Booking.com data breach GDPR

 
 
 

 

Fine of €475,000 for delayed reporting of a data protection breach

At the latest since the introduction of the General Data Protection Regulation in May 2018, companies should take the GDPR and the obligations mentioned therein seriously. Data protection authorities repeatedly impose high fines for non-compliance with data protection principles. For example, the Dutch accommodation booking portal Booking.com was fined €475,000 for the late reporting of a data protection breach.

 

The most important points in brief

  • A data breach occurs when personal data is lost, destroyed, or altered, or when unauthorized third parties gain knowledge of the personal data.

  • Art. 33(1) GDPR obliges the controller to report a data breach to the competent supervisory authority without undue delay, preferably within 72 hours of becoming aware of it.

  • An exception to the reporting obligation to the supervisory authority is possible if the data protection breach poses no or only a low risk to the rights and freedoms of a natural person.

  • A violation of the reporting requirement may be punishable by a fine of up to €10,000 or, in the case of a company, up to 2% of its annual global revenue.

 

The data breach

The penalty notice from the Dutch Data Protection Authority was issued as a result of a severe data breach that occurred at the international online accommodation booking portal Booking.com. In December 2018, cybercriminals gained access to the personal data of over 4,000 customers.

For this, they allegedly obtained login details for the Booking.com accounts of approximately 40 hotel employees in the United Arab Emirates.

Through subsequent use of the platform, the hackers were able to access customers' personal data.

Complete datasets including names, addresses, and payment methods were stolen. However, according to Booking.com, there was no compromise of the code or databases.

Furthermore, the hackers were able to obtain credit card data by phone and email by posing as platform employees, with the security numbers sometimes being visible.

 

GDPR violation: Delayed data breach notification

The company, based in the Netherlands, discovered the security breach on January 13, 2019. In contrast, reporting to the data protection authority did not occur until 25 days later, on February 7, 2019, after the company had notified its customers three days prior. This course of action constitutes a serious violation of the reporting obligation under the GDPR.

 

When is there a reporting obligation?

Pursuant to Art. 33(1) GDPR, the controller has the obligation to notify the competent supervisory authority of a personal data breach without undue delay, and where feasible, not later than 72 hours after having become aware of it.

A data breach occurs pursuant to Article 4(12) GDPR when the protection of personal data is breached, resulting in the loss, destruction, or alteration of personal data or in unauthorized third parties gaining knowledge of it.

The term data breach encompasses the following situations:

  • Annihilation

All forms of data deletion that result in the irrevocable destruction of data are covered, regardless of whether this occurs intentionally or unintentionally.

  • Loss

Even data that is unexpectedly lost, whether temporarily or permanently, can constitute a data breach.

  • Change

This refers to the substantive alteration of data, through which personal data acquires new informational content.

  • Offenlegung/Weitergabe

In particular, the transfer of data to third parties or disclosure to third parties can constitute a data protection violation if the data subject has not consented or another legal basis is applicable.

  • Unauthorized access

If third parties can gain unauthorized access to personal data and gain knowledge of it due to insufficient security measures, this also constitutes a data protection violation.

If one of these situations occurs, it is usually a notifiable data breach within the meaning of Article 33(1) of the GDPR.

 

First to report a data breach

According to Art. 33(1) of the GDPR, a personal data breach must be reported to the competent supervisory authority without undue delay, and where feasible, not later than 72 hours after having become aware of it.

The 72-hour deadline is intended to ensure rapid reporting and subsequent measures to contain risks to the rights and freedoms of natural persons.

An extension of the deadline under Article 33(1) GDPR is only permissible if there is insufficient information available for a notification at that time. If this is the case, a convincing justification for the delay must be attached when the notification is made.

If the minimum content requirements cannot be met immediately but only gradually, Article 33(4) GDPR provides the option to provide the required information to the competent authority incrementally.

To comply with the relatively short deadline, it is of great importance to be able to detect data breaches within your own company as quickly as possible. For this reason, it is recommended to establish processes for reporting data incidents.

 

Controller's reporting obligation

The reporting obligation generally applies to the data controller.

If joint responsibility exists, a prior determination of responsibility for a notification is required. Regularly, the person whose duties include data breaches of this nature will be responsible.

If a data breach occurs within the scope of contract processing, the processor must immediately report it to the controller according to Art. 33 para. 2 GDPR so that the controller can contact the competent supervisory authority. However, the processor does not have to report the data breach to the competent supervisory authority.

 

Exemption from reporting requirements

An exception to the reporting obligation to the supervisory authority is possible if the data protection breach poses no or only a low risk to the rights and freedoms of a natural person.

The central point of reference is therefore a previously made risk prognosis. The person responsible must carry out a risk assessment that takes into account the relationship between the severity and probability of occurrence of the breach, as well as the amount of damage. There is no need for proof of the absence of risk. A coherent prognosis is sufficient.

 

Substantive requirements for the reporting obligation

Article 33(3) GDPR regulates the minimum content requirements of a notification to the supervisory authority.

Afterwards, the notification must include a comprehensive description of the nature of the data breach (e.g., access by unauthorized third parties). It must, to the extent possible, state the categories (e.g., customer data) and the approximate number of individuals concerned, as well as the approximate number of personal data records concerned.

Furthermore, the name and contact details of the Data Protection Officer or any other contact point, a description of the likely consequences of the data breach, and a description of the measures taken or planned by the controller to address the data breach, and, where appropriate, to mitigate its possible adverse effects.

 

Notification of Affected Parties of a Data Breach

Furthermore, the regulation contains a tiered reporting and notification obligation.

In contrast to the supervisory authority, those affected must always be notified only when the data breach is likely to pose a high risk to their rights and freedoms, according to Art. 34(1) GDPR.

Unlike towards the supervisory authority, the controller does not have to provide the data subject with a comprehensive picture of the personal data breach. The notification only needs to state the nature of the personal data breach, any contact details of the data protection officer, and a description of the likely consequences, as well as the measures already taken and recommended.

If the data controller takes appropriate security measures beforehand that effectively prevent third-party access to the protected data (e.g., through encryption), the data subject does not need to be notified in accordance with Article 34(3) GDPR. The same applies if the data controller takes measures in response to the data breach that are highly likely to ensure that the high risk to the data subject's data no longer exists.

 

Data breach notification form

Even though Art. 33 GDPR does not specify the form of a notification, it is recommended to keep written proof of notification for evidentiary purposes.

Because in this context, the data controller has a general documentation obligation under the GDPR, which is intended both for supervisory authority inspection and to serve as proof for the data controller.

Corresponding reporting forms can regularly be found on the websites of the state data protection authorities.

 

Penalty for late reporting of data breach

In the case of Booking.com, the Dutch Data Protection Authority imposed a fine of 475,000 euros for the late notification.

Pursuant to Article 83(4)(a) of the GDPR, a fine of up to €10,000 or, in the case of an enterprise, up to 2% of its global annual turnover may be imposed on the controller for a breach of the obligation under Article 33 of the GDPR.

 

Outlook

Fines, such as in the case of Booking.com, clearly illustrate the consequences of inadequate implementation of the GDPR and the resulting obligations. Supervisory authorities take the GDPR seriously and not only examine whether companies are taking sufficient measures to prevent data protection breaches, but also sanction the incorrect handling of data breaches, especially delayed reporting to the competent authority. Prepare your company now for the correct handling of data protection breaches by establishing internal guidelines for handling data protection violations and implementing technical measures to prevent them.

Get in touch