Record Breaking Proposed Fines Against British Airways and Marriott International Under GDPR
The Information Commissioner’s Office (ICO), the UK’s independent authority on data privacy, issued notices of its intention to fine British Airways and Marriott International £183,390,000 and £99,200,396, respectively, for infringement of the EU General Data Protection Regulations (GDPR). The proposed fines arise from unrelated data breaches at the two companies. These fines are of interest to Canadian businesses both because some Canadians do business in the EU and in light of recent government indications that Canada may revise its privacy laws in a manner bringing them closer to GDPR.
The proposed fine against British Airways relates to a cyber incident beginning in June 2018. The personal data of approximately 500,000 customers was harvested by attackers as user traffic was diverted from the British Airways website to a fraudulent site. The ICO asserts that information such as log in details, payment cards, travel booking details, names and addresses were compromised as a result of poor security arrangements by British Airways.
The proposed fine against Marriott International relates to a cyber incident involving the exposure of the personal data contained in approximately 339 million guest records globally. The vulnerability is believed to have begun within the systems of the Starwood Hotels Group in 2014, which was subsequently acquired by Marriott International in 2016. The exposure was not discovered until 2018. The ICO asserts that Marriott International failed to undertake sufficient due diligence for the 2016 purchase, and failed to ensure proper security of its systems.
British Airways and Marriott International will have the opportunity to make representations to the ICO regarding the ICO’s findings and these proposed large fines.
The EU General Data Protection Regulations
GDPR, which came into effect in May 2018, is directed at protecting the security of, and providing greater control for, personal information collected by organizations. The regulations apply to any information relating to an identifiable person who can be directly or indirectly identified in particular by reference to an identifier (e.g., name, IP address). The regulations impose significant accountability obligations on both data controllers (the entity determining how data is collected and used by the organization) and processors (third parties engaged in processing personal data for controllers).
Under the regime, organizations engaged in serious breaches of the GDPR can be fined up to 4% of annual global turnover or €20,000,000, whichever is greater. Less significant infringements, such as not notifying the supervising authority and data subject about a breach, or failing to conduct an impact assessment, can result in lesser fines.
Why This Matters to Canadian Businesses
GDPR can apply to Canadian businesses that conduct business in the EU. This does not just mean having physical offices in the EU but includes offering goods and services to individuals in the EU through websites or mobile apps. In some circumstances, collecting personal information about individuals in the EU can also engage GDPR. In light of the large fines that can potentially be levied, businesses that collect personal information about individuals in the EU should seek professional advice.
Canada’s own privacy regime may also be headed toward a more GDPR-like approach. The Privacy Commissioner of Canada has recently taken aggressive actions based on a potential interpretation of Canadian legislation that incorporates concepts found in the GDPR, such as recently making a reference to the Federal Court of Canada seeking a ruling about whether Canadian law includes a GDPR-type “right to be forgotten”. The Government of Canada has also announced a Digital Charter, that appears to foreshadow an evolution of Canadian privacy law toward a GDPR-like system. Canadian businesses should ensure not only that they have the safeguards to comply with current law but also the ability to adapt to future requirements.
Authors
Insights
-
Litigation and Dispute Resolution
Ontario Court of Appeal Confirms Directors Can Be Personally Liable for Civil Fraud Without Piercing the Corporate Veil
In CHU de Québec-Université Laval v. Tree of Knowledge International Corp.,1 the Ontario Court of Appeal held that direct participation in civil fraud is a standalone basis for imposing personal… -
Litigation and Dispute Resolution
International Comparative Legal Guide - Enforcement of Foreign Judgments 2026 11th Edition – Canada Chapter
Peter Kolla, Sarah Stothart and Ayesha Khanna co-authored the Canada Chapter of the International Comparative Legal Guide - Enforcement of Foreign Judgements 2026 11th Edition. The Canada Chapter… -
Litigation and Dispute Resolution
International Law and Climate Change – Federal Court Decision in Lho'Imggin v. Canada
The Federal Court’s recent decision in Lho'Imggin v. Canada adds further guidance to existing case law regarding how governments in Canada may potentially face liability for climate change… -
Capital Markets
Successful Exercise of Dissent Rights Reaffirms Importance of Transaction Price
In a rare example of a successful exercise of statutory dissent rights, a group of shareholders dissenting from a court-approved merger recently obtained a fair value determination five times above… -
Energy
Supreme Court of Canada Interprets the Telecommunications Act
In Telus Communications Inc. v. Federation of Canadian Municipalities, the Supreme Court of Canada considered the correct interpretation of the term “transmission line”, as used in sections 43 and… -
Litigation and Dispute Resolution
International Comparative Legal Guide - Enforcement of Foreign Judgments 2025 10th Edition – Canada Chapter
Peter Kolla and Sarah Stothart co-authored the Canada Chapter of International Comparative Legal Guide - Enforcement of Foreign Judgements 2025 10th Edition. The Canada Chapter covers common…
Featured Work
-
Mining
Hudbay Minerals to acquire Arizona Sonoran for US$1.48 billion
Goodmans LLP is advising Hudbay Minerals Inc. in connection with its definitive agreement to acquire Arizona Sonoran Copper Company Inc. (“ASCU”) for US$1.48 billion in an all-share transaction… -
Mining
Gold Candle Ltd. to acquire Fokus Mining Corporation
Goodmans LLP is advising Gold Candle Ltd. in connection with its definitive agreement to acquire all of the issued and outstanding common shares in the capital of Fokus by way of a plan of arrangement… -
REITS and Income Securities
Minto Apartment REIT announces going-private transaction with Crestpoint and Minto Group
Goodmans LLP is acting for Minto Apartment Real Estate Investment Trust (the “REIT”) in connection with its going-private transaction with Crestpoint Real Estate Investments Limited Partnership… -
Shareholder Activism
Plantro Ltd. and Calian Group enter cooperation agreement
Goodmans LLP advised Plantro Ltd. in connection with entering a cooperation agreement with Calian Group Ltd. to accelerate its board renewal process and establish a temporary board committee to… -
Mergers and Acquisitions
Andlauer Healthcare Group acquired by UPS
Goodmans LLP acted for Andlauer Healthcare Group (“AHG”) in connection with its acquisition by UPS via an all-cash transaction that values AHG at an equity value of approximately C$2.2 billion… -
Mergers and Acquisitions
Onex sells WestJet stakes to Delta and Korean Air
Goodmans LLP advised WestJet Airlines Ltd. and its controlling shareholder, Onex Corporation, in connection with the sale of Onex’s minority stakes in WestJet to Delta Air Lines and Korean Air…
News & Events
-
- Construction and Infrastructure
Joe Cosentino and Brad Halfin at the OGCA 15th Construction Symposium
Goodmans Partners Joe Cosentino and Brad Halfin will be speaking at the OGCA 15th Construction Symposium. Their session, “Construction Liens and Insolvency - Recent Developments and Knowing Your… -
Banking and Financial Services
The Canadian Legal Lexpert Directory 2026 Recognizes Goodmans
We are proud to announce Goodmans continues to be recognized in the 2026 edition of The Canadian Legal Lexpert Directory.Congratulations to the 90 Goodmans lawyers recognized as leaders across… -
- 03:25 PM Litigation and Dispute Resolution
Randy McAuley at the BLSA Canada 35th Annual National Conference
Join Goodmans Partner Randy McAuley at the BLSA Canada 35th Annual National Conference on Friday, February 13, 2026, from 2:25 - 3:25pm at Fairmont The Queen Elizabeth in Montréal for the session…