So this week the UK's data protection regulator finally showed some teeth, and I have to admit I did a little air-punch at my desk when I saw the numbers.
On Monday the ICO said it intends to fine British Airways £183.39 million over that data breach from September last year, the one where about 500,000 customers had payment card info and login details skimmed off the BA website through a compromised script. Then Tuesday, like the ICO was on a roll, they announced a second one: £99.2 million against Marriott, tied to the Starwood reservation system breach that exposed something like 339 million guest records worldwide. Two record-setting GDPR fines back to back, both bigger than anything the regulation had produced before by an order of magnitude.
I've flown BA more times than I'd like to admit, mostly for work trips to London that I didn't ask for, and I remember getting the breach notification email last September and just kind of shrugging at it. New card, fine, whatever, itll sort itself out. Which is exactly the problem, isn't it? Nobody really feels a data breach in the moment. You don't find out your identity got sold on some forum until months later when a stranger opens a credit line in Ohio using your name. The damage is diffuse and delayed, so companies have never had much incentive to actually spend money preventing it. That's the whole point of these fines existing at percentage-of-revenue instead of flat penalties, they're trying to make the math hurt enough that boards actually care.
And for once it seems to be working, at least on paper. 4% of global turnover is not a rounding error, it's the kind of number that gets a CFO to sit up. BA's fine alone is something like 1.5% of its parent company IAG's revenue for the year. That's real money out of a real budget, not a symbolic slap.
I do wonder how much of this actually changes anything on the ground, though. Filing a breach report and writing a bigger check is one thing. Rebuilding your security posture so this doesn't happen again in three years is a completely different and much less glamorous project, and it's the kind of thing that gets deprioritized the second the news cycle moves on. The Marriott breach in particular traces back to Starwood's systems from 2014, before the two companies even merged, which tells you these vulnerabilities can sit around for years quietly leaking data before anyone notices. That's not a "add two-factor auth" fix, that's years of technical debt and a hundred different vendor integrations nobody fully understands anymore.
The other thing that strikes me is the timing gap. The ICO's fines are for breaches from a year or more ago. GDPR itself only started being enforced in May 2018. So this is really the first real test of whether the teeth are as sharp as advertised, and both companies still get to respond and appeal before anything is final, so don't be shocked if the actual numbers shrink by the time this gets settled for real. I'd bet money on it, honestly.
Small aside because I can't help myself: BA's Executive Club loyalty program has been driving me up a wall for unrelated reasons lately, tier point calculations that don't match what the app tells you, avios that expire without warning, that sort of thing. None of that has anything to do with the breach, I just wanted to say it somewhere and this is my blog so here we are.
What I keep coming back to is that this is the first time in years I've seen a privacy story where the headline number is genuinely surprising rather than the usual "company fined an amount that is less than what they made from your data in the first place." £183 million against BA's roughly £2 billion in annual profit is not nothing. Whether regulators keep this up against the much bigger fish everyones expecting a decision on soon is the real question, and one I don't think anybody outside the ICO's building actually knows the answer to yet.
Either way, if you're one of the half a million people who got that BA email last September, this is probably the closest thing to an apology with a receipt attached that you're going to get.