Preiskel & CoPreiskel & Co
Preiskel & Co
  • Home
  • About Us
    • Diversity, Social Responsibility, and Pro Bono
  • Services
    • Corporate
    • Commercial
    • Regulatory
    • Competition & Antitrust
    • Data Protection, Privacy, and Retention
    • Intellectual Property
    • Dispute Resolution
    • Employment
  • Sectors
    • Telecommunications
    • IT, Technology, & Internet
    • Media and Broadcasting
    • Websites, Blogging, & Social Media
    • Film & Television
    • Gambling & Online Gaming
    • Leisure & Retail
    • Energy & Minerals
    • Cryptocurrency & Blockchain
    • Creative Industries
  • People
    • Daniel Preiskel
    • Ronnie Preiskel
    • Tim Cowen
    • Jose Saras
    • Robert Dougans
    • Tina Cowen
    • D A T Green
    • Karthyaeni Vittala
    • Mor Swiel
    • Ilanit Appelfeld
    • Charles Soden-Bird
    • Nick Bromfield
    • Stephen Dnes
    • Daniel Oakland
    • Robert Harvey
    • Martina Raciti
    • Matthew Fox
    • Joanna Coombs-Huang
    • Xavier Prida
    • Mark Clough
    • Stewart White
    • Hannah Leader
    • Peter Dally
    • Antony Corel
    • Sue Warwick
    • Galyna Carey
    • Stephen Hornsby
    • Claire Barraclough
  • International
  • Blog
  • News
    • Publications
  • Contact
Menu back  

Inherited GDPR breach still leads to a record fine for Marriott

November 3, 2020By Preiskel & Co

A mere two weeks from the record-breaking British Airways information Commissioner’s Office (“ICO”) £20million fine, Marriott has been handed the second highest General Data Protection Regulation (“GDPR”) penalty at £18million. A striking similarity between the two fines is the steep discount from the original figure (£99.2million) from the ICO’s intention to fine notice dated from July 2019.

Marriott has not admitted liability for the breach, and indeed the hack originally started in the Starwood Hotels and Resorts Worldwide Inc. network in 2014, before Marriott had even offered to acquire the company. The penalty issued at the end of last week, however, only relates to the breach from 25 May 2018 when the new GDPR came into effect.

In their assistance with the investigation, Marriott has estimated that 339 million guest records worldwide were affected following the attack in 2014. The attack, from an unknown source, remained undetected until September 2018, by which time the company had been acquired by Marriott. This has been the source of some discussion as to whether the breach was identifiable during due diligence for purchase. There have been arguments made as to whether Marriott, as an inherited owner of the security failings was being treated fairly by being fined such a significant amount. This was especially pointed when the original notice was for such a large amount, £99.2million. It is worth highlighting that the final decision notice from the ICO does not state whether Marriott would have been able to conduct a due diligence to find the security breach in their acquisition process.

As the breach was dated from before the UK was to leave the EU, and approximately 7 million of the personal data records related to UK data subjects, the ICO led the investigation on behalf of all EU authorities under the GDPR. This is key as the penalty and action taken by the ICO have been approved by the other EU Data Protection Authorities in accordance with the GDPR’s corporation process. To add to their woes, Marriott is also dealing with a separate London class action from the many former guests demanding compensation, as the personal data that was accessed in the breach had included names, email addresses, phone numbers and unencrypted passport numbers among other things.

The ICO found in their investigation that the failure of Marriott to instigate and put into place appropriate technical or organisational measures to protect personal data lead to the increased risk of a breach as required by the GDPR. Representations by Marriott evidencing their penetration testing, and that the use of the Starwood legacy system was to soon be halted, were not accepted as sufficient or a reason to lessen liability.

As a step in the regulatory process the ICO took into consideration Marriott’s actions once they had been informed of the breach. The ICO considered the mitigation Marriott undertook to lessen the impact of the incident and the significant difficulties the company was facing due to COVID-19. It was specifically noted in the report that Marriott acted swiftly to notify customers and the ICO once the breach had been brought to their attention, and that the company has since implemented multiple measures to improve the security of their IT systems.

Following the Marriott representations, the ICO proposed a final fine of £28million. The figure was then discounted by 20 percent to account for the company putting mitigating measures in place and making multimillion-pound security investments in the IT systems reducing the figure to £22.4million. A further 4 million-pound reduction to account for the impact of the COVID-19 pandemic was applied, to reach the final figure of 18.4 million pounds.

As with the British Airways fine, the ICO is demonstrating that there are significant reductions available for companies that demonstrate willingness to cooperate with the regulators, enabling swift communication to affected parties, mitigation of impact of the breach and remediating any damage suffered by the individuals. They may also be opening the door for significant delays in issuing final penalty notices due to lengthy representations by the companies. Marriott’s representation was subject to four extensions for time. Despite the length of the process, it is worth highlighting that there was no such delay in notification of the ICO at the outset, or in contacting customers. These actions and application of the GDPR principles are still a guiding force in how the ICO views the actions of any company that is subject to a breach.

Please contact Jose Saras and Joanna Coombs-Huang if you have any questions relating to data protection policies and procedures.

The material contained in this article is only a general review of the topics covered and does not constitute any legal advice. No legal or business decision should be based on its content.

Latest blog posts
  • CMA announces investigation into Apple
    March 5, 2021
  • Council of Europe publishes guidelines on facial recognition
    February 26, 2021
  • Epic Games files antitrust complaint with European Commission
    February 22, 2021
  • Will the UK keep the VABER?
    February 16, 2021
  • CMA publishes Issues Statement in Liberty Global/Telefónica merger inquiry
    January 22, 2021
  • Epic Games, creator of Fortnite, launches claims against Google and Apple in Competition Appeal Tribunal
    January 21, 2021
  • European Commission proposal for Digital Services Act published
    December 15, 2020
  • Facebook faces antitrust lawsuits in the US
    December 11, 2020
  • CMA issues advice for Government on regulatory regime for tech giants
    December 10, 2020
  • New Telecoms Security Law Laid before Parliament for tougher Rules and Fines for Telecoms Companies
    November 25, 2020
  • New Ofcom Consultation on Copper Retirement
    November 23, 2020
  • European Commission releases draft new Standard Contractual Clauses
    November 19, 2020
The Preiskel Blog
  • CMA announces investigation into Apple 5 Mar 2021
  • Council of Europe publishes guidelines on facial recognition 26 Feb 2021
  • Epic Games files antitrust complaint with European Commission 22 Feb 2021
  • Will the UK keep the VABER? 16 Feb 2021
Preiskel news
  • Tim Cowen to speak at Mediaspace panel on 18 March
  • Tim Cowen gives exclusive interview to Mediaspace
  • English Speaking Union (ESU) educational charity appoints Danny Preiskel to its Board of Trustees
  • Law360 reports on Preiskel & Co dispute resolution team case Dynasty Company for Oil and Gas Trading v the Kurdistan Regional Government of Iraq and Dr Ashti Hawrami
Preiskel tweets
  • The @CMAgovUK announces investigation into @Apple. Find out more here: https://t.co/YQVNzqRMb5 #CompetitionLawyesterday
  • Chair, Antitrust Practice, @TC_4KBW to speak at Mediaspace (@wr_mediabrowser) panel on 18 March. Find out more here… https://t.co/MyxH8lidZg2 days ago
  • Chair of our antitrust practice, @TC_4KBW has given an exclusive interview to Mediaspace @wr_mediabrowser Find out… https://t.co/6Ioii4cf9t3 days ago
Preiskel & Co LLP
4 King's Bench Walk,
Temple,
London
EC4Y 7DL
United Kingdom

Tel:
+44 20 7332 5640
Email:
info@preiskel.com

Find us on:

TwitterLinkedinMail
© Preiskel & Co LLP 2021 | Site map | Legal notices | Privacy | Cookie Policy