Court Rules
All enforcement actions
Consent DecreeLow Risk

FTC Orders Marriott and Starwood Security Overhaul After 344M Breach

Marriott International, Inc. and Starwood Hotels & Resorts Worldwide LLCOctober 9, 2024Federal Trade Commission

Consumers Affected

344,000,000

Summary

The FTC charged Marriott International and Starwood Hotels with failing to implement reasonable data security, leading to three data breaches affecting over 344 million customers. Under a proposed consent order, the companies must implement a comprehensive information security program, certify compliance annually for 20 years, and provide customers with ways to delete personal information and restore stolen loyalty points.

Remedy

Marriott and Starwood must establish and maintain a comprehensive information security program with robust safeguards, undergo independent third-party assessments every two years, and certify compliance annually for 20 years. They must provide customers with a method to request deletion of personal information associated with their email or loyalty account, and review loyalty accounts upon request to restore stolen points. The companies are prohibited from misrepresenting their data security practices.

Compliance ProgramAudit RequirementData DeletionInjunctionReporting Requirements

Violation Types

Entity Details

Entity

Marriott International, Inc. and Starwood Hotels & Resorts Worldwide LLC

Also known as: Marriott

Industry

Other

Official Sources

Related Enforcement Actions

FTC

Air AI

$18.0M

Consumer fraud enforcement action where the FTC settled with Air AI for misleading entrepreneurs with false earnings and refund guarantees. The company will be banned from marketing business opportunities and pay a suspended $18 million judgment with $50,000 for consumer relief. Violations included failure to provide required disclosures and false claims under the Telemarketing Sales Rule and Business Opportunity Rule.

FTC

Xponential Fitness

$17.0M

Consumer fraud enforcement action where the FTC settled with Xponential Fitness for violating the Franchise Rule by misrepresenting key information to franchisees, including time to open and costs. The settlement includes a $17 million monetary judgment for redress and prohibits future misrepresentations.

FTC

97 Auto Dealership Groups

Consumer fraud and advertising enforcement action where the FTC sent warning letters to 97 auto dealership groups for deceptive pricing practices, such as advertising prices that exclude mandatory fees, misleading consumers about total costs. The letters stress the need for truthful and transparent pricing in the automotive industry.

FTC

Walmart, Inc.

$100.0M

The FTC and 11 states settled with Walmart for $100 million over deceptive earnings claims in its Spark Driver gig worker app, where drivers were misled about base pay, tips, and incentives. The settlement also addressed GLBA violations for failing to provide proper notice regarding the handling of drivers' financial information. Walmart must implement an earnings verification program and is banned from misrepresenting driver earnings.

FTC

Website and Online Service Operators

The FTC issued a policy statement announcing it will not enforce COPPA against operators that collect age verification data under specific conditions. The policy aims to encourage the use of age verification technologies to protect children online. Operators must limit data use, ensure security, provide notice, and use accurate verification methods.

FTC

Operators of General Audience and Mixed Audience Sites and Services

The FTC issued a policy statement announcing that it will not enforce the COPPA Rule against website and online service operators that use age verification technologies solely to determine user age, provided they comply with conditions such as limiting data use, ensuring security, and providing clear notice. This policy aims to incentivize age verification tools to protect children online.