Search
Contact
09.07.2019 | KPMG Law Insights

Fine of around 205 million euros for inadequate safety measures

Fine of around 205 million euros for inadequate safety measures

The UK’s Information Commissioner’s Office (ICO) today announced that it has fined British Airways £183.39 million for failing to take sufficient measures to protect personal data. Last year, approximately 500,000 users of British Airways’ website were redirected by hackers to their own website, allowing them to obtain information including booking details, names, address details and credit card information. In the view of the supervisory authority, this was made possible by inadequate security measures taken by the airline. The latter has announced that it will appeal the fine.

The fine might have been significantly higher if British Airways had not cooperated extensively with the authority and improved its own security measures. In any case, such behavior has led German regulators to reduce fines in the past.

Regardless of the outcome of the further proceedings, the ICO’s decision is in line with the already observed practice of imposing heavy fines, in particular for violations of the provisions of the GDPR to ensure the security of personal data. Their importance in practice can therefore hardly be overestimated. On the other hand, those who, as data controllers, neglect the security of personal data out of disinterest or even for cost reasons will expose themselves to the risk of high fines in the future. In addition to these fines, there are other risks, such as reputational risks or the risk of further regulatory measures, such as the (temporary) prohibition of individual processing operations.”

Explore #more

12.01.2026 | In the media

Guest article in Economy and Competition: Earnings calls under (AI) control: New starting point for the Commission’s dawn raids

Public statements made by companies in earnings calls harbor antitrust risks: In such presentations of quarterly or annual results and the subsequent discussion with analysts,…

09.01.2026 | KPMG Law Insights

EmpCo comes into force – answers to the most important practical questions

Environmental statements are becoming increasingly risky for companies. Due to the Empowering Consumers Directive (EmpCo), much stricter rules will soon apply to environmental claims and…

05.01.2026 | In the media

KPMG Law expert in the Börsen-Zeitung on the digital euro

The digital euro is set to arrive by 2029. However, the central bank still has a lot of convincing to do. There is a great…

22.12.2025 | KPMG Law Insights

New EU directive tightens environmental criminal law

Environmental crime will be punished more severely in future. Directive (EU) 2024/1203 on the protection of the environment through criminal law is being transposed into…

19.12.2025 | KPMG Law Insights

Digital Omnibus: More efficiency instead of deregulation

The EU Commission wants to streamline digital laws. On November 19, 2025, it presented its proposals for the “Digital Omnibus” (including a separate AI Omnibus).…

18.12.2025 | Deal Notifications

KPMG Law and KPMG advise the shareholders of Frerk Aggregatebau on the sale to DEUTZ

KPMG Law Rechtsanwaltsgesellschaft mbH (KPMG Law) and KPMG AG Wirtschaftsprüfungsgesellschaft (KPMG) provided comprehensive advice to the shareholders of Frerk Aggregatebau GmbH (Frerk) on the sale…

17.12.2025 | KPMG Law Insights

AI-supported risk checks of NDAs and CoCs: how legal departments benefit

Artificial intelligence can relieve legal departments of routine tasks such as checking non-disclosure agreements (NDAs) or codes of conduct (CoCs). These documents are part of…

16.12.2025 | In the media

Interview with KPMG Law experts: CSDDD after the omnibus: “Toothless tiger” or pragmatic solution?

The agreement on the Omnibus I package is causing discussion. Among other things, the thresholds for the EU Supply Chain Directive (CSDDD) have been significantly…

15.12.2025 | In the media

KPMG Law guest article in Tagesspiegel Background: What the digital omnibus means for companies today

The debate on the digital omnibus has only just begun. Companies should contribute their expertise to the ongoing process and strengthen their internal foundations –…

12.12.2025 | KPMG Law Insights

Focus offshore: NRW buys extensive tax data on international tax havens

According to recent press reports from December 11, 2025, the state of North Rhine-Westphalia has purchased an extensive data set with tax-relevant information from international…

Contact

Sebastian Hoegl, LL.M. (Wellington)

Senior Manager
Lawyer
Specialist lawyer for IT law
LL.M. (Wellington)

Heinrich-von-Stephan-Straße 23
79100 Freiburg im Breisgau

Tel.: +49 761 769999-20
shoegl@kpmg-law.com

Maik Ringel

Senior Manager

Münzgasse 2
04107 Leipzig

Tel.: +49 341 22572563
mringel@kpmg-law.com

© 2026 KPMG Law Rechtsanwaltsgesellschaft mbH, associated with KPMG AG Wirtschaftsprüfungsgesellschaft, a public limited company under German law and a member of the global KPMG organisation of independent member firms affiliated with KPMG International Limited, a Private English Company Limited by Guarantee. All rights reserved. For more details on the structure of KPMG’s global organisation, please visit https://home.kpmg/governance.

KPMG International does not provide services to clients. No member firm is authorised to bind or contract KPMG International or any other member firm to any third party, just as KPMG International is not authorised to bind or contract any other member firm.

Scroll