Skip to content

Menu

LexBlog, Inc. logo
NetworkSub-MenuBrowse by SubjectBrowse by PublisherJoin the NetworkGet StartedSubscribeSupportContact
Search
Close

UK ICO Intends to Fine Marriott over £99m for Personal Data Breach under the GDPR

By Oliver Yaros & Mark A. Prinsley on July 11, 2019
Email this postTweet this postLike this postShare this post on LinkedIn

In its second statement of intent of the week, on 9 July 2019, the UK’s Information Commissioner’s Office (“ICO”) announced its intention to fine Marriott International, Inc (“Marriott”) £99.2m under the General Data Protection Regulation (“GDPR”) for a personal data breach that occurred in relation to the Starwood guest reservation database system.

The breach is believed to have started when Starwood hotels systems were affected by a cyber-attack in 2014.  The breach was uncovered and notified to the ICO in November 2018, two years after Starwood’s acquisition by Marriott.  Personal data contained in over 330 million guest records were exposed by the incident.  About 30 million records related to individuals from over 30 countries in the European Economic Area (EEA). Around 7 million records related to individuals located in the UK.

The ICO determined that Marriott should have taken additional steps to review and secure the IT infrastructure used by Starwood.  The ICO noted that Marriott had co-operated with the investigation conducted by the ICO and had improved its security practices since the incident.  Marriott has been invited to make further representations to the ICO about the calculation of the fine before the ICO takes its final decision.   The ICO has said that it will carefully consider any representations made by Marriott and the other European data protection supervisory authorities before it makes its final determination.

Under the GDPR, a data protection supervisory authority can issue a maximum fine of up to 20 million Euros or 4% of the total annual worldwide turnover in the preceding financial year of the relevant undertaking for a serious violation of the GDPR, whichever figure is higher.

 

This article was originally published on AllAboutIP – Mayer Brown’s blog on relevant developments in the fields of intellectual property and unfair competition law.

Photo of Oliver Yaros Oliver Yaros

Oliver Yaros is a partner in the Intellectual Property & IT Group as well as the Technology & IP Transactions and Cybersecurity & Data Privacy practices of the London office of Mayer Brown. He advises clients on technology and outsourcing transactions with a…

Oliver Yaros is a partner in the Intellectual Property & IT Group as well as the Technology & IP Transactions and Cybersecurity & Data Privacy practices of the London office of Mayer Brown. He advises clients on technology and outsourcing transactions with a particular focus on fintech and digital transformation projects, as well as clients operating within a broad range of sectors on data protection matters and cybersecurity incidents, intellectual property transactions and related issues.

Read Oliver’s full bio.

Read more about Oliver YarosEmail
Show more Show less
Photo of Mark A. Prinsley Mark A. Prinsley

Mark Prinsley is a partner and heads the technology practice in the London office, and is a member of the firm’s Cybersecurity & Data Privacy practice. He concentrates on technology transactions, in particular IT projects and outsourcing.

A substantial element of Mark’s practice…

Mark Prinsley is a partner and heads the technology practice in the London office, and is a member of the firm’s Cybersecurity & Data Privacy practice. He concentrates on technology transactions, in particular IT projects and outsourcing.

A substantial element of Mark’s practice involves data protection issues and he has worked extensively for clients in the pensions and financial services sector designing and implementing GDPR compliant systems for the collection and processing of personal data by businesses and related sub-contractors, commercial transactions involving data sharing and reaction to data breach scenarios including managing data breach notifications. Recent projects Mark has worked on involving personal data include working for an automobile manufacturer implementing a connected vehicle programme globally, a supplier of facial recognition technology on methods of marketing that technology in Europe in compliance with data protection laws and for an insurtech business licensing technology and services to enable life insurers to underwrite life cover for diabetics using AI.

Read Mark’s full bio.

Read more about Mark A. PrinsleyEmail
Show more Show less
  • Posted in:
    Privacy and Cybersecurity
  • Blog:
    All About IP
  • Organization:
    Mayer Brown

Call us at 1-800-913-0988 or email sales@lexblog.com.

Facebook LinkedIn Twitter RSS
The Library at LexBlog
  • About LexBlog
  • The Field We Built
  • Library at LexBlog
  • Our Beliefs
  • Our Team
  • Contact LexBlog
  • Disclaimer
  • Editorial Policy
  • Terms of Service
  • Get Started
  • Publishing Solutions
  • Compass
  • Submit a Request
  • Support Center
  • System Status
Copyright © 2026, LexBlog, Inc. All Rights Reserved.
Law blog design & platform by LexBlog LexBlog Logo