Advertisement

British Airways faces $229 million fine after 2018 breach of passenger data

The G-EUPH British Airways Airbus A319-131 makes its final approach for landing at Toulouse-Blagnac airport, France, March 20, 2019. REUTERS/Regis Duvignau/File Photo

British Airways is facing a 183 million-pound ($229 million) fine over a breach that compromised information on half a million customers — the biggest penalty to date under new, tougher regulations and one that is likely to be seen as a test case for companies that fail to secure big data caches.

Britain’s Information Commissioner proposed the fine on Monday, months after BA revealed it had been the victim of a hack. The scam saw customers diverted to a fake website where credit card details were harvested by the attackers.

WATCH: (Sept. 2018) British Airways website suffers data breach

Click to play video: 'British Airways website suffers data breach'
British Airways website suffers data breach

“People’s personal data is just that – personal. When an organization fails to protect it from loss, damage or theft it is more than an inconvenience,” Information Commissioner Elizabeth Denham said. “That’s why the law is clear – when you are entrusted with personal data you must look after it.”

Story continues below advertisement

The regulator said that the proposed fine — equivalent to 1.5% of the airline’s annual revenue — is the biggest it has ever imposed. It comes about a year after European Union member states began implementing the most sweeping change in data protection rules in a generation.

Breaking news from Canada and around the world sent to your email, as it happens.
For news impacting Canada and around the world, sign up for breaking news alerts delivered directly to you when they happen.

Get breaking National news

For news impacting Canada and around the world, sign up for breaking news alerts delivered directly to you when they happen.
By providing your email address, you have read and agree to Global News' Terms and Conditions and Privacy Policy.

The General Data Protection Regulation, or GDPR for short, is designed to make it easier for EU residents to give and withdraw permission for companies to use personal information — but also forces companies that hold data to be accountable for looking after it. Authorities can fine companies up to 4% of annual revenue or 20 million euros ($22.5 million), whichever is higher, for breaching the rules.

The Information Commissioner’s Office says its investigation of BA found that “poor security arrangements” compromised login, payment card, and travel booking details as well as name and address information.

The parent company of BA, International Airlines Group, said it would fight the proposed fine. It has 28 days to make its case in the first step of the process, which could take some time to complete.

“We intend to take all appropriate steps to defend the airline’s position vigorously, including making any necessary appeals,” said IAG CEO Willie Walsh.

Story continues below advertisement

The proposed fine is the largest for the ICO since telling Facebook to pay 500,000 pounds ($663,000) for allowing the political consultancy Cambridge Analytica to forage through the personal data of millions of unknowing Facebook users.

WATCH:  Is your personal data becoming “weaponized?”

Click to play video: 'Is your personal data becoming “weaponized?”'
Is your personal data becoming “weaponized?”

But the Facebook matter took place before the new GDPR rules came into effect and was the maximum penalty at the time of the incidents.

Monday’s announcement is a watershed moment for Denham’s office, in that it marks the first major foray into what happens under the new legislation when information authorities accuse well-meaning companies of falling short in data protection regimes.

The proposed BA fine could particularly worry companies that use lots of data, even though their business concerns something else, such as flying planes. These companies have to really open themselves to securing their data despite the cost or face scary fines, said Emily Taylor, CEO of Oxford Information Labs, a cyber security consultancy.

Story continues below advertisement

″(The information commissioner’s office) are going for a very big signal to the entire marketplace,” Taylor said. “This is the message: Get your information security house in order.”

Sponsored content

AdChoices