The fine imposed by the British security watchdog on Marriott for a data breachhas been reduced by £14.4 million (~$23.8 million) from £99 million ($123 million).

The data breach took place in 2014 and involved the Starwood and was not discovered before November 2018.
The personal data involved in the breach varied between individuals, but the ICO said it could include names, email, phone numbers, unencrypted passport numbers, arrival/departure information, VIP guest status and loyalty scheme membership numbers.
Globally, around 339 million visitor records were affected, but fewer people are believed to have been compromised because some of the records were duplicates. The breach is thought to have affected around 30 million users across the EU, according to a previous estimate by the ICO.

In a statement, UK Information Commissioner Elizabeth Denham said: “Millions of people’s data was affected by the Marriott breach. Thousands contacted the helpline and others may have to take legal action to protect their personal data after the company they trusted failed to do so. When a business fails to look after its customers’ data, the impact is not just a potential fine. What matters most is the public whose data it had a duty to protect.”
The initial penalty set by the ICO for Marriott’s breach would have been one of the largest fines imposed under GDPR. The first proposed amount represented around 3% of the company’s 2018 revenue, but it has since been reduced to around 0.6%. This reduction is partly due to the pandemic.
Regarding the reduction in the size of the penalty, Marriott said it reflected the “extensive mitigation measures” put in place after the security incident. It also said it had created a dedicated website to provide information to concerned guests and opened a dedicated helpline. It also sent “millions” of email notifications to people whose information was involved in the breach. It also said it offered guests the opportunity to sign up for a personal information monitoring service where available.
