GDPR Fines

A public record of GDPR enforcement across Europe — compiled by INPLP members

British Airways

Country
United Kingdom
Fine
20,000,000 GBP
Date
2020-10-16
Sector
Transport and leisure
Articles
Art 32 GDPR

Monetary fine for failure to provide adequate security arrangements to protects its customers' personal data as per Art 32 GDPR

In July 2019, the ICO issued a notice of its intention to fine British Airways £183.39 million for a breach of Art. 32 GDPR. The proposed fine related to a cyber incident in 2018, where users searching for the British Airways website were diverted to a fraudulent website. The website harvested personal data of approximately 500,000 customers. The ICO’s investigation found that different types of personal data were compromised due to poor security arrangements at BA. Some of the personal data compromised included log in, payment card, and travel booking details as well names and addresses. The ICO subsequently reduced the final fine to £20 million (approximately €22,046,000) further to represenations from BA, subsequent review of the case and other factors such as the economic impact of the COVID-19 pandemic on the aviation industry.