Ticketmaster UK Limited
- Country
- United Kingdom
- Fine
- 1,250,000 GBP
- Date
- 2020-11-13
- Sector
- Retail and manufacturer
- Articles
- Art 5(1)(f), 32 GDPR
Monetary fine for failure to provide adequate physical security arrangements to protects its customers' personal data as per Art 32 GDPR. The company also failed to prevent fraudulent activities on its customers' bank cards as per Art 5(1)(f).
Ticketmaster UK Limited was fined £1.25 million (approximately €1.405 million) for failing to protect the personal data of its customers with adequate security measure, as required by Art.32 GDPR. Potentially 9.4 million European customers were affected by a cyber attack that occured between February 2018 and June 2018. The attack originated from an unsecured chat bot hosted by a third party on its online payment site. This arrangement allowed an attacker to gain access to customers' financial information, such as names, full payment card details and Ticketmaster log in details. <br /><br />The DPA found that 60,000 payment cards belonging to Barclays Bank customers were subject to fraud, and several international banks also reported fraudulent activity to Ticketmaster. This was deemed to be a breach of Art 5(1)(f).
Source: https://ico.org.uk/media/action-weve-taken/2618609/ticketmaster-uk-limited-mpn.pdf
Reported by: Pinsent Masons (UK)
