Preiskel & CoPreiskel & Co
Preiskel & Co
  • Home
  • About Us
    • Diversity, Social Responsibility, and Pro Bono
  • Services
    • Corporate
    • Commercial
    • Regulatory
    • Competition & Antitrust
    • Data Protection, Privacy, and Retention
    • Intellectual Property
    • Dispute Resolution
    • Employment
  • Sectors
    • Telecommunications
    • IT, Technology, & Internet
    • Media and Broadcasting
    • Websites, Blogging, & Social Media
    • Film & Television
    • Gambling & Online Gaming
    • Leisure & Retail
    • Energy & Minerals
    • Cryptocurrency & Blockchain
    • Creative Industries
  • People
    • Daniel Preiskel
    • Ronnie Preiskel
    • Tim Cowen
    • Jose Saras
    • Robert Dougans
    • Tina Cowen
    • D A T Green
    • Karthyaeni Vittala
    • Richard Stewart
    • Mor Swiel
    • Ilanit Appelfeld
    • Stephen Dnes
    • Daniel Oakland
    • Robert Harvey
    • Martina Raciti
    • Joanna Coombs-Huang
    • Xavier Prida
    • Mark Clough
    • Stewart White
    • Alison MacFarlane
    • Hannah Leader
    • Peter Dally
    • Antony Corel
    • Sue Warwick
    • Shardi Shameli
    • Stephen Hornsby
    • Ewelina Korgol
    • Maria Constantin
    • Sophia Yakhno
  • International
  • Blog
  • News
    • Publications
  • Contact
Menu back  

Inherited GDPR breach still leads to a record fine for Marriott

November 3, 2020By Preiskel & Co

A mere two weeks from the record-breaking British Airways information Commissioner’s Office (“ICO”) £20million fine, Marriott has been handed the second highest General Data Protection Regulation (“GDPR”) penalty at £18million. A striking similarity between the two fines is the steep discount from the original figure (£99.2million) from the ICO’s intention to fine notice dated from July 2019.

Marriott has not admitted liability for the breach, and indeed the hack originally started in the Starwood Hotels and Resorts Worldwide Inc. network in 2014, before Marriott had even offered to acquire the company. The penalty issued at the end of last week, however, only relates to the breach from 25 May 2018 when the new GDPR came into effect.

In their assistance with the investigation, Marriott has estimated that 339 million guest records worldwide were affected following the attack in 2014. The attack, from an unknown source, remained undetected until September 2018, by which time the company had been acquired by Marriott. This has been the source of some discussion as to whether the breach was identifiable during due diligence for purchase. There have been arguments made as to whether Marriott, as an inherited owner of the security failings was being treated fairly by being fined such a significant amount. This was especially pointed when the original notice was for such a large amount, £99.2million. It is worth highlighting that the final decision notice from the ICO does not state whether Marriott would have been able to conduct a due diligence to find the security breach in their acquisition process.

As the breach was dated from before the UK was to leave the EU, and approximately 7 million of the personal data records related to UK data subjects, the ICO led the investigation on behalf of all EU authorities under the GDPR. This is key as the penalty and action taken by the ICO have been approved by the other EU Data Protection Authorities in accordance with the GDPR’s corporation process. To add to their woes, Marriott is also dealing with a separate London class action from the many former guests demanding compensation, as the personal data that was accessed in the breach had included names, email addresses, phone numbers and unencrypted passport numbers among other things.

The ICO found in their investigation that the failure of Marriott to instigate and put into place appropriate technical or organisational measures to protect personal data lead to the increased risk of a breach as required by the GDPR. Representations by Marriott evidencing their penetration testing, and that the use of the Starwood legacy system was to soon be halted, were not accepted as sufficient or a reason to lessen liability.

As a step in the regulatory process the ICO took into consideration Marriott’s actions once they had been informed of the breach. The ICO considered the mitigation Marriott undertook to lessen the impact of the incident and the significant difficulties the company was facing due to COVID-19. It was specifically noted in the report that Marriott acted swiftly to notify customers and the ICO once the breach had been brought to their attention, and that the company has since implemented multiple measures to improve the security of their IT systems.

Following the Marriott representations, the ICO proposed a final fine of £28million. The figure was then discounted by 20 percent to account for the company putting mitigating measures in place and making multimillion-pound security investments in the IT systems reducing the figure to £22.4million. A further 4 million-pound reduction to account for the impact of the COVID-19 pandemic was applied, to reach the final figure of 18.4 million pounds.

As with the British Airways fine, the ICO is demonstrating that there are significant reductions available for companies that demonstrate willingness to cooperate with the regulators, enabling swift communication to affected parties, mitigation of impact of the breach and remediating any damage suffered by the individuals. They may also be opening the door for significant delays in issuing final penalty notices due to lengthy representations by the companies. Marriott’s representation was subject to four extensions for time. Despite the length of the process, it is worth highlighting that there was no such delay in notification of the ICO at the outset, or in contacting customers. These actions and application of the GDPR principles are still a guiding force in how the ICO views the actions of any company that is subject to a breach.

Please contact Jose Saras and Joanna Coombs-Huang if you have any questions relating to data protection policies and procedures.

The material contained in this article is only a general review of the topics covered and does not constitute any legal advice. No legal or business decision should be based on its content.

Latest Preiskel & Co blog posts
  • Claim against NHS Trust for breach of DPA 1998 and misuse of private information dismissed
    April 28, 2022
  • TikTok Class action for the Misuse of Child Personal Data
    April 28, 2022
  • ICO consultation on draft guidance for the research provisions within the UK GDPR and the DPA 2018
    April 20, 2022
  • European Strategy for Artificial Intelligence – a framework to regulate AI and its potential impact on the UK
    April 19, 2022
  • Meta hit by 17 million euro fine by Irish regulator
    April 19, 2022
  • Ofcom has mandated that telecoms providers ensure British Sign Language (BSL) for 999
    March 18, 2022
  • Ofcom publishes statement on the future of telephone numbers
    March 15, 2022
  • German court sends biometric data questions to the ECJ
    February 23, 2022
  • Meta fined £1.5m by CMA
    February 7, 2022
  • International data transfer agreement and addendum laid before Parliament
    February 4, 2022
  • CMA publishes statement of scope in music and streaming market study
    February 1, 2022
  • Google Privacy Sandbox faces European Commission complaint from German publishers
    January 24, 2022

The Preiskel Blog

  • Claim against NHS Trust for breach of DPA 1998 and misuse of private information dismissed 28 Apr 2022
  • TikTok Class action for the Misuse of Child Personal Data 28 Apr 2022
  • ICO consultation on draft guidance for the research provisions within the UK GDPR and the DPA 2018 20 Apr 2022
  • European Strategy for Artificial Intelligence – a framework to regulate AI and its potential impact on the UK 19 Apr 2022

Preiskel news

  • Daniel Preiskel and Xavier Prida lecturing to Academia Mexicana del Derecho Informático and Abogado Digital
  • Preiskel & Co advises Mexico-based premium content production company Dopamine
  • Danny Preiskel was ranked as a Global Elite Thought Leader in Telecoms & Media by WhosWhoLegal Data 2022
  • Danny Preiskel featured in GCCM (Global Carrier Community Magazine)
Preiskel tweets
  • @jwrosewell @m4aow @w3c @IABTechLab Our pleasure!63 days ago
  • RT @jwrosewell: Great work from @Preiskel and the whole @m4aow team. Thank you. Much for @w3c, @IABTechLab, and others to consider in this…63 days ago
  • RT @TC_4KBW: Google’s battle with publishers shows that at every turn it seeks to block others from competing. it blocked header bidding, b…63 days ago
Preiskel & Co LLP
4 King's Bench Walk,
Temple,
London
EC4Y 7DL
United Kingdom

Tel: +44 20 7332 5640
Email: info@preiskel.com

Find us on:

TwitterLinkedinMail
© Preiskel & Co LLP 2022 | Site map | Legal notices | Privacy | Cookie Policy | Privacy | Fraud Notice