ICO Fines Uber £385,000 for Breach

Following the news that the ICO has fined Uber £385,000 for the 2016 data breach affecting the company, Andrew Lloyd, president of Corero Networks, commented:
"This was one of the last pre-GDPR breaches. Under the previous EU/UK Data Protection rules, the maximum fine was £500k. In this context, a £385k penalty is a hefty fine. I suspect that Uber was hit with a fine at the upper end of the scale (77 percent) as they took rather a long time between the incident and their disclosure.
"Clearly, if a similar incident was to occur again, the ICO could impose a much larger penalty now that GDPR and, for those covered by it, the NIS Regulations are in force. If we assume that the maximum penalty under GDPR and NIS is £17m, a 77 percent fine would be an eye-watering £13m. That level of penalty should act as a wake-up call to all organisations."