{"id":3311,"date":"2021-05-25T02:53:17","date_gmt":"2021-05-25T02:53:17","guid":{"rendered":"https:\/\/www.tech-battery.com\/batteriesblog\/?p=3311"},"modified":"2021-05-25T02:53:17","modified_gmt":"2021-05-25T02:53:17","slug":"three-years-of-gdpr-the-biggest-fines-so-far","status":"publish","type":"post","link":"https:\/\/www.tech-battery.com\/batteriesblog\/three-years-of-gdpr-the-biggest-fines-so-far\/","title":{"rendered":"Three years of GDPR: the biggest fines so far"},"content":{"rendered":"\n<p>It&#8217;s been three years since the introduction of Europe&#8217;s data privacy and security law on 25 May 2018.<\/p>\n\n\n\n<p>GDPR governs the way organisations that operate within the EU can use, process and store consumers&#8217; personal data.<\/p>\n\n\n\n<p>At first smaller firms and start-ups feared they did not have adequate resources to fully comply with its rules.<\/p>\n\n\n\n<p>Other critics suggested the legislation relied too much on consumers knowing and understanding their rights.<\/p>\n\n\n\n<p>Since its launch, hundreds of millions of euros worth of fines have been handed out by information commissioners around Europe.<\/p>\n\n\n\n<p>Offences have included retailers misrepresenting the way they use CCTV cameras to monitor employees, and companies not complying with the &#8220;right to be forgotten&#8221; law.<\/p>\n\n\n\n<p>The legislation replaced older data protection laws, and while it was drafted in Europe, regulators can fine organisations anywhere in the world which target or collect data in the EU.<\/p>\n\n\n\n<p>There are two tiers of penalties, with a maximum of 20m euros (\u00a317.29m) or 4% of global revenue.<\/p>\n\n\n\n<p>The money collected is used to fund public services. Here are the biggest fines recorded so far:<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>British Airways (211.7m euros)<br>\nBritish Airways was fined in 2019 after users of its website were directed to a fraudulent site.<\/li><\/ol>\n\n\n\n<p>Through the data breach, hackers were able to harvest the personal data of about 500,000 consumers.<\/p>\n\n\n\n<p>The leaked data included login and travel booking details, names, addresses and credit card information.<\/p>\n\n\n\n<p>The Information Commissioner&#8217;s Office (ICO) said the hack was the result of British Airways&#8217; negligence.<\/p>\n\n\n\n<p>Alex Cruz, the airline&#8217;s chairman and chief executive, said it was &#8220;surprised and disappointed&#8221; in the ICO&#8217;s initial findings.<\/p>\n\n\n\n<p>&#8220;British Airways responded quickly to a criminal act to steal customers&#8217; data. We have found no evidence of fraud\/fraudulent activity on accounts linked to the theft, he said.<\/p>\n\n\n\n<p>&#8220;We apologise to our customers for any inconvenience this event caused.&#8221;<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Marriott International Hotels (110.3m euros)<br>\nBritish hotel chain Marriott International was fined in 2018 in relation to a hack dating back to 2014, but not uncovered until four years later.<\/li><\/ol>\n\n\n\n<p>The hack exposed the personal details of about 300 million customers including credit card information, passport numbers and dates of birth.<\/p>\n\n\n\n<p>Following an investigation, the ICO ruled that Marriott had failed to do enough to safeguard its systems.<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Google (50m euros)<br>\nGoogle was one of the first companies to be hit by a substantial GDPR fine.<\/li><\/ol>\n\n\n\n<p>It was fined after a French regulator ruled that the company had failed to make its consumer data processing statements easily accessible to its users.<\/p>\n\n\n\n<p>The tech giant was also found guilty of not seeking the consent of its users to harness their data for targeted advertising campaigns.<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>H&amp;M (35.3m euros)<br>\nH&amp;M was fined by German regulators in 2020 after it was found to have been secretly monitoring hundreds of its employees.<\/li><\/ol>\n\n\n\n<p>If workers took holiday or sick leave, they were required to attend a meeting with senior staff at the retail giant on their return.<\/p>\n\n\n\n<p>These meetings were recorded, and made accessible to H&amp;M managers without the knowledge of staff.<\/p>\n\n\n\n<p>The data collected from the interviews was used to make a &#8220;detailed profile&#8221; of workers, which then influenced decisions concerning their employment.<\/p>\n\n\n\n<ol class=\"wp-block-list\"><li>Amazon (35m euros)<br>\nAmazon was fined by a French regulator over cookie consent violations.<\/li><\/ol>\n\n\n\n<p>It was found that the tech giant had deposited cookies on users&#8217; devices without their permission.<\/p>\n\n\n\n<p>It also failed to provide enough information about the cookies, or how visitors to its French website could refuse them.<\/p>\n\n\n\n<p>Where does GDPR money go?<br>\nIn the UK, all penalties handed out by the ICO are paid into a central government fund which belongs to the Treasury.<\/p>\n\n\n\n<p>The Consolidated Fund is the government&#8217;s general bank account at the Bank of England.<\/p>\n\n\n\n<p>It was established in 1787 with the purpose of being &#8220;one fund into which shall flow every stream of public revenue and from which shall come the supply of every service&#8221;.<\/p>\n\n\n\n<p>This means that just like tax revenue, GDPR fines are used to fund public services.<\/p>\n\n\n\n<p>The majority of other countries in the EU use a similar structure.<\/p>\n\n\n\n<p>Rob Elliss, from tech company Thales, says that despite success so far in handing out substantial fines, GDPR will face more challenges in a post-Covid world.<\/p>\n\n\n\n<p>&#8220;When GDPR was first drafted, the legislation did not necessarily account for the adoption of new technologies and rapid migration to the cloud brought on by the pandemic,&#8221; he said.<\/p>\n\n\n\n<p>&#8220;In this remote working era, businesses needed to digitally transform almost overnight just to keep the lights on, without necessarily incorporating security in the design of new systems and processes.&#8221;   <\/p>\n","protected":false},"excerpt":{"rendered":"<p>It&#8217;s been three years since the introduction of Europe&#8217;s data privacy and security law on 25 May 2018. GDPR governs the way organisations that operate within the EU can use, process and store consumers&#8217; personal data. At first smaller firms and start-ups feared they did not have adequate resources to fully comply with its rules. &hellip; <a href=\"https:\/\/www.tech-battery.com\/batteriesblog\/three-years-of-gdpr-the-biggest-fines-so-far\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Three years of GDPR: the biggest fines so far&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-3311","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"_links":{"self":[{"href":"https:\/\/www.tech-battery.com\/batteriesblog\/wp-json\/wp\/v2\/posts\/3311","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.tech-battery.com\/batteriesblog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.tech-battery.com\/batteriesblog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.tech-battery.com\/batteriesblog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.tech-battery.com\/batteriesblog\/wp-json\/wp\/v2\/comments?post=3311"}],"version-history":[{"count":1,"href":"https:\/\/www.tech-battery.com\/batteriesblog\/wp-json\/wp\/v2\/posts\/3311\/revisions"}],"predecessor-version":[{"id":3312,"href":"https:\/\/www.tech-battery.com\/batteriesblog\/wp-json\/wp\/v2\/posts\/3311\/revisions\/3312"}],"wp:attachment":[{"href":"https:\/\/www.tech-battery.com\/batteriesblog\/wp-json\/wp\/v2\/media?parent=3311"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.tech-battery.com\/batteriesblog\/wp-json\/wp\/v2\/categories?post=3311"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.tech-battery.com\/batteriesblog\/wp-json\/wp\/v2\/tags?post=3311"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}