← All enforcement actions
GDPRHospitality

Marriott International£18.4M GDPR fine (2020)

Starwood acquisition inherited a 4-year undetected breach — 339M records

Penalty
£18.4M
Regulator
UK ICO
Jurisdiction
United Kingdom
Records affected
339M

What happened

When Marriott acquired Starwood in 2016, it inherited a guest-reservation database that had been compromised since 2014. The breach was not detected until 2018, exposing 339M guest records (passport numbers, payment cards, contact info). ICO's penalty was reduced from a proposed £99M to £18.4M.

Root cause

What every team should do

  1. Make a security + privacy assessment a mandatory closing condition for M&A
  2. Plan post-close re-platforming with a hard sunset date for inherited systems
  3. Run threat-hunting + SIEM coverage extension on day 1 post-close
Source: ICO monetary penalty notice (Oct 30, 2020).
Would your controls have stopped this?

ComplianceIQ audits your existing policies in 60 seconds and shows you exactly which GDPR controls you are missing — mapped to enforcement patterns like this one.

Run my GDPR audit Generate missing policies

Related enforcement actions

Meta Platforms
€1.2B
Largest GDPR fine ever — EU→US data transfers under invalidated Privacy Shield framework
Amazon Europe Core
€746M
Largest GDPR fine at the time — behavioural ad targeting without valid consent
TikTok
€345M
Children's accounts defaulted to public — GDPR Articles 5, 12, 24, 25 violations
Meta / Instagram
€405M
Children's business-account email + phone exposed publicly