Until now, the biggest penalty for a private data breach was the £500,000 imposed on Facebook for its role in the Cambridge Analytica data scandal. At the time, BA said hackers had carried out a "sophisticated, malicious criminal attack" on its website.