Daily Express

BA’s record £ 20m fine

- By

BRITISH Airways has been fined a record £ 20million after a data hack hit more than 400,000 customers.

Informatio­n watchdogs said the airline should have prevented security weaknesses which went undetected for more than two months.

Investigat­ors for the Informatio­n Commission­er’s Office ( ICO) found bosses should have spotted security failings which let the attack happen.

They did not protect users’ personal and financial details and did not notice the 2018 for weeks, the ICO added.

Informatio­n Commission­er Elizabeth Denham said: “Their failhack ure to act was unacceptab­le and affected hundreds of thousands of people, which may have caused some anxiety and distress.

“That’s why we have issued BA with a £ 20million fine – our biggest to date. When organisati­ons take poor decisions around people’s personal data, that can have a real impact on people’s lives. The law now gives us the tools to encourage businesses to make better decisions about data, including investing in up- to- date security.”

The ICO warned in July last year BA might be fined more than £ 183million, but now said it considered “representa­tions from BA and the economic impact of Covid- 19” on the firm before setting the fine.

An airline spokeswoma­n said BA was “sorry we fell short of our customers’ expectatio­ns. We are pleased the ICO recognises that we have made considerab­le improvemen­ts to the security of our systems since the attack and that we fully co- operated with its investigat­ion”.

The ICO said the investigat­ion found the airline was “processing a significan­t amount of personal data without adequate security measures”, breaking data protection law.

Investigat­ors said BA ought to have identified data weaknesses and resolved them with security measures that were available at the time.

Newspapers in English

Newspapers from United Kingdom