Data Protection Academy » Data Protection News » First fine after introduction of the GDPR in the UK hits British Airways
First fine after introduction of the GDPR in the UK hits British Airways
Date: 08.07.2019
Responsible body: British Airways
Type of data breach: personal data were stolen
First fine after the introduction of the GDPR in the UK hits British Airways. In the summer of 2018, customer data was allegedly redirected from the British Airways website to a site run by the fraudsters. In the process individual-related data such as credit card and address data were stolen. Due to "weak security precautions", around 500,000 customers were affected, according to the authority.
Categories of data concerned: Travel data, credit card data, identity card data, passport data
Legal classification: British Airways has reported the data breach itself
Country: Great Britain
Fines: 183.39 million British pounds (just under 205 million euros)
Source: Mirror
- Compliance management in the company - 13 March 2023
- The Supply Chain Act (LkSG) - 2 January 2023
- Hamburg imposes data protection fine on Facebook - 18 February 2020