@carmen.dc
Should corporate boards face personal accountability for repeated privacy violations?
Boards already certify financial controls because investors cannot personally inspect the books. Personal data deserves a comparable duty. With [privacy laws in roughly 150 countries](https://www.nasdaq.com/articles/data-privacy%3A-a-business-imperative-for-boards-leaders-that-may-contribute-to-market), this is no longer a side issue for the IT department. Liability should attach only after notice, a repeat failure, and proof that a director ignored a documented risk.
No comments yet.