British Airways: the £20m decision

The final 2020 penalty is a useful reminder to distinguish a proposed fine from an issued one.

By GDPRFix · Published · 2 min read
AI-assisted reporting and commentary · Official sources linked below.
Source / announcement date: 16 October 2020

Historical final penalty notice dated 16 October 2020; not a new enforcement announcement.

What happened

The ICO’s October 2020 penalty notice imposed a £20 million fine on British Airways following a data-security incident. The notice records that this was lower than the earlier proposed penalty after consideration of representations and relevant circumstances. Using the original proposed amount as though it were the final fine would misstate the outcome.

Source: ICO — original source ↗

What it means for your website

For a website owner, the case belongs in the security conversation, not as a claim that any cookie warning leads to a similar bill. Customer information can pass through booking tools, payment journeys and third-party integrations. Ask your provider how those routes are maintained and monitored. Keep an inventory of who can change the website and which external scripts can run on sensitive pages. If a supplier says a system is secure, ask what scope and date the evidence covers. A cookie scan is a different kind of test and does not replace penetration testing or a security review.

Three useful next steps

  1. Keep an inventory of sensitive website journeys.
  2. Review access to payment and booking integrations.
  3. Use the issued decision when discussing enforcement figures.

Sources & context

Official sources consulted on 1 October 2026. A regulator’s announcement records its findings at that time; it is not proof of payment or the outcome of every later appeal.

ICO — original source

Our practical suggestions are GDPRFix commentary. A public website scan cannot establish your full legal position. For advice on a specific obligation or enforcement matter, use a suitably qualified adviser.

Keep reading