Court Rules
All enforcement actions
SettlementCritical RiskMultistate

Multistate AGs Settle with Marriott for $52M Over Data Breach

Marriott International, Inc.October 9, 2024Connecticut Attorney General

Penalty Amount

$52,000,000

Consumers Affected

131,500,000

Summary

A multistate settlement with Marriott International for a data breach affecting 131.5 million guest records. Marriott failed to secure the Starwood network from 2014 to 2018, exposing personal information. The settlement includes a $52 million payment and requires Marriott to implement enhanced cybersecurity measures and consumer protections.

Remedy

Marriott must pay $52 million to states, implement a comprehensive Information Security Program with risk assessments, data minimization, encryption, and vendor oversight, undergo independent audits every two years for 20 years, and provide consumers with data deletion options and multi-factor authentication for loyalty accounts.

Monetary PenaltyConsent DecreeAudit RequirementCompliance ProgramData DeletionReporting Requirements

Contract Impact

In-house legal teams should review all vendor and customer agreements where Marriott processes or stores personal data, particularly those involving guest reservation systems. Focus on data security clauses to ensure they mandate a dynamic, risk-based approach to security controls, including regular risk assessments and encryption of sensitive data. Breach notification provisions must align with the multistate settlement's requirements and various state laws, specifying clear timelines and consumer remediation steps. Data processing and retention clauses should incorporate data minimization principles, limiting collection and storage to what is necessary for business purposes. Contracts may need amendments to include audit rights for security compliance and requirements for third-party security assessments.

Contract Search Terms

risk assessment clauseencryption standardsbreach notification timelinedata minimization requirementsecurity incident responsethird-party auditorsecurity frameworkconsumer remedy provision

Laws Cited

state consumer protection lawspersonal information protection lawsbreach notification laws

Violation Types

Entity Details

Entity

Marriott International, Inc.

Also known as: Marriott

Industry

Other

Multistate Coalition

Official Sources

Source Evidence

Entity Name
"Marriott International, Inc."
Fine Amount
"$52 million"
Laws Cited
"state consumer protection laws, personal information protection laws, and, where applicable, breach notification laws"
Violation Types
"failing to implement reasonable data security and remediate data security deficiencies"

Related Enforcement Actions

NJ

Marriott International, Inc.

$52.0M

A multistate coalition of 50 attorneys general, including New Jersey, reached a $52 million settlement with Marriott International, Inc. for two data breaches that exposed personal information of over 131 million consumers. The breaches resulted from inadequate cybersecurity practices at Starwood and Marriott networks. The settlement mandates comprehensive security improvements and monetary penalties.

NY

Marriott International, Inc.

$52.0M

A multistate coalition of 50 attorneys general led by New York AG Letitia James reached a $52 million settlement with Marriott International, Inc. over a 2014-2018 data breach of its Starwood subsidiary’s guest reservation database that exposed 131.5 million consumers’ personal information. The breach, which went undetected for four years, compromised contact details, dates of birth, passport numbers, payment card information, and loyalty program data. Marriott is required to overhaul its data security practices, implement new compliance measures, and allow customers to delete their stored data as part of the settlement.

TX

Marriott International, Inc.

$3.5M

Texas Attorney General Ken Paxton secured a $3.5 million settlement with Marriott International, Inc. following an investigation into a data breach of the company’s reservation database that exposed 131 million U.S. guest records. The breach included sensitive customer information such as contact details, dates of birth, unencrypted passport numbers, and unexpired payment card information. Marriott is required to implement enhanced data security measures, including zero-trust principles and regular security reporting to its CEO, as part of the settlement.

CT

Glenmark

$29.6M

Attorney General Jennifer Davenport joined a coalition of 48 states and territories in a $29.6 million settlement with Glenmark, a generic drug manufacturer, for allegedly conspiring to artificially inflate and manipulate prices, reduce competition, and restrain trade for numerous generic prescription drugs. The settlement includes cooperation in ongoing litigations and internal reforms to ensure fair competition.

CT

Glenmark

$29.6M

Attorney General William Tong led a coalition of 48 states and territories in a $29.6 million settlement with Glenmark, a generic drug manufacturer, to resolve allegations of a widespread conspiracy to artificially inflate prices, reduce competition, and unreasonably restrain trade for numerous generic prescription drugs. The settlement includes cooperation from Glenmark in ongoing multistate litigations and internal reforms to ensure fair competition and compliance with antitrust laws.

CT

23andMe

$18.0M

Attorney General William Tong led a coalition of 42 attorneys general in a settlement with the bankruptcy trustee for 23andMe, resolving allegations from a 2023 data breach that compromised the genetic data of 6.9 million customers. The settlement includes $150 million in allowed claims, with $18 million paid from bankruptcy funds, and requires enhanced data security measures for the new entity holding the data.