GDPR went live on 25th May 2017. The GDPR monetary penalties fall into two classifications: for less severe breaches, the maximum fine is €10 million or two per cent of a company's annual revenue, whichever is greater. for more severe breaches, the maximum fine is €20 million or four per cent of a company's annual revenue, whichever is greater.
On August 5, 2019, Marriott International announced that it had taken a $126 million charge in the second quarter, primarily as a result of the data breach it announced in 2018. Coincidentally, on July 9, 2019, The United Kingdom’s Information Commissioner’s Office (ICO), which enforces the General Data Protection Regulation in the UK, announced that it intends to impose a fine of £99,200,396 ($123,705,870) on Marriott for last year’s data breach.
The breach relates to a 2014 data breach in systems of the Starwood hotel group, prior to the acquisition of Starwood by Marriott in 2016 – the breach itself was not discovered until 2018 following completion of the corporate acquisition. The hackers stole a breathtaking array of sensitive data:
383 million guest records
25 million encrypted passport numbers
5 million encrypted passport numbers
1 million encrypted payment card numbers
385,000 card numbers that were still valid at the time of the breach
This event has had a far reaching consequence on the Hotel industry as well. Virtually every major hotel company, and many minor ones, have announced data breaches in the past few years, and there are likely many more that either chose not to announce a breach, or that were unaware that they were hacked. Until now, the impact of a breach has been limited. While the cost of discovering, announcing and remediating the breach is high, the GDPR has only begun issuing fines this year. And while Marriott’s fine is large, it is dwarfed by the fine that the ICO levied on British Airways on the same day – $228 million.
On August 5, 2019, Marriott International announced that it had taken a $126 million charge in the second quarter, primarily as a result of the data breach it announced in 2018. Coincidentally, on July 9, 2019, The United Kingdom’s Information Commissioner’s Office (ICO), which enforces the General Data Protection Regulation in the UK, announced that it intends to impose a fine of £99,200,396 ($123,705,870) on Marriott for last year’s data breach.
The breach relates to a 2014 data breach in systems of the Starwood hotel group, prior to the acquisition of Starwood by Marriott in 2016 – the breach itself was not discovered until 2018 following completion of the corporate acquisition. The hackers stole a breathtaking array of sensitive data:
383 million guest records
25 million encrypted passport numbers
5 million encrypted passport numbers
1 million encrypted payment card numbers
385,000 card numbers that were still valid at the time of the breach
This event has had a far reaching consequence on the Hotel industry as well. Virtually every major hotel company, and many minor ones, have announced data breaches in the past few years, and there are likely many more that either chose not to announce a breach, or that were unaware that they were hacked. Until now, the impact of a breach has been limited. While the cost of discovering, announcing and remediating the breach is high, the GDPR has only begun issuing fines this year. And while Marriott’s fine is large, it is dwarfed by the fine that the ICO levied on British Airways on the same day – $228 million.
No comments:
Post a Comment