City
Epaper

UK watchdog fines Marriott 18.4mn pounds over data breach

By IANS | Updated: November 2, 2020 20:49 IST

London, Nov 2 The UK's Information Commissioner's Office (ICO) has fined Marriott International 18.4 million pounds (nearly $23.8 million) ...

Open in App

London, Nov 2 The UK's Information Commissioner's Office (ICO) has fined Marriott International 18.4 million pounds (nearly $23.8 million) over a 2014 customer data breach.

The penalty announced last Friday is significantly lower than the 99 million pounds fine originally proposed in July 2019.

The ICO said before setting a final penalty, it considered representations from Marriott, the steps Marriott took to mitigate the effects of the incident and the economic impact of Covid-19 on their business.

Marriott estimates that 339 million guest records worldwide were affected following a cyberattack in 2014 on Starwood Hotels and Resorts Worldwide Inc.

The attack, from an unknown source, remained undetected until September 2018, by which time the company had been acquired by Marriott.

The personal data involved differed between individuals but may have included names, email addresses, phone numbers, unencrypted passport numbers, arrival/departure information, guests' VIP status and loyalty programme membership number.

The precise number of people affected is unclear as there may have been multiple records for an individual guest, ICO said, adding that seven million guest records related to people in the UK.

The ICO's investigation found that there were failures by Marriott to put appropriate technical or organisational measures in place to protect the personal data being processed on its systems, as required by the General Data Protection Regulation (GDPR).

"Personal data is precious and businesses have to look after it. Millions of people's data was affected by Marriott's failure; thousands contacted a helpline and others may have had to take action to protect their personal data because the company they trusted it with had not," Information Commissioner, Elizabeth Denham, said in a statement.

"When a business fails to look after customers' data, the impact is not just a possible fine, what matters most is the public whose data they had a duty to protect."

The ICO's investigation traced the cyberattack back to 2014, but the penalty only relates to the breach from 25 May 2018, when new rules under the GDPR came into effect.

 

( With inputs from IANS )

Disclaimer: This post has been auto-published from an agency feed without any modifications to the text and has not been reviewed by an editor

Open in App

Related Stories

NationalFive killed in Chhattisgarh road accident

CricketIndia A seal nail biting win in third One Day to clinch 2-1 series win against Australia A

Other SportsWomen’s World Cup: 'I'm sure everyone back home is happy as well', says Harmanpreet after big win over Pakistan

NationalHagrama Mohilary sworn in as BTC chief; possible BPF-BJP alliance on the horizon

Other SportsWomen’s World Cup: Kranti, Deepti three-fers give India emphatic 88-run win over Pakistan

Technology Realted Stories

TechnologyBSNL’s indigenous 4G network to be upgraded to 5G in next 6-8 months: Minister

TechnologyPeople’s Plan Campaign paves the way for more responsive, empowered Panchayats

TechnologyIndia should focus on atmanirbhar innovation, aims to rank in top five AI nations globally: Scindia

TechnologyImpact of GST reforms starts showing as festive sales breaks 10-year record: Experts

TechnologyBitcoin touches record high crossing $125,000