Information pursuant to Art. 34 (1) GDPR on an unauthorized data access in January 2024

In January 2024, an IT system at a service provider commissioned by the Lufthansa Group, which makes hotel bookings in the event of flight cancellations, was subject to unauthorized access. In accordance with Art. 34 (1) GDPR, the Lufthansa Group airlines in question were transparent in informing all affected passengers about this incident and the measures taken by the Lufthansa Group immediately after becoming aware of it in order to protect their data (as long as the contact details were entered at the time of booking). Despite implementing stringent measures, Lufthansa Group could not reach all those affected due to missing or incorrect contact details. To ensure that all those affected are fully informed of the incident, all the relevant information is listed below.