BA faces 229 million pounds fine over breach of customers' data

Image
AP London
Last Updated : Jul 08 2019 | 6:05 PM IST

Britain's data regulator said Monday it wants to fine British Airways 183 million pounds over a data breach that compromised information on half a million customers the biggest to date under new, tougher data regulations.

The airline revealed in September that it had been the victim of a hack. The scam saw customers diverted to a fake website where credit card details were harvested by the attackers.

"People's personal data is just that - personal. When an organization fails to protect it from loss, damage or theft it is more than an inconvenience," Information Commissioner Elizabeth Denham said.

"That's why the law is clear - when you are entrusted with personal data you must look after it." The regulator said that the proposed fine equivalent to 1.5% of the airline's annual turnover is the biggest it has ever imposed.

It comes about a year after European Union member states began implementing the most sweeping change in data protection rules in a generation.

The General Data Protection Regulation, or GDPR for short, is designed to make it easier for EU residents to give and withdraw permission for companies to use personal information but also forces companies that hold data to be accountable for looking after it. Authorities can fine companies up to 4% of annual revenue or 20 million euros (USD 22.5 million), whichever is higher, for breaching the rules.

The Information Commissioner's Office says its investigation of BA found that "poor security arrangements" compromised login, payment card, and travel booking details as well as name and address information.

The parent company of BA, International Airlines Group, said it would fight the proposed fine. It has 28 days to make its case in the first step of the process, which could take some time to complete.

"British Airways will be making representations to the ICO in relation to the proposed fine," said IAG's CEO Willie Walsh said.

"We intend to take all appropriate steps to defend the airline's position vigorously, including making any necessary appeals." Shares in IAG were down as much as 1.95% in early trading on Monday.

The proposed fine is the largest for the ICO since telling Facebook to pay 500,000 pounds (USD 663,000) for allowing the political consultancy Cambridge Analytica to forage through the personal data of millions of unknowing Facebook users.

But the Facebook matter took place before the new GDPR rules came into effect and was the maximum penalty at the time of the incidents.

Disclaimer: No Business Standard Journalist was involved in creation of this content

*Subscribe to Business Standard digital and get complimentary access to The New York Times

Smart Quarterly

₹900

3 Months

₹300/Month

SAVE 25%

Smart Essential

₹2,700

1 Year

₹225/Month

SAVE 46%
*Complimentary New York Times access for the 2nd year will be given after 12 months

Super Saver

₹3,900

2 Years

₹162/Month

Subscribe

Renews automatically, cancel anytime

Here’s what’s included in our digital subscription plans

Exclusive premium stories online

  • Over 30 premium stories daily, handpicked by our editors

Complimentary Access to The New York Times

  • News, Games, Cooking, Audio, Wirecutter & The Athletic

Business Standard Epaper

  • Digital replica of our daily newspaper — with options to read, save, and share

Curated Newsletters

  • Insights on markets, finance, politics, tech, and more delivered to your inbox

Market Analysis & Investment Insights

  • In-depth market analysis & insights with access to The Smart Investor

Archives

  • Repository of articles and publications dating back to 1997

Ad-free Reading

  • Uninterrupted reading experience with no advertisements

Seamless Access Across All Devices

  • Access Business Standard across devices — mobile, tablet, or PC, via web or app

More From This Section

First Published: Jul 08 2019 | 6:05 PM IST

Next Story