ICO (UK) · 10 February 2020
Cathay Pacific Airways Limited
About: Data principles
- Regulator
- ICO (UK)
- Decided
- 10 February 2020
- Country
- United Kingdom
- Sector
- Not given
- Regulator’s reference
- Monetary penalty to Cathay Pacific Airways Limited
- Fino case number
- 2020/GB/011
What happened
The ICO imposed a fine (monetary penalty) of GBP 500,000 on Cathay Pacific Airways Limited (“Cathay Pacific”), for failing to protect the security of its customers’ personal data. Respective investigation that led to said fine, was started on October 25th, 2018, after Cathay Pacific self-reported the data breaches in violation of Article 5(1)(f) GDPR. Between October 2014 and May 2018 Cathay Pacific’s computer systems lacked appropriate security measures which led to customers’ personal data being exposed, 111,578 of whom were from the UK, and approximately 9.4 million more worldwide.
Summary from GDPRhub (noyb), written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Data principles
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2020/GB/011.