Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupport
Contact Us
Search
Close

British Airways Ultimately Fined £20m for Personal Data Breach by the UK ICO Under the GDPR (Reduced from £183.39m)

By Mark A. Prinsley, Oliver Yaros, Valerie Vanryckeghem, Reece Randall & Ondrej Hajda on October 19, 2020
Email this postTweet this postLike this postShare this post on LinkedIn

The UK Information Commissioner’s Office (“ICO”) announced on 16 October 2020 that it has ultimately decided to fine British Airways (“BA”) £20 million for BA’s contraventions of the General Data Protection Regulation (“GDPR”) associated with the personal data breach BA first disclosed on 6 September 2018, which affected the personal data of over 400,000 customers and staff. This final amount is a substantial reduction from the £183.39 million fine the ICO first announced it intended to issue in its notice of intent in July 2019 (the “Initial Notice”), although the fine still remains a significant sum and the largest issued by the ICO to date under the GDPR.

The £20 million fine is approximately 0.16% BA’s worldwide annual turnover for the year ending on 31 December 2017 (approximately £12.23 billion), coming well under the maximum 4% fine that could have been issued by the ICO using its powers under the GDPR (a £183.39m fine would have been just under 1.5% of BA’s worldwide annual turnover in that year).  Before reducing the fine, as part of the lengthy process undertaken by the ICO, the ICO explained that it considered both representations from BA and the economic impact of COVID-19 on BA’s business before setting the final penalty.

Continue reading.

Photo of Mark A. Prinsley Mark A. Prinsley

Mark Prinsley is a partner and heads the technology practice in the London office, and is a member of the firm’s Cybersecurity & Data Privacy practice. He concentrates on technology transactions, in particular IT projects and outsourcing.

A substantial element of Mark’s practice…

Mark Prinsley is a partner and heads the technology practice in the London office, and is a member of the firm’s Cybersecurity & Data Privacy practice. He concentrates on technology transactions, in particular IT projects and outsourcing.

A substantial element of Mark’s practice involves data protection issues and he has worked extensively for clients in the pensions and financial services sector designing and implementing GDPR compliant systems for the collection and processing of personal data by businesses and related sub-contractors, commercial transactions involving data sharing and reaction to data breach scenarios including managing data breach notifications. Recent projects Mark has worked on involving personal data include working for an automobile manufacturer implementing a connected vehicle programme globally, a supplier of facial recognition technology on methods of marketing that technology in Europe in compliance with data protection laws and for an insurtech business licensing technology and services to enable life insurers to underwrite life cover for diabetics using AI.

Read Mark’s full bio.

Read more about Mark A. PrinsleyEmail
Show more Show less
Photo of Oliver Yaros Oliver Yaros

Oliver Yaros is a partner in the Intellectual Property & IT Group as well as the Technology & IP Transactions and Cybersecurity & Data Privacy practices of the London office of Mayer Brown. He advises clients on technology and outsourcing transactions with a…

Oliver Yaros is a partner in the Intellectual Property & IT Group as well as the Technology & IP Transactions and Cybersecurity & Data Privacy practices of the London office of Mayer Brown. He advises clients on technology and outsourcing transactions with a particular focus on fintech and digital transformation projects, as well as clients operating within a broad range of sectors on data protection matters and cybersecurity incidents, intellectual property transactions and related issues.

Read Oliver’s full bio.

Read more about Oliver YarosEmail
Show more Show less
Photo of Reece Randall Reece Randall
Read more about Reece RandallEmail
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    Inside Cybersecurity & Privacy Law
  • Organization:
    Mayer Brown

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
  • About LexBlog
  • The Field We Built
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo