Back to Glossary

Entry · Business

Cambridge Analytica

Cambridge Analytica was a political consulting firm that collapsed in 2018 after it emerged that it had obtained personal data on tens of millions of social media users without their informed consent.

In finance and accounting circles the name is now shorthand for a data governance failure: the risk that how a business handles personal information destroys value faster than any operational setback. It is studied as a case in reputational risk, contingent liabilities and weak internal control over data.

From the Money Master HQ dictionary, founded by Shihan Sheriff (FCMA, VP of Finance at Nomod, CFO at Esanjo Ventures). How these definitions are written.

What it means

The firm was a London-based affiliate of a wider group that sold behavioural targeting services to political campaigns and commercial clients. Its sales claim was that it could profile people psychologically and then tailor advertising to those profiles.

A large part of the underlying data had been gathered through a third-party personality quiz app that also pulled information about the quiz taker's friends. When journalists and a former employee exposed the practice in 2018, the consequences were financial as well as political.

The firm and connected entities entered insolvency proceedings within weeks, and the social network whose platform had supplied the data faced regulatory action in several countries, including a $5 billion settlement with the United States Federal Trade Commission. Investors learned that a permission setting inside a product team could move a share price.

For a finance leader, the lesson is that personal data sits in the business in two ways that standard accounts do not show well. It supports revenue, so mishandling it threatens future cash flows, and it creates contingent liabilities in the form of fines, legal costs and remediation spending.

Neither shows up clearly in a set of financial statements until something has already gone wrong. In practice the episode is cited whenever boards review consent records, third-party data sharing and vendor due diligence.

Audit committees now routinely ask who can export customer data, under which contract, and what happens to that data once the contract ends. Those are internal control questions, which is exactly why finance belongs in the discussion.

An important nuance is that the firm's claims about how well its profiling actually worked were widely disputed, and no clear effect on voting behaviour was ever established. The damage came from the breach of trust and the regulatory response, not from proof that the technique worked.

Reputational risk does not wait for evidence of effectiveness before it hits the numbers. A simple frame helps non-specialists.

Treat customer data as cash held on behalf of someone else: you would not let a supplier walk out with the petty cash tin without a signed record, and a customer list deserves the same standard. That single comparison changes how a data-sharing request is reviewed.

In practice

Real-world examples.

1

Example

A software company's finance director reviews a partnership agreement that would send customer contact records to a marketing analytics vendor. She asks for the legal basis, the retention period and a deletion certificate at contract end. The clause is rewritten before signature, which later saves a costly unwinding exercise.

2

Example

A retailer's audit committee asks internal audit to list every third party that receives loyalty scheme data. The exercise finds eleven recipients, three of which have expired contracts. The retailer terminates those feeds and records the exposure in its risk register.

3

Example

A marketing agency pitching for a bank's work is asked to show written consent records for the audience lists it proposes to use. It cannot produce them for two of the five lists. The bank awards the contract to a competitor whose records are complete.

Case study

Seen in the real world.

Northwind Signal is an illustrative analytics start-up invented for this example, not a real company. It grew quickly by buying audience data from app developers and reselling enriched segments to advertisers, and its valuation rested almost entirely on the size of its data library. Its finance team recorded the purchased data as an intangible asset and carried it at cost.

A prospective acquirer's due diligence asked a single question the founders had never answered in writing: for each data source, what did the original user actually agree to? Roughly 40% of the library had no traceable consent record. The acquirer cut its offer and then withdrew, and Northwind Signal had to write the affected intangible asset down to zero in this fictional scenario.

The practical lesson in the illustration is unglamorous. A register naming every data source, its consent basis, its retention period and an internal owner would have cost very little to maintain, and its absence was what destroyed the valuation rather than any technical failure.

Watch out

Common mistakes.

  • Treating the episode as a political story with no finance content, when the measurable damage was lost enterprise value, regulatory fines and remediation spending.
  • Assuming the data was stolen by outside attackers, when it was collected through an app whose permissions were far wider than users understood.
  • Believing a signed vendor contract is enough protection, when without monitoring a contract only records what should have happened rather than what did.

Questions

People also ask.

Does Cambridge Analytica still operate?

No, the firm and connected entities entered insolvency proceedings in 2018 and the business was wound down.

Why should an accountant care about a data scandal?

Because data mishandling creates contingent liabilities, impairs intangible assets and can affect going concern judgements, all of which are accounting matters.

What single control reduces this risk most?

A maintained register of every third party that receives personal data, showing the legal basis, the retention period and a named internal owner for each one.

Was this explanation helpful?

From the founder's library

Accounting Fundamentals: A Non-Finance Manager's Guide to Finance and Accounting, by Shihan Sheriff

Take it further with the book.

Build your financial confidence beyond this definition. Shihan's full-length guide, Accounting Fundamentals, takes the same plain-English approach and turns it into a complete, practical playbook for non-finance managers, business owners and students - with chapter-end quiz answers and presentation slides included.

US$2.24US$2.99

25% off with code MMHQ25, applied at checkout. Priced in USD - checkout may show the equivalent in your local currency.

View the book and save 25%
Last updated · October 8, 2026
Browse all terms →

Disclaimer

The information provided in this finance dictionary is for educational and informational purposes only. It should not be construed as financial, investment, legal, or tax advice. Always consult with a qualified professional before making any financial decisions. Money Master HQ makes no representations or warranties about the accuracy, completeness, or suitability of this information. Use of this content is at your own risk.