Fino

ICO (UK) · 10 February 2020

Cathay Pacific Airways Limited

About: Data principles

FineGBP500,000≈ €591,000Violation found
Regulator
ICO (UK)
Decided
10 February 2020
Country
United Kingdom
Sector
Not given
Regulator’s reference
Monetary penalty to Cathay Pacific Airways Limited
Fino case number
2020/GB/011
Export as PDF

What happened

The ICO imposed a fine (monetary penalty) of GBP 500,000 on Cathay Pacific Airways Limited (“Cathay Pacific”), for failing to protect the security of its customers’ personal data. Respective investigation that led to said fine, was started on October 25th, 2018, after Cathay Pacific self-reported the data breaches in violation of Article 5(1)(f) GDPR. Between October 2014 and May 2018 Cathay Pacific’s computer systems lacked appropriate security measures which led to customers’ personal data being exposed, 111,578 of whom were from the UK, and approximately 9.4 million more worldwide.

Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.

Rules involved

  • Data principles

Sources

The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.

Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2020/GB/011.