Search
Contact
09.07.2019 | KPMG Law Insights

Fine of around 205 million euros for inadequate safety measures

Fine of around 205 million euros for inadequate safety measures

The UK’s Information Commissioner’s Office (ICO) today announced that it has fined British Airways £183.39 million for failing to take sufficient measures to protect personal data. Last year, approximately 500,000 users of British Airways’ website were redirected by hackers to their own website, allowing them to obtain information including booking details, names, address details and credit card information. In the view of the supervisory authority, this was made possible by inadequate security measures taken by the airline. The latter has announced that it will appeal the fine.

The fine might have been significantly higher if British Airways had not cooperated extensively with the authority and improved its own security measures. In any case, such behavior has led German regulators to reduce fines in the past.

Regardless of the outcome of the further proceedings, the ICO’s decision is in line with the already observed practice of imposing heavy fines, in particular for violations of the provisions of the GDPR to ensure the security of personal data. Their importance in practice can therefore hardly be overestimated. On the other hand, those who, as data controllers, neglect the security of personal data out of disinterest or even for cost reasons will expose themselves to the risk of high fines in the future. In addition to these fines, there are other risks, such as reputational risks or the risk of further regulatory measures, such as the (temporary) prohibition of individual processing operations.”

Explore #more

18.11.2025 | In the media

KPMG Law Statement in the FAZ on the subject of deepfakes

Fraudsters can easily falsify invoices or even act as company bosses. Companies can defend themselves against this, but there are no miracle weapons against AI…

17.11.2025 | KPMG Law Insights

Video surveillance in rental properties: What should landlords be aware of?

Video surveillance of rented properties is only possible under strict legal conditions. More and more owners want to keep an eye on and secure their…

13.11.2025 | KPMG Law Insights

Implementing AI in the legal department – these are the success factors

Artificial intelligence (AI) only benefits the legal department if it is implemented correctly. The technology promises to automate time-consuming routine work and fundamentally improve the…

13.11.2025 | KPMG Law Insights

First omnibus package to relax CSDDD, CSRD and EU taxonomy obligations

On November 13, 2025, the EU Parliament voted on its negotiating position regarding the so-called omnibus package, which provides for a relaxation of the CSRD,…

12.11.2025 | In the media

KPMG Law Statement in In-house Counsel: More stability under the umbrella of corporate governance

There is a lot of talk about “corporate governance” in the face of multiple crises and regulatory tendencies on the part of legislators. But what…

07.11.2025 | Deal Notifications

KPMG Law and KPMG advise Diehl Defence on the acquisition of the Tauber Group

KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) and KPMG AG Wirtschaftsprüfungsgesellschaft (KPMG) advised Diehl Defence on the acquisition of the Tauber Group. KPMG Law provided legal…

07.11.2025 | KPMG Law Insights

Changes to the H-1B visa and their consequences for US hiring and secondment practices

President Trump’s administration has introduced two significant changes to the highly popular H-1B visa program for skilled workers: The previous random lottery will be replaced…

07.11.2025 | In the media

KPMG Law Statement on HAUFE: Confusion surrounding the EU Deforestation Regulation – and what companies should do now

Possibly, perhaps, under certain circumstances, the EU Deforestation Regulation (EUDR) will not be binding for large and medium-sized enterprises on December 30, 2025 and for…

06.11.2025 | KPMG Law Insights

External personnel: authorities tighten checks with AI support

AI is a blessing for many companies, but it can also quickly become a curse, especially when authorities use the technology to uncover legal violations…

06.11.2025 | KPMG Law Insights

Deforestation regulation – simplification instead of postponement?

In September, the EU Commission wanted to postpone the EUDR deforestation regulation. On October 21, 2025, it published a comprehensive proposal to simplify the EUDR

Contact

Sebastian Hoegl, LL.M. (Wellington)

Senior Manager
Lawyer
Specialist lawyer for IT law
LL.M. (Wellington)

Heinrich-von-Stephan-Straße 23
79100 Freiburg im Breisgau

Tel.: +49 761 769999-20
shoegl@kpmg-law.com

Maik Ringel

Senior Manager

Münzgasse 2
04107 Leipzig

Tel.: +49 341 22572563
mringel@kpmg-law.com

© 2024 KPMG Law Rechtsanwaltsgesellschaft mbH, associated with KPMG AG Wirtschaftsprüfungsgesellschaft, a public limited company under German law and a member of the global KPMG organisation of independent member firms affiliated with KPMG International Limited, a Private English Company Limited by Guarantee. All rights reserved. For more details on the structure of KPMG’s global organisation, please visit https://home.kpmg/governance.

 KPMG International does not provide services to clients. No member firm is authorised to bind or contract KPMG International or any other member firm to any third party, just as KPMG International is not authorised to bind or contract any other member firm.

Scroll