Booking.com fined €475k for reporting data breach too late
therecord.media
therecord.media
Also: the crime isn't that bad. They did reported the breach on their own accord, and acted according to the laws at hand. The report may have been two weeks too late, but it was there. Their preventative measures and reaction were deemed good enough, just not timely. A crippling fine wouldn't have been appropriate, given the verdict.
The company could have avoided the fine by doing exactly the same thing they did, just a little faster. The fine counterbalances the cost-savings they may have had by having fewer people work on this. A future manager will probably see the fine, and decide just to put a little more resources into this, so the report can be on time. When that happens, the fine has served its purpose.
OTOH, in a wider context, you have to concede OP's "lol" perspective is true too. The money itself has little/no possible deterrent effect.
"Just for their Dutch operations" is a lawyerly frame... it isn't a business frame. booking.com's Dutch business operations aren't really separate. Any security/transparency practices beyond "compliance" almost certainly exist across borders.
I agree though that a fine (any amount) can be enough to adjust resources/practices on a small scale. On a bigger scale, the threat of a fine (any amount) probably is not enough to deter much. IE, if changes are strategic, costly or impact revenue... a fine will always be cheaper.
Companies spend a lot of money and energy on projecting an image, not only to the outsider but also to the insiders.
Unless they pride themselves for being evil and the cut-throat office politics, I bet this fine will make a dent in someones image and will trigger some policy change or similar.
Companies are not really monoliths, despite of their effort to be seen as such.
The fine? It wasn't even mentioned that a fine would be forthcoming. Until city hall took steps to replace the organisation they refused to modify their systems and stop the still-in-progress leak. It got to be a scandal.
So clearly: the idea is to fine only people they feel like fining. Anything even tangentially related to the government (this is a private for-profit organization (running quite a decent profit I might add, as well as paying management very nicely) that merely works for the government) does not get fined, even for leaking much, much more sensitive information.
Needless to say, CPS has still not changed their processes to better secure medical files. They are still being sent, without any encryption or authentication, over email. So it's not just that they weren't fined: the whole purpose of the data protection law, actually keeping the data safe, was ignored entirely even when they got caught spreading extremely sensitive information around and storing it without encryption.
https://www.rtlnieuws.nl/tech/artikel/4672826/jeugdzorg-data...
> Dit is het ergste wat ons kan overkomen
Sounds like they think it’s some sort of natural disaster that happened to them. I have no words.
Thank god it was two good guys registering the domain.
2. HN is not a single instance but consits out of many individuals.
=> The "opposing reactions" are expectable.
The relevant question, then: what is the history of GDPR enforcement against small companies? Personally I have no idea, as typically only the big cases make the front-page.
For example, a police officer was fined 48 euro for accessing "personal data in a police database for private research activities", a housing association was fined 500 euro for "publishing photos showing members of the association without their consent" and Borjamotor, S.A. (which appears to be a Spanish Opel dealership) was fined 4000 euro for "sending commercial advertisements to the data subject via email and SMS, even though the data subject had previously revoked his/her consent to receive advertisements and submitted a request to delete his/her data".
[1]https://n7uofv7rfwwdpbwmcuqmohfsnu-adwhj77lcyoafdy-www-aki-e...
Netherlands being 1% of the global GDP, this would be proportional to a $50B "global fine" or 50% of the company valuation. So in that sense, it even seems too big.
EU being 20% of the global GDP, this would be proportional to a $2.5B "global fine" or 2.5%, which IMHO seems small-to-fair for a data leak of this type.
>Infringements of the following provisions shall, in accordance with paragraph 2, be subject to administrative fines up to 20 000 000 EUR, or in the case of an undertaking, up to 4 % of the total worldwide annual turnover of the preceding financial year, whichever is higher:
Still, should be 10 or 100 times more.
To be honest, I can live with that.
I would consider as desirable that egregious, systematic and catastrophic security failures would be resulting in fines and penalties large enough to bankrupt companies[0]. But starting from that is rather not a good idea, I agree that some warning is a good idea.
[0] for example 2000$ for every single leaked address that they deliberately collected (if company is scared: then they should not ask user for address data! Companies very rarely actually need it, and they still ask.).
That number is meaningless for how much a company is hurt by a fine. A market valuation is just based on the current stock price. It doesn’t mean that the company has access to that much cash or assets.
>When deciding whether to impose an administrative fine and deciding on the amount of the administrative fine in each individual case due regard shall be given to the following:
>(e) any relevant previous infringements by the controller or processor;
Interesting precedent. The platform is responsible not just for their own security practices, but also their users' security practices.
Well, not really. Booking didn't get fined over security practices. They got fined over not notifying of a breach of their users data within 72 hours.
So you're not really "responsible for users' security practices", you're "responsible for notifying users/authorities in time when you notice leaks/breaches". Seems rather different to me.
As someone booking a hotel on the site, I would expect booking.com to take responsibility for keeping my payment details secure (or, if they want to operate like a marketplace, make it clear that they're not taking responsibility, but in that case it looses a lot of value toe as an end user)
Of course they don't always make this very clear to the consumer, and it seems to have gotten more muddled in the last few years. I think they're trying to nudge people more towards their own payment platform nowadays.
[1] https://www.businessinsider.in/this-is-why-booking-coms-agen...
yeah I stopped using booking because of this. an hotel decided that the card used for reservation was the one to charge for my stay and charged it the day of arrival and I only discovered later when trying to reserve a rental car and I hit my card limit and couldn't.
that pissed me off in so many ways, first because the booking wasn't a upfront pay but hotel did it anyway, second because booking disclosed my cc details to a third party instead of being a neutral escrow, and third of course because it bite me in the ass at the worst possible moment, as my car broke down and I needed to cover a rental and repairs while sorting out the rest of the travel.
> The property will charge you: €xxx
> The date you'll be charged—and what happens if you cancel—depends on the booking conditions.
And then the booking conditions (set by the property):
> You'll be charged a prepayment of the total price at any time.
On top of that, anyone taking a large payment via CC will usually require payment on the same card used for the authorization hold. Accepting another card is risky as funds can be easily made unavailable before the transaction settles.
You just had wrong expectations - on cc charges, that booking would be a “neutral escrow” or be able/willing to help. I’ve been in a similar situation where they held the entire reservation amount, in the thousands, while having already taken payment, and it’s 100% up to the hotel. They just don’t give a shit.
This is yet another reason why CCs are a terrible idea. Having the funds in a checking account and not being able to use them because of credit limit shenanigans is infuriating.
again, you're over generalizing your personal experience. booking on arrival happened to me exactly once. but you're not listening and keep repeating points that don't really apply to the situation at hand.
That's why I've used Agoda every time I could (works well in Asia, spotty elsewhere), because they allow paypal payment. Hotel will still want your card for the deposit but you can just provide it on the first day.
This way you don't have to fight with a place that did overbooking or similar and still has your card on file.
If you as a consumer give your booking.com login information to someone and your information is subsequently stolen, Booking.com would not be responsible for your security practices.
Of course, as the leak would be traced to them as well. When it comes to GDPR you'd like to manage the expose and the liability associated with having the data. Normally it should that even the admin operators are not to be trusted with full account/payment/etc. details enmasse and very special care is taken to exports/reports.
From a certain (not my) point of view poor compliance was just incentivized.
I expect some manager will get a strongly-worded message about their department costing the company half a million because they waited too long before reporting the breach. That department, likely, will also see bad evaluations.
I also expect Booking will use this case as an example to all other departments.
And that’s ignoring the fact that, if Booking doesn’t change, and something similar were to happen again, the fine likely would be higher.
Also, if this article is correct, they have everything in place to handle this kind of breach. In the handling, the only thing that went wrong was that they informed the authority too late. It took them 3 weeks, while it has to happen within 3 days. Booking states they contacted affected customers before that.
If the behavior they were fined for was strategically useful to the company, then they will definitely think “it’s only half a million” and keep doing it unless they think the fine will be much larger next time.
If it was just a fuck-up, then what you're describing will happen.
This is a fine for failing to report a breach after 22 days (not for the breach itself), of around 4000 users.
Though I agree it could be higher for these organizations, it's also not a small fine just to fail to report.
Moreover, repeated violations is expressly a parameter for higher fines. So non compliance as a strategy is not really viable.
https://www.troyhunt.com/data-breach-disclosure-101-how-to-s...
It's such a boring dystopia that the only response they have is "it's from 2019", like WTH?
Any purchase I make, the shop needs my address and my payment info. It's always the same. Every browser can autofill it, if they bothered using the correct forms. Once the transaction is done, the invoice mailed and the product shipped - there is 0 need for this data to still be stored in their database.
-> Address and payment info - browser auto fill
-> purchase history - invoice via mail
I used to be heavily biased to buy from Amazon, since it is basically one click. But lately, I'm more and more buying from smaller online shops which provide checkout without user account.
I'm sure there is many things where you need to store user data, but also, there is definitely more things were user data is stored although it is not needed.
And ultimately, that is the spirit of GDPR - ask yourself if you really need to store that data.
Then the invoice itself (containing your name/address/payment method) will need to be stored by the company in some form for accounting regulations.
This data can often still be necessary for legal and/or tax purposes.
Article 83 ("General conditions for imposing administrative fines") states that:
> Each supervisory authority shall ensure that the imposition of administrative fines pursuant to this Article [...] shall in each individual case be effective, proportionate and dissuasive.
SAs can't just hand out big fines for the sake of big fines. If a fine is issued then the SA's ruling can be challenged on the basis of proportionality.