British Airways suffered a major 2018 data breach in which attackers injected malicious code into the BA booking website and app, exposing payment card details (including CVV numbers) of up to 500,000 customers. The ICO fined BA £20 million. BA processes extensive personal data including travel itineraries, passport details, frequent flyer records, and full payment history.
This letter is pre-addressed to British Airways Plc, the official EU data controller for British Airways. Fill in your details and copy or send it directly.
British Airways does not publish a direct DPO email. Use their privacy contact form or send by post to the address shown in the letter.
Dear Data Protection Officer,
I am writing to exercise my rights under the General Data Protection Regulation (GDPR). As an individual whose personal data you process, I am requesting the following information:
Below is my information for your reference:
Name:
Email:
Address:
This request is of utmost importance to me and should not be ignored. The GDPR mandates that you respond within one month. Failure to comply may result in further action being taken.
Thank you for your prompt attention to this matter.
Sincerely,
1. Copy and send this letter to the data controller of the organisation.
2. Follow up until you hear back. The GDPR requires a response within one month.
3. No response? Lodge a complaint with your local data protection authority.
Select your country to find your data protection authority: