Business Travel News EuropeBusiness Travel News Europe
Business Travel News Europe
  • NEWSOpen Menu
    • Accommodation
    • Air Travel
    • Ground Transport
    • Management
    • Meetings
    • On the Move
    • Payment & Expense
    • Technology
    • TMC & Distribution
    • Travel Procurement
    • Recent Issues
  • FEATURESOpen Menu
    • View All Features
  • CONVERSATIONSOpen Menu
    • Interviews and Q&As
    • Guest columns
    • Podcasts
    • VIEW ALL CONVERSATIONS
  • RESOURCESOpen Menu
    • Powered Up: The travel tech of today & tomorrow
    • The Future of Meetings
    • Smart Money: Cards, payments & expenses
    • The Journey Towards Sustainable Business Travel
    • Safety Measures: Risk, duty of care & wellbeing
    • Stepping It Up: Small & midsized travel programmes
    • Diversity, Equity & Inclusion in business travel
    • Business Travel Rebooted
    • New Horizons: The 2022 sourcing guide
    • Wheels in Motion
  • EVENTSOpen Menu
    • Webinars
    • Business Travel Show Europe
    • Business Travel Show Europe Kick Off
    • Business Travel Awards Europe
    • Business Travel Intelligence Summit Europe
    • Business Travel Accommodation Summit
    • Business Travel Tech Talk
    • Entertainment Travel Summit
    • Global Travel Risk Summit
    • Strategic Meetings Summit
    • Sustainable Business Travel Summit Europe
    • VIEW ALL EVENTS
  • SUBSCRIBE
  • NEWSOpen Menu
    • Accommodation
    • Air Travel
    • Ground Transport
    • Management
    • Meetings
    • On the Move
    • Payment & Expense
    • Technology
    • TMC & Distribution
    • Travel Procurement
    • Recent Issues
  • FEATURESOpen Menu
    • View All Features
  • CONVERSATIONSOpen Menu
    • Interviews and Q&As
    • Guest columns
    • Podcasts
    • VIEW ALL CONVERSATIONS
  • RESOURCESOpen Menu
    • Powered Up: The travel tech of today & tomorrow
    • The Future of Meetings
    • Smart Money: Cards, payments & expenses
    • The Journey Towards Sustainable Business Travel
    • Safety Measures: Risk, duty of care & wellbeing
    • Stepping It Up: Small & midsized travel programmes
    • Diversity, Equity & Inclusion in business travel
    • Business Travel Rebooted
    • New Horizons: The 2022 sourcing guide
    • Wheels in Motion
  • EVENTSOpen Menu
    • Webinars
    • Business Travel Show Europe
    • Business Travel Show Europe Kick Off
    • Business Travel Awards Europe
    • Business Travel Intelligence Summit Europe
    • Business Travel Accommodation Summit
    • Business Travel Tech Talk
    • Entertainment Travel Summit
    • Global Travel Risk Summit
    • Strategic Meetings Summit
    • Sustainable Business Travel Summit Europe
    • VIEW ALL EVENTS
  • SUBSCRIBE
Business Travel News Europe
  • Business Travel News Europe on Twitter
  • BTN Europe on LinkedIn
  • BTN Europe on Facebook
  • NEWS
    • Accommodation
    • Air Travel
    • Ground Transport
    • Management
    • Meetings
    • On the Move
    • Payment & Expense
    • Technology
    • TMC & Distribution
    • Travel Procurement
    • Recent Issues
    SubscribeBTN Europe NewsletterBTN Europe Magazine
  • FEATURES
    • View All Features
    2023 Hotlist BTN EuropeThe 2023 Hotlist
    Shanghai ChinaThe great reopening of China?
    Europe from spaceA European tour

  • CONVERSATIONS
    • Interviews and Q&As
    • Guest columns
    • Podcasts
    • VIEW ALL CONVERSATIONS
    David DuffyHow the EU has fixed ESG
    Helen HodgkinsonLet payments shine a light on your environmental impact
    John Sturino, vice president of product and technology, EgenciaWhy business travellers need more control over their trips
  • RESOURCES
    • Powered Up: The travel tech of today & tomorrow
    • The Future of Meetings
    • Smart Money: Cards, payments & expenses
    • The Journey Towards Sustainable Business Travel
    • Safety Measures: Risk, duty of care & wellbeing
    • Stepping It Up: Small & midsized travel programmes
    • Diversity, Equity & Inclusion in business travel
    • Business Travel Rebooted
    • New Horizons: The 2022 sourcing guide
    • Wheels in Motion
    Tools & ResourcesEurope's Leading TMCs 2022Booking tools – the essential guideCorporate Travel Index EuropeTravel entry requirementsBTN Europe podcastsBTSE Kick Off - CEO InterviewsRecent issues of BTN Europe
  • EVENTS
    • Webinars
    • Business Travel Show Europe
    • Business Travel Show Europe Kick Off
    • Business Travel Awards Europe
    • Business Travel Intelligence Summit Europe
    • Business Travel Accommodation Summit
    • Business Travel Tech Talk
    • Entertainment Travel Summit
    • Global Travel Risk Summit
    • Strategic Meetings Summit
    • Sustainable Business Travel Summit Europe
    • VIEW ALL EVENTS
    Business Travel Show Europe Kick Off

    Business Travel Show Europe Kick Off, 23 February,

    7th Annual Global Travel Risk Summit Europe

    Global Travel Risk Summit Europe, April 2023,

    Sustainable Business Travel Summit Europe

    3rd Annual Sustainable Business Travel Summit

  • SUBSCRIBE

ICO's One-Two Punch Hits Marriott with GDPR Fine

By Elizabeth West / 10 July 2019 / Contact Reporter
Share

After sending a chill through the European business community on Monday by levying a record $230 million fine on British Airways for a June 2018 data breach, the U.K.'s Information Commission Office has announced its intent to pursue Marriott International with a $123 million penalty under the EU's General Data Protection Regulation for the hacking incident the hotel giant announced in November 2018.

Marriott's data issues began in 2014 in a system operated by Starwood. Marriott inherited the breach when it acquired Starwood in 2016. Critics, including the U.K. data security watchdog, say Marriott failed in its due diligence, allowing the hack to go unchecked for years as the companies merged their systems.

Ultimately, the breach exposed personal information of 339 million consumers, including 18.5 million encrypted passport numbers, 5 million unencrypted passport numbers, more than 9 million encrypted payment card numbers and 385,000 payment cards still live when Marriott disclosed the breach in November. According to the ICO, 30 million European consumers were affected.


Personal data has a real value so organizations have a legal duty to ensure its security, just like they would do with any other asset. If that doesn’t happen, we will not hesitate to take strong action when necessary to protect the rights of the public."

U.K. Information Commission Office's Elizabeth Denham

In a statement posted on the ICO website, commissioner Elizabeth Denham called out Marriott for its lack of data due diligence and cautioned any company that might have similar lapses of the commission's intent to enforce the GDPR.

"Personal data has a real value so organizations have a legal duty to ensure its security, just like they would do with any other asset. If that doesn’t happen, we will not hesitate to take strong action when necessary to protect the rights of the public," she wrote.

In a securities and exchange filing, Marriott emphasized the fine has been proposed by the ICO and that the hotel company has the right to respond before the ICO can formally impose it. Further, Marriott president and CEO Arne Sorenson voiced his opposition to the ICO's decision to pursue the penalty even as the hotel company has cooperated with the commission's investigation.

"We are disappointed with this notice of intent from the ICO, which we will contest. Marriott has been cooperating with the ICO throughout its investigation into the incident, which involved a criminal attack against the Starwood guest reservation database."

The filing noted that the affected database was no longer used for Marriott business operations.

RELATED: Marriott's Plans for Data Protection

Are More Fines on the Way for Travel Companies?

GDPR fines for data breaches can range up to 10 million euro or 2 percent of a company's annual global revenue, whichever is greater. While the fines for BA and Marriott sound high, the ICO has not exhausted its fining power, according to Samantha Simms, a London-based attorney who specializes in corporate data security and is the senior partner and founder of The Information Collective.

"The 183 million pound [US$230 million] fine was just 1.5 percent of [BA parent company] IAG's annual global turnover," she said. "The ICO warned us big fines are coming. It is making a clear statement to organizations and other data protection authorities. With Brexit looming and the [country potentially then] falling outside of the EU data protection regime, the U.K. will need to prove that it maintains a high standard of GDPR compliance. Hefty fines are a great way to achieve this."

Asked whether the travel industry is uniquely prone to data breaches, Simms demurred. "It's not that the industry is uniquely positioned, but it is a personal-data-rich industry, making it ripe for picking. Prudent travel companies will use this as a warning and an opportunity." Simms advised travel companies to review their data collection and retention to ensure they have no more data than is necessary and to check the controls they put in place for GDPR and other data privacy laws to be certain that they are "living and breathing compliance."

Further, she said, travel managers should expect their travelers to be aware of the potential for data breaches at supplier airlines and hotels, even those mandated under the travel program. If a data breach does occur, there are standard precautions that both travel managers and travelers can take.

"This is just the beginning. We should expect more fines of this nature from the ICO and other EU data protection authorities as they continue to show that the GDPR is a law with real teeth," said Simms. "We should also expect fines from regulators and class action cases outside of the EU as data privacy continues to be a key issue globally."

More

SPONSORED CONTENT

The workplace has changed. Does your travel & expense match up?
The workplace has changed. Does your travel & expense match up?By Cytric by Amadeus

Does your travel & expense match up?... KEEP READING

The eight trends shaping ground transportation
The eight trends shaping ground transportationBy Enterprise National

Eight emerging ground transportation priorities shaping business travel in 2022 and beyond... KEEP READING

  • Most Read
  • Most Shared
  1. Amex GBT adopts ‘segment-driven model’ as Geall takes SME role
  2. Eurostar Group aims to double traffic as new brand launches
  3. Air France launches new business class cabin on long-haul routes
  4. Managed travel unicorn TripActions to rebrand next week
  5. The great reopening of China?
  1. Brexit challenges pile up for UK-EU business travel
  2. Netherlands government appoints business travel partners
  3. European hotel bookings approaching pre-Covid levels
  4. TouristMobile adds Torsten Kriedt to leadership roster
  5. Countries agree goal of achieving net zero for aviation by 2050
Business Travel News EuropeBusiness Travel News Europe
  • About us
  • Contact us
  • Advertise
  • EDITORIAL CALENDAR
  • Business Travel Show Europe
  • Business Travel News Europe on Twitter
  • BTN Europe on LinkedIn
  • BTN Europe on Facebook
BUSINESS TRAVEL NEWS EUROPE
NORTHSTAR TRAVEL GROUP
Business Travel News
  • About us
  • Contact us
  • Advertise
  • Editorial calendar
  • Editorial guidelines
  • Subscribe to BTN Europe
  • Subscribe to BTN U.S.
  • Subscribe to Travel Procurement
  • Privacy policy
  • Terms & conditions
Northstar Travel Group
  • Corporate travel
  • Business Travel Show
  • Business Travel Awards
  • BTN U.S.
  • The Beat
  • Travel Procurement

  • Travel Technology
  • Travel Tech Show
  • Phocuswire
  • Phocuswright
  • Intelliguide
  • Meetings & incentives
  • M&IT
  • AMI
  • ConventionSource
  • M&IT Awards

  • Retail travel
  • Travel Weekly
  • Travel Pulse

  • Northstar Travel Group
  • View all Northstar brands
BTNGroup
Business Travel News EuropeBusiness Travel NewsTravel ProcurementThe BeatBusiness Travel Show Europe
Northstar Travel Group
Copyright ©2022, Northstar Travel Media Ltd, The Epworth, 25 City Road, London EC1Y 1AA, UK
RRManagement rrtestprocurement