British Airways faces record $ 230 m fine over data theft

Thursday, 11 July 2019 00:00 -     - {{hitsCtrl.values.hits}}

Commuters pass a British Airways advert on the tube at Canary wharf station in London, Britain - Reuters

 

LONDON (Reuters): British Airways-owner IAG is facing a record $230 million fine for the theft of data from 500,000 customers from its website last year under tough new data-protection rules policed by the UK’s Information Commissioner’s Office (ICO).

The ICO proposed a penalty of 183.4 million pounds, or 1.5% of British Airways’ 2017 worldwide turnover, for the hack, which it said exposed poor security arrangements at the airline.

BA indicated that it planned to appeal against the fine, the product of European data protection rules, called GDPR, that came into force in 2018. They allow regulators to fine companies up to 4% of their global turnover for data-protection failures.

The attack involved traffic to the British Airways website being diverted to a fraudulent site, where customer details such as log in, payment card and travel booking details as well as names and addresses were harvested, the ICO said.

Information Commissioner Elizabeth Denham said: “People’s personal data is just that – personal. When an organization fails to protect it from loss, damage or theft it is more than an inconvenience. That’s why the law is clear – when you are entrusted with personal data you must look after it.”

BA’s Chairman and Chief Executive Alex Cruz said he was “surprised and disappointed” by the proposed penalty. “British Airways responded quickly to a criminal act to steal customers’ data,” he said. “We have found no evidence of fraud/fraudulent activity on accounts linked to the theft.”

Willie Walsh, CEO of parent company IAG, said BA would be making representations to the ICO about the proposed fine.

“We intend to take all appropriate steps to defend the airline’s position vigorously, including making any necessary appeals,” he said.

The ICO, which could impose fines up to 500,000 under previous rules, had also investigated BA on behalf of other European regulators.

The ICO fined Facebook 500,000 pounds in 2018 for serious breaches of data protection law. It said the penalty would have “inevitably have been significantly higher under GDPR”.

 

Discover Kapruka, the leading online shopping platform in Sri Lanka, where you can conveniently send Gifts and Flowers to your loved ones for any event including Valentine ’s Day. Explore a wide range of popular Shopping Categories on Kapruka, including Toys, Groceries, Electronics, Birthday Cakes, Fruits, Chocolates, Flower Bouquets, Clothing, Watches, Lingerie, Gift Sets and Jewellery. Also if you’re interested in selling with Kapruka, Partner Central by Kapruka is the best solution to start with. Moreover, through Kapruka Global Shop, you can also enjoy the convenience of purchasing products from renowned platforms like Amazon and eBay and have them delivered to Sri Lanka.

COMMENTS

Discover Kapruka, the leading online shopping platform in Sri Lanka, where you can conveniently send Gifts and Flowers to your loved ones for any event including Valentine ’s Day. Explore a wide range of popular Shopping Categories on Kapruka, including Toys, Groceries, Electronics, Birthday Cakes, Fruits, Chocolates, Flower Bouquets, Clothing, Watches, Lingerie, Gift Sets and Jewellery. Also if you’re interested in selling with Kapruka, Partner Central by Kapruka is the best solution to start with. Moreover, through Kapruka Global Shop, you can also enjoy the convenience of purchasing products from renowned platforms like Amazon and eBay and have them delivered to Sri Lanka.