The fine for Marriott comes just two weeks after the ICO issued a record £20 million penalty to British Airways for its own data breach under GDPR rules.
The Marriott incident relates to a cyber attack in 2014 on Starwood Hotels and Resorts’ systems – Starwood was subsequently purchased by Marriott in 2016.