policies, vendor terms, incident timeline, notification analysis, and copies of required notices.
Private entities collecting or using covered biometric identifiers or information, subject to statutory exclusions. Biometric time clocks and access systems deserve review before deployment.
A prevailing claimant may recover $1,000 for a negligent violation or $5,000 for an intentional or reckless violation, or actual damages if greater, plus fees and other relief. These are civil damages, not automatic government fines. The 2024 amendment limits repeated same-person, same-method collection and specified repeated disclosures to a single recovery; do not multiply by every time-clock scan.
Notices, releases, retention and destruction records, security controls, and vendor agreements.
Defense contractors and subcontractors whose applicable contracts require a CMMC level for systems handling federal contract information (FCI) or controlled unclassified information (CUI). Contract terms and rollout phase matter.
CMMC is not a simple per-record fine schedule. Required CMMC status can be a condition of contract award; missing it can prevent eligibility. Other contractual or legal consequences require a separate review.
System scope, security plans, control evidence, assessment results, and required affirmations. A general vulnerability scan is not a CMMC assessment.
Service organizations whose customers want independent assurance about relevant security, availability, processing integrity, confidentiality, or privacy controls.
SOC 2 itself does not impose government fines. It is an examination and report, not a law or a universal compliance certificate. Gaps may affect customer due diligence or contractual commitments.
Control descriptions, policies, review records, and evidence for the agreed examination scope and period.
Organizations choosing an information security management system, or whose customers require certification within a defined scope.
ISO/IEC 27001 itself does not levy statutory fines. Certification is optional unless required by a contract or other obligation. A certificate applies to its stated scope and does not establish compliance with every privacy law.
Risk assessments, treatment decisions, policies, audit findings, corrective actions, and management reviews.
Organizations of any size looking to organize cybersecurity risk management. The framework may also be referenced in customer or regulatory expectations.
The framework is guidance, not a stand-alone penalty law. Using it can help organize a security program, but does not by itself satisfy every legal, contractual, or industry requirement.
A current and target profile, prioritized action plan, assigned owners, and evidence of progress.
No matching topics. Try a broader word or reset the filters.
A USEFUL START FOR ANY BUSINESS
This starter list helps organize the work. It is not a certification checklist or proof that every applicable requirement is met.
COMMON QUESTIONS
Not automatically. Coverage depends on the particular law, data, activities, thresholds, and exemptions. PCI guidance includes small merchants; the FTC Safeguards Rule has only limited small-institution exemptions. Check the topic’s official sources.
No. A scan can identify certain technical weaknesses. Compliance can also require policies, contracts, privacy notices, training, operational controls, ongoing evidence, and formal assessment. Fixes and follow-up matter.
No. Start with your actual legal and contractual duties, then choose supporting frameworks or assurance work. An independent SOC 2 examination, ISO certification, and a CMMC assessment are different engagements.
No. This guide focuses on common data-security and privacy topics. Other state privacy laws, children’s privacy, education records, sector rules, employment obligations, and international laws can also apply. It does not cover all workplace, tax, environmental, or licensing requirements.
TURN AWARENESS INTO ACTION
DiamondGuards can help identify technical weaknesses and provide findings for your improvement plan. Legal advice, formal certification, and regulator approval are separate from a security scan.