Penalty Amount
$52,000,000
Consumers Affected
131,500,000
A multistate settlement with Marriott International for a data breach affecting 131.5 million guest records. Marriott failed to secure the Starwood network from 2014 to 2018, exposing personal information. The settlement includes a $52 million payment and requires Marriott to implement enhanced cybersecurity measures and consumer protections.
Marriott must pay $52 million to states, implement a comprehensive Information Security Program with risk assessments, data minimization, encryption, and vendor oversight, undergo independent audits every two years for 20 years, and provide consumers with data deletion options and multi-factor authentication for loyalty accounts.
In-house legal teams should review all vendor and customer agreements where Marriott processes or stores personal data, particularly those involving guest reservation systems. Focus on data security clauses to ensure they mandate a dynamic, risk-based approach to security controls, including regular risk assessments and encryption of sensitive data. Breach notification provisions must align with the multistate settlement's requirements and various state laws, specifying clear timelines and consumer remediation steps. Data processing and retention clauses should incorporate data minimization principles, limiting collection and storage to what is necessary for business purposes. Contracts may need amendments to include audit rights for security compliance and requirements for third-party security assessments.
Entity
Marriott International, Inc.
Also known as: Marriott
Industry
Other"Marriott International, Inc."
"$52 million"
"state consumer protection laws, personal information protection laws, and, where applicable, breach notification laws"
"failing to implement reasonable data security and remediate data security deficiencies"
$52.0M
A multistate coalition of 50 attorneys general, including New Jersey, reached a $52 million settlement with Marriott International, Inc. for two data breaches that exposed personal information of over 131 million consumers. The breaches resulted from inadequate cybersecurity practices at Starwood and Marriott networks. The settlement mandates comprehensive security improvements and monetary penalties.
$52.0M
A multistate coalition of 50 attorneys general led by New York AG Letitia James reached a $52 million settlement with Marriott International, Inc. over a 2014-2018 data breach of its Starwood subsidiary’s guest reservation database that exposed 131.5 million consumers’ personal information. The breach, which went undetected for four years, compromised contact details, dates of birth, passport numbers, payment card information, and loyalty program data. Marriott is required to overhaul its data security practices, implement new compliance measures, and allow customers to delete their stored data as part of the settlement.
$3.5M
Texas Attorney General Ken Paxton secured a $3.5 million settlement with Marriott International, Inc. following an investigation into a data breach of the company’s reservation database that exposed 131 million U.S. guest records. The breach included sensitive customer information such as contact details, dates of birth, unencrypted passport numbers, and unexpired payment card information. Marriott is required to implement enhanced data security measures, including zero-trust principles and regular security reporting to its CEO, as part of the settlement.
$2.0M
Attorney General Tong and a coalition of four other states and the FTC sued Zillow and Redfin after Zillow paid Redfin $100 million to shut down its multifamily rental advertising business and transfer clients to Zillow. The settlement requires the companies to restore competition, with Redfin rebuilding its apartment advertising business, and pay $2 million to the coalition.
Attorney General William Tong sent a letter to the Connecticut Insurance Department urging rejection of double-digit rate increases sought by Anthem, ConnectiCare, and UnitedHealthcare for individual and small group health insurance plans covering about 220,000 people. The letter argues the rates exceed inflationary measures and criticizes the carriers for failing to control costs and for poor claims system management, particularly ConnectiCare's transition to Molina Healthcare.
$275K
Connecticut Attorney General William Tong announced a $275,000 settlement with TaxAct, an online tax preparation company, over allegations that between January 2018 and December 2022, TaxAct improperly disclosed detailed customer financial information to Meta and Google through third-party tracking technologies without notifying taxpayers. The settlement requires TaxAct to pay $275,000 and implement new third-party tracking compliance measures, including a review committee, written policies, a tag monitoring system, and two independent third-party audits.