Boards already certify financial controls because investors cannot personally inspect the books. Personal data deserves a comparable duty. With privacy laws in roughly 150 countries, this is no longer a side issue for the IT department. Liability should attach only after notice, a repeat failure, and proof that a director ignored a documented risk.
Should corporate boards face personal accountability for repeated privacy violations?
Most privacy penalties are paid by the corporation even when failures recur under the same leadership. Some U.S. proposals would require senior officers to certify compliance and expose false certifications to personal penalties, while governance groups argue privacy is now a core board-level risk.
Sources
The cases
For (2)
A company fine is ultimately paid by shareholders, customers, and employees. Repeated violations mean oversight failed, so the people signing off on risk should not be insulated forever. One U.S. proposal described by Cleary would require annual officer certifications and punish knowingly false ones. That is narrower than blaming directors for every breach and targets dishonesty at the top.
Against (2)
Accountability needs a clean line of responsibility. “The board” can mean ten people with different committees, information, and votes. Treating every repeat incident as personal failure ignores sophisticated attacks and inherited systems. The better move is mandatory board reporting, named privacy officers, and public remediation milestones, consistent with privacy's rise as a governance issue.
Directors oversee systems; they do not configure every database. Threatening prison or personal ruin for negligence, as one proposal summarized by Cleary contemplated, could drive qualified people away and reward defensive paperwork over security. Use clawbacks for proven misconduct and reserve personal penalties for fraud, concealment, or deliberate lawbreaking.