British Airways asked customers to post personal information on Twitter ‘to comply with GDPR’
Complaining about airlines on Twitter is a universal pastime for disgruntled travelers, and yet somehow British Airways has managed to turn the activity into a data privacy debacle of its own doing. Security researcher and PhD student Mustafa Al-Bassam discovered yesterday that the airline’s social media team was demanding customers post a trove of personal information publicly on Twitter, so it could help investigate customer service claims. That included passport numbers, full addresses, and other sensitive info, as reported earlier today by TechCrunch.
Even weirder: the airline kept insisting this was to “comply with GDPR,” which is the General Data Protection Regulation. It’s the EU’s new widespread consumer privacy law designed to keep companies from collecting and selling personal information of internet users without their consent. So it doesn’t make much sense why British Airways would require customers post their personal information on Twitter for all to see just to get assistance about a missed or delayed flight.
Al-Bassam notes how, after some users complained about the airline’s bizarrely worded request, it began altering its replies to say that customers should DM them the info instead. Granted, GDPR is an 88-page, 56,000-word law that is quite complex and confusing. It also just went into effect on May 25th and many companies have struggled with compliance. Still, there’s nothing about GDPR that should imply it involves asking people to post personal information to Twitter.
Making matters worse for British Airways, Al-Bassam was only looking into the company’s Twitter activity because he discovered he couldn’t check in for his flight — to a security conference no less — without disabling his ad blocker. It turns out British Airways uses tracking cookies when you check into flights on a web browser that then sends your personal information to third-party sites.
As he notes, without proper consent, this is a violation of GDPR, the same GDPR that British Airways’ social media team thinks it’s complying with by asking people to post personal information on Twitter. After a frustrating back-and-forth with various members of the British Airways team about why there was no consent form or opt-out mechanism, Al-Bassam submitted a complaint to the airline, reposted here, voicing his concerns. He also outlined his plans to submit a more formal GDPR complaint with the UK’s Information Commissioner’s Office within 30 days if the company doesn’t remedy the issue with its web check-in process and ad-tracking practices.
Now, while it’s well understood that GDPR is confusing and takes some time to parse, it seems like there’s a more profound misunderstanding going on over at British Airways.
- eDiscovery Relativity Consultant
- Up to £65,000
REFCH7559 eDiscovery Relativity Consultant, Processing onwards, London, £65,000 London Experienced eDiscovery Relativity Consultant needed to join a London based client. The eDiscovery Relativity Consultant MUST have experience from the process stage onwards of the EDRM cycle. Processing, Review, Analysis, Production, Presentation. Experience optimising and improving analytics highly desirable. Identification and collection experience is useful but not essential. This individual commutable to London based as the role will be predominately office based Relativity Certified Administrator (RCA) Relativity Analytics Specialist Relativity Processing Specialist Relativity Certified User Relativity Infrastructure Specialist Fluency one or more European languages is desirable but not essential. Structured career progression available. All details kept in the strictest of confidence. Contact me on Chris.email@example.com 07884666351 or 02086634030
- Cyber Security Consultant, New Job, Devon, £60,000
Can interview and hire remotely without face to face. Cyber Security Consultant is needed in a client-facing consultancy role in the Devon area. Cyber Security Consultant needs to have a strong information security experience with a technical hands-on background. Travel will be involved with other clients, but a larger proportion of the time will be within the Devon area. This is a Security consultancy role so travel to other client site locations across the country will be expected. Broad InfoSec experience is desirable given the range of projects/programmes you will be involved in. The individual will be required to achieve or currently hold SC security clearance. Apply today. All details kept in the strictest of confidence. Chris.Holt@dclsearch.com 07884666351
- New Business Hunter - Cloud interconnect Services
- €75,000 + €75,000 OTE
Paris Reference RA 7376 Salary up to €75,000 plus 75,000 OTE New Business Hunter - Cloud Interconnect Services A new business hunter is required for this expanding Cloud Connect Services company who are looking to expand their presence within the French Market. They are looking for the right individual who enjoys targeting and winning large enterprise clients, You will be responsible for developing and managing a sales pipeline (qualification of leads, prospecting, monitoring of opportunities, closing ...) in order to go in search of future customers This is a great opportunity to join a rapidly growing business, where you will have the opportunity to become a key member of the Paris team, you will be selling a solution that is in high demand at the moment and will only become more in demand as more business adopt their cloud strategies The company currently has a number of large scale global enterprises as customers so you will have plenty of case studies to call upon. We are looking fr someone with proven new business skills, who can demonstrate new Logo accounts that they have won recently, you will need to be selling either telecom or cloud solutions and have a good understanding on connectivity services
- Hybrid Business Development Manager
- Up to £72,000 + £48,000 Commission
Hybrid Business Development Manager Location: London Salary: up to £72k basic + £48k commission Ref DD7797 JD Our client who is a leading telecommunications provider is looking for a Hybrid Business Development Manager who has experience selling into multinational corporations. This role will be a 40/60 split in favor of new business. As a Hybrid Business Development Manager, you should have the following experience: Experienced in selling network centric managed services sales, encompassing WAN (traditional MPLS, but also SDN/SD WAN) , security, Datacentre (hosting plus saaS), Cloud services and someone who understands the context of these services in the DX landscape. Previous experience targeting large Global MNC’s anchored out of EMEA, that have a significant APAC footprint. Proven track record of new logo/ account management sales. Telecommunications Jobs | Jobs in Telecommunications | Telecoms Jobs