British Airways has settled a lawsuit brought against it over a 2018 data breach which leaked personal information belonging to thousands of customers.
The settlement has been resolved on confidential terms, according to PGMBM, the law firm which brought the case against BA on behalf of customers.
According to PGMBM, the resolution includes provisions for compensation for “qualifying claimants” who were part of the action against British Airways.
PGMBM filed the claim in April 2020 on behalf of customers affected by the data breach.
In January this year, the firm claimed British Airways could face more than £800 million in claims after thousands had backed the legal challenge.
Harris Pogust, PGMBM Chairman, said: “We are very pleased to have come to a resolution on this matter after constructive mediation with British Airways.
“This represents an extremely positive and timely solution for those affected by the data incident.”
In September 2018, British Airways confirmed its security systems had been breached. The subsequent leak exposed personal information belonging to more than 420,000 customers and staff.
Data exposed included names, debit and credit card numbers, addresses, and email addresses.
In July 2019, the Information Commissioner’s Office (ICO) issued the airline with a £183 million fine for breaching GDPR.
An investigation by the regulator found the airline had been processing “a significant amount” of personal data without adequate security measures in place.
BA’s failure to properly mitigate security risks led to the breach, which went undetected for nearly two months before a third party informed the airline.
In October last year, the fine was later revised down to £20 million, however. At the time, the ICO said it considered representations from BA as well as the economic impact of the coronavirus pandemic on the business before setting a final penalty.
Recommended
- DIGIT Movers and Shakers | June 2021
- Cyber attacks against UK companies fall for first time in three years
- Kaseya ransomware attack strikes deep at the heart of the supply chain
Notably, the settlement resolution does not include any admission of liability on the part of British Airways, Pogust added.
He said: “The Information Commissioner’s Office laid out how BA did not take adequate measures to keep its passengers’ personal and financial information secure,
“However, this did not provide redress to those affected. This settlement now addresses that.”
PGMBM is also representing a growing number of claimants in a case relating to the EasyJet data breach first revealed in May 2020.
This breach saw nine million passengers’ data exposed, including names, email addresses, and travel information.
Harris added: “The pace at which we have been able to resolve this process with British Airways has been particularly encouraging and demonstrates how seriously the legal system is taking mass data incidents.
“This is a very positive sign as we look ahead to what will be an even bigger case against easyJet relating to their 2020 data breach, as well as other similar international actions.”





