header-logo header-logo

10 July 2019
Issue: 7848 / Categories: Legal News , Data protection
printer mail-detail

‘Gloves off’ as first GDPR fine issued

Business fears about a tough GDPR regime have been confirmed after the first company to be penalised, British Airways, received a £183.39m fine.

The Information Commissioner's Office (ICO) issued the penalty this week for a data breach that compromised 500,000 BA customers. Businesses have waited since 25 May 2018 to get an idea of the possible size of General Data Protection Regulation (GDPR) fines.

BA has said it will make representations to the ICO about the size of the proposed fine and intends to appeal.

David White, commercial and IP associate at Rollits, said the fine ‘demonstrates that the ICO is not afraid to use the weapons at its disposal to hammer home the importance of data protection. 

‘Any organisation that has ignored to its data protection responsibilities, or seen data protection compliance as a “tick-box” exercise, should take stock: the gloves are off.’

The BA fine represents about 1.5% of its annual worldwide turnover. Under the GDPR, organisations can be fined up to 20 million euros or 4% of annual worldwide turnover for a serious breach, whichever is highest, and 10 million euros or 2% of annual worldwide turnover for a less serious breach. This is considerably higher than the maximum £500,000 fines possible under the Data Protection Act.

Raoul Parekh, partner at GQ|Littler, said: ‘The first GDPR fine is the display of shock and awe that many feared.

‘Politicians and pressure groups have been lobbying for heavy penalties and it seems they have listened. The ICO has used its first announcement of intention to fine as a major deterrent to ensure businesses take GDPR extremely seriously.

‘British Airways has acted very responsibly since the breach was discovered, notifying the ICO and co-operating with the regulator to fix the issues and repair the damage. For the ICO, though, businesses need prevention and not just cure if they are to avoid fines.’

Issue: 7848 / Categories: Legal News , Data protection
printer mail-details

MOVERS & SHAKERS

Jurit LLP—Caroline Williams

Jurit LLP—Caroline Williams

Private wealth and tax team welcomes cross-border specialist as consultant

Freeths—Michelle Kirkland Elias

Freeths—Michelle Kirkland Elias

International hospitality and leisure specialist joins corporate team as partner

Flint Bishop—Deborah Niven

Flint Bishop—Deborah Niven

Firm appoints head of intellectual property to drive northern growth

NEWS
Talk of a reserved ‘Welsh seat’ on the Supreme Court is misplaced. In NLJ this week, Professor Graham Zellick KC explains that the Constitutional Reform Act treats ‘England and Wales’ as one jurisdiction, with no statutory Welsh slot
The government’s plan to curb jury trials has sparked ‘jury furore’. Writing in NLJ this week, David Locke, partner at Hill Dickinson, says the rationale is ‘grossly inadequate’
A year after the $1.5bn Bybit heist, crypto fraud is booming—but so is recovery. Writing in NLJ this week, Neil Holloway, founder and CEO of M2 Recovery, warns that scams hit at least $14bn in 2025, fuelled by ‘pig butchering’ cons and AI deepfakes
After Woodcock confirmed no general duty to warn, debate turns to the criminal law. Writing in NLJ this week, Charles Davey of The Barrister Group urges revival of misprision or a modern equivalent
Family courts are tightening control of expert evidence. Writing in NLJ this week, Dr Chris Pamplin says there is ‘no automatic right’ to call experts; attendance must be ‘necessary in the interests of justice’ under FPR Pt 25
back-to-top-scroll