<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: First big fine by ICO in Privacy</title>
    <link>https://community.isc2.org/t5/Privacy/First-big-fine-by-ICO/m-p/24849#M806</link>
    <description>&lt;P&gt;This case, although painful for BA, will and should be raised as a what if risk example at all senior executive boards in forthcoming weeks. I would be interested if anybody in this community has any references or good examples of non technical briefings as to the web site hack.&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 09 Jul 2019 08:59:15 GMT</pubDate>
    <dc:creator>Wakeling_S</dc:creator>
    <dc:date>2019-07-09T08:59:15Z</dc:date>
    <item>
      <title>First big fine by ICO</title>
      <link>https://community.isc2.org/t5/Privacy/First-big-fine-by-ICO/m-p/24766#M802</link>
      <description>&lt;P&gt;I suppose it had to happen; the first big fine under GDPR in the UK for a data breach; 1.5% of its worldwide revenue.&amp;nbsp; &amp;nbsp;&lt;A href="https://www.bbc.co.uk/news/business-48905907" target="_blank"&gt;https://www.bbc.co.uk/news/business-48905907&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2019 07:24:07 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/First-big-fine-by-ICO/m-p/24766#M802</guid>
      <dc:creator>Steve-Wilme</dc:creator>
      <dc:date>2019-07-08T07:24:07Z</dc:date>
    </item>
    <item>
      <title>Re: First big fine by ICO</title>
      <link>https://community.isc2.org/t5/Privacy/First-big-fine-by-ICO/m-p/24774#M803</link>
      <description>&lt;P&gt;&lt;FONT size="3"&gt;&lt;A href="https://ico.org.uk/about-the-ico/news-and-events/news-and-blogs/2019/07/statement-ico-announces-intention-to-fine-british-airways/" target="_blank" rel="noopener"&gt;ICO Statement :Intention to fine British Airways £183.39m under GDPR for data breach&lt;/A&gt;&lt;/FONT&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 08 Jul 2019 12:48:02 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/First-big-fine-by-ICO/m-p/24774#M803</guid>
      <dc:creator>leroux</dc:creator>
      <dc:date>2019-07-08T12:48:02Z</dc:date>
    </item>
    <item>
      <title>Re: First big fine by ICO</title>
      <link>https://community.isc2.org/t5/Privacy/First-big-fine-by-ICO/m-p/24849#M806</link>
      <description>&lt;P&gt;This case, although painful for BA, will and should be raised as a what if risk example at all senior executive boards in forthcoming weeks. I would be interested if anybody in this community has any references or good examples of non technical briefings as to the web site hack.&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2019 08:59:15 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/First-big-fine-by-ICO/m-p/24849#M806</guid>
      <dc:creator>Wakeling_S</dc:creator>
      <dc:date>2019-07-09T08:59:15Z</dc:date>
    </item>
    <item>
      <title>Re: First big fine by ICO</title>
      <link>https://community.isc2.org/t5/Privacy/First-big-fine-by-ICO/m-p/24854#M807</link>
      <description>&lt;P&gt;It sounds diluted to me. Wouldn't be 4% what applies in these cases?&lt;/P&gt;</description>
      <pubDate>Tue, 09 Jul 2019 10:36:29 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/First-big-fine-by-ICO/m-p/24854#M807</guid>
      <dc:creator>pcarner</dc:creator>
      <dc:date>2019-07-09T10:36:29Z</dc:date>
    </item>
    <item>
      <title>Re: First big fine by ICO</title>
      <link>https://community.isc2.org/t5/Privacy/First-big-fine-by-ICO/m-p/24879#M809</link>
      <description>&lt;P&gt;&lt;SPAN&gt;You are right.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;The ICO's intended fine isn't the maximum. For British Airways, the potential fine amounts to 1.5% of its annual turnover in 2017, under half of the maximum GDPR penalty of 4% of annual turnover. If the ICO had deemed it appropriate, it could have issued a fine of over £450m.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;SPAN&gt;But this&amp;nbsp;is four times the size of the previous largest fine – that €50m penalty was issued to Google by the French data protection authority for a lack of transparency in its advertising&lt;/SPAN&gt;&lt;/P&gt;&lt;LI-SPOILER&gt;&amp;nbsp;&lt;/LI-SPOILER&gt;</description>
      <pubDate>Tue, 09 Jul 2019 13:43:22 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Privacy/First-big-fine-by-ICO/m-p/24879#M809</guid>
      <dc:creator>leroux</dc:creator>
      <dc:date>2019-07-09T13:43:22Z</dc:date>
    </item>
  </channel>
</rss>

