top of page
Melih R. Çalıkoğlu

Marriott International Inc. Fined 1.450.000 TL for Data Breach


🗓️ Decision Date: May 2019

🔍 Complaint: Marriott International Inc., a multinational hotel chain, faced allegations of potential breach of data protection regulations. The complaints centered around the company's data breach incident where unauthorized access to the Starwood Hotels & Resorts Worldwide Inc.'s (Starwood) guest reservation database was detected.


🔬 Investigation: The Personal Data Protection Authority (KVKK), the country's authority for ensuring compliance with data protection laws, launched an investigation into these claims. The investigation period spanned from July 2014 to November 2018.


🚫 Violation: KVKK found that Marriott's data security practices violated the Personal Data Protection Law. The company was found to have failed to take necessary technical and administrative measures to ensure data security, leading to unauthorized access to the Starwood guest reservation database.


📝 Reason for Non-compliance: The Personal Data Protection Law necessitates necessary technical and administrative measures to ensure data security. Marriott's failure to detect unauthorized access to the Starwood guest reservation database for about four years indicated a serious security gap and showed that the necessary audits and controls were not carried out by the company.


💰 Penalty: The infringement led KVKK to impose an initial fine of 1.100.000 TL on Marriott for failing to take necessary technical and administrative measures, and an additional fine of 350.000 TL for not notifying the Authority and the data subjects as soon as possible, totaling 1.450.000 TL. (248.00 USD by 2019 prices)


🏁 Resolution: The details of the resolution are not specified in the available summaries.

🔎 Who's Who:

KVKK (Personal Data Protection Authority): An independent authority that ensures Turkey’s compliance with data protection laws.

Marriott International Inc.: A multinational hotel chain found guilty of breaching data security guidelines.


📑 Find the detailed decision here: KVKK Decision (Turkish)



AI TRANSPARENCY NOTICE:




This summary was created with AI assistance of ChatGPT mostly with AI Contribution.




The article image was created with AI assistance of Leonardo.ai with full AI Contribution.


24 views0 comments

Comments


bottom of page