MKB Juristen drafts custom legal documents
It is best not to cobble together or copy important contracts, terms and conditions, and other legal documents yourself. We help entrepreneurs on a budget with customized legal solutions, clear costs upfront, and practical explanations.
- Custom contracts, terms and conditions, and legal documents
- Budget-friendly and clear about the costs upfront
- Request a free consultation or a no-obligation quote
Booking.com was fined €475,000 because it failed to report a data breach to the Dutch Data Protection Authority within the statutory 72 hours. The lesson: a data breach must be reported within 72 hours of discovery, even if it occurs outside Europe — after all, Booking is based in the Netherlands. Moreover, acting quickly limits the damage for victims.
Although the data breach occurred in the United Arab Emirates and Booking is a subsidiary of the American Booking Holdings Inc., it is officially based in the Netherlands and should have reported the breach to the AP in a timely manner.
What happened?
In December 2018, criminals gained access to data of people who had booked a hotel room in the UAE. The problem originated with the extranet, an online dashboard accessible to accommodations using a username, password, and a 2FA PIN. The criminals had obtained login credentials from local hotel staff; the leak was therefore unrelated to Booking's own security regarding codes or databases.
The criminals obtained the names, phone numbers, booking details, and addresses of 4,109 people, as well as credit card details for 283 of them, and in 97 cases even the security code. They then called customers, pretended to be from the hotel — credible, because they had all the booking details — and scammed them by asking for a second payment.
The error: late notification
On January 13, 2019, Booking was notified by the hotels. Like every Dutch company, Booking is required to report a data breach within 72 hours of discovery — as IT company RDC, for example, also did with the data breach at car companies. However, Booking waited until February 7: 22 days too late. This prompt reporting is mandatory for a reason — it ensures victims are warned sooner and criminals do not get weeks to scam thousands of customers.
A fine of 475,000 euros
The AP imposed a fine for the late notification. However, the regulator did take damage-mitigating measures into account: Booking pledged compensation, posted warnings on the platform, and informed affected accommodations. Therefore, the AP reduced the fine by 50,000 euros, to a final 475,000 euros. The fine relates only to the late notification, not to the security measures. Booking acknowledged the error, paid the fine, fully reimbursed affected customers, and did not appeal.
The case shows that the AP can impose heavy fines even without security flaws. The number of data breach notifications has been rising for some time — by about 30% in 2020 compared to 2019.
Frequently Asked Questions
Within what timeframe must I report a data breach?
In principle, within 72 hours of discovery to the Dutch Data Protection Authority. In the event of a high risk, the data subjects must also be informed without delay.
Does the reporting obligation also apply to a leak outside Europe?
Yes, if your company falls under the GDPR (for example, due to being established in the Netherlands), the notification obligation also applies to breaches that occur elsewhere.
Will I get a fine if I haven't made a security mistake?
That is possible. The Booking fine related purely to the late notification, not to the security. Reporting late is punishable by a fine in itself.
Ensure your data breach process is in order
A late notification can result in a hefty fine. The privacy experts at MKB Juristen help you set up a watertight data breach process. View our expertise in privacy and data protection or schedule a free intake consultation .