Historical final penalty notice dated 16 October 2020; not a new enforcement announcement.
What happened
The ICO’s October 2020 penalty notice imposed a £20 million fine on British Airways following a data-security incident. The notice records that this was lower than the earlier proposed penalty after consideration of representations and relevant circumstances. Using the original proposed amount as though it were the final fine would misstate the outcome.
Source: ICO — original source ↗
What it means for your website
For a website owner, the case belongs in the security conversation, not as a claim that any cookie warning leads to a similar bill. Customer information can pass through booking tools, payment journeys and third-party integrations. Ask your provider how those routes are maintained and monitored. Keep an inventory of who can change the website and which external scripts can run on sensitive pages. If a supplier says a system is secure, ask what scope and date the evidence covers. A cookie scan is a different kind of test and does not replace penetration testing or a security review.
Three useful next steps
- Keep an inventory of sensitive website journeys.
- Review access to payment and booking integrations.
- Use the issued decision when discussing enforcement figures.
Sources & context
Official sources consulted on 1 October 2026. A regulator’s announcement records its findings at that time; it is not proof of payment or the outcome of every later appeal.
ICO — original sourceOur practical suggestions are GDPRFix commentary. A public website scan cannot establish your full legal position. For advice on a specific obligation or enforcement matter, use a suitably qualified adviser.