Data

€7.1 billion in fines, 19 states, one deadline: 2 August

If you have been treating data consent as paperwork — a checkbox, a banner, a job for the legal team once a year — this is the fortnight the bill comes due. Not as a scare story, but as a simple change in the weather that is worth reading correctly.

Three numbers and a date

Start with the date. On 2 August, the EU AI Act reaches full force for higher-risk systems, adding a fresh layer of penalties on top of the ones you already know — reaching as high as €35 million or 7% of global turnover for the worst breaches. That is a bigger stick than GDPR’s.

Now the numbers. Cumulative GDPR fines have passed €7.1 billion. Nineteen US states now have comprehensive privacy laws in effect, with more arriving each January. Read together, they say one thing clearly: the era where “we’ll sort out privacy later” was a survivable plan is over.

Why this is really about your data, not your lawyers

It is tempting to file all of this under “compliance” and send it to someone else. But look at what these rules actually demand, and it is not legalese — it is data hygiene. Can you show what each customer agreed to? Can you prove when they agreed and to what? When someone withdraws consent or asks to be deleted, can you make it happen everywhere, including the new places AI has quietly copied their data to?

Those are not questions about law. They are questions about whether your data is organised. A business with one clean, consented record per customer answers them in an afternoon. A business with the same customer scattered across five systems, three spreadsheets, and now an AI’s memory cannot answer them at all — and that gap is exactly what turns into a fine.

Consent as foundation, not friction

Here is the reframe that makes all of this feel less like a threat. Consent is not the tax you pay for using data — it is the foundation that makes the data safe to use in the first place. Every agent you switch on, every prediction you run, every campaign you send stands on top of it. Get it right and the clever new tools have solid ground to work on. Get it wrong and everything built above it is at risk, no matter how good the technology is.

The practical version is calm and doable. Ask for consent plainly, so people actually understand and say yes. Record it in one place, tied to each customer, so you can always prove it. And make withdrawal real — one action that reaches every system, memory included. That is not a legal project. It is the same “one honest record per customer” work that makes everything else in your data work better too.

The deadlines and the fines sound frightening because they are meant to. But underneath, they are pushing everyone toward exactly the thing good data teams wanted anyway: know what you hold, know you are allowed to hold it, and be able to prove it. Do that, and 2 August is just another Tuesday.

Want help putting this into practice?

We turn Adobe, data and AI strategy into shipped, measurable outcomes.