Your Subscription

We would like to ensure that you are still receiving content that you find useful – please confirm that you would like to continue to receive ILO newsletters.





Login
Twitter LinkedIn




Login
  • Home
  • About
  • Updates
  • Awards
  • Contact
  • Directory
  • OnDemand
  • Partners
  • Testimonials
Forward Share Print
Bird & Bird LLP

Marriott International faces class action in addition to potential GDPR fine

Newsletters

02 October 2020

Tech, Data, Telecoms & Media United Kingdom

​What happened?
What is a class action?
Conclusions


​What happened?

Marriott International announced a significant data breach two years ago following which the UK's data protection regulator, the ICO, issued a statement in July 2019 citing an intention to fine Marriott £99.2 million for breaches of the General Data Protection Regulation (GDPR).(1) Whatever comes of that intention, recent filings in the High Court in London reveal that Marriott now faces the additional threat of a customer class action which cites GDPR non-compliance in respect of the same security breach.

The lawsuit was launched by technology consultant Martin Bryant, represented by international law firm Hausfeld. It has been reported that Mr Bryant is seeking damages on behalf of affected data subjects as he wants to serve a notice to data controllers to treat the data that they hold responsibly.

The ICO's July 2019 statement suggests that hackers had gained unauthorised access to around 30 million EU citizen's guest records within the Starwood guest reservation database, Starwood having been purchased by Marriott in 2016.

What is a class action?

Class actions are an increasing trend in Europe following the notification of data breaches to regulators and data subjects in line with the requirements of the GDPR. Such action have been advertised or commenced in respect of companies ranging from British Airways to the UK supermarket Morrison's, the latter following the leaking by a rogue employee of staff records relating to approximately 100,000 individuals.

There are two class action types that can be initiated; a group litigation order (CPR 19.11) or a representative action (CPR 19.6). Marriott is facing a representative action, which allows for numerous individuals to bring forward a joint claim if they have a common grievance and seek the same relief on an opt in basis.

Conclusions

If this class action succeeds, Marriott will face multiple payouts which although individually may be for small amounts cumulatively could be substantial. It was the size of the maximum fine available to regulators under the GDPR that caught the eye in the run up to its go live date of 25 May 2018 (the greater of 4% of worldwide turnover or €20 million), but the threat of class actions looks to be of equal motivation when it comes to those in the hotel sector taking steps to ensure GDPR compliance.

For further information on this topic please contact James Mullock​ at Bird & Bird LLP by telephone (+44 20 7415 6000) or email (james.mullock@twobirds.com​). The Bird & Bird LLP website can be accessed at www.twobirds.com.

Endnotes

(1) See here.

This article has been reproduced in its original format from Lexology – www.Lexology.com.

The materials contained on this website are for general information purposes only and are subject to the disclaimer.

ILO is a premium online legal update service for major companies and law firms worldwide. In-house corporate counsel and other users of legal services, as well as law firm partners, qualify for a free subscription.

Forward Share Print

Author

James Mullock

James Mullock

Register now for your free newsletter

View recent newsletter

More from this firm

  • ICO's investigation into data broking sector and enforcement notice to Experian
  • New UK regulatory regime on horizon to tackle digital platforms
  • COVID-19 and games industry: opportunities and challenges
  • Online harms: government publishes response to consultation on proposals for internet regulation
  • Information Commissioner publishes draft Code of Practice on Direct Marketing

More articles

  • Home
  • About
  • Updates
  • Awards
  • Contact
  • My account
  • Directory
  • OnDemand
  • Partners
  • Testimonials
  • Follow on Twitter
  • Follow on LinkedIn
  • Disclaimer
  • Privacy policy
  • GDPR Compliance
  • Terms
  • Cookie policy
Online Media Partners
Inter-Pacific Bar Association (IPBA) International Bar Association (IBA) European Company Lawyers Association (ECLA) Association of Corporate Counsel (ACC) American Bar Association Section of International Law (ABA)

© 1997-2021 Law Business Research

You need to be logged in to make a comment. Log in here.
Many thanks. Your comment has been sent.

Your details



Your comment or question *