Marriott’s £18.4m security penalty

Inherited systems still need clear ownership and ongoing security checks.

By GDPRFix · Published · 2 min read
AI-assisted reporting and commentary · Official sources linked below.
Source / announcement date: 30 October 2020

Historical October 2020 penalty notice, presented as a case study.

What happened

The ICO’s 30 October 2020 penalty notice imposed an £18.4 million fine on Marriott International. The decision concerned protection of personal information following a major incident involving the Starwood guest database. The final penalty was not the same as the figure originally proposed during the investigation.

Source: ICO — original source ↗

What it means for your website

A smaller business can inherit similar uncertainty when it buys a website, changes agencies or takes over an old customer database. Do not assume that a handover folder explains everything the system does. Ask which plugins are still supported, where old backups sit and which users retain access. Set a review date after migration rather than treating launch day as the end of responsibility. The practical recommendation is to assign ownership to the inherited system and close unknowns deliberately. This historical case does not establish that a particular acquisition automatically breaches GDPR, and a consent scan cannot audit an entire database.

Three useful next steps

  1. Review inherited systems after a handover or acquisition.
  2. Confirm who owns updates, backups and access reviews.
  3. Record unresolved issues and a plan to investigate them.

Sources & context

Official sources consulted on 1 October 2026. A regulator’s announcement records its findings at that time; it is not proof of payment or the outcome of every later appeal.

ICO — original source

Our practical suggestions are GDPRFix commentary. A public website scan cannot establish your full legal position. For advice on a specific obligation or enforcement matter, use a suitably qualified adviser.

Keep reading