Skip to content
Sunday 9 August 2026London --:--Frankfurt --:--Zurich --:--
NewslettersSearchEN · DE
MorningWire

European business, markets and politics

FTSE 100
10,901.09
+0.31%
DAX
26,319.45
+0.69%
CAC 40
8,714.93
+0.17%
STOXX 50
6,523.86
+0.33%
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
More
GermanyFranceBankingAIEnergyFintechPropertyCapital Markets
  • Germany
  • France
  • Europe
  • Markets
  • Business
  • Economy
  • Technology
  • Politics
  • Opinion
  • DE
Friday 30 October 2020 12:46 pm

Marriott International fined £18.4m over customer data breach

By: James Warrington

Add as a preferred source on Google
CHINA-US-POLITICS-INVESTIGATION-HOTELS-MARRIOTT
Marriott has been fined £18.4m over a cyber attack on the Starwood hotel chain

Marriott International has been handed an £18.4m fine by the UK data watchdog over a data breach that compromised the personal details of millions of customers.

The fine relates to an attack on the Starwood hotels chain that exposed records belonging to 339m guests worldwide.

The cyber attack began in 2014, before Marriott took over the chain, but went undetected until September 2018.

Names, email addresses, phone numbers and passport details were among the data impacted by the breach.

The Information Commissioner’s Office (ICO) today said Marriott had failed to put appropriate measures in place to protect customer data.

While the cyber attack dates back to 2014, the fine only applies to the breach from May 2018, when new GDPR laws came into force.

“Millions of people’s data was affected by Marriott’s failure; thousands contacted a helpline and others may have had to take action to protect their personal data because the company they trusted it with had not,” said information commissioner Elizabeth Denham.

“When a business fails to look after customers’ data, the impact is not just a possible fine, what matters most is the public whose data they had a duty to protect.”

Read more

London-listed healthcare services firm hit by cyberattack

Assura has been the subject of a ferocious bidding war for nearly six months

The £18.4m fine is significantly lower than the £99m penalty originally proposed by the ICO. The data watchdog said it had considered the steps Marriott took to mitigate the incident and the impact of Covid-19 on its businesses before setting the final amount.

The company is also facing a group legal action in London on behalf of millions of customers in England and Wales who were affected by the breach.

The hotel chain said it did not intend to appeal the decision, but made no admission of liability relating to the decision or underlying allegations.

It comes after the ICO fined British Airways £20m for a 2018 data breach that affected more than 400,000 customers.

The two fines are the largest to be handed down by the watchdog for failures to properly protect customer data.

“Given the dramatic fall in revenue that the travel and leisure sector has experienced during the coronavirus pandemic, these fines send a very powerful message to organisations that they must invest in keeping their customers’ data secure,” said Chris Combemale, chief executive of the Data & Marketing Association.

“Otherwise they will face penalties that could prove far more costly to the business.”

Read more

‘The problems didn’t begin with John Edwards’: Pressure grows for wider data watchdog overhaul

Offi

Share this article

  • Facebook
  • X
  • LinkedIn
  • WhatsApp
  • Email

Similarly tagged content:

Sections

  • News

Categories

  • Business
  • Tech

Related Topics

  • Data protection

Trending Articles

  • Stop burying us in swollen corporate reports, says audit watchdog boss

  • Hargreaves Lansdown orders staff back to office

  •  Burnham to unveil new cost of living measures on UK tour

  • How Britain can stay clear of rivals as home of overseas sport club owners

  • Why the Loire Valley is about so much more than fairytale castles

More from Morning Wire

  • London-listed healthcare services firm hit by cyberattack

    Markets
    Assura has been the subject of a ferocious bidding war for nearly six months
  • ‘The problems didn’t begin with John Edwards’: Pressure grows for wider data watchdog overhaul

    Tech
    Offi
  • UK government probes OpenAI breach after ‘unprecedented’ hack

    Tech
    Sam Altman discussing OpenAIs ChatGPT advancements at a press conference, emphasizing AI innovation and future developments
  • Tesco Mobile breaches £600m debt facility after reporting failure

    Telecoms
    Overhead view of a brightly lit Tesco store interior with shoppers, product aisles, and Clubcard Prices signage.
  • Virgin Media slapped with £28m fine for stopping customers cancelling deals

    Telecoms
    Vans parked at a bustling city intersection surrounded by tall buildings and pedestrians, highlighting urban transportatio...
  • Thames Water faces fresh threat to survival after pensions regulation breach

    Water
    Thames Water infrastructure with pipes and maintenance workers, highlighting water management efforts in London
  • TikTok loses court battle over £12.7m child privacy fine

    Tech
    Tiktok appeals to overturn US ban in a broader battle for tech regulation
  • Former Southern Water boss charged with conspiracy to defraud

    Law
    Southern Water safety sign on a chain link fence, detailing required PPE like hard hats and safety boots.
MorningWire

Independent European business, markets and political news for decision-makers.

Morning Briefing

Europe

  • Germany
  • France
  • Europe
  • UK & Ireland

Business

  • Markets
  • Banking
  • Technology
  • Energy
  • Property
  • Fintech

Editorial

  • Opinion
  • Editorial Policy
  • Corrections
  • Contact

Company

  • About Morning Wire
  • Privacy Policy
  • Terms of Use
  • Cookie Policy
© 2026 Morning Wire Ltd · Published by Morning Wire Media, Bahnhofstrasse 65, 8001 Zürich, Switzerland
Privacy · Terms · Cookies · Facebook