Penalty Amount
$52,000,000
Consumers Affected
131,500,000
A multistate settlement with Marriott International for a data breach affecting 131.5 million guest records. Marriott failed to secure the Starwood network from 2014 to 2018, exposing personal information. The settlement includes a $52 million payment and requires Marriott to implement enhanced cybersecurity measures and consumer protections.
Marriott must pay $52 million to states, implement a comprehensive Information Security Program with risk assessments, data minimization, encryption, and vendor oversight, undergo independent audits every two years for 20 years, and provide consumers with data deletion options and multi-factor authentication for loyalty accounts.
In-house legal teams should review all vendor and customer agreements where Marriott processes or stores personal data, particularly those involving guest reservation systems. Focus on data security clauses to ensure they mandate a dynamic, risk-based approach to security controls, including regular risk assessments and encryption of sensitive data. Breach notification provisions must align with the multistate settlement's requirements and various state laws, specifying clear timelines and consumer remediation steps. Data processing and retention clauses should incorporate data minimization principles, limiting collection and storage to what is necessary for business purposes. Contracts may need amendments to include audit rights for security compliance and requirements for third-party security assessments.
Entity
Marriott International, Inc.
Also known as: Marriott
Industry
Other"Marriott International, Inc."
"$52 million"
"state consumer protection laws, personal information protection laws, and, where applicable, breach notification laws"
"failing to implement reasonable data security and remediate data security deficiencies"
$52.0M
A multistate coalition of 50 attorneys general, including New Jersey, reached a $52 million settlement with Marriott International, Inc. for two data breaches that exposed personal information of over 131 million consumers. The breaches resulted from inadequate cybersecurity practices at Starwood and Marriott networks. The settlement mandates comprehensive security improvements and monetary penalties.
$52.0M
A multistate coalition of 50 attorneys general led by New York AG Letitia James reached a $52 million settlement with Marriott International, Inc. over a 2014-2018 data breach of its Starwood subsidiary’s guest reservation database that exposed 131.5 million consumers’ personal information. The breach, which went undetected for four years, compromised contact details, dates of birth, passport numbers, payment card information, and loyalty program data. Marriott is required to overhaul its data security practices, implement new compliance measures, and allow customers to delete their stored data as part of the settlement.
$3.5M
Texas Attorney General Ken Paxton secured a $3.5 million settlement with Marriott International, Inc. following an investigation into a data breach of the company’s reservation database that exposed 131 million U.S. guest records. The breach included sensitive customer information such as contact details, dates of birth, unencrypted passport numbers, and unexpired payment card information. Marriott is required to implement enhanced data security measures, including zero-trust principles and regular security reporting to its CEO, as part of the settlement.
$29.6M
Attorney General Jennifer Davenport joined a coalition of 48 states and territories in a $29.6 million settlement with Glenmark, a generic drug manufacturer, for allegedly conspiring to artificially inflate and manipulate prices, reduce competition, and restrain trade for numerous generic prescription drugs. The settlement includes cooperation in ongoing litigations and internal reforms to ensure fair competition.
$29.6M
Attorney General William Tong led a coalition of 48 states and territories in a $29.6 million settlement with Glenmark, a generic drug manufacturer, to resolve allegations of a widespread conspiracy to artificially inflate prices, reduce competition, and unreasonably restrain trade for numerous generic prescription drugs. The settlement includes cooperation from Glenmark in ongoing multistate litigations and internal reforms to ensure fair competition and compliance with antitrust laws.
$18.0M
Attorney General William Tong led a coalition of 42 attorneys general in a settlement with the bankruptcy trustee for 23andMe, resolving allegations from a 2023 data breach that compromised the genetic data of 6.9 million customers. The settlement includes $150 million in allowed claims, with $18 million paid from bankruptcy funds, and requires enhanced data security measures for the new entity holding the data.