Search

How can we help?

Icon

GDPR: ICO issues second intent to fine in two days

Just one day after the ICO delivered a notice of intent to fine British Airways £183 million for alleged personal data breaches, it has delivered another, this time to global hotel group, the Marriott International.

In a statement published yesterday the ICO has confirmed it had issued a notice of intent to impose a £99,200,396 million penalty for infringements of the General Data Protection Regulation (GDPR).

The infringements in question related to a global data exposure of approximately 339 million guest records, 30 million of which related to EU residents including 7 million residents in the UK.

These guest records were held on a database operated by Starwood hotels group which Marriott acquired in 2016.

The exposure apparently commenced in 2014 but it was not until November 2018 that the Marriott notified the ICO of the breach. Personal details potentially accessed included names, addresses, passport details, account and booking information and some encrypted credit card details.

What did Marriott get wrong?

The ICO has cited Marriott’s failure to “undertake sufficient due diligence” when it bought Starwood and that it “should also have done more to secure its systems”.

Under the GDPR, organisations must implement appropriate technical and organisational measures to safeguard personal data.

What constitutes sufficient technical and organisational measures is a question of a degree and largely depends on the nature of the processing. If an organisation is in the business of bulk processing of personal data and the risk to such individuals is high because for example the data processed includes identity data or financial information, its technical and organisational measures must be adequate to mitigate these risks.

 Some obvious examples of technical and organisational measures include:

  1. Installation of basic technical systems such as those described in Cyber Essentials, a UK government quality assurance scheme;
  2. Regular testing and monitoring of the adequacy of IT systems;
  3. Implementation and regular review of internal IT and security policies; and
  4. Staff training and education.

ICO has confirmed it had issued a notice of intent to impose a £99,200,396 million penalty for infringements of the GDPR

Lesson to be learned: Data Compliance risk when acquiring a business

The Marriott case illustrates the importance of proper due diligence when acquiring the shares or assets of a business.  It is not always apparent to a purchaser whether a business has fully complied with data protection laws. Organisations that simply play lip service to data protection compliance run the risk of being exposed when and if a data breach occurs. Unfortunately for purchasers such as the Marriott, these failures may only come to light subsequent to completion of the sale.

It is therefore essential that a comprehensive due diligence of an organisation’s technical and organisational measures is undertaken before acquisition. It may also be appropriate to require the seller to provide indemnities in respect of data protection compliance within the asset or share sale documentation.

For sellers of businesses, an audit of data protection compliance is warranted to ensure the business passes any due diligence of potential buyers and guard against potential liability in the future.

If you are considering buying or selling your business, Clarkslegal’s Corporate and Commercial Team, can offer you tailored advice and assistance.

Disclaimer
This information is for guidance purposes only and should not be regarded as a substitute for taking legal advice. Please refer to the full General Notices on our website.

Author profile

About this article

Read, listen and watch our latest insights

art
  • 23 June 2026
  • Employment

Pride month and employment law: Ensuring compliance with LGBTQ+ protections

With each Pride month, companies unveil rainbow logos and send office wide emails of solidarity. These gestures are valuable, giving visible demonstrations of support, but only really make a difference if those companies are able to truly say that their policies and practices are inclusive and legally compliant.

art
  • 22 June 2026
  • Commercial Real Estate

Do you need an EPC for lease renewals? Key insights for commercial property owners

When is an EPC required for leases? The non-domestic EPC guidance makes it clear that an EPC is not required on renewal. The Ministry for Housing, Communities and Local Government’s (MHCLG’s) “A guide to energy performance certificates for the construction, sale and let of non-dwellings: Improving the energy efficiency of our buildings”

Pub
  • 18 June 2026
  • Employment

Employment Rights Act 2025: Key Changes for Employers

Join Katie Glendinning and Lucy White for an on demand webinar as they break down the key changes introduced by the Employment Rights Act 2025, offering clear insights into what these reforms mean in practice for employers and HR professionals.

art
  • 18 June 2026
  • Corporate and M&A

Business sales and NDAs: Creating a safe space to open up your business

You have accepted an offer to sell your business, but taking an agreement in principle through to completion may involve the need to divulge your company’s private information – perhaps deep secrets which have given your business its competitive edge.  

art
  • 16 June 2026
  • Employment

Shaping the Future of Work: Insights from the 114th ILO International Labour Conference

Having recently returned from the 114th Session of the International Labour Conference in Geneva, I have been reflecting on the work of the International Labour Organisation (ILO) and the important role it plays in global standard setting, as well as promoting social and economic inclusivity.

art
  • 11 June 2026
  • Immigration

MAC report reveals who stays in the UK on the Skilled Worker Route – Key insights for employers

Key insights from the MAC report: Who stays in the UK on the Skilled Worker route? Essential findings and takeaways for employers.