Court Rules
All enforcement actions
Consent DecreeLow Risk

FTC Orders Marriott and Starwood Security Overhaul After 344M Breach

Marriott International, Inc. and Starwood Hotels & Resorts Worldwide LLCOctober 9, 2024Federal Trade Commission

Consumers Affected

344,000,000

Summary

The FTC charged Marriott International and Starwood Hotels with failing to implement reasonable data security, leading to three data breaches affecting over 344 million customers. Under a proposed consent order, the companies must implement a comprehensive information security program, certify compliance annually for 20 years, and provide customers with ways to delete personal information and restore stolen loyalty points.

Remedy

Marriott and Starwood must establish and maintain a comprehensive information security program with robust safeguards, undergo independent third-party assessments every two years, and certify compliance annually for 20 years. They must provide customers with a method to request deletion of personal information associated with their email or loyalty account, and review loyalty accounts upon request to restore stolen points. The companies are prohibited from misrepresenting their data security practices.

Compliance ProgramAudit RequirementData DeletionInjunctionReporting Requirements

Contract Impact

In-house legal teams should review vendor agreements (especially those involving data processing or IT services), customer privacy policies and terms of service, and employee data handling agreements. Specific clauses to scrutinize include data security obligations, breach notification timelines and procedures, data retention and deletion mechanisms, loyalty program terms regarding point security and restoration, and audit or certification requirements. Changes may be needed to incorporate specific security standards, mandate annual compliance certifications, establish clear processes for customer-initiated personal information deletion and loyalty point restoration, and strengthen third-party vendor oversight provisions.

Contract Search Terms

information security programdata breach notificationpersonal information deletionloyalty points restorationannual compliance certificationreasonable data securitycustomer data rightssecurity audit requirementsdata retention policythird-party vendor management

Violation Types

Entity Details

Entity

Marriott International, Inc. and Starwood Hotels & Resorts Worldwide LLC

Also known as: Marriott

Industry

Other

Official Sources

Source Evidence

Entity Name
"Marriott International, Inc. and its subsidiary Starwood Hotels & Resorts Worldwide LLC"
Violation Types
"The FTC alleged that security failures by Marriott and Starwood resulted in at least three separate data breaches wherein malicious actors obtained the passport information, payment card numbers, loyalty numbers, dates of birth, email addresses and/or personal information from hundreds of millions of consumers"

Related Enforcement Actions

FTC

Humboldt Merchant Services

$12.0M

The FTC alleged that payment processor Humboldt Merchant Services knowingly processed payments for more than 1,000 shell merchant entities serving as fronts for fraudulent companies engaged in unauthorized billing scams, despite red flags including chargeback rates nearly 10 times higher than card-brand thresholds. Under the proposed stipulated order filed in the U.S. District Court for the Eastern District of Michigan, Humboldt will pay $12 million for consumer redress and is permanently banned from processing payments for merchants with a heightened risk of potential fraud.

FTC

Nuvei Corporation

$4.8M

The FTC charged Canada-based payment processor Nuvei Corporation and its subsidiaries with knowingly processing payments for fraudulent merchants, including more than $30 million in payments for the Reimage tech support scam from 2017 to 2023, as well as merchants making false earnings claims and impersonating government tax authorities. Under the stipulated order filed in the U.S. District Court for the District of Arizona, Nuvei will pay $4.85 million for consumer redress, is banned from serving tech support telemarketers, and must implement robust merchant screening and chargeback monitoring practices. Note: this is a payments-fraud facilitation action under the FTC Act and Telemarketing Sales Rule, not a data privacy violation.

FTC

N/A (no entity named - agency policy announcement)

The FTC announced a seven-day extension of the public comment period on its proposed enforcement policy statement regarding personalized pricing, pushing the deadline from Sept. 18, 2026 to Sept. 25, 2026. Personalized pricing refers to using personal data to set prices based on what the company believes an individual consumer is willing to spend. This is a procedural announcement about draft agency guidance, not an enforcement action against any company, and no entity was named, no violation found, and no penalty imposed.

FTC

Amazon.com, Inc.

Colorado Attorney General Phil Weiser joined the FTC and 22 state attorneys general in filing a lawsuit against Amazon for manipulating the auctions used to set advertising prices, replacing actual auction results with higher prices since 2019 and overcharging nearly 1.2 million U.S. advertising customers. The FTC estimates total improper surcharges from 2018 to 2026 exceed $20 billion, with costs ultimately passed to shoppers through higher prices. The states seek a permanent injunction and monetary relief; no penalty has been imposed yet as this is a newly filed complaint.

FTC

CMG Media Corporation

$930K

The FTC finalized orders requiring CMG Media Corporation (doing business as Cox Media Group), MindSift LLC, and 1010 Digital Works LLC to pay a total of $930,000 for falsely claiming they offered an AI-powered service that could target ads based on conversations captured from consumers' smart devices, and that consumers had opted into such targeting. The orders also prohibit the companies from making misrepresentations about their advertising services, voice data collection, and consumer consent.

FTC

Federal Trade Commission

The FTC announced it is seeking public comment on a proposed enforcement policy statement regarding personalized pricing, which is the use of personal data to set prices based on what a company believes an individual consumer is willing to spend. The statement warns that undisclosed collection or use of personal data for personalized pricing could violate the FTC Act's prohibition on unfair or deceptive practices. The Commission voted 2-0 to authorize the Federal Register notice.