GDPR Fines

A public record of GDPR enforcement across Europe — compiled by INPLP members

Marriott International Inc

Country
United Kingdom
Fine
18,400,000 GBP
Date
2020-10-30
Sector
Transport and leisure
Articles
Art 32 GDPR

Monetary fine for failure to provide adequate security arrangements to protects its customers' personal data as per Art 32 GDPR

The ICO issued a notice of its intention to fine Marriott International Inc for a breach of Art. 32 GDPR relating to a cyber incident in November 2018. Personal data belonging to approximately 339 million guest records globally were exposed by the incident, of which 7 million were UK residents. It is believed the vulnerability began when the systems of the Starwood Hotels group were compromised in 2014. Marriott subsequently acquired Starwood in 2016, but the exposure of customer information was not discovered until 2018. The ICO’s investigation found that Marriott failed to undertake sufficient due diligence when it bought Starwood and should have done more to secure its systems. On 30 October 2020, the ICO announced its final decision to impose a fine of £ 18.4 million (approximately €20.4 million) on Marriott International Inc. In its decision, the ICO outlined various factors that influenced its calculation of the fine, which included Marriott's lack of prior violations and the fact that Marriott had fully cooperated with the investigation. In addition, the ICO noted that the fine was in line with other fines imposed by other European data protection authorities.