British Airways faces record £183m ICO GDPR fine

The penalty represents 1.5% of the firm’s annual turnover for hacks that affected 500,000 people

A BA plane in transit

The UK data regulator has issued British Airways (BA) with a notice of its intent to fine the company 183 million after hackers compromised the personal data of half a million customers.

Following an investigation under the EU's General Data Protection Regulation (GDPR), the Information Commissioner's Office (ICO) has issued the airline with a notice of its intention to fine it 183.39 million.

The UK airline revealed last year that cyber criminals had attacked the company and stole personal data belonging to 380,000 people over a two-week period between late August and early September. This included payment information from those using the BA website and mobile app to make bookings.

BA then disclosed a second cyber security incident a month later, affecting a further 185,000 customers who had made bookings using the Avios reward currency between late April and late July.

Advertisement - Article continues below
Advertisement - Article continues below

The hacks were part of a wider malicious campaign said to be orchestrated by the Magecart group, an organisation that also attacked Ticketmaster and Newegg in similar data breach incidents over 2018.

"People's personal data is just that - personal," said the Information Commissioner Elizabeth Denham. "When an organisation fails to protect it from loss, damage or theft it is more than an inconvenience.

"That's why the law is clear - when you are entrusted with personal data you must look after it. Those that don't will face scrutiny from my office to check they have taken appropriate steps to protect fundamental privacy rights."

Under GDPR, organisations that violate the data protection laws are exposed to financial penalties totalling 20 million, or 4% of global annual turnover. For scale, a figure of 183 million represents 1.5% of BA's revenue for 2017.

A notice of intent is not a fine in itself; rather a reliable estimate for the region in which the final decision will lie, with the 183 million figure subject to change.

The ICO said its decisions are based on the incident's severity, including how many people were affected, the data involved, any failings by the organisation, and measures it took to co-operate, as well as mitigate any damage.

Advertisement - Article continues below

BA will have 28 days to argue against the penalty and any points the ICO has raised before the data regulator consults with its European counterparts and comes to a final decision. The ICO says this process can take up to 16 weeks in total.

"We are surprised and disappointed in this initial finding from the ICO," said BA's chairman and chief executive Alex Cruz.

"British Airways responded quickly to a criminal act to steal customers' data. We have found no evidence of fraud/fraudulent activity on accounts linked to the theft. We apologise to our customers for any inconvenience this event caused."

BA's parent company the International Airlines Group (IAG) also confirmed the company will make representations to the ICO within the 28-day window, and will "take all appropriate steps to defend the airline's position vigorously".

Advertisement - Article continues below

"The industry needs to understand not only how to prevent, but how to react to large breaches if it is to avoid major action," said CEO of the Chartered Institute of Information Security Professionals Amanda Finch.

"Businesses need not only the technical skills that help make the organisation secure, but the "soft" interpersonal skills that help create a security-minded culture across the company.

Advertisement - Article continues below

"IT security is in the middle of a long-overdue period of professionalisation - standardising approaches and skills to ensure best practice at all times. Events like these show that it can't happen quickly enough."

If the 183 million fine is issued in its entirety, it will represent the largest GDPR fine an organisation has been given since the regulations came into force more than a year ago.

Moreover, this will be more than three times as large as the sum regulators have accrued through GDPR fines across the continent, 50 million up to February 2019.

The prospective penalty also dwarves the 45 million fine the French data protection authorities slapped Google with at the start of 2019.

Featured Resources

Digitally perfecting the supply chain

How new technologies are being leveraged to transform the manufacturing supply chain

Download now

Three keys to maximise application migration and modernisation success

Harness the benefits that modernised applications can offer

Download now

Your enterprise cloud solutions guide

Infrastructure designed to meet your company's IT needs for next-generation cloud applications

Download now

The 3 approaches of Breach and Attack Simulation technologies

A guide to the nuances of BAS, helping you stay one step ahead of cyber criminals

Download now


data management

EU-US data transfer tools used by Facebook ruled legal

19 Dec 2019
internet security

Avast and AVG extensions pulled from Chrome

19 Dec 2019

Google confirms Android cameras can be hijacked to spy on you

20 Nov 2019

Arcserve UDP 9240DR review: Beef up your backups

4 Apr 2019

Most Popular

operating systems

17 Windows 10 problems - and how to fix them

13 Jan 2020
Microsoft Windows

What to do if you're still running Windows 7

14 Jan 2020
web browser

What is HTTP error 503 and how do you fix it?

7 Jan 2020
mergers and acquisitions

Xerox to nominate directors to HP's board – reports

22 Jan 2020