Information Commissioner (ICO) · 30 October 2020
Marriott International, Inc
Insufficient technical and organisational measures to ensure information security
- Regulator
- Information Commissioner (ICO)
- Decided
- 30 October 2020
- Country
- United Kingdom
- Sector
- Accommodation and Hospitality
- Regulator’s reference
- Not recorded
- Fino case number
- 2020/GB/002
What happened
The Information Commissioner’s Officer (ICO) imposed a fine of € 20.7 million on Marriott International Inc (“Marriott”) for failing to ensure appropriate security when processing its costumers’ personal data, thus violating Article 5(1)(f) and Article 32 GDPR. Investigations began following notification of an attack on Marriott’s IT systems that took place over a period of time that includes May 2018 (when the GDPR came into force) to September 2018 . As a result, the attacker(s) had access to vast amounts of costumers’ personal data: Marriot estimated that they accessed 339 million guest records, with 30.1 million being EEA members’ records and 7 million being associated with the UK.
Summary from the GDPRhub page for this decision, written by its volunteers, not by Fino. CC BY-NC-SA 4.0.
Rules involved
- Data security
Sources
The facts on this page come from the sources above, as they recorded them. Nothing has been estimated or filled in. Not legal advice.
Spotted a mistake? Write to angelillolorenzo@gmail.com and quote 2020/GB/002.