UK Regulators Propose $123 Million Fine Against Marriott for Massive Data Breach
The UK's Information Commissioner's Office proposes a £99 million fine against Marriott for failing to secure the guest database of its acquired Starwood properties. The penalty follows a record GDPR fine issued to British Airways just one day prior.
The UK Information Commissioner's Office (ICO) proposes a £99 million ($123 million) fine against Marriott for a massive data breach that exposes up to 383 million guest records. The incident stems from a hack on the Starwood guest reservation database, which includes five million unencrypted passport numbers and eight million credit card records. Although the breach dates back to 2014, Marriott does not discover the intrusion until November 2018, long after acquiring the Starwood hotel brand.
The ICO states that Marriott fails to undertake sufficient due diligence when it buys Starwood and does not do enough to secure its systems. This lack of proper security impacts approximately 30 million European Union residents. Under the strict GDPR regime, regulators have the authority to fine companies up to four percent of their annual global turnover, making this proposed penalty roughly three percent of Marriott's 2018 revenue.
Marriott strongly disagrees with the proposed penalty and plans to vigorously defend its position before a final decision is made. The hotel giant insists it cooperates fully with the ICO throughout the investigation and characterizes the incident as a criminal attack. This massive proposed fine arrives just one day after the ICO issues a record £183 million penalty to British Airways for a separate credit card skimming breach.