Trust has always been the defining feature of financial services. Unlike in many industries, financial institutions do not merely sell products; they hold assets, process transactions, and manage highly sensitive personal and financial information. In the digital era, trust increasingly depends on how institutions collect, use, retain, and protect their customers’ data. The consequences of a data breach are more profound than ever before.
IBM’s 2024 Cost of a Data Breach report reveals that the global average cost of a data breach has risen to $4.88 million.[1] In the financial sector, this average cost has reached $6.08 million, approximately 22% higher than the cross-industry average.[2]
Despite improvements in detection capabilities, organizations still require an average of 168 days to identify a breach.[3] This delay results in months of potential undetected exposure.[4] These figures underscore that robust data governance serves as the backbone of institutional stability and carries both financial and operational repercussions.
It is important, however, to differentiate between data security and data privacy. Data security involves technical and organizational safeguards designed to prevent unauthorized access to, or use of, information.[5] By contrast, data privacy governs the lawful collection, use, disclosure, and retention of personal data, as well as individuals’ rights over that data, including notice, access, and deletion when required.[6] A firm may invest heavily in encryption and monitoring tools and still fail to meet privacy obligations if it collects excessive information, retains it indefinitely, or ignores statutory deletion or access requests.[7] In financial services, compliance requires attention to both dimensions: security to protect data from compromise, and privacy to ensure its lawful and transparent handling.[8]
The regulatory landscape reflects this duality. In the United States, financial institutions operate under sector-specific statutes that combine privacy and security mandates.[9] The Gramm-Leach-Bliley Act of 1999 requires financial institutions to protect the privacy and confidentiality of consumers’ nonpublic personal information and to disclose their information-sharing practices to customers.[10] Covered entities must provide clear privacy notices and implement safeguards that protect customer information from unauthorized access or misuse.[11]
Institutions must also comply with a growing array of state privacy and breach notification laws.[12] This includes comprehensive statutes, such as the California Consumer Privacy Act, as well as similar frameworks in other states, and mandatory breach notification laws in all 50 states, which require notice to affected individuals after unauthorized disclosure of personal data.[13] At the federal and regulatory level, agencies such as the U.S. Securities and Exchange Commission (SEC), Financial Industry Regulatory Authority (FINRA), and the New York State Department of Financial Services (NYDFS) have adopted rules that require enhanced cybersecurity governance, incident reporting, and risk management practices for regulated entities.[14]
Internationally, financial institutions confront even broader obligations. The European Union’s General Data Protection Regulation (GDPR) sets stringent requirements for lawful processing of personal data.[15] It outlines principles such as data minimization, purpose limitation, transparency, and data subject rights, including access and erasure.[16] Recent developments at the EU level, including the EU Artificial Intelligence Act, further overlay requirements for risk-based governance of automated systems that handle personal data.[17]
Brazil’s Lei Geral de Proteção de Dados (LGPD), Singapore’s Personal Data Protection Act (PDPA), and China’s Personal Information Protection Law illustrate that data governance has become a global norm rather than a regional exception.[18] For multinational financial institutions, privacy compliance is essential and requires continuous jurisdictional analysis and management of cross-border risks.[19]
As privacy regulations expand, data architecture grows more complex. Institutions must grapple not only with substantive privacy rights but also with questions of data sovereignty and residency.[20] Data sovereignty means that data is subject to the laws of the jurisdiction in which it is collected or processed.[21] In contrast, data residency concerns the physical location where data is stored.[22] These distinctions have material operational consequences for cloud deployments, cross-border transfers, vendor arrangements, and contractual protections.[23]
Simultaneously, cybersecurity risk remains a persistent and costly threat. Malicious attacks continue to account for the majority of breaches in the financial sector, though human error and system failures also contribute significantly.[24] The financial consequences of a data breach extend well beyond forensic investigation and system repair. Regulatory fines, civil litigation, customer loss, and reputational damage frequently exceed the initial technical costs.[25] Breach cost analyses show that many reported breaches involve customer personal data, and the per-record cost of compromised information continues to increase.[26] Such consequences are critical for financial institutions, as their credibility depends on protecting client information and maintaining sustained public trust.[27]
Institutions with established incident response teams, strong identity and access controls, and automated monitoring tools tend to report lower breach costs.[28] These controls improve detection speed and containment efficiency.[29] However, emerging technologies, including artificial intelligence, require defined oversight frameworks.[30] Organizations must implement clear internal policies governing data sources, model training, access permissions, and review procedures to effectively manage this risk.[31]
The central issue for financial institutions is organizational design. Privacy strategy should align closely with enterprise risk management and data governance functions.[32] High-volume compliance tasks, including data subject request processing and retention enforcement, require standardized procedures.[33] Institutions must also determine which privacy functions remain core internal competencies and which can be supported through external expertise.[34] These decisions affect cost allocation, oversight capacity, and long-term institutional knowledge.
In conclusion, data breaches are a recurring feature of the digital economy. Institutional resilience depends on adequate preparation, governance discipline, and effective response capability. In financial services, privacy management reinforces institutional credibility. Embedding a privacy program within corporate strategy strengthens client trust and enhances regulatory stability.
[1] IBM Sec., Cost of a Data Breach Report 2024: Financial Industry, https://www.ibm.com/think/insights/cost-of-a-data-breach-2024-financial-industry (last visited Feb. 11, 2026).
[2] Id.
[3] Id.
[4] See id.
[5] See AccountableHQ, Understanding the Difference Between Data Privacy and Data Security (Aug. 23, 2025), https://www.accountablehq.com/post/understanding-the-difference-between-data-privacy-and-data-security.
[6] See Alation, Data Privacy vs Data Security: Definition & Comparison (Oct. 14, 2024), https://www.alation.com/blog/data-privacy-vs-data-security/.
[7] See Cal. Civ. Code § 1798.105(a) (right to delete personal information); see also Kelley Drye, State Privacy Law Requirements (Nov. 22, 2024), https://www.kelleydrye.com/viewpoints/blogs/ad-law-access/state-privacy-law-requirements-instructing-vendors-and-partners-to-fulfill-deletion-and-opt-out-privacy-rights-requests.
[8] See AccountableHQ, supra note 5; Alation, supra note 6.
[9] See Michael R. Cohen, A Legal Guide to Privacy and Data Security 3 (Minn. Dep’t of Emp. & Econ. Dev. & Lathrop GPM, 2025).
[10] See Gramm-Leach-Bliley Act, Pub. L. No. 106-102, 113 Stat. 1338 (1999); Federal Trade Commission, Gramm-Leach-Bliley Act, https://www.ftc.gov/business-guidance/privacy-security/gramm-leach-bliley-act (last visited Feb. 11th, 2026).
[11] See id.
[12] See Cohen, supra note 9, at 78, 132.
[13] See id. at 78–79, 132–33.
[14] See Squire Patton Boggs, Overview of U.S. Privacy Law, Privacy World Blog, https://www.privacyworld.blog/summary-of-data-privacy-protection-laws-in-the-united-states/ (last visited Feb. 17, 2026).
[15] See European Parliament and Council Regulation 2016/679 (General Data Protection Regulation), 2016 O.J. (L 119) 1 (EU), https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX%3A32016R0679 (last visited Feb. 12, 2026).
[16] See id.
[17] See European Parliament and Council Regulation 2024/1689 (Artificial Intelligence Act), 2024 O.J. (L 1689) 1 (EU), https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng (last visited Feb. 12, 2026).
[18] See Brazilian General Data Protection Law (LGPD), Law No. 13,709/2018 (Braz.), https://www.dlapiperdataprotection.com/index.html?c=BR&t=law (last visited Feb. 13, 2026); Global Cybersecurity & Privacy Regulations, https://www.breachrx.com/global-regulations-data-privacy-laws/ (last visited Feb. 13, 2026).
[19] See Cohen, supra note 9, at 140, 146; see also General Data Protection Regulation, supra note 15, arts. 44–49.
[20] See Matthew Kosinski, Data Sovereignty vs. Data Residency, IBM Think, https://www.ibm.com/think/topics/data-sovereignty-vs-data-residency (last visited Feb. 12, 2026).
[21] Id.
[22] See id.
[23] See id.
[24] See Jesse R. Taylor & Marina G. Aronchik, Study Finds Average Cost of Data Breaches Increased Globally in 2024, Tech & Sourcing @ Morgan Lewis (May 14, 2025), https://www.morganlewis.com/blogs/sourcingatmorganlewis/2025/05/study-finds-average-cost-of-data-breaches-significantly-increased-globally-in-2024.
[25] See IBM, Cost of a Data Breach Report 2024, https://wp.table.media/wp-content/uploads/2024/07/30132828/Cost-of-a-Data-Breach-Report-2024.pdf (last visited Feb. 15, 2026).
[26] See id.
[27] See Cohen, supra note 9, at 181; see also IBM, supra note 25.
[28] See IBM, supra note 25.
[29] See id.
[30] See EU AI Act, supra note 17, arts. 6–9; see also Cohen, supra note 9, at 180.
[31] See EU AI Act, supra note 17, arts. 9, 14; see also Cohen, supra note 9, at 180; Nat’l Inst. of Standards & Tech., Artificial Intelligence Risk Management Framework (AI RMF 1.0) 2–5, 20–25 (Jan. 2023), https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf.
[32] See Cohen, supra note 9, at 165.
[33] See General Data Protection Regulation, supra note 15.
[34] See Cohen, supra note 9, at 169–70, 177–78.
