ICO Fines Marriott and British Airways for Violating GDPR

Опубликовано: 16 Апрель 2026
на канале: DPO Adviser
897
11

The most powerful asset of the modern digital age is data. The use of data analytics is playing a more significant role in business interactions than ever before. However, Europe's General Data Protection Regulation, or GDPR, aims to hold companies accountable for safeguarding the personal data increasingly swept up in today's digital world. To ensure accountability, national regulators such as the UK's Information Commissioner's Office, or ICO, enforce the rules for companies within their jurisdiction.

This past week, Marriot International, the largest hotel chain in the world, felt the strong headwind of the GDPR after being fined by the ICO fined for 123.6 million dollars following a data breach of personal data from roughly 339 million guests. The ICOs investigation found that Marriot failed to undertake sufficient due diligence when it bought the Starwood Hotel and should have taken more steps to secure its systems.

The Marriot's fine comes only one day after the ICO proposed a staggering 230 Million dollar fine against British Airways for failing to protect its passenger data after suffering a cyberattack last year resulting in over a half-million passenger records breached.

According to the ICO Commissioner Elizabeth Denham,"The GDPR makes it clear that organizations must be accountable for the personal data they hold. This can include carrying out proper due diligence when making a corporate acquisition and putting in place proper accountability measures to assess not only what personal data has been acquired, but also how it is protected."

The GDPR is a big deal for any business that touches customer data. Building an effective Compliance Program is not only the right thing to do, but it also makes good business sense. Earning a reputation as an organization that fails to meet its compliance obligations can jeopardize customer trust and loyalty. The GDPR presents an opportunity to earn trust with your customers and prospects.

No matter where you are in your compliance journey, we are ready to help you build and sustain a company-wide culture of privacy and compliance. For more information, check out our website at dpoadviser.com.

And as always, if you found this video helpful please give it a like or share. If you have any questions or suggestions, throw them in the comments below.