GDPR Fines

A public record of GDPR enforcement across Europe — compiled by INPLP members

Ticketmaster UK Limited

Country
United Kingdom
Fine
1,250,000 GBP
Date
2020-11-13
Sector
Retail and manufacturer
Articles
Art 5(1)(f), 32 GDPR

Monetary fine for failure to provide adequate physical security arrangements to protects its customers' personal data as per Art 32 GDPR. The company also failed to prevent fraudulent activities on its customers' bank cards as per Art 5(1)(f).

Ticketmaster UK Limited was fined £1.25 million (approximately €1.405 million) for failing to protect the personal data of its customers with adequate security measure, as required by Art.32 GDPR. Potentially 9.4 million European customers were affected by a cyber attack that occured between February 2018 and June 2018. The attack originated from an unsecured chat bot hosted by a third party on its online payment site. This arrangement allowed an attacker to gain access to customers' financial information, such as names, full payment card details and Ticketmaster log in details. <br /><br />The DPA found that 60,000 payment cards belonging to Barclays Bank customers were subject to fraud, and several international banks also reported fraudulent activity to Ticketmaster. This was deemed to be a breach of Art 5(1)(f).