Close Menu
    What's Hot

    About Us

    Purchase Our Services

    Can personal data be processed outside of the UK and EU?

    LinkedIn X (Twitter)
    GDPR Subject Access Request HelpGDPR Subject Access Request Help
    • The ICO
    • About Us
    • Purchase
    LinkedIn X (Twitter)
    CONTACT
    • Home
    • Business

      Can personal data be processed outside of the UK and EU?

      Are there correct ways to respond to a GDPR subject access request?…

      When can a SAR be refused in full or in part?

      Do all businesses need to be compliant with the UK GDPR?

      Should you register your company with the ICO?

    • Personal

      Will the UK police respond to a GDPR subject access request?

      What does the UK GDPR mean for individuals?

      I don’t live in the UK or EU, what are my rights under GDPR?

      A company has not responded to my GDPR subject access request, what can I do?

      Dealing with unwanted and nuisance calls…

    • Technology

      A faulty server could be considered a breach of the GDPR…

      A glossary and explanation of GDPR terms

      Significant fines and breaches in the news…

      Why IT Security is at the core of good GDPR practice…

    • Purchase Our Services
    GDPR Subject Access Request HelpGDPR Subject Access Request Help
    Home » Significant fines and breaches in the news…
    Technology

    Significant fines and breaches in the news…

    Martin Kayes, CISSPBy Martin Kayes, CISSPUpdated:April 15, 20242 Mins Read
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Below are some examples of large fines and actions issued in the UK under the General Data Protection Regulation (GDPR):

    1. **British Airways (BA)**: In July 2019, the UK Information Commissioner’s Office (ICO) announced its intention to fine British Airways £183.39 million for a data breach that compromised the personal and financial details of approximately 500,000 customers. The fine was later reduced to £20 million after BA appealed the decision.

    2. **Marriott International**: Also in July 2019, the ICO announced its intention to fine Marriott International £99.2 million for a data breach that exposed the personal data of approximately 339 million guests. The breach occurred in systems associated with the Starwood Hotels group, which Marriott acquired in 2016. Marriott contested the fine, and in March 2020, the fine was reduced to £18.4 million.

    3. **Ticketmaster**: In November 2020, the ICO fined Ticketmaster UK Limited £1.25 million for failing to secure its payment systems adequately, leading to a data breach affecting over 9 million customers across Europe. The breach occurred between February and June 2018 and involved malicious software on Ticketmaster’s online payment page.

    4. **Cathay Pacific**: In October 2020, the ICO issued a fine of £500,000 to Cathay Pacific Airways Limited for failing to protect customers’ personal data adequately. The breach, which occurred between October 2014 and May 2018, exposed the personal details of approximately 111,578 passengers, including names, passport details, and travel histories.

    These examples demonstrate the significant financial penalties that can be imposed for violations of the GDPR in the UK.

    It is worth noting that fines are determined based on various factors, including the severity of the breach, the level of cooperation with the regulatory authority, and the measures taken to mitigate the impact on affected individuals.

    Additionally, fines may be subject to appeal or negotiation, leading to potential reductions in the initial penalty amounts.

    Contact us immediately for help if you suffer a data breach. In our experience, if all reasonable precautions were already in place and the breach is handled correctly, then it is possible that the ICO may not issue your company with a fine.

    News
    Martin Kayes, CISSP
    • Website

    Related Posts

    A faulty server could be considered a breach of the GDPR…

    What you shouldn’t do when responding to a SAR…

    A glossary and explanation of GDPR terms

    How to submit a SAR that will achieve what you need

    The ICO has the power to prosecute directors…

    Why IT Security is at the core of good GDPR practice…

    Don't Miss
    Business

    Can personal data be processed outside of the UK and EU?

    By Martin Kayes, CISSP

    Yes, data can be processed internationally under the UK GDPR (General Data Protection Regulation). Under…

    Are there correct ways to respond to a GDPR subject access request?…

    When can a SAR be refused in full or in part?

    Will the UK police respond to a GDPR subject access request?

    Stay In Touch
    • LinkedIn
    • Twitter
    Specialist Investigations
    About Us
    About Us

    A trading style of Cobalt ICT Limited

    Providing affordable, professional help with GDPR, Subject Access Requests, Data Privacy and Cyber Essentials.

    Offering services and consultancy with PAYG and Monthly Retainer options

    Based in London

    We are based in London but for security reasons we do not publish our physical address.

    Our registered office is:
    c/o Kinnair & Company
    Aston House, 21 Redburn Road
    Newcastle Upon Tyne
    NE5 1NB

    A registered company in England and Wales. Registration Number 05484135

    Business Hours

    Monday - Friday
    9am - 5pm
    Terms and Conditions

    LinkedIn X (Twitter)
    • Home
    • Business
    • Personal
    • Technology
    • Fines & Breaches
    • GDPR News
    • Privacy Policy
    © 2025 Cobalt ICT Limited.

    Type above and press Enter to search. Press Esc to cancel.