Marriott fined £18.4m under GDPR

UK – Hotel group Marriott International has been fined £18.4m by the Information Commissioner’s Office (ICO) for a data protection breach. 

Marriott hotel_crop

The fine relates to a cyber attack in 2014 on Starwood Hotels and Resorts Worldwide, which was not detected until September 2018, when the company had been acquired by Marriott.

The number of guest records affected by the breach is estimated to be 339 million, and seven million guest records related to people in the UK.

Personal data involved may have included names, email addresses, phone numbers and unencrypted password numbers, the ICO said.

An investigation by the regulator found Marriott had failed to put in place ‘appropriate measures’ to protect the personal data being processed, as required by the General Data Protection Regulation (GDPR).

While the investigation traced the cyber attack to 2014, the penalty only relates to the breach from 25th May 2018, when GDPR came into effect.

The ICO initially issued a notice of intent to fine Marriott £99m in July 2019. The regulator said Marriott had promptly contacted customers and the ICO about the incident and has since introduced new security measures.

Information commissioner Elizabeth Denham said: “Personal data is precious and businesses have to look after it. Millions of people’s data was affected by Marriott’s failure; thousands contacted a helpline and others may have had to take action to protect their personal data because the company they trusted it with had not.”

In a statement posted on the Marriott International website, the company said: “Marriott does not intend to appeal the decision, but makes no admission of liability in relation to the decision or the underlying allegations. As the ICO acknowledges, Marriott cooperated fully throughout the investigation.” 

We hope you enjoyed this article.
Research Live is published by MRS.

The Market Research Society (MRS) exists to promote and protect the research sector, showcasing how research delivers impact for businesses and government.

Members of MRS enjoy many benefits including tailoured policy guidance, discounts on training and conferences, and access to member-only content.

For example, there's an archive of winning case studies from over a decade of MRS Awards.

Find out more about the benefits of joining MRS here.

0 Comments


Display name

Email

Join the discussion

Newsletter
Stay connected with the latest insights and trends...
Sign Up
Latest From MRS

Our latest training courses

Our new 2025 training programme is now launched as part of the development offered within the MRS Global Insight Academy

See all training

Specialist conferences

Our one-day conferences cover topics including CX and UX, Semiotics, B2B, Finance, AI and Leaders' Forums.

See all conferences

MRS reports on AI

MRS has published a three-part series on how generative AI is impacting the research sector, including synthetic respondents and challenges to adoption.

See the reports

Progress faster...
with MRS 
membership

Mentoring

CPD/recognition

Webinars

Codeline

Discounts