GDPR fines are seemingly like buses, you wait over a year for enforcement action by the UK’s data supervisory authority, the ICO, and then two come along at once – and with quite dramatic effect.

The ICO has stretched its wings and in recent days has issued two notices of intent to fine following investigations. The companies in question can now make representations in an attempt to reduce the fines. Once the ICO issues a penalty notice, the companies can again appeal those fines.

The companies in question are firstly, British Airways, where the ICO has issued a notice of intent to fine the company £183.39 million ($228.89 million) which reportedly equates to 1.5% of their annual turnover and 5 months profit (using 2017 figures). This relates to a cyber incident that was discovered and notified to the ICO in September 2018. BA’s website was compromised causing 500,000 customers data to be harvested by attackers. In its investigation the ICO found that the information was compromised due to poor security arrangements.

The second company to be issued a notice of intent to fine is Marriott International, Inc who are set to be fined £99.2 million ($123.88 million). This again related to a security incident that the ICO was noticed about in November 2018. The personal data of approximately 339 million guests globally was compromised, 30 million of those were resident in 31 countries in the European Economic Area (EEA), 7 million in the U.K.

It is suspected that the system vulnerability dates back to 2014 and Marriott then subsequently acquired Starwood Hotels group in 2016. The security breach was not discovered until 2018.

The ICO noted: “Marriott failed to undertake sufficient due diligence when it bought Starwood and should have done more to secure its systems”.

The full statements from the ICO with regard to both of these incidents are available here and here.

https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2019/07/ico-announces-intention-to-fine-british-airways/

https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2019/07/statement-intention-to-fine-marriott-international-inc-more-than-99-million-under-gdpr-for-data-breach/

The fines are in stark contrast to the previous highest fine in the U.K. of £500,000 under the prior legislation and certainly show a statement of intent from the ICO that in this new era the protection of personal data should be afforded the highest priority.

Watch this space for a further post/s once the ICO issues penalty notices with full reasons for their decisions.

Photo of Kelly McMullon Kelly McMullon

Kelly M. McMullon is special international labor, employment & data protection counsel in the Labor & Employment Law Department and member of the Firm’s International Labor & Employment, Privacy & Cybersecurity and Sports Groups. Kelly has been recommended in Legal 500 UK for…

Kelly M. McMullon is special international labor, employment & data protection counsel in the Labor & Employment Law Department and member of the Firm’s International Labor & Employment, Privacy & Cybersecurity and Sports Groups. Kelly has been recommended in Legal 500 UK for her “responsiveness and practicality.”

Kelly assists clients in a variety of sectors including financial services, asset management, life sciences, fintech, consultancy, retail, sports, leisure and manufacturing in a wide range of contentious and non-contentious matters.

In her employment practice, she provides general day-to-day counselling and advice on all employment-related issues, including hires, terminations, grievances and redundancies, as well as the employment aspects of transactions.

In her data protection practice, Kelly provides strategic advice as well as practical support and guidance on all aspects of data protection compliance, including international transfers of personal data, data breaches, direct marketing and employee data protection concerns. She also provides advice on the data protection aspects of transactions.

Kelly also has experience working with businesses on CSR and ESG initiatives, human rights and modern slavery issues.

Kelly is a contributor to Proskauer’s International Labor and Employment Law and Proskauer on Privacy blogs and is the Editor for Proskauer on Privacy’s “International Data Privacy” chapter. She regularly provides training and speaks on employment and data protection issues.

Her pro bono experience includes counselling not-for-profit organizations on data privacy and employment-related issues.