MCD · 10-Q · 2026Q2 · Full report
Privacy and Data Regulation
MCDONALDS CORP · 2026-08-07 · Importance 40 · Surprise 42
McDonald’s is subject to the European Union’s General Data Protection Regulation and various U.S. state-level privacy and data-protection laws. The company is expanding digital engagement, data collection and personalization through AI, increasing exposure to the EU AI Act and other U.S. state-level requirements. Non-compliance or misuse of personal data could result in substantial administrative fines, criminal or civil penalties, litigation and reputational harm, although no dollar amount or specific investigation is disclosed.
Key facts
- We maintain insurance coverage designed to address certain aspects of cybersecurity risks, but such coverage may be insufficient to cover all losses or all types of claims. source
- Failure to comply with privacy and data protection laws (including the EU GDPR and various U.S. state-level laws) could result in substantial administrative fines, criminal or civil penalties or civil liabilities. source