At 7.42 on a Tuesday morning, Sarah Williams stood inside a branch of her bank holding a brown envelope and trying not to cry. The letter inside said her mortgage application had been declined. She had saved for six years, worked two jobs after her divorce and promised her daughter that the red-brick house near the school would be theirs.
The branch adviser looked at the screen, frowned and called a colleague. A score had been generated somewhere in the bank’s machinery, but nobody could explain it. Sarah was told that the decision was “system-driven” and advised to submit a complaint, one of those phrases that sounds efficient until it lands on a human being whose future has just been suspended by software.
By midday, the complaint had reached the Data Protection Officer. The questions were immediately recognisable: was the decision automated, was the underlying information accurate, had Sarah been properly informed, and could someone with judgement review the outcome? Yet another question sat quietly behind them all, one rarely taught on privacy courses: how much would this failure cost the bank?
For a DPO, the most revealing financial ratio is the cost-to-income ratio. It shows how much an organisation spends to generate its income. If a bank spends £62 to earn £100, its cost-to-income ratio is 62 percent, a simple calculation that reveals whether the institution is operating with discipline or carrying expensive dysfunction beneath polished annual reports.
Sarah’s complaint soon gathered a small army. Customer Operations searched for call recordings, Technology traced the source of the score, Legal reviewed the wording of the notice, Compliance examined the lending process, and an external consultant was asked to reconstruct the decision trail. What had begun as one unexplained rejection became weeks of paid human effort because the bank could neither find its information quickly nor explain what its system had done.
That is where privacy failures enter the financial statements, although they rarely arrive labelled “privacy”. They appear as consultancy fees, duplicated systems, excessive cloud storage, prolonged investigations, compensation payments and employees spending expensive hours searching chaotic shared drives. They also appear as abandoned applications and departing customers, costs that are harder to isolate but no less real.
This does not turn privacy into a cost-cutting department or make people’s rights conditional upon profit. It means recognising that dignity and efficiency often depend on the same foundations: accurate information, clear ownership, sensible retention, explainable decisions and controls designed before harm occurs. Good privacy governance protects the customer while removing the organisational confusion that consumes money.
The DPO can therefore influence financial performance without surrendering independence. A credible data inventory shortens investigations; a working retention schedule reduces storage and litigation exposure; well-designed rights processes reduce manual handling; and firm supplier contracts prevent processors from passing the cost of their failures back to the organisation. These are privacy controls, but they are also instruments of operational discipline.
When the case was finally reviewed, the bank discovered that Sarah’s employment information had been matched against an outdated record. Her application was reconsidered and approved, but the victory felt smaller than it should have. She received the keys months later, after losing the first house and explaining repeatedly to her daughter why their promised move had disappeared.
Boards often ask DPOs how many assessments, training sessions and policies they completed. Those figures record movement, not value. The sharper conversation is about investigation time reduced, external fees avoided, storage removed, complaints resolved faster, products launched without expensive redesign and customers spared the indignity of fighting a machine nobody can explain.
Sarah will never appear as a line in the bank’s cost-to-income ratio. She will appear, if at all, as a complaint reference and a corrected lending decision. Yet she is precisely why the ratio matters: behind every avoidable cost is often a person paying a price before the organisation does.
- business a.m. commits to publishing a diversity of views, opinions and comments. It, therefore, welcomes your reaction to this and any of our articles via email: comment@businessamlive.com
Michael Irene, CIPM, CIPP(E) certification, is a data and information governance practitioner based in London, United Kingdom. He is also a Fellow of Higher Education Academy, UK, and can be reached via moshoke@yahoo.com; twitter: @moshoke






