Netherlands-based Booking.com suffered a breach in 2018 and failed to report it within the GDPR’s required 72-hour notification period.
Monique Verdier, vice president of the Dutch Data Protection Authority, said in a statement announcing the fine, “This is a serious violation.”