Skip to content
City PM
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Opinion
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Opinion
Friday 30 October 2020 12:46 pm

Marriott International fined £18.4m over customer data breach

By: James Warrington

Add as a preferred source on Google
CHINA-US-POLITICS-INVESTIGATION-HOTELS-MARRIOTT
Marriott has been fined £18.4m over a cyber attack on the Starwood hotel chain

Marriott International has been handed an £18.4m fine by the UK data watchdog over a data breach that compromised the personal details of millions of customers.

The fine relates to an attack on the Starwood hotels chain that exposed records belonging to 339m guests worldwide.

The cyber attack began in 2014, before Marriott took over the chain, but went undetected until September 2018.

Names, email addresses, phone numbers and passport details were among the data impacted by the breach.

The Information Commissioner’s Office (ICO) today said Marriott had failed to put appropriate measures in place to protect customer data.

While the cyber attack dates back to 2014, the fine only applies to the breach from May 2018, when new GDPR laws came into force.

“Millions of people’s data was affected by Marriott’s failure; thousands contacted a helpline and others may have had to take action to protect their personal data because the company they trusted it with had not,” said information commissioner Elizabeth Denham.

“When a business fails to look after customers’ data, the impact is not just a possible fine, what matters most is the public whose data they had a duty to protect.”

Read more

Episode 91: Royal Ascot 2026 – Day 1 & 2

CityAM promotional teaser showcasing business innovation and urban development in a metropolitan skyline setting

The £18.4m fine is significantly lower than the £99m penalty originally proposed by the ICO. The data watchdog said it had considered the steps Marriott took to mitigate the incident and the impact of Covid-19 on its businesses before setting the final amount.

The company is also facing a group legal action in London on behalf of millions of customers in England and Wales who were affected by the breach.

The hotel chain said it did not intend to appeal the decision, but made no admission of liability relating to the decision or underlying allegations.

It comes after the ICO fined British Airways £20m for a 2018 data breach that affected more than 400,000 customers.

The two fines are the largest to be handed down by the watchdog for failures to properly protect customer data.

“Given the dramatic fall in revenue that the travel and leisure sector has experienced during the coronavirus pandemic, these fines send a very powerful message to organisations that they must invest in keeping their customers’ data secure,” said Chris Combemale, chief executive of the Data & Marketing Association.

“Otherwise they will face penalties that could prove far more costly to the business.”

Read more

Episode 89: Epsom Derby Festival preview with George Waud on Maltese Cross

City skyline with prominent skyscrapers, illustrating economic growth and urban development in a bustling business district

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Business
  • Tech

Related Topics

  • Data protection

Trending Articles

  • Revealed: Secret Treasury plan to tax State Pension before it is paid out

  • Two solicitors linked to Post Office scandal charged with misconduct

  • Burnham’s new chief of staff ran City firm advising Thames Water and rival Heathrow bidder

  • Barclays and Lloyds join banking sector plan for digital ID

  • Clarkson’s Farm and why businesses must stop blaming the weather

More from City PM

  • Episode 91: Royal Ascot 2026 – Day 1 & 2

    Sport
    CityAM promotional teaser showcasing business innovation and urban development in a metropolitan skyline setting
  • Episode 89: Epsom Derby Festival preview with George Waud on Maltese Cross

    Sport
    City skyline with prominent skyscrapers, illustrating economic growth and urban development in a bustling business district
  • Episode 94: Northumberland Plate, Irish Derby and Marco Botti interview

    Sport
    Promotional teaser for upcoming business event showcasing innovative solutions and market trends.
  • Episode 90: George Scott interview, York and the Chris Barnett Memorial Handicap at Sandown

    Sport
    Cityscape with modern architecture and business district skyline, vibrant evening lights illuminating the urban landscape
  • Expensify Launches MCP for AI-powered Expense Management

    Business Wire
  • Manchester City and Chelsea boosted by lawyer’s compensation claims verdict

    Sport Business
    Business professional speaking at a conference podium with a projected presentation slide in the background.
  • Everton ‘surprised and angered’ at losing £40m legal case with Burnley

    Sport Business
    GettyImages 2272351712 showing a business meeting with diverse professionals discussing strategies around a conference table
  • The Debate: Should CEOs be held personally accountable for cyberattacks?

    Opinion
    Evil-looking keyboard symbolizing cybersecurity threats and hacking risks in a digital landscape.

City PM — European politics, business and analysis.

Europe

  • Germany
  • France
  • Europe
  • UK & Ireland

Topics

  • Business
  • Markets
  • AI
  • Technology
  • Opinion
  • Energy

More

  • Politics
  • Economics
  • Fintech
  • Legal
  • Sport
  • Life

Company

  • About City PM
  • Editorial Policy
  • Corrections
  • Contact
  • Terms of Use
  • Privacy Policy
  • Cookie Policy
© 2026 City PM · Published by CityPM Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
About · Editorial Policy · Corrections · Contact · Privacy