The BA Fine Is Huge, But Watch Where the Money Actually Goes

The BA Fine Is Huge, But Watch Where the Money Actually Goes

Tech News data breach gdpr privacy regulation

So this week the UK's data protection regulator, the ICO, said it intends to fine British Airways £183.39 million over that card-skimming hack from last year. And then, like clockwork, the very next day it announced a second huge one against Marriott, this time £99.2 million, over the Starwood reservation system breach that exposed guest records going back years. Two record-setting GDPR fines announced back to back. I don't think that's a coincidence, I think someone at the ICO wanted the headlines on consecutive days.

The BA number is the one that's grabbing attention because it's huge, biggest fine any UK regulator has ever handed out under this law by a mile. For anyone who forgot the details: attackers redirected people on ba.com to a fake site for about two weeks in August and September last year and skimmed off names, addresses, card numbers, the lot, for something like 500,000 customers. Classic Magecart-style attack, the kind that was hitting a bunch of retail and travel sites around that same period. BA fixed it once they caught it and notified people, but the ICO clearly felt the underlying security was nowhere near good enough for a company handling that much payment data.

Here's the thing though that I keep seeing skipped over in the coverage: that £183 million doesn't go to the roughly half a million people whose card details got lifted. It goes to the ICO, and from there, to the Treasury. Not one penny of it becomes a check in some customer's mailbox. If you were one of the people affected, your compensation (if you're getting any at all) comes from a completely separate track, either BA's own goodwill gestures at the time or a civil claim, and there's already a law firm running a group litigation case for exactly that reason. The fine itself is a government revenue event dressed up as accountability theater. It's real money and it clearly stings BA's parent company IAG, don't get me wrong, but functionally it's punishment aimed at deterring the next company, not restitution for this one.

And even as punishment it's smaller than it sounds. GDPR technically allows fines up to 4% of a company's global annual revenue. £183m works out to something like 1.5% of BA's 2017 turnover, the year the ICO used as the baseline. So this is being reported as the maximum hammer coming down, and it's actually the regulator pulling well short of what the law lets them do. I'd be curious whether that's deliberate calibration (don't want your first big test case getting appealed into oblivion) or just the formula landing where it landed.

None of this is final yet either, both companies have a chance to argue the number down before it's confirmed, and BA has already said it's disputing it. So the £183m figure everyone's quoting today could easily shrink by the time this actually gets paid, if it gets paid on this timeline at all.

Small personal aside since I'm apparently on a fraud-and-payments kick this week: I had my own debit card skimmed at a gas pump in, I want to say, March, and the part that annoyed me wasn't the fraud itself, it was that my bank's automated fraud line asked me to confirm charges by pressing 1 or 2 on a phone keypad and then STILL made me call back a second time to actually get a new card issued. Two calls, maybe forty minutes total, for something the bank's own system had already correctly flagged. If a five-hundred-thousand-customer breach at an airline only nets a 1.5%-of-revenue fine, I have zero faith my bank is losing any sleep over my forty minutes on hold.

Anyway. Watch what BA's actual final number ends up being in a few months, and watch whether Marriott's appeal (if there is one) goes anywhere. The headline number on announcement day is basically never the number that gets paid.