British Airways

€22,046,000

Insufficient technical and organisational measures to ensure information security

Дата принятия решения

16 октября 2020 г.

Авторитет

Information Commissioner (ICO)

GB

Сектор

Aviation

Страна

GB

Закон

GDPR

Статус

FINAL

Описание

In July 2019, the ICO issued a notice of its intention to fine British Airways £183.39M for GDPR infringements which likely involve a breach of Art. 32 GDPR. The proposed fine relates to a cyber incident notified to the ICO by British Airways in September 2018. This incident in part involved user traffic to the British Airways website being diverted to a fraudulent site. Through this false site, customer details were harvested by the attackers. Personal data of approximately 500,000 customers were compromised in this incident, which is believed to have begun in June 2018. The ICO’s investigation has found that a variety of information was compromised by poor security arrangements at the company, including log in, payment card, and travel booking details as well name and address information. In the meantime, the final fine imposed on the airline has been set at £20 million (approximately EUR 22,046,000). The ICO emphasized that when setting the amount of the fine, it also took into account the economic impact of the COVID-19 ('Coronavirus') pandemic on the airline industry.

Юридические цитаты

Art. 5 (1)Art. 32

Проблемы и нарушения

Insufficient technical and organisational measures to ensure information security

Будьте в курсе событий, связанных с соблюдением конфиденциальности

Мы уважаем вашу конфиденциальность. Одно письмо в месяц, без спама, отказ от подписки в любое время.