UK's ICO reduces Marriott fine for a 2014 data breach, in which 339M Starwood hotels guest records were affected, from £99M to £14.4M
The UK's ICO has reduced the size of a data breach penalty for hotel business Marriott — dropping it to £14.4 million (~$23.8M) …
Context & Ripple Effects
The ICO first moved against Marriott in July 2019, when it signaled a ~$123M fine over GDPR violations tied to the Starwood reservation database hack that Marriott disclosed in late 2018 as 500M stolen records dating back to 2014. The final £14.4M penalty lands just two weeks after the regulator made the same move on British Airways, cutting its proposed £184M fine to £20M.
The reduction is not an exoneration — it is a recalibration of how the ICO prices breaches, and Marriott's exposure was never confined to the UK: four years later it would agree to a $52M multi-state settlement with the FTC plus a mandated infosec program.
First-order effects
- Marriott's UK GDPR liability for the Starwood breach drops by roughly 85%, from £99M to £14.4M, closing out its largest European regulatory threat from the 2014-2018 intrusion.
Second-order effects
- Every company with a pending ICO investigation now has two precedents — British Airways and Marriott — showing that proposed headline fines shrink substantially on review, which strengthens the case for contesting initial penalty notices rather than settling early.
Third-order effects
- If the ICO's discounting pattern holds, GDPR enforcement shifts from headline-number deterrence toward negotiated outcomes pairing reduced fines with mandated security programs — the model Marriott itself accepted in the US, where the $52M state settlement came bundled with a court-supervised infosec overhaul.
The trend: GDPR-era mega-fines are being systematically discounted on appeal, pushing data-breach enforcement away from headline penalties and toward negotiated settlements paired with mandated security programs.