UK Regulator Slaps British Airways With Record $230M GDPR Fine

The UK's Information Commissioner's Office issues a historic $230 million fine to British Airways over a 2018 data breach that exposes the personal and payment details of 500,000 customers.

The UK's Information Commissioner's Office issues a record-breaking £183.39 million ($230 million) fine to British Airways over a massive data breach from last year. The investigation reveals that poor security arrangements expose the login, payment card, travel booking, name, and address information of approximately 500,000 customers. This penalty represents 1.5% of the airline's total 2018 revenues and stands as the largest fine ever levied by the ICO.

British Airways and its parent company, International Airlines Group (IAG), express surprise and disappointment at the proposed penalty. Company executives defend their response to the criminal attack and note that they find no evidence of fraudulent activity on the compromised accounts. However, IAG shares drop 1.5% in early London trading as the market reacts to the significant financial liability, and the airline vows to appeal the decision vigorously.

This unprecedented enforcement action highlights how GDPR transforms data breaches from mere public relations issues into massive financial threats. The ICO makes this announcement under a new directive designed to increase transparency by publicly disclosing the details of its investigations and fines. The regulator emphasizes that organizations hold a strict responsibility to protect people's personal information under the law.

Read More at the original source →