• news-banner

    Expert Insights

ICO issues British Airways with a ground-breaking fine

On 16 October 2020, The Information Commissioner’s Office (the “ICO”) imposed a monetary penalty notice fining British Airways Plc (“BA”) £20million for breaching its data security obligations under the General Data Protection Regulation (the “GDPR”) when they faced a cyber-attack in 2018. This is the ICO’s largest fine to date and the amount imposed was a significant reduction on the £183.39 million the ICO announced that it intended to fine BA back in July 2019.

Details of the cyber attack

The attacker is believed to have accessed the personal data of over 400,000 BA customers and staff members worldwide. Information obtained includes names, addresses, payment card numbers and CVV numbers; although it is thought only around 100,000 customers had their payment information accessed. The attack went undetected for over 2 months spanning from 22 June to 5 September 2018.

Usernames and passwords of BA employee accounts, as well as usernames and PINs of up to 600 BA Executive Club accounts, were also potentially accessed.

Failure to prevent the attack

The ICO listed a number of factors in its penalty notice report that BA could have used to mitigate the risk of the attacker being able to access personal data through the BA network. These include:

  • limiting access to applications, data and tools to only those which are required to fulfil a user’s role;
  • undertaking rigorous testing, in the form of simulating a cyber-attack, on the business’ systems; and
  • protecting employee and third party accounts with multi-factor authentication.

It was noted that these additional measures would not have entailed excessive costs or technical barriers to BA, with some of these measures already available through the Microsoft Operating System that they used.

Another consequential factor taken into account by the ICO was that on 22 June 2018 BA did not detect the attack themselves but were informed by a third party more than two months after, on 5 September 2018. The ICO considered this to be a severe failing because it is not clear whether or when BA would have identified the attack themselves. Had it not been for this third party the financial harm could have been even more widespread.

Significance

The fine payable by BA is the largest imposed to date by the ICO for a breach of the GDPR. Although £20million appears to be a narrow escape (compared to the £183million originally suggested by the ICO), Article 83 of the GDPR does require the ICO to ensure any fine imposed is "effective, proportionate and dissuasive". The ICO considered BA’s prompt action that was taken to mitigate the risk of harm suffered (once aware of the attack), as well as the economic impact of COVID-19 on the business – and with all considerations taken into account, imposed a greatly reduced (albeit still eye-watering) fine.

Our thinking

  • Business over Breakfast: Arbitration is cheaper – Myth or Reality?

    Thomas R. Snider

    Events

  • The UK’s March 2024 budget: Offshore trusts - have reports of their demise been greatly exaggerated?

    Sophie Dworetzsky

    Insights

  • Playing with FYR: planning opportunities offered by the UK’s proposed four-year regime for newcomers to the UK

    Catrin Harrison

    Insights

  • James Broadhurst writes for the Financial Times’ Your Questions column on inheriting company shares

    James Broadhurst

    In the Press

  • Charles Russell Speechlys bolsters corporate and commercial offering with the appointment of Shirley Fu in Hong Kong

    Simon Green

    In the Press

  • Cara Imbrailo and Ilona Bateson write for Fashion Capital on pop-up shops

    Cara Imbrailo

    In the Press

  • City AM quotes Charlotte Duly on the importance of business branding

    Charlotte Duly

    In the Press

  • Planning and Life Sciences: the challenges and opportunities in the Golden Triangle

    Sophie Willis

    Quick Reads

  • Personnel Today quotes Rose Carey on Italy’s new digital nomad visa

    Rose Carey

    In the Press

  • Regime change: The beginning of the end of the remittance basis

    Dominic Lawrance

    Insights

  • Essential Intelligence – UAE Fraud, Asset Tracing & Recovery

    Sara Sheffield

    Insights

  • IFA Magazine quotes Julia Cox on the possibility of more tax cuts before the general election

    Julia Cox

    In the Press

  • ‘One plus one makes two': Court of Protection finds conflict of interest within law firm structure

    Katie Foulds

    Insights

  • City AM quotes Charlotte Duly on Tesco’s Clubcard rebrand after losing battle with Lidl

    Charlotte Duly

    In the Press

  • Michael Powner writes for Raconteur on AI and automating back-office roles

    Michael Powner

    In the Press

  • Arbitration: Getting value for your money

    Daniel McDonagh

    Insights

  • Portfolio Adviser quotes Richard Ellis on the FCA's first public findings against former fund manager Neil Woodford

    Richard Ellis

    In the Press

  • eprivateclient quotes Sally Ashford on considerations around power of attorney

    Sally Ashford

    In the Press

  • Michael Powner and Sophie Rothwell write for Law360 on anti-bias protection

    Michael Powner

    In the Press

  • Computer says No - my prediction of UK border chaos on Wednesday 1 January 2025

    Paul McCarthy

    Quick Reads

  • Providing pro bono support on social housing issues

    Susan Field

    Insights

  • Charles Russell Speechlys Partner Promotions 2024

    Bart Peerless

    News

  • London’s Knowledge Clusters: From Emerging to Maturing – Start Ups on the Global Stage?

    Lynsey Inglis

    Quick Reads

  • Fashion and the Green Claims Code brought into focus by open letter from the CMA.

    Ilona Bateson

    Quick Reads

  • Will new powers at Companies House stop or slow down fraudsters?

    Peter Carlyon

    Quick Reads

  • Charles Russell Speechlys hosts international arbitration event in Dubai

    Peter Smith

    Quick Reads

  • It’s not just a High Court decision, it’s a successful M&S High Court Decision

    Sophie Willis

    Quick Reads

  • The ongoing fight against fakes

    Charlotte Duly

    Quick Reads

  • Abu Dhabi’s New Arbitral Centre Unveils its Rules

    Dalal Alhouti

    Quick Reads

  • New Regulations for the UAE’s Media Sector in 2024

    Mark Hill

    Quick Reads

  • Planning essentials case update: when can an enforcement notice against an unlawful use also require the removal of related structures?

    Sadie Pitman

    Quick Reads

  • Under the Influence: Legal Considerations for Social Media Influencer Partnerships in the UAE

    Mark Hill

    Quick Reads

  • EU AI Act – Will it become a law for all the world?

    Nick White

    Quick Reads

  • Ctrl + GCC: The Rise of e-Sports in the Gulf

    Mark Hill

    Quick Reads

  • Digital Markets, Competition and Consumers Bill: Will new consumer protection rules restrict access to Gift Aid?

    Quick Reads

  • The End of the SAG-AFTRA Strike & What it Means for the Middle East

    Mark Hill

    Quick Reads

  • UAE Strengthens its Position as Leading Destination for A.I.

    Mark Hill

    Quick Reads

  • Dubai Court of Cassation Extends Arbitration Agreement Across Subsequent Contracts

    Peter Smith

    Quick Reads

  • Good news for users of the Madrid System

    Charlotte Duly

    Quick Reads

  • Michael Gove's announcement on transitional period for two staircase requirement for new residential buildings

    Melanie Hardingham

    Quick Reads

Back to top