Federal Trade Commission Consent Decree Mandates for Marriott International
20 Questions and Answers Regarding the Regulatory Action
| 1. What did the Federal Trade Commission finalize on December 20 2024? | The agency finalized a consent order against Marriott International and Starwood Hotels. |
| 2. What penalty did Marriott pay to state regulators? | The company paid 52 million dollars to 49 states and the District of Columbia. |
| 3. How consumers were affected by the data breaches? | More than 344 million customers worldwide experienced data exposure. |
| 4. When did the data breaches occur? | The network intrusions took place between 2014 and 2020. |
| 5. What type of data did attackers steal? | Attackers obtained passport numbers, payment card details, and loyalty account information. |
| 6. How long does the consent decree last? | The regulatory mandates remain active for 20 years. |
| 7. What specific security program must Marriott implement? | The hotel chain must establish an extensive Information Security Program. |
| 8. How frequently must Marriott undergo independent security assessments? | Third party professionals must evaluate the company every two years. |
| 9. What new data deletion rights do United States consumers gain? | Customers can request the deletion of personal information tied to their email or loyalty accounts. |
| 10. What happens to stolen loyalty points? | Marriott must review accounts upon request and restore any stolen points. |
| 11. What authentication method is mandated? | The order requires the implementation of multi factor authentication across the network. |
| 12. How did the breach happen? | Malicious actors compromised Starwood point of sale systems for 14 months starting in 2014. |
| 13. When did Marriott acquire Starwood? | The acquisition took place in 2016 for 12. 2 billion dollars. |
| 14. How long did the second breach go? | The guest reservation database intrusion remained hidden for four years until 2018. |
| 15. What caused the third breach in 2020? | Attackers compromised employee credentials at a franchised property to access the corporate network. |
| 16. What data minimization rules apply? | Marriott must retain personal information only as long as reasonably necessary. |
| 17. Who praised the vendor oversight provisions? | The Electronic Privacy Information Center submitted a letter supporting the third party auditing requirements. |
| 18. What executive oversees the Federal Trade Commission Bureau of Consumer Protection? | Samuel Levine directs the bureau and announced the settlement details. |
| 19. Does the Federal Trade Commission collect a financial penalty in this case? | The agency does not have legal authority to obtain civil penalties for this specific violation. |
| 20. What must Marriott do regarding future acquisitions? | The company must evaluate the security posture of acquired entities to identify and fix vulnerabilities. |
Regulatory Action and Breach History
On December 20 2024, the Federal Trade Commission finalized a consent order requiring Marriott International Inc and its subsidiary Starwood Hotels and Resorts Worldwide LLC to implement an extensive Information Security Program. The regulatory action settles charges that the companies failed to deploy reasonable data security measures. These failures led to three distinct data breaches between 2014 and 2020. The network intrusions exposed the personal information of more than 344 million customers worldwide.
The breach began in 2014 before Marriott acquired Starwood in 2016 for 12. 2 billion dollars. Attackers compromised Starwood point of sale systems and exposed payment cards for 14 months. The second breach involved the Starwood guest reservation database. Malicious actors maintained access for four years until 2018. This intrusion compromised 339 million guest records. The exposed data included 5. 25 million unencrypted passport numbers. The attackers also obtained encrypted passport numbers, email addresses, phone numbers, and mailing addresses. The exposure of unencrypted passport numbers presented a serious risk of identity theft for international travelers. The Federal Trade Commission noted that Marriott failed to verify the security practices of Starwood before completing the acquisition. This failure allowed the existing network intrusion to continue without interruption. The third breach occurred in 2020 when intruders compromised employee credentials at a franchised property. This access allowed attackers to view 5. 2 million guest records.
Marriott Data Breach Exposure 2014 to 2020
Information Security Program Mandates
The Federal Trade Commission complaint detailed specific security failures. The agency charged that Marriott and Starwood deceived consumers by claiming to maintain reasonable data security. The investigation revealed that the companies failed to implement appropriate password controls and access controls. The network environment showed an absence of adequate firewall configurations and network segmentation. The companies failed to patch outdated software and systems. The network environments operated with an absence of adequate logging and monitoring capabilities. The absence of adequate multi factor authentication allowed attackers to escalate privileges within the corporate network.
The finalized consent decree imposes strict operational requirements for 20 years. Marriott must establish an extensive Information Security Program. The company must implement multi factor authentication, data encryption, asset inventory tracking, and patch management. The order requires Marriott to undergo an independent third party security assessment every two years. The company must submit the initial assessment to the Federal Trade Commission. Marriott must retain subsequent assessments for five years.
The mandated Information Security Program requires Marriott to document all security procedures. The company must implement data access controls for all employees and vendors. The security architecture must follow the principle of least privilege. Marriott must maintain an active incident response plan. The order mandates regular security reporting to top management. The Chief Executive Officer must receive direct updates regarding the security posture. The company must provide mandatory training to employees regarding data handling and security. Marriott must inventory and classify all information technology assets that contain personal data.
Consumer Rights and Data Deletion
The settlement introduces specific consumer protection mandates. Marriott must post a clear link on its website allowing United States customers to request the deletion of their personal information. This rule applies to data associated with email addresses or loyalty rewards account numbers. The company must also implement a data minimization policy. This policy restricts the retention of personal information to the period reasonably necessary to fulfill the original collection purpose.
The Federal Trade Commission order obligates Marriott and Starwood to provide consumers with deletion rights. The companies must prominently link to the deletion request process from their websites and mobile applications. This requirement represents a new addition for a Federal Trade Commission order. The mandate aligns with requirements common in state privacy laws. Marriott must honor these deletion requests regardless of whether the customer resides in a state jurisdiction that provides a legal right to delete data. The companies must also share the specific business need for retaining any personal information.
Marriott and Starwood must develop a method for consumers to request a review of their account for unauthorized activity. If the review determines that a security incident resulted in the loss of rewards points, the companies must restore the points. The loyalty rewards program, known as Marriott Bonvoy, holds significant financial value for frequent travelers. Malicious actors frequently target these accounts to drain accumulated points for fraudulent travel bookings. The Federal Trade Commission mandate ensures that consumers do not bear the financial loss of these security failures. Marriott must establish a dedicated customer service channel to process these point restoration requests. The companies are prohibited from misrepresenting how they collect, maintain, use, delete, or disclose consumer personal information. The order forbids misrepresentations regarding the extent to which the companies protect the privacy, security, availability, confidentiality, or integrity of personal information.
State Penalties and Vendor Oversight
In a parallel regulatory action, Marriott agreed to pay a 52 million dollar civil penalty. A coalition of 49 states and the District of Columbia secured this financial settlement. California did not participate in this specific coalition. The state agreement requires full implementation of the security measures by October 9 2025.
The state coalition settlement requires Marriott to adopt a risk based method to cybersecurity. The measures include ongoing risk assessments and specific security controls. The state agreement mandates increased vendor and franchisee oversight. The state attorneys general launched parallel investigations into Marriott and Starwood. The investigations focused on the guest reservation database breaches. The 52 million dollar payment resolves the state level data security violation allegations. The financial penalty is distributed among the participating states. The state attorneys general emphasized that hotel chains collect large volumes of highly sensitive personal information. The state regulators stated that Marriott held a legal obligation to protect this data from unauthorized access. The settlement requires Marriott to provide annual certifications of compliance to the state regulators.
The Electronic Privacy Information Center submitted a public comment supporting the consent decree. The organization praised the inclusion of vendor oversight and independent auditing requirements. The group noted that attention to vendor security practices serves as a necessary preventative measure against network intrusions.
The consent decree includes specific provisions for future corporate expansion. If Marriott acquires another entity, the company must assess the Information Security Program of the acquired business. Marriott must identify vulnerabilities within the newly acquired network. The company must address these security gaps promptly to prevent lateral movement by malicious actors.
Financial Penalties and Compliance Costs Imposed by Regulators
20 Questions and Answers Regarding Financial Penalties and Compliance Costs
1. What exact financial penalty did Marriott agree to pay in October 2024?
Marriott agreed to pay 52 million dollars to 49 states and the District of Columbia.
2. Which federal agency finalized the consent order against Marriott in December 2024?
The Federal Trade Commission finalized the order.
3. How data breaches occurred between 2014 and 2020?
Three separate data breaches occurred during that period.
4. How customer records were exposed across these breaches?
The breaches exposed 344 million customer records worldwide.
5. Did the Federal Trade Commission fine Marriott directly?
The Federal Trade Commission does not have legal authority to obtain civil penalties in this specific case.
6. Who receives the 52 million dollar penalty?
State attorneys general divide the penalty among 49 states and the District of Columbia.
7. What penalty did the United Kingdom Information Commissioner Office impose on Marriott in 2020?
The agency imposed an 18. 4 million pound fine.
8. What regulation did the United Kingdom fine enforce?
The fine enforced the General Data Protection Regulation.
9. How long must Marriott submit to external cybersecurity monitoring?
The company must submit to independent assessments every two years for 20 years.
10. Who conducts the required cybersecurity assessments?
An independent third party professional conducts the assessments.
11. What specific customer data was exposed in the breaches?
Exposed data included passport numbers, payment card numbers, loyalty numbers, dates of birth, and email addresses.
12. When did the data breach begin?
The breach began in June 2014.
13. How payment cards were exposed in the breach?
Malicious actors exposed more than 40, 000 payment cards.
14. When did Marriott acquire Starwood Hotels?
Marriott acquired the brand in 2016.
15. How guest records were accessed in the 2020 breach?
Malicious actors accessed 5. 2 million guest records worldwide.
16. How American guest records were included in the 2020 breach?
The breach included 1. 8 million American guest records.
17. What must Marriott do regarding stolen loyalty points?
The company must review loyalty rewards accounts upon customer request and restore stolen points.
18. What data deletion rights do United States customers have?
Customers can request the deletion of personal information associated with their email address or loyalty rewards account number.
19. How frequently must Marriott certify compliance with the Federal Trade Commission?
The company must certify compliance annually.
20. What specific security failures did regulators identify?
Regulators identified deficient firewalls, outdated software, absent multifactor authentication, and poor access controls.
State and Federal Financial Penalties
Marriott International faces serious financial consequences following a series of data breaches. The company agreed to pay 52 million dollars to 49 states and the District of Columbia in October 2024. The Federal Trade Commission coordinated this settlement. The federal agency does not have the statutory authority to levy civil penalties directly for these specific violations. State attorneys general divide the 52 million dollar payment. The settlement resolves allegations that Marriott and its Starwood subsidiary failed to protect consumer data between 2014 and 2020.
The financial impact extends beyond the immediate 52 million dollar payment. The Federal Trade Commission finalized its consent order on December 20, 2024. This order forces Marriott to absorb large compliance costs over the two decades. The company must implement an exact information security program. Marriott must hire an independent third party professional to conduct security assessments every two years. The mandate continues for 20 years. The company must also certify compliance with the Federal Trade Commission annually.
International Fines and General Data Protection Regulation Enforcement
Financial penalties extend beyond the United States borders. The United Kingdom Information Commissioner Office fined Marriott 18. 4 million pounds in 2020. This penalty enforced the General Data Protection Regulation. Regulators determined that Marriott failed to protect the personal data of millions of European residents. The initial breach began in 2014 within the Starwood network. Marriott acquired Starwood in 2016 failed to discover the ongoing intrusion until 2018. Regulators penalized the company for insufficient due diligence during the corporate acquisition.
The European breach affected 30 million residents. Seven million of those guest records belonged to United Kingdom residents. The Information Commissioner Office stated that Marriott should have done more to secure its systems after buying Starwood. The agency noted that the company failed to undertake sufficient due diligence. The fine represents one of the largest penalties issued under the General Data Protection Regulation for a data breach.
Mandated Compliance Costs and Operational Expenses
The Federal Trade Commission consent order dictates specific operational changes that require substantial capital investment. Marriott must provide a method for United States customers to request the deletion of their personal data. The company must offer an online method for customers to request the deletion of personal information associated with their email addresses or loyalty rewards account numbers. Marriott must also restore stolen loyalty points upon customer request.
The order mandates strict data minimization practices. Marriott must implement a policy to retain personal information only for as long as is reasonably necessary to fulfill the purpose for which it was collected. The companies are prohibited from misrepresenting how they collect, maintain, use, delete, or disclose consumer personal information. These mandated operational changes force Marriott to rebuild its data architecture. The company must dedicate significant financial resources to maintain this compliance over the 20 year monitoring period.
Data Breach Scope and Security Failures
Regulators documented three separate data breaches affecting 344 million customers worldwide. The breach began in June 2014 and compromised more than 40, 000 payment cards. Malicious actors installed malware on point of sale systems at Starwood properties. A second breach remained hidden from 2014 until 2018. This intrusion exposed 339 million guest records. Exposed data included passport numbers, mailing addresses, and loyalty account information.
A third breach occurred in 2020 when malicious actors compromised employee credentials. This event exposed 5. 2 million guest records. The compromised records contained names, mailing addresses, email addresses, phone numbers, month and day of birth, and loyalty account information. The 2020 breach included 1. 8 million American guest records. Forensic examinations revealed deficient firewalls, outdated software, absent multifactor authentication, and poor access controls.
Cost of Remediation and Security Upgrades
The financial weight of the Federal Trade Commission consent decree includes the immediate cost of security upgrades. Regulators found that Starwood and Marriott failed to patch outdated software and systems. The companies failed to adequately log and monitor network environments. Marriott must deploy exact multifactor authentication across its entire corporate network. The company must implement strict password controls, access controls, firewall controls, and network segmentation.
These technical upgrades require Marriott to purchase new security software and hire additional cybersecurity personnel. The company must document, implement, and maintain its Information Security Program. Regulators require Marriott to inform its customers how it handles personal information. The company must accurately inform its customers of the security measures it implements to ensure the confidentiality, availability, security, and integrity of sensitive personal data. The total cost of these mandatory upgrades far exceeds the 52 million dollar civil penalty.
Samuel Levine, Director of the Federal Trade Commission Bureau of Consumer Protection, stated that Marriott poor security practices led to multiple breaches affecting hundreds of millions of customers. The agency action, in coordination with state partners, ensures that Marriott improves its data security practices in hotels around the globe.
Financial Penalties and Exposed Records Data
| Metric Category | Entity or Event | Value | Visual Representation |
|---|---|---|---|
| Financial Penalty | United States Attorneys General | 52 Million Dollars |
100%
|
| Financial Penalty | United Kingdom Information Commissioner | 23. 8 Million Dollars |
45%
|
| Exposed Records | Starwood Database Breach | 339 Million Records |
98%
|
| Exposed Records | Marriott Network Breach | 5. 2 Million Records |
2%
|
Starwood Acquisition Vulnerability Data and Legacy System Failures
20 Questions and Answers Regarding the Starwood Acquisition and Legacy System Failures
1. When did the initial unauthorized access to the Starwood network begin? The intrusion started in July 2014.
2. When did Marriott complete the acquisition of Starwood Hotels? Marriott finalized the purchase in September 2016.
3. How long did the attackers remain hidden inside the Starwood systems? The hackers operated unnoticed for four years.
4. When did Marriott discover the security breach? An internal security tool flagged suspicious activity on September 8 2018.
5. When did Marriott publicly disclose the data breach? The company announced the breach on November 30 2018.
6. How Starwood guest account records did malicious actors access? Attackers compromised 339 million guest records worldwide.
7. How unencrypted passport numbers were exposed? Hackers accessed 5. 25 million unencrypted passport numbers.
8. How encrypted passport numbers were involved? The breach included 20. 3 million encrypted passport numbers.
9. What cryptographic method protected the payment card numbers? Marriott initially believed the data used Advanced Encryption Standard 128 later determined it used Secure Hash Algorithm 1.
10. How encrypted payment cards were compromised? Approximately 8. 6 million encrypted payment cards were exposed.
11. What specific network security failures did the Federal Trade Commission identify? The agency found failures in password controls, access controls, firewall controls, and network segmentation.
12. Did Marriott patch outdated software on the legacy Starwood systems? The Federal Trade Commission complaint states the company failed to patch outdated software and systems.
13. Did the company deploy multifactor authentication on the compromised network? The regulatory agency found that Marriott failed to deploy adequate multifactor authentication.
14. How did the attackers maintain a foothold in the network? The hackers deployed malware including a Remote Access Trojan.
15. What type of malware did the attackers install at Starwood properties? Malicious actors installed key loggers, memory scraping malware, and remote access Trojans.
16. Did Marriott conduct adequate cybersecurity due diligence during the acquisition? The Federal Trade Commission noted that Marriott had extensive visibility into the Starwood environment failed to detect the ongoing breach.
17. When did the Federal Trade Commission finalize the consent order regarding these failures? The agency finalized the agreement on December 20 2024.
18. How unexpired payment cards were involved in the breach? Approximately 354, 000 payment cards were unexpired as of September 2018.
19. Did the attackers access the master encryption key for the payment cards? Marriott stated there is no evidence the unauthorized third party accessed the components needed to decrypt the payment cards.
20. What other personal information did the compromised records contain? The records included names, mailing addresses, email addresses, phone numbers, birth dates, and loyalty account information.
The 2014 Intrusion and 2016 Acquisition Timeline
The unauthorized access into the Starwood guest reservation network began in July 2014. Attackers infiltrated the system and deployed malware to maintain their foothold. The malicious software included remote access Trojans, key loggers, and memory scraping tools. These tools allowed the hackers to move laterally across the network and access sensitive customer data. The intrusion remained completely hidden from Starwood security personnel.
Forensic investigators determined that the malicious actors installed memory scraping malware on the Starwood point of sale systems. This specific software captures payment card data while it resides in the random access memory of the infected device. The attackers also deployed key loggers to harvest administrative credentials from Starwood employees. These stolen credentials granted the hackers elevated privileges across the entire corporate network. The combination of memory scraping tools and compromised administrative accounts created a highly data exfiltration pipeline.
Marriott International acquired Starwood Hotels and Resorts Worldwide in September 2016. The transaction created the largest hotel chain globally. During the due diligence phase and the post closing integration, Marriott assumed responsibility for the Starwood information security environment. The Federal Trade Commission complaint states that Marriott had extensive visibility into the Starwood network during this period. Even with this visibility, the company failed to identify the active intrusion. The attackers continued to operate inside the newly acquired infrastructure for another two years.
The 2018 Discovery and Data Exposure Metrics
An internal security tool flagged a suspicious attempt to access the Starwood guest reservation database on September 8 2018. Marriott launched an investigation and discovered that unauthorized parties had been copying and encrypting information for years. The company publicly disclosed the breach on November 30 2018. The initial estimates suggested that 500 million guests were affected. Marriott later revised this number and the Federal Trade Commission confirmed that malicious actors accessed 339 million Starwood guest account records worldwide.
The compromised database contained a massive volume of sensitive personal information. The stolen records included names, mailing addresses, email addresses, phone numbers, birth dates, gender, and Starwood loyalty program account details. The exposure of loyalty points became a serious matter for consumers. The Federal Trade Commission recognized these loyalty points as personal assets in the December 2024 consent order. Marriott agreed to restore the stolen loyalty points to affected customers.
Cryptographic Failures and Unencrypted Data
The breach exposed specific vulnerabilities in how Starwood stored highly sensitive identification and financial data. Hackers accessed 25. 5 million passport numbers. Marriott confirmed that 5. 25 million of these passport numbers were stored in plain text. The absence of encryption for these documents provided attackers with direct access to valuable identity information. The remaining 20. 3 million passport numbers were encrypted. Marriott stated there was no evidence that the attackers accessed the master encryption key needed to decrypt those specific files.
The database also contained approximately 8. 6 million encrypted payment cards. Out of that total, approximately 354, 000 payment cards were unexpired as of September 2018. Marriott initially reported in 2018 that the payment card numbers and certain passport numbers were protected using Advanced Encryption Standard 128. The company updated this assessment in April 2024. Following a forensic investigation, Marriott determined that the payment card numbers and a portion of the passport numbers were actually protected with a different cryptographic method known as Secure Hash Algorithm 1. The Federal Trade Commission noted these cryptographic failures in its final complaint.
| Starwood Database Breach: Compromised Records Breakdown | |
|---|---|
| Total Guest Records |
339 Million
|
| Encrypted Passports |
20. 3M
|
| Encrypted Payment Cards |
8. 6M
|
| Unencrypted Passports |
5. 25M
|
| Data Source: Federal Trade Commission Complaint and Marriott International Disclosures 2018 to 2024 |
Federal Trade Commission Findings on Legacy System Failures
The Federal Trade Commission finalized its consent order against Marriott on December 20 2024. The regulatory agency detailed specific security failures within the legacy Starwood systems. The complaint alleges that Marriott and Starwood failed to implement appropriate password controls and access controls. The companies also failed to establish proper firewall controls and network segmentation. These structural weaknesses allowed the attackers to move freely through the network after the initial intrusion.
The Federal Trade Commission complaint states that Marriott and Starwood deceived consumers by claiming to have reasonable and appropriate data security. The companies unfairly failed to deploy reasonable or appropriate security to protect personal information.
The agency also found that the companies failed to patch outdated software and systems. The legacy infrastructure ran on outdated applications that provided easy entry points for the hackers. The network environments absence adequate logging and monitoring capabilities. This absence of visibility explains why the bulk data extraction went unnoticed for four years. The Federal Trade Commission also noted that Marriott failed to deploy adequate multifactor authentication across the acquired network. The December 2024 consent order mandates a complete overhaul of these security practices and requires Marriott to undergo independent third party assessments every two years.
The regulatory investigation revealed that Starwood stored sensitive guest information in a centralized database without adequate internal access restrictions. Employees and third party contractors could query the database without triggering security alerts. The Federal Trade Commission emphasized that implementing proper network segmentation would have contained the breach to a smaller subset of the infrastructure. Marriott failed to isolate the legacy reservation system from the broader corporate network during the integration process. This architectural failure maximized the volume of data available to the attackers.
Due Diligence Failures and Post Acquisition Integration
The acquisition of Starwood Hotels presented a massive technical integration challenge for Marriott. The Federal Trade Commission complaint explicitly recites the timeline for the due diligence and acquisition of Starwood. The agency used this timeline as the basis for holding Marriott responsible for the pre acquisition security incidents. Regulators determined that Marriott became fully responsible for all Starwood systems following the transaction close in September 2016. The failure to identify the ongoing breach during the integration phase highlighted severe flaws in the corporate merger process.
Industry standards dictate that acquiring companies must perform rigorous technical audits on target networks. Marriott laid off IT and security staff from Starwood after the acquisition. This decision eliminated the personnel who understood the legacy network architecture. The remaining team members did not possess the institutional knowledge required to identify anomalous database queries. The attackers continued to copy and encrypt guest data while Marriott operated the compromised systems. The Federal Trade Commission action establishes a clear precedent that acquiring companies bear full responsibility for the cybersecurity posture of their subsidiaries.
Mandatory Data Minimization Rules Required by 2025
Mandatory Data Minimization Rules Required by 2025

20 Questions and Answers Regarding Data Minimization Mandates
| Question | Answer |
|---|---|
| 1. What does the Federal Trade Commission mandate regarding data retention? | The agency requires Marriott to keep personal information only as long as reasonably necessary. |
| 2. When is the deadline for full implementation under the parallel state settlement? | The deadline is October 9 2025. |
| 3. What specific right must Marriott offer to its customers? | Marriott must provide a link for customers to request the deletion of their personal information. |
| 4. Does this deletion right apply to all United States customers? | Yes. |
| 5. Which specific data points are tied to the deletion request link? | The link applies to personal information associated with an email address or a loyalty rewards account number. |
| 6. How long does the Federal Trade Commission consent order last? | The order remains in effect for 20 years. |
| 7. What must Marriott document regarding its data retention? | The company must document its business justifications for retaining specific types of personal data. |
| 8. What happens to removed information technology assets? | Marriott must destroy or encrypt personal information on any removed assets. |
| 9. How frequently must an independent third party assess the security program? | An independent assessor must evaluate the program every two years. |
| 10. What must Marriott certify annually? | The company must certify its compliance with the consent order to the Federal Trade Commission every year. |
| 11. What principle governs the new data collection rules? | The principle of data minimization restricts collection to what is necessary for specific business purposes. |
| 12. How does the order address loyalty points? | Marriott must restore loyalty points stolen by malicious actors upon customer request. |
| 13. What must Marriott disclose at the time of data collection? | The company must share the specific purpose for collecting the information. |
| 14. How states participated in the parallel settlement? | Forty nine states and the District of Columbia participated. |
| 15. What financial penalty accompanied the state settlement? | Marriott agreed to pay 52 million dollars to the participating states. |
| 16. What must Marriott do regarding vendor oversight? | The company must select vendors capable of safeguarding personal information and contractually require them to maintain sufficient safeguards. |
| 17. What is the deadline for the Federal Trade Commission consent order implementation? | The federal order carries a 180 day implementation deadline from its finalization date. |
| 18. When did the Federal Trade Commission finalize the consent order? | The agency finalized the agreement on December 20 2024. |
| 19. How customer records were affected by the breaches? | The breaches affected more than 344 million customers worldwide. |
| 20. What must Marriott do regarding asset inventory? | The company must use scanning tools to regularly inventory and classify all information technology assets containing personal data. |
The Federal Trade Commission finalized a consent order against Marriott International and its subsidiary Starwood Hotels on December 20 2024. The regulatory action addresses multiple data breaches that exposed the personal information of more than 344 million customers between 2014 and 2020. The final order mandates strict data minimization rules that the hotel chain must implement. The agency requires Marriott to establish a complete information security program. The company must retain personal information only for as long as reasonably necessary to fulfill the specific purpose for which it was collected. The order prohibits the company from misrepresenting its practices regarding the collection, maintenance, use, deletion, or disclosure of consumer data. The agency imposes a 20 year term on these requirements.
Data minimization represents a core component of the federal mandate. Marriott must implement a formal policy that restricts data retention. The company must document its business justifications for keeping specific types of personal information. Regulators found that the hotel chain previously held vast amounts of consumer data without a valid business reason. This practice increased the severity of the data breaches. The new rules force the company to evaluate why it needs the data and what specific data elements are actually necessary. The company must share the purpose behind collecting personal information with consumers. The company must also explain its specific business need for retaining the data.
The consent order introduces a specific deletion mandate for the hotel chain. Marriott must provide a clear link on its website and mobile application for United States customers to request the deletion of their personal information. This requirement applies to data associated with an email address or a loyalty rewards account number. The agency imposes this obligation regardless of whether the customer resides in a state jurisdiction that provides a statutory right to delete. Legal analysts note that this marks the time the Federal Trade Commission has required a company that suffered a security breach to provide all customers with such a deletion link. The company must honor these requests even if the data otherwise meets the standard for retention.
Vendor oversight forms another serious part of the regulatory requirements. Marriott must select and retain vendors capable of safeguarding the personal information of its customers. The company must contractually require these third party vendors to implement and maintain sufficient security safeguards. The order addresses security weaknesses introduced through external partnerships and acquired entities. If Marriott acquires another entity in the future, the company must assess the information security program of the acquired entity to identify security weaknesses and address them promptly. The failure to properly evaluate the Starwood network after the 2016 acquisition contributed directly to the prolonged data exposure.
The regulatory framework includes strict deadlines for compliance. The Federal Trade Commission order carries a 180 day implementation deadline from its finalization date. A parallel settlement with 49 states and the District of Columbia requires full implementation of similar security measures by October 9 2025. The state agreement also mandates a 52 million dollar payment. The company must use scanning or equivalent monitoring tools to regularly inventory and classify its information technology assets that contain personal information. This inventory must include hardware, software, and location information for any relevant assets. The company must destroy or encrypt personal information on any removed assets.
Marriott FTC Compliance Timeline
The order establishes strict accountability measures to ensure ongoing compliance. Marriott must undergo an independent assessment of its information security program every two years. This third party evaluation continues for the entire 20 year duration of the consent order. The company must also provide an annual certification to the Federal Trade Commission confirming its compliance with the terms of the agreement. The company must submit notifications to the agency within 10 days of any legally mandated reportable incident. The order requires Marriott to provide a method for consumers to request a review of unauthorized activity in their loyalty rewards accounts. The company must restore any loyalty points stolen by malicious actors.
The historical context of the regulatory action shows the danger of excessive data retention. Malicious actors accessed 5. 2 million guest records worldwide during the breaches. The compromised records contained significant amounts of personal information. The stolen data included names, mailing addresses, email addresses, phone numbers, birth dates, and loyalty account information. The attackers also obtained 5. 25 million unencrypted passport numbers. The Federal Trade Commission noted that much of the exposed data was either unnecessary for the company to collect or was held for significantly longer than needed. The new data minimization policy directly addresses this specific security weakness by forcing the destruction of unneeded records.
The regulatory action aligns with broader shifts in privacy enforcement across the United States. State privacy laws increasingly adopt data minimization as a fundamental requirement. The Maryland Online Data Privacy Act of 2024 requires companies to limit data collection to what is reasonably necessary to provide a specific product or service. The Colorado Privacy Act mandates that collected data be necessary, adequate, and relevant. The Federal Trade Commission uses the Marriott consent order to establish a clear standard for reasonable security practices. The agency demonstrates its readiness to bring enforcement actions against companies that fail to implement data disposal policies. The 52 million dollar penalty from the state attorneys general reinforces the financial consequences of improper data handling.
Third Party Vendor Oversight Requirements Under the Settlement Terms
20 Questions and Answers Regarding Third Party Vendor Oversight
| Question | Answer |
|---|---|
| 1. What exact date did the Federal Trade Commission finalize the consent order? | The agency finalized the consent order on December 20 2024. |
| 2. How long does the Federal Trade Commission order remain active? | The order remains active for 20 years. |
| 3. What specific vendor category does the state settlement define? | The state settlement defines a category for essential IT vendors. |
| 4. What penalty did Marriott agree to pay in October 2024? | Marriott agreed to pay 52 million dollars to 49 states and the District of Columbia. |
| 5. How frequently must Marriott obtain independent security assessments? | Marriott must obtain independent security assessments every two years. |
| 6. When is the third party assessment due? | The assessment covers the 365 days after the order issuance. |
| 7. What specific property type led to the 2020 breach? | A franchised property led to the 2020 breach. |
| 8. How guest records were exposed in the 2020 breach? | Hackers accessed 5. 2 million guest records in the 2020 breach. |
| 9. What must Marriott do regarding franchised hotel compliance? | Marriott must develop a risk based audit program to review franchised hotel compliance. |
| 10. What contractual rights must Marriott retain over franchises? | Marriott must retain contractual rights to enforce security requirements at franchised hotels. |
| 11. How fast must Marriott review logs for anomalous activity? | Marriott must review logs for anomalous activity within 24 hours. |
| 12. What access controls must Marriott implement for vendors? | Marriott must implement data access controls and use the principle of least privilege. |
| 13. What authentication method is required for vendor access? | Multi factor authentication is required for vendor access. |
| 14. How long did the 2014 breach go unnoticed? | The 2014 breach went unnoticed for four years. |
| 15. What specific data was exposed in the Starwood breach? | Hackers accessed 339 million guest records including 5. 25 million unencrypted passport numbers. |
| 16. What must Marriott provide to the independent assessor? | Marriott must provide all relevant information and IT assets to the independent assessor. |
| 17. Who must receive the biennial assessment reports? | The Associate Director for Enforcement at the Federal Trade Commission must receive the reports. |
| 18. How days does Marriott have to submit the report upon request? | Marriott has 10 days to submit the report upon request. |
| 19. What must Marriott do before hiring new vendors? | Marriott must select vendors capable of safeguarding personal information. |
| 20. What must Marriott include in vendor contracts? | Marriott must contractually require vendors to implement and maintain sufficient safeguards. |
Federal Trade Commission Mandates for Vendor Management
The Federal Trade Commission finalized a consent order on December 20 2024. This order requires Marriott International and Starwood Hotels to implement strict oversight over third party service providers. The regulatory action follows a 2020 breach where malicious actors gained access to the corporate network using compromised credentials from a franchised property. Hackers accessed 5. 2 million guest records during this intrusion.
The agency mandates that Marriott develop and maintain written policies for all third party vendors. Marriott must select and retain vendors capable of safeguarding personal information. The corporation must contractually require these vendors to implement sufficient safeguards. The order remains active for 20 years.
State Settlement Rules for Essential IT Vendors
In October 2024 Marriott agreed to pay 52 million dollars to 49 states and the District of Columbia. The state settlement establishes a specific category for essential IT vendors. These vendors manage significant components of the information security program and have access to corporate databases.
For these essential IT vendors Marriott must develop and maintain enhanced security procedures. The requirements include strict contractual provisions and active vendor performance monitoring. Marriott must enforce access limitations for these external providers. The state settlement requires full implementation by October 9 2025.
Franchised Hotel Audit Requirements
The Federal Trade Commission defines a franchised hotel as any property owned and operated by a third party under a Marriott brand. The 2020 breach demonstrated that franchised properties pose a serious risk to the central corporate network.
Marriott must develop a risk based audit program to review compliance at all franchised hotels. The corporation must retain appropriate contractual rights to enforce security requirements at these properties. Marriott must ensure that franchised hotels follow the mandated information security program.
Independent Biennial Assessments
The Federal Trade Commission requires Marriott to obtain an independent assessment of its information security program. A third party assessor must conduct this evaluation every two years. The assessment covers the 365 days after the December 20 2024 order issuance.
Marriott must provide the assessor with all relevant information and IT assets. The assessor determines whether Marriott implemented the required security measures. Marriott must retain these assessment reports until the order terminates in 2044. The corporation must provide the reports to the Associate Director for Enforcement within 10 days of a request.
Access Controls and Network Monitoring
Marriott must implement strict data access controls for all employees and vendors. The corporation must use the principle of least privilege. This principle ensures that vendors only access the data necessary for their specific tasks.
The order requires multi factor authentication for all vendor access. Marriott must use technical measures to actively review logs for anomalous activity. The security team must review these logs within 24 hours. The corporation must investigate any suspicious activity within 24 hours.
Pre Engagement Due Diligence and Vendor Selection
The Federal Trade Commission complaint details how Marriott failed to conduct adequate security due diligence during the Starwood acquisition. Attackers compromised the Starwood network in July 2014. Marriott acquired Starwood in 2016 and inherited the compromised network. The breach remained active until September 2018.
The finalized order requires Marriott to implement strict pre engagement measures for all third party service providers. Marriott must evaluate the security posture of any vendor before granting network access. The corporation must assess the risk from any third party whose network could affect Marriott systems if compromised. This requirement directly addresses the failures observed during the Starwood integration.
Legal Accountability and the Accenture Lawsuit
The data breaches resulted in multiple class action lawsuits against Marriott and its vendors. Plaintiffs filed lawsuits against Accenture. Accenture served as the third party IT provider for Marriott.
On June 3 2025 the Fourth Circuit Court of Appeals ruled in favor of Marriott. The court reversed a lower court decision that certified the class action. The Fourth Circuit upheld the validity of a waiver in the Starwood Preferred Guest contracts. This ruling allowed the hotel chain to avoid shared legal action regarding the vendor security failures.
Technical Specifications for Vendor Access
The state settlement mandates specific technical requirements for vendor access. Marriott must comply with Payment Card Industry Data Security Standards. The corporation must implement Zero Trust principles for all external connections. Zero Trust requires strict identity verification for every person and device attempting to access resources on a private network.
Marriott must use digital certificates to authenticate vendor devices. The corporation must maintain an accurate asset inventory that tracks all hardware and software used by third party providers. The security team must apply vulnerability and patch management procedures to all vendor facing systems.
Data Minimization and Vendor Retention
The Federal Trade Commission requires Marriott to minimize the data shared with third party vendors. Marriott must retain personal information only as long as reasonably necessary to fulfill the specific purpose for data collection. The corporation must implement data disposal policies to ensure vendors delete consumer information when it is no longer required.
Within 180 days of the order issuance Marriott must provide a clear link on its website and mobile applications. This link allows U. S. consumers to request the deletion of their personal information. Marriott must verify receipt of each request and explain the deletion process within 60 days. The corporation must ensure that third party vendors also delete the requested consumer data.
Board Management and Vendor Oversight
The state settlement imposes strict board management requirements regarding vendor oversight. Marriott must appoint a Chief Information Security Officer. The corporation must appoint a Board Committee focused entirely on the information security program.
This Board Committee must meet at least four times a year. The committee reviews vendor performance monitoring reports and assesses the risks posed by essential IT vendors. The Chief Information Security Officer must provide regular security reporting to top management and the Chief Executive Officer.
Mandatory Training and Tabletop Exercises
Marriott must provide specialized training to employees who manage third party vendors. The state settlement requires annual tabletop exercises. These exercises simulate cyber attacks originating from vendor networks.
The security team uses these simulations to test the incident response plan. The 2020 breach demonstrated the need for rapid diagnosis after the breach. Marriott detected the 2020 franchise breach in six weeks. The tabletop exercises aim to reduce this detection time to the mandated 24 hour window.
Financial Penalties and International Regulatory Action
The vendor security failures resulted in severe financial penalties across multiple jurisdictions. The United Kingdom Information Commissioner Office fined Marriott 18. 4 million pounds in 2020 for violating the General Data Protection Regulation. This fine specifically addressed the poor security due diligence during the Starwood acquisition.
In the United States Marriott agreed to pay 52 million dollars to resolve the state investigations. The total financial impact of the data breaches exceeds 100 million dollars when combining settlements, fines, and recovery costs. The Federal Trade Commission order does not include an additional financial penalty imposes heavy compliance costs for the two decades.
Specific Data Exposed Through Vendor Vulnerabilities
The compromised third party networks allowed hackers to access highly sensitive consumer information. During the Starwood breach attackers stole 339 million guest records. The exposed data included 5. 25 million unencrypted passport numbers.
The 2020 breach through the franchised property exposed 5. 2 million guest records. This data included names, mailing addresses, email addresses, phone numbers, dates of birth, and loyalty account information. The Federal Trade Commission noted that bad actors could use this detailed information to create highly successful phishing campaigns and commit financial fraud.
Continuous Monitoring and Incident Response
The Federal Trade Commission order mandates continuous monitoring of all network traffic involving third party vendors. Marriott must deploy an Information and Event Management solution to collect logs from all IT assets. The security team must actively review these logs to detect active threats within a 24 hour period.
If the monitoring system detects suspicious activity Marriott must initiate an investigation within 24 hours. The corporation must submit notifications to the authorities within 10 days of any legally mandated reportable incident. This rapid response requirement directly addresses the four year delay in detecting the initial Starwood breach.
Chart: Multi Colored Vendor Oversight Compliance Timeline
| Compliance Phase | Required Action | Completion Date | Regulatory Body |
|---|---|---|---|
| Phase 1: Consumer Rights | Deploy data deletion request link on website and mobile applications | June 18 2025 | Federal Trade Commission |
| Phase 2: State Mandates | Full implementation of essential IT vendor security procedures | October 9 2025 | State Attorneys General |
| Phase 3: Independent Audit | Complete biennial third party information security assessment | December 20 2025 | Federal Trade Commission |
| Phase 4: Long Term Oversight | Final termination of the consent order and continuous monitoring requirements | December 20 2044 | Federal Trade Commission |
Multi Factor Authentication Implementation Across Corporate Networks
20 Questions and Answers Regarding Multi Factor Authentication Mandates
| Question | Answer |
|---|---|
| 1. What specific authentication protocol does the Federal Trade Commission mandate for Marriott? | The agency mandates Multi Factor Authentication for all network access. |
| 2. When did the Federal Trade Commission finalize the consent order? | The agency finalized the order on December 20 2024. |
| 3. What is the deadline for Marriott to implement the mandated security program under the federal order? | The deadline is June 17 2025. |
| 4. What is the deadline for full implementation under the state attorneys general settlement? | The state settlement requires full implementation by October 9 2025. |
| 5. Who must use the new authentication for remote access? | All Marriott employees and vendors must use the for remote access. |
| 6. Does the order require customer facing authentication changes? | Yes Marriott must offer enhanced authentication options for United States consumers. |
| 7. Which specific customer accounts require the new authentication option? | Loyalty rewards accounts require the new authentication option. |
| 8. Can Marriott use authentication data for marketing purposes? | No the company can only use the data for authentication purposes. |
| 9. How long did the initial Starwood breach go due to poor access controls? | The initial breach went for 14 months ending in 2015. |
| 10. How guest records did the third breach expose between 2018 and 2020? | The third breach exposed more than 5. 2 million guest records. |
| 11. How did attackers execute the third breach? | Attackers compromised the credentials of employees at a franchise property. |
| 12. Could enhanced authentication have prevented the third breach? | Security experts indicate the protocol can stop attackers from using stolen credentials. |
| 13. How long does the federal consent order remain in effect? | The order remains in effect for 20 years. |
| 14. How frequently must Marriott undergo independent security assessments? | The company must undergo independent assessments every two years. |
| 15. How much money did Marriott agree to pay to state regulators? | The company agreed to pay 52 million dollars to 49 states and the District of Columbia. |
| 16. What specific network assets require enhanced authentication for remote access? | All information technology assets including databases require the protocol. |
| 17. Did Starwood comply with its own internal authentication policies before the acquisition? | No the subsidiary failed to comply with internal policies requiring enhanced remote access. |
| 18. What happens if Marriott fails to implement the required by the 2025 deadline? | The company faces further federal enforcement actions and financial penalties. |
| 19. Does the mandate apply to franchised hotel locations? | Yes Marriott must ensure franchised hotels implement comparable access controls. |
| 20. How quickly must Marriott report future security incidents to the federal government? | The company must report incidents within 10 days of notifying other government entities. |
Federal Directives for Corporate Network Access Controls
The Federal Trade Commission finalized a consent order on December 20 2024. The directive forces Marriott International to overhaul its corporate network security. Regulators identified the absence of Multi Factor Authentication as a primary failure that enabled attackers to compromise systems between 2015 and 2020. The mandate requires the hospitality corporation to deploy enhanced authentication across all internal networks by June 17 2025. State attorneys general imposed a parallel deadline of October 9 2025 for full implementation.
Network access controls represent the core of the federal mandate. Marriott must require Multi Factor Authentication for all employees and vendors accessing corporate information technology assets remotely. This requirement covers all internal databases and administrative portals. The Federal Trade Commission noted that Starwood Hotels failed to enforce its own internal authentication policies before the 2016 acquisition. Attackers exploited this vulnerability to extract records for years.
Vulnerabilities Exposed by Legacy Authentication Failures
The third major breach occurred between September 2018 and early 2020. Malicious actors compromised the credentials of employees at a franchised property. The attackers used these stolen credentials to access the central network. They extracted more than 5. 2 million guest records. Security analysts confirm that mandatory Multi Factor Authentication can prevent unauthorized access even when attackers possess valid passwords. The new federal order directly addresses this specific vulnerability.
Consumer protections form another pillar of the December 2024 settlement. Marriott must offer enhanced authentication options to United States consumers for their loyalty rewards accounts. The Marriott Bonvoy program holds sensitive personal data and valuable points. The company must allow users to secure their accounts with Multi Factor Authentication. The federal order strictly prohibits Marriott from using the data collected for authentication for any other purpose. The company cannot use phone numbers provided for security verification to send marketing messages.
Financial Penalties and Mandatory Independent Audits
The financial consequences of these security failures are severe. Marriott agreed to pay 52 million dollars to 49 states and the District of Columbia. The company faces 20 years of federal oversight. Independent assessors must evaluate the corporate security program every two years. Marriott must submit the initial assessment to the Federal Trade Commission and retain subsequent reports for five years. The company must report any new security incidents to the federal government within 10 days of notifying other authorities.
Corporate network segmentation and access logging accompany the authentication mandates. The Federal Trade Commission requires Marriott to monitor all information technology assets continuously. The system must detect anomalous activities within 24 hours. Attackers operated inside the Starwood network for four years without detection. The new force the company to identify unauthorized access attempts immediately. Multi Factor Authentication generates specific logs when users fail to provide the secondary credential. Security teams can use these logs to track targeted attacks against employee accounts.
Third Party Vendor Integration and Access Restrictions
Vendor oversight integrates directly with the new authentication rules. Third party contractors frequently require remote access to corporate databases. The federal order mandates that all vendors use Multi Factor Authentication when connecting to Marriott systems. The company must evaluate the security posture of its partners before granting access. Marriott cannot integrate newly acquired systems from mergers until those networks meet the new authentication standards. This rule prevents a repeat of the Starwood acquisition disaster.
The implementation timeline demands rapid action from corporate executives. The Federal Trade Commission provided exactly 180 days from the December 20 2024 finalization date. Marriott must complete the initial deployment by June 17 2025. The company must train all employees on the new access. Franchised hotel locations must also adopt comparable security measures. The corporate office must enforce these rules through strict contractual agreements with franchise owners.
Consumer Privacy and Data Minimization Standards
The authentication data restrictions protect consumer privacy. Regulators discovered that corporations misuse security data for commercial gain. The consent order explicitly blocks this practice at Marriott. If a customer provides a mobile number to secure a rewards account the company can only use that number to send verification codes. This strict data minimization rule aligns with broader federal efforts to limit corporate data collection.
The independent audit requirement ensures long term compliance. The biennial assessments test the effectiveness of the Multi Factor Authentication deployment. Auditors attempt to bypass the access controls during penetration testing. Marriott must cooperate fully with the independent assessors. The company must provide access to all relevant information and network assets. If the auditors discover vulnerabilities Marriott must design and execute a remediation plan immediately.
Duration of Network Intrusions Prior to Authentication Mandates
The absence of enhanced authentication allowed malicious actors to maintain persistent access to corporate networks. The chart details the duration of the three major intrusions in the federal complaint.
| Breach 1 (Ending 2015) |
14 Months
|
| Breach 2 (Ending 2018) |
48 Months
|
| Breach 3 (2018 to 2020) |
18 Months
|
The data confirms that attackers operated freely within the network infrastructure for extended periods. The implementation of Multi Factor Authentication forces attackers to present secondary credentials. This requirement disrupts the intrusion lifecycle and alerts security personnel to compromised accounts. The Federal Trade Commission mandate ensures that Marriott establishes these necessary blocks to protect the personal information of millions of global consumers.
Independent Information Security Assessments and Biennial Audits
| Query | Verified Data |
|---|---|
| What is the duration of the Federal Trade Commission consent order? | 20 years |
| How frequently must Marriott conduct third party security assessments? | Every two years |
| Who finalized the consent order? | The Federal Trade Commission |
| When was the federal order finalized? | December 20, 2024 |
| What is the deadline for full implementation under the parallel state settlement? | October 9, 2025 |
| How states participated in the parallel settlement? | 49 states and the District of Columbia |
| Who must approve the independent assessor? | The Federal Trade Commission |
| What qualifications must the assessor hold under the state agreement? | CISSP or CISA certification and five years of experience |
| What period does the initial federal assessment cover? | The 365 days after the order issuance |
| Are franchised hotels included in the audit requirements? | Yes, Marriott must implement a risk based audit program for franchisees |
| What happens when Marriott acquires a new entity? | Marriott must conduct post acquisition assessments to verify compliance |
| How much did Marriott pay in civil penalties to the states? | $52 million |
| How customers were affected by the breaches? | More than 344 million |
| What specific technical safeguards must the audits verify? | Multi factor authentication, encryption, and patch management |
| To whom must Marriott submit the biennial assessments? | The Associate Director for Enforcement |
| How long must Marriott retain the assessment reports? | Until the 20 year order terminates |
| How quickly must Marriott supply the reports upon federal request? | Within 10 days |
| Does the federal order require annual internal evaluations? | Yes, Marriott must evaluate the security program at least once annually |
| What testing must occur after a covered incident? | Prompt testing within 120 days |
| Can Marriott use an assessor rejected by the federal government for the state requirements? | No, the state agreement prohibits using a rejected assessor |
The Federal Trade Commission finalized a consent agreement with Marriott International and Starwood Hotels on December 20, 2024. The mandate enforces a 20 year oversight period requiring the hospitality corporation to execute an information security program. The directive demands an independent third party assessment of the security infrastructure every two years. Marriott must submit the initial evaluation covering the 365 days following the order issuance. The company must deliver subsequent biennial reports to the Associate Director for Enforcement.
The parallel settlement with 49 states and the District of Columbia imposes a strict timeline. Marriott must achieve full implementation of the security program by October 9, 2025. The state agreement requires the independent assessor to hold specific credentials. The auditor must possess a Certified Information Systems Security Professional or Certified Information Systems Auditor designation. The evaluator must also demonstrate at least five years of experience in computer system security. The Federal Trade Commission retains the authority to approve or reject the selected assessor. The state attorneys general prohibit Marriott from using any auditor rejected by federal regulators.
The compliance mandate extends beyond corporate owned properties. Marriott must enforce a risk based audit program across all franchised hotels. The corporation must maintain contractual rights to compel franchisee compliance with the security obligations. The oversight requirements apply to future business expansion. Marriott must evaluate any newly acquired entity to verify the target company meets the security standards outlined in the consent order.
The independent audits must validate specific technical controls. The assessors evaluate the deployment of multi factor authentication, data encryption, and asset inventory management. The evaluation includes verifying vulnerability patching and network segmentation. Marriott must conduct internal risk assessments annually. The company must execute penetration testing at least once a year and within 120 days of any covered security incident. Marriott must retain all biennial assessment reports until the 20 year order expires. The corporation must provide these documents to federal regulators within 10 days of a formal request.
| Requirement | Frequency | Governing Body | Deadline / Duration |
|---|---|---|---|
| Full Program Implementation | One time | State Attorneys General | October 9, 2025 |
| Independent Security Assessment | Biennial | Federal Trade Commission | 20 Years |
| Internal Risk Evaluation | Annual | Federal Trade Commission | 20 Years |
| Post Incident Penetration Testing | Per Incident | Federal Trade Commission | Within 120 Days |
Customer Data Deletion Requests and Processing Timelines
20 Questions and Answers Regarding Data Deletion Mandates
| Question | Answer |
|---|---|
| 1. What exact date did the Federal Trade Commission finalize the Marriott consent order? | The agency finalized the order on December 20 2024. |
| 2. How days does Marriott have to implement the deletion link under the federal order? | Marriott has 180 days from the order issuance to implement the link. |
| 3. What is the deadline for Marriott to deploy the deletion link? | The deadline falls in June 2025. |
| 4. How days does Marriott have to verify receipt of a customer deletion request? | Marriott must verify receipt within 60 days. |
| 5. What must Marriott explain to the consumer within that 60 day window? | The company must explain the exact process of data deletion. |
| 6. Which platforms must feature the clear and conspicuous deletion link? | The link must appear on the Marriott website and mobile applications. |
| 7. Which specific customer identifiers trigger the deletion process? | Customers can request deletion using their email address or loyalty rewards account number. |
| 8. Does the federal mandate apply to all global customers? | The federal mandate specifically requires the deletion option for United States consumers. |
| 9. How states participated in the parallel settlement regarding data deletion? | A coalition of 49 states and the District of Columbia participated. |
| 10. What is the implementation deadline under the state attorney general settlement? | The state settlement requires full implementation by October 9 2025. |
| 11. Can Marriott retain data if a customer requests deletion? | Marriott can retain data only if required for documented accounting tax or legal obligations. |
| 12. What historical data breach timeframe prompted these deletion requirements? | The breaches occurred between 2014 and 2020. |
| 13. How total customer records were exposed during the breaches? | Malicious actors accessed more than 344 million customer records. |
| 14. What specific loyalty program is subject to these new deletion and review rules? | The rules apply to the Marriott Bonvoy loyalty rewards program. |
| 15. Did the Federal Trade Commission rely on a notice and choice model for this order? | The agency departed from that model to mandate an active right to delete. |
| 16. How states already had data privacy laws with deletion provisions before 2025? | Twenty states had enacted such laws. |
| 17. What happens if Marriott removes an IT asset containing personal information? | The company must encrypt the data or physically destroy the asset. |
| 18. What penalty amount did Marriott agree to pay the states? | Marriott agreed to pay 52 million dollars. |
| 19. How long does the federal consent order remain active? | The order remains active for 20 years. |
| 20. Who voted to approve the final federal order? | The commission voted three to zero with two recusals to approve the final order. |
Federal Mandates for Consumer Data Deletion
The Federal Trade Commission finalized a consent order against Marriott International on December 20 2024. The agency dictates exact parameters for how the hotel chain must handle consumer data deletion requests. Regulators require Marriott to deploy a clear and conspicuous link on its website and mobile applications. This portal must allow United States consumers to request the permanent deletion of their personal information. The directive specifically data tied to email addresses and Marriott Bonvoy loyalty rewards account numbers.
The regulatory action from three large data breaches occurring between 2014 and 2020. Malicious actors accessed more than 344 million customer records during this period. The compromised databases contained passport numbers payment card details and loyalty account information. The Federal Trade Commission responded by forcing Marriott to abandon passive privacy policies. The agency mandated an active right to delete framework. This represents a major shift in federal privacy enforcement. Regulators previously relied on a notice and choice model where consumers simply accepted or declined privacy terms. The new order forces Marriott to actively manage and destroy data upon request.
The 180 Day Implementation Window
Marriott faces a rigid timeline to build and deploy this deletion infrastructure. The federal order grants the company exactly 180 days from the December 20 2024 issuance date to make the deletion link live. This places the federal compliance deadline in June 2025. The company must engineer a system capable of receiving processing and verifying requests across its entire digital footprint. The mandate covers the primary Marriott website and all associated mobile applications.
A parallel settlement with 49 state attorneys general and the District of Columbia enforces a similar mandate. The state agreement requires full implementation of the data deletion system by October 9 2025. Marriott must meet the earlier federal deadline to avoid violating the consent decree. The company agreed to pay 52 million dollars to the states to resolve the parallel investigations. The Federal Trade Commission does not have the authority to impose civil penalties in this specific case the agency retains the power to fine Marriott up to 51744 dollars for each future violation of the consent order.
The 60 Day Processing Requirement
Once a consumer submits a deletion request the clock starts for Marriott. The federal order compels the company to verify receipt of the request within 60 days. During this 60 day window Marriott must also explain the exact process it uses to delete the data. This forces the company to maintain precise tracking systems for all inbound requests. Regulators designed this timeline to prevent corporations from ignoring consumer privacy demands.
The 60 day rule requires Marriott to overhaul its internal data architecture. The company must map all databases storing personal information to ensure it can locate and delete specific user records. The order requires Marriott to establish scanning tools to inventory and classify all IT assets containing personal data. The company must know exactly where consumer information resides to comply with the 60 day processing mandate. If Marriott cannot locate the data it cannot delete it. The Federal Trade Commission requires the company to certify compliance with these rules annually for the 20 years.
Exceptions and Retained Data Categories
The right to delete is not absolute. Regulators permit Marriott to retain specific subsets of consumer data even after receiving a valid deletion request. The company can keep information if a documented accounting tax or legal obligation requires retention. Marriott must disclose the specific business need for retaining any personal information in its privacy policy. The company must also implement a strict data minimization policy. This policy must ensure Marriott retains personal information only for as long as is reasonably necessary to fulfill the original collection purpose.
The consent order also dictates how Marriott must handle physical hardware. If the company decommissions an IT asset containing personal data it must encrypt the information or destroy the hardware completely. Marriott cannot simply unplug a server and leave the data intact. The company must actively wipe or physically destroy the storage media. This requirement prevents discarded hardware from becoming a future security risk.
State Level Privacy Law Integration
The Federal Trade Commission order aligns with a growing trend in state level privacy legislation. Twenty states enacted data privacy laws with deletion provisions prior to 2025. These states include California Colorado and Delaware. The federal order forces Marriott to provide deletion rights to all United States consumers regardless of their state of residence. This eliminates the patchwork problem where only residents of specific states enjoy data privacy rights. Marriott must apply the highest standard of data deletion across its entire domestic customer base.
The company must also provide a method for consumers to request a review of unauthorized activity in their Marriott Bonvoy loyalty rewards accounts. If malicious actors stole loyalty points Marriott must restore them. This requirement directly addresses the financial harm consumers suffered during the 2014 to 2020 breaches. Loyalty points hold real monetary value and the Federal Trade Commission views their theft as a serious consumer injury.
Independent Audits and Compliance Verification
The Federal Trade Commission requires Marriott to undergo independent third party assessments every two years. These biennial audits verify if Marriott actually processes deletion requests within the mandated 60 day window. The assessor must evaluate the technical infrastructure Marriott uses to receive and execute these requests. If the auditor finds that Marriott ignores requests or fails to delete data from all connected databases the company faces heavy regulatory consequences. The assessment must cover the period beginning 60 days after the date of the order.
Marriott must retain detailed records of its compliance efforts. The company must keep accounting records and documentation of all consumer deletion requests. The order requires Marriott to maintain these records for five years. The Federal Trade Commission can demand access to these logs at any time. This record keeping mandate ensures regulators can verify Marriott claims of compliance. The company cannot simply state it deleted the data. It must provide technical proof that the information no longer exists on its servers.
The Federal Trade Commission order specifically identifies the data points subject to deletion. Consumers can demand the removal of any personal information linked to their email address or their Marriott Bonvoy loyalty rewards account number. This encompasses a vast array of data including names mailing addresses phone numbers dates of birth and reservation histories. The order forces Marriott to sever the connection between these identifiers and the underlying personal data. If a consumer submits a valid request using their email address Marriott must locate every database entry tied to that address and execute the deletion process. The commission voted three to zero with two recusals to approve the final order.
Marriott Data Deletion Compliance Timeline 2024 to 2025
Executive Accountability and Board Level Security Certifications

| Question | Answer |
|---|---|
| 1. Who must submit an annual compliance certification to the Federal Trade Commission? | The Chief Executive Officer of Marriott and Starwood must submit the document. |
| 2. How frequently must the Chief Executive Officer submit this certification? | The certification must be submitted annually. |
| 3. What penalty applies if Marriott executives submit a false certification? | The corporation faces serious monetary penalties. |
| 4. Which board committee oversees the information security program? | The Technology and Information Security Oversight Committee handles this responsibility. |
| 5. How times per year must the board committee meet? | The committee must meet at least four times per year. |
| 6. What must the board committee acknowledge in its meeting minutes? | The members must acknowledge the receipt of required security materials and presentations. |
| 7. By what date did the board committee need to acknowledge these materials? | The deadline was on or before December 31 2024. |
| 8. Who is mandated to oversee the implementation of the information security program? | An appointed Chief Information Security Officer or qualified executive must oversee the program. |
| 9. To whom must the Chief Information Security Officer report? | The officer must report directly to the board committee. |
| 10. What specific topics must the Chief Information Security Officer present to the board? | The officer must present risk assessments and updates on the information security program. |
| 11. How long do the Federal Trade Commission consent order obligations last? | The obligations extend for 20 years. |
| 12. When was the Federal Trade Commission consent order finalized? | The agency finalized the order on December 20 2024. |
| 13. What is the deadline for reporting a covered cyber incident to the governing body? | Marriott must report within 120 days of any legally required notification to authorities. |
| 14. Does the settlement require third party audits? | Yes, independent third party assessments are required biennially. |
| 15. Who must approve the third party assessor? | The Federal Trade Commission must approve the independent assessor. |
| 16. What must Marriott do if a covered entity is operating without a formal board of directors? | The entity must report to a senior officer responsible for the information security program. |
| 17. What penalty did Marriott pay to state attorneys general in October 2024? | Marriott paid 52 million dollars to 49 states and the District of Columbia. |
| 18. Does the consent decree mandate employee training? | Yes, the decree requires enhanced employee training on data handling and security. |
| 19. Which federal agency receives the annual executive certification? | The Federal Trade Commission receives the document. |
| 20. Are franchisees included in the security oversight mandates? | Yes, Marriott must enforce security compliance across franchised hotels. |
Executive Certification Mandates
The Federal Trade Commission finalized a consent order against Marriott International on December 20 2024. This regulatory action forces strict executive accountability for corporate data security. The Chief Executive Officer of Marriott and Starwood must submit a written certification of compliance to the Federal Trade Commission annually. This document verifies that the corporation adheres to the mandated information security program. Regulators designed this requirement to prevent executives from claiming ignorance about network weaknesses. If the Chief Executive Officer submits a false certification or fails to meet the requirements, the corporation faces serious monetary penalties. The obligations under this consent order extend for 20 years.
Board of Directors Oversight and Governance
The settlement mandates structural changes to how the Marriott Board of Directors handles cybersecurity. Marriott must maintain a specific board committee to oversee the information security program. This group, known as the Technology and Information Security Oversight Committee, must meet no less than four times per year. The committee assists the board with oversight of technology platforms, privacy regulations, and emerging technologies. On or before December 31 2024, and annually thereafter, the committee must acknowledge in its official minutes that it received the required security presentations and materials. The corporation must provide a written report to this governing body within 120 days of any cyber incident that legally requires notification to state or federal authorities. For any covered entity operating without a formal board, the organization must report directly to a senior officer responsible for the security program.
Chief Information Security Officer Responsibilities
Marriott must appoint a qualified employee to serve as the Chief Information Security Officer. This executive holds direct responsibility for implementing, maintaining, and monitoring the information security program. The mandate requires this officer to possess the education and experience appropriate for the size and complexity of the corporate network. The Chief Information Security Officer must report directly to the board committee regarding corporate risk assessments and security rules. This reporting structure removes middle management filters that previously obscured network weaknesses from top executives. The appointed officer must also guarantee that the corporation conducts an annual enterprise risk assessment and performs continuous risk analyses throughout the year.
Post Acquisition and Franchisee Security Audits
The Federal Trade Commission order forces Marriott to extend its security governance beyond its immediate corporate boundaries. Marriott must contractually bind its franchisees to the terms of the consent order and implement a risk based audit program to review franchisee compliance. Also, the settlement dictates strict rules for future corporate acquisitions. Before any newly acquired entity can access Marriott information technology assets, the corporation must conduct a post acquisition assessment. Executives must develop a formal plan and timeline to remediate any identified security gaps in the acquired network. This mandate directly addresses the failures that occurred during the 2016 Starwood acquisition, where intruders remained hidden in the legacy system for years.
Vendor Risk Management and Cloud Provider Contracts
The parallel 52 million dollar settlement with 49 state attorneys general imposes extra executive oversight requirements for third party vendors. Marriott executives must conduct specific risk assessments for all entities identified as essential information technology vendors. The corporation must also outline security expectations and data protection rules in all contracts with cloud service providers. These vendor management rules force corporate leaders to take legal responsibility for the security posture of their external partners, eliminating the ability to shift blame to third party contractors during a breach.
Independent Assessments and Compliance Verification
Beyond internal executive reporting, the Federal Trade Commission requires external validation. Marriott must engage an independent third party assessor on a biennial basis. The Federal Trade Commission retains the authority to approve or reject this chosen assessor. The assessor evaluates the effectiveness of the information security program and verifies that the executive certifications match the operational reality. The initial assessment covers the 365 days after the order publication. Subsequent assessments occur every two years for the duration of the 20 year consent decree. Marriott must submit these reports to the Associate Director for Enforcement at the Federal Trade Commission within 10 days of receiving them.
Enforcement Actions and Civil Penalties
The Federal Trade Commission possesses broad authority to enforce the terms of the 20 year consent decree. While the agency did not impose a direct financial penalty for the initial breaches, any violation of the new executive certification requirements triggers immediate civil penalties. The state attorneys general also retain the right to pursue further legal action if Marriott fails to maintain the mandated security rules. The settlement requires the corporation to maintain all third party assessment reports for five years after completion. Regulators can demand access to these documents at any time to verify that the board of directors and the Chief Information Security Officer are fulfilling their legal obligations. This continuous oversight guarantees that corporate executives remain legally liable for the security of consumer data.
Compliance Reporting Frequency Chart
Marriott Security Reporting Mandates
Loyalty Program Data Encryption Standards and Implementation Metrics
Loyalty Program Data Encryption Standards and Implementation Metrics
The Federal Trade Commission finalized a consent order on December 20 2024 that forces Marriott International to overhaul data protection standards for its Marriott Bonvoy loyalty program. Regulators mandate that the hotel chain encrypt all personal information transmitted externally or stored on corporate assets. The agency requires the company to meet industry recognized encryption key management standards. This regulatory action follows three data breaches between 2014 and 2020 that exposed 344 million guest records. Hackers accessed 5. 25 million unencrypted passport numbers and 20. 3 million encrypted passport numbers during these intrusions. The new mandates strictly govern how the company handles reservation details, hotel stay preferences, loyalty rewards numbers, and points balances.
To provide immediate clarity on these regulatory mandates, the following table answers twenty specific questions regarding the loyalty program encryption rules and implementation metrics.
| Query | Verified Data |
|---|---|
| What date did the Federal Trade Commission finalize the Marriott consent order? | December 20 2024. |
| How long do the Federal Trade Commission security mandates last? | 20 years. |
| What loyalty program is directly affected by this decree? | Marriott Bonvoy. |
| How total guest records were exposed across the breaches? | 344 million. |
| How unencrypted passport numbers did hackers access? | 5. 25 million. |
| How encrypted passport numbers were exposed? | 20. 3 million. |
| What specific authentication method must Marriott offer for loyalty accounts? | Multi factor authentication. |
| What must Marriott do if malicious actors steal loyalty points? | Restore the stolen points. |
| What must Marriott provide for loyalty account reviews? | A method for consumers to request a review of unauthorized activity. |
| What data deletion rights do consumers gain? | The right to request deletion of personal information tied to an email or loyalty account. |
| What encryption standard must Marriott meet? | Industry recognized encryption key management standards. |
| What happens if Marriott transmits personal information externally? | The data must be encrypted or protected by compensating controls. |
| What penalty did Marriott pay to the state attorneys general? | 52 million dollars. |
| How states participated in the parallel settlement? | 49 states and the District of Columbia. |
| When did the third data breach affecting Marriott networks end? | February 2020. |
| How American guest records were exposed in the 2020 breach? | 1. 8 million. |
| What must Marriott do regarding suspicious loyalty account activity? | Investigate the activity within 24 hours. |
| How frequently must Marriott undergo independent security assessments? | Every two years. |
| What principle must the new information security program incorporate? | Zero trust principles. |
| What specific data elements are protected under the covered databases rule? | Reservation details, hotel stay preferences, loyalty numbers, and points balances. |
The Federal Trade Commission settlement the exact weaknesses that allowed hackers to remain unnoticed inside the Starwood and Marriott networks for years. Regulators specify that Marriott must deploy multi factor authentication across all Marriott Bonvoy accounts. This authentication requirement directly addresses the credential theft that facilitated the 2020 breach. During that intrusion, attackers compromised the credentials of two Marriott employees and accessed 5. 2 million guest records. The agency forces the company to implement logging and monitoring systems that detect anomalies within 24 hours. The corporation must investigate any suspicious activity within that same 24 hour window. These rules eliminate the delays that previously allowed bulk data extraction to continue without triggering internal alarms.
Encryption forms the core of the 2025 implementation metrics. The consent decree requires Marriott to encrypt all personal information at rest and in transit. The company must separate encryption keys from the encrypted data to prevent attackers from decrypting stolen files. The state attorneys general settlement, which includes a 52 million dollar financial penalty, mirrors these encryption demands. Regulators require the hotel chain to apply component hardening, conduct asset inventories, and segment networks to limit an intruder’s ability to move across the system. The corporation must apply security patches in a timely manner to close known weaknesses. The absence of these basic security measures in the past directly contributed to the exposure of payment card information and contact details for hundreds of millions of guests.
Consumer rights regarding loyalty data receive significant upgrades under the December 2024 order. Marriott must provide a clear method for customers to request a review of unauthorized activity in their Marriott Bonvoy accounts. If malicious actors steal loyalty points, the company must restore those points to the consumer. The corporation must also offer a data deletion option. Customers can request the deletion of personal information associated with their email address or loyalty rewards account number. The company must honor these deletion requests even if the consumer resides in a state that does not legally mandate such rights. The agency prohibits Marriott from misrepresenting how it collects, maintains, uses, deletes, or discloses personal information.
To track the 2025 implementation progress, regulators established specific compliance deadlines and audit requirements. Marriott must complete independent security assessments every two years for the duration of the 20 year order. The company must certify compliance to the Federal Trade Commission annually. The corporation must document its justifications for retaining any consumer data under its new data minimization policy. The company must dispose of data when it is no longer reasonably necessary to fulfill the purpose for which it was collected. These metrics guarantee that the hotel chain maintains strict oversight over its loyalty program databases.
The following chart illustrates the specific encryption and security implementation metrics required for the Marriott Bonvoy program in 2025.
| Security Metric | Implementation Requirement | 2025 Compliance Target |
|---|---|---|
| Data Encryption at Rest | Encrypt all personal information in covered databases | 100 Percent Compliance |
| Encryption Key Management | Separate keys from data using industry recognized standards | Continuous Audit |
| Multi Factor Authentication | Offer enhanced authentication for all Marriott Bonvoy accounts | Mandatory Availability |
| Anomaly Detection | Log and monitor database activity to detect unauthorized access | Within 24 Hours |
| Suspicious Activity Investigation | Investigate alerts regarding loyalty account breaches | Within 24 Hours |
| Loyalty Points Restoration | Restore points stolen by malicious actors upon review | Upon Verified Request |
The regulatory framework established by the Federal Trade Commission and the state attorneys general creates a strict baseline for corporate data security. Marriott must integrate zero trust principles into its network architecture. This method requires the company to verify every access request regardless of whether the user connects from inside or outside the corporate network. The corporation must apply role based access controls for individual accounts, administrator accounts, service accounts, and vendor accounts. These controls limit the damage a hacker can inflict if they compromise a single set of credentials. The agency mandates that the highest levels of the company, including the Chief Executive Officer, receive regular security reports. This executive oversight guarantees that data protection remains a primary corporate objective rather than a delegated technical task.
The scope of the exposed data shows the severity of the security failures that prompted this regulatory action. Hackers stole 339 million Starwood guest account records between July 2014 and September 2018. This massive data theft included contact information, gender, dates of birth, and legacy Starwood Preferred Guest information. The attackers also accessed unexpired payment card information. The new encryption rules specifically target these data categories. The consent decree defines a covered database as any system that processes reservation details, hotel stay preferences, loyalty rewards program numbers, or points balances. If Marriott shares security measures for these databases with a third party, the company must enforce the same strict encryption and access controls across the shared infrastructure.
Third party vendor oversight plays a major role in securing the Marriott Bonvoy ecosystem. The state attorneys general settlement requires increased vendor and franchisee oversight with a special emphasis on risk assessments for essential information technology vendors. Marriott must outline security contracts with cloud providers that host loyalty program data. Franchised hotels must notify the corporate office within 24 hours of any system compromise that affects corporate assets. Franchises must also report the termination of any employee or contractor who has access to corporate systems within five business days. These strict reporting timelines prevent terminated employees from using active credentials to access the loyalty databases. The Federal Trade Commission holds Marriott directly responsible for the security practices of its subsidiaries and third party partners.
Franchisee Compliance and Local Network Security Upgrades
Franchisee Compliance Mandates and Local Network Security Upgrades
The Federal Trade Commission finalized a binding consent order against Marriott International on December 20 2024. The regulatory action forces the hospitality corporation to overhaul data security across its massive global footprint. The mandate extends beyond corporate owned infrastructure. Regulators require Marriott to enforce strict information security rules across all franchised locations. At year end 2024 Marriott reported 9361 total properties worldwide. Independent operators manage 7192 of those locations under franchise and licensing agreements. The agency holds Marriott directly responsible for the security posture of these independent operators.
Historical data breaches drove the agency to target local property networks. The third major intrusion into the Marriott network originated at a franchised location. Malicious actors compromised the credentials of employees at a franchise property. The attackers used those credentials to access the central corporate network. The intrusion exposed 5. 2 million guest records. The exposed data included loyalty account information and basic personal identifiers. Regulators concluded that weak local network security directly threatens the entire corporate ecosystem.
20 Questions and Answers Regarding Franchisee Compliance
| Question | Answer |
|---|---|
| 1. How franchised properties does Marriott operate globally? | 7192 franchised and licensed properties at year end 2024. |
| 2. What specific Federal Trade Commission mandate applies to Marriott franchisees? | Marriott must contractually bind franchisees to the information security program. |
| 3. What type of audit program must Marriott implement for franchisees? | A risk based audit program to review compliance. |
| 4. What happens if a franchisee fails the security audit? | Marriott must retain and exercise contractual rights to enforce compliance. |
| 5. How much is Marriott investing in technology in 2026? | Marriott expects to deploy 1. 1 billion dollars in tech investments. |
| 6. What portion of the 2026 tech budget digital transformation? | More than one third of the 1. 1 billion dollar budget. |
| 7. Which core systems is Marriott replatforming? | Central reservations, the property management system, and the loyalty platform. |
| 8. What authentication standard is required at the local network level? | Multi factor authentication. |
| 9. How frequently must Marriott assess franchisee risk? | The consent order mandates annual risk assessments and assessments within 120 days of a covered incident. |
| 10. What data protection method is required for local property networks? | Encryption of personal information. |
| 11. How total properties are in the Marriott system? | 9361 properties at year end 2024. |
| 12. What percentage of Marriott properties are franchised or licensed? | Approximately 76 percent. |
| 13. When did the Federal Trade Commission finalize the consent order? | December 20 2024. |
| 14. How long does the Federal Trade Commission consent order remain active? | 20 years. |
| 15. What specific security flaw management is required locally? | Patch management and security flaw scanning. |
| 16. What must Marriott maintain regarding local network hardware? | A complete asset inventory. |
| 17. How customers were affected by the historical breaches? | 344 million customers worldwide. |
| 18. What was the root cause of the third breach at a franchise property? | Malicious actors compromised the credentials of employees at a franchise property. |
| 19. What must franchisees implement regarding vendor access? | Strict access controls and vendor oversight. |
| 20. Who must approve the independent third party assessor? | The Federal Trade Commission. |
The consent decree explicitly requires Marriott to contractually bind its franchisees to the new security standards. Marriott must amend existing franchise agreements to include mandatory cybersecurity provisions. The corporation must develop and deploy a risk based audit program to verify local compliance. The agency requires Marriott to retain specific contractual rights to enforce these security rules. If a franchisee fails to meet the required standards Marriott must exercise its authority to force compliance or terminate the relationship.
Local network upgrades represent a massive operational undertaking. Franchisees must implement multi factor authentication for all network access points. The agency prohibits the use of single password authentication for any system containing personal information. Local properties must encrypt all guest data stored on local servers and during transmission to the central corporate database. Franchisees must maintain a strict asset inventory of all hardware and software connected to the property network.
Security flaw management at the local level requires immediate attention. The consent order mandates strict patch management rules for all franchised properties. Local IT administrators must apply security updates to operating systems and applications within specific timeframes. The corporation must scan local networks for security flaws and unauthorized personal information storage. Franchisees must deploy advanced logging and monitoring tools to detect unauthorized access attempts in real time.
Vendor oversight at the local property level introduces another level of regulatory scrutiny. Franchisees frequently contract with local third party vendors for IT support, payroll processing, and property maintenance. The consent decree requires franchisees to evaluate the security posture of these local vendors. Franchisees must contractually require their vendors to implement safeguards that protect personal information. The corporation must audit how franchisees manage these local vendor relationships.
Financial investments in technology reflect the size of the regulatory requirements. During the fourth quarter 2025 earnings call on February 11 2026 Marriott executives announced a 1. 1 billion dollar technology investment budget for the year. The corporation allocated more than one third of that budget to digital transformation initiatives. The technology overhaul includes replatforming the central reservations system, the property management system, and the loyalty platform. These core systems connect directly to local franchise networks. The replatforming effort aims to eliminate legacy security flaws and standardize security rules across the 7192 franchised properties.
Verified Property and Investment Metrics
| Metric | Verified Data |
|---|---|
| Total Global Properties (Year End 2024) | 9361 |
| Franchised and Licensed Properties | 7192 |
| Company Operated Properties | 2032 |
| 2026 Technology Investment Budget | 1. 1 Billion Dollars |
| Digital Transformation Allocation | Over 366 Million Dollars |
| Federal Trade Commission Consent Decree Duration | 20 Years |
| Multistate Settlement Penalty | 52 Million Dollars |
The independent third party assessor evaluates franchisee compliance during the biennial audits. The assessor tests the effectiveness of the risk based audit program. The assessor reviews the contractual agreements between Marriott and its franchisees. The assessor samples local property networks to verify the implementation of multi factor authentication and encryption. The Federal Trade Commission retains the right to review these assessment reports and demand corrective action if the corporation fails to enforce the mandate at the local level.
Data minimization rules apply equally to corporate data centers and local property servers. Franchisees must delete guest data when they no longer have a legitimate business need to retain it. Local properties cannot store unencrypted payment card information outside of the secure cardholder data environment. The corporation must provide a system for consumers to request the deletion of their personal information from both corporate and local databases.
The 20 year duration of the consent order guarantees long term regulatory oversight. Marriott must submit an annual certification of compliance to the agency. The Chief Executive Officer must sign this certification under penalty of perjury. The certification must confirm that the corporation actively enforces the security requirements across all franchised properties. The financial penalties for violating the consent order are severe. The agency can levy massive fines for each individual violation of the mandate.
The size of the franchise network complicates the enforcement of the information security program. Marriott operates in 144 countries and territories. Franchisees operate under diverse local privacy laws and technical constraints. The corporation must standardize security controls across this fragmented environment. The replatforming of the property management system serves as the primary vehicle for this standardization. The new property management system forces local properties to adopt centralized identity management and access controls.
The agency explicitly banned deceptive security statements. Marriott and its franchisees cannot misrepresent the extent to which they protect personal information. Local properties must update their privacy policies to accurately reflect their data handling practices. The corporation must monitor local property websites and marketing materials to prevent unauthorized claims about data security. The 52 million dollar penalty paid to 49 states and the District of Columbia serves as a baseline for future enforcement actions if the corporation fails to police its franchisees.
Incident response planning requires tight coordination between corporate security teams and local property managers. The consent order mandates that Marriott report any covered incident to the governing body within 120 days. A covered incident includes any breach at a franchised property that requires notification to state or federal authorities. Local properties must establish direct reporting lines to the corporate security operations center. Franchisees must participate in annual risk assessments to identify possible security flaws before malicious actors exploit them.
Incident Response Plan Testing and Notification Deadlines
Incident Response Plan Testing and Notification Deadlines
20 Questions and Answers Regarding Incident Response and Notification Deadlines
| Query | Verified Data |
|---|---|
| 1. When did the Federal Trade Commission finalize the consent order? | December 20 2024. |
| 2. How days does Marriott have to test safeguards after a covered incident? | 120 days. |
| 3. How frequently must Marriott conduct incident response tabletop exercises? | Once per year. |
| 4. What is the deadline for Marriott to submit notifications to the Federal Trade Commission after a reportable incident? | 10 days. |
| 5. When must Marriott provide a written report to its Board of Directors following a covered cyber incident? | Within 120 days. |
| 6. How quickly must franchised hotels notify Marriott of a system compromise? | Within 24 hours. |
| 7. What is the notification deadline for franchised hotels when terminating an employee with system access? | Five business days. |
| 8. When does the state attorney general settlement require full implementation? | October 9 2025. |
| 9. How days does the Safeguards Rule allow for notifying the Federal Trade Commission of a breach? | 30 days. |
| 10. How days does the Health Breach Notification Rule allow for reporting a breach of 500 or more individuals? | 60 days. |
| 11. When did the Health Breach Notification Rule take effect? | July 29 2024. |
| 12. How long is the term of the Federal Trade Commission consent order? | 20 years. |
| 13. How data breaches did the Federal Trade Commission cite between 2014 and 2020? | Three data breaches. |
| 14. How customers worldwide were affected by the breaches? | 344 million customers. |
| 15. What specific assessment must Marriott conduct annually and after incidents? | Risk assessments. |
| 16. Who must receive the annual written reports regarding the information security program? | The Board of Directors. |
| 17. What penalty did Marriott agree to pay to state attorneys general? | 52 million dollars. |
| 18. How states participated in the parallel settlement? | 49 states and the District of Columbia. |
| 19. What specific type of independent assessment is required biennially? | Third party independent assessment. |
| 20. What specific security protocol must Marriott use to protect consumer data? | Multi Factor Authentication. |
Federal Trade Commission Notification Mandates
The Federal Trade Commission finalized a consent order against Marriott International on December 20 2024. The regulatory action mandates strict incident response testing and precise notification deadlines. Marriott must overhaul its internal reporting structures to comply with the 20 year agreement. The agency requires the hotel chain to execute tabletop exercises at least once per year. These exercises test the readiness of the corporate security apparatus against simulated intrusions. The settlement dictates that Marriott must complete a risk assessment within 120 days of any covered cyber incident. The company must also adjust all safeguards based on the findings of these assessments. The attorney general settlement requires full implementation of these security measures by October 9 2025.
The regulatory framework imposes rigid timelines for external notifications. Marriott must submit formal notifications to the Federal Trade Commission within 10 days of any legally mandated reportable incident. The Health Breach Notification Rule took effect on July 29 2024. This rule forces covered entities to notify the agency within 60 days of discovering a breach involving 500 or more individuals. The Safeguards Rule applies to nonbanking financial institutions and demands notification within 30 days of discovery. Marriott must align its corporate incident response plans to meet these exact deadlines. Failure to meet these reporting windows exposes the corporation to further regulatory penalties. The company must verify that its monitoring services detect unauthorized access immediately to start the countdown clocks accurately.
Internal Governance and Board Reporting
Internal governance requirements force Marriott to elevate cybersecurity to the highest corporate levels. The consent order compels the company to provide a written report to its Board of Directors within 120 days of any cyber incident that requires state or federal notification. Marriott must designate a qualified employee to oversee the execution of the information security program. This executive holds the responsibility for presenting annual written reports to the board. The corporate leadership can no longer claim ignorance regarding network vulnerabilities. The Federal Trade Commission designed these governance mandates to force accountability at the executive tier. The board must actively review the outcomes of the annual risk assessments and the post incident evaluations.
Franchise Network Reporting
Franchised hotel operators face their own strict reporting mandates under the New York State Attorney General settlement. Marriott must enforce written policies requiring franchised hotels to notify the corporate office within 24 hours of any system compromise. The local operators must report any breach that affects corporate assets within this tight window. The franchise agreements must also mandate notification within five business days when a local property terminates an employee or contractor who holds access to corporate systems. These downstream reporting requirements close a major visibility gap. The corporate security team relies on these rapid alerts to initiate the broader incident response. Marriott must test these specific franchise communication channels during the annual tabletop exercises.
Regulatory Notification Deadlines Chart
The History of the Breaches Driving the Deadlines
The Federal Trade Commission three massive data breaches occurring between 2014 and 2020 as the catalyst for these strict deadlines. The intrusion began in June 2014 and compromised the payment card information of 40, 000 Starwood customers. This breach remained for 14 months. The second breach started in July 2014 and exposed 339 million Starwood guest records. The attackers operated inside the network until September 2018. The third breach impacted the proprietary Marriott network from September 2018 until February 2020. The attackers accessed 5. 2 million guest records during this period. The prolonged dwell times of these intrusions directly influenced the aggressive notification deadlines in the 2024 consent order. The agency designed the 10 day and 120 day reporting windows to eliminate the multi year delays that characterized the previous incidents.
Mechanics of the Tabletop Exercises
The consent order explicitly requires Marriott to conduct incident response plan exercises once per year. These tabletop exercises must simulate real world attack scenarios. The security teams must practice their response to unauthorized access events. The exercises must involve the qualified employee and the executive leadership. The corporate security apparatus must document the outcomes of these simulations. The documentation must identify gaps in the response strategy. Marriott must update the incident response plan based on the lessons learned during these annual drills. The New York State Attorney General settlement specifically mandates that the plan must conform to a nationally recognized standard. The independent assessor review the tabletop exercise reports to confirm that the company actively improves its defensive posture.
Logging and Monitoring Requirements
Rapid incident response relies on accurate detection method. The New York State Attorney General settlement requires Marriott to configure and test logging and monitoring services. These services must identify security events and escalate them according to the incident response plan. The company must implement controls to alert on the execution of unauthorized applications on corporate assets. The intrusion detection systems must operate continuously. The security operations center must analyze the logs to detect anomalous behavior. The 24 hour franchise reporting window means nothing if the central monitoring systems fail to detect the initial compromise. Marriott must prove to the regulators that its logging infrastructure can support the strict notification deadlines. The technical safeguards must provide the forensic data necessary to compile the 120 day board reports.
The Role of the Qualified Employee
The Federal Trade Commission mandates the appointment of a qualified employee to oversee the information security program. This individual carries the load of regulatory compliance. The employee must coordinate the annual risk assessments. This executive must also manage the incident response when a breach occurs. The consent order requires this person to draft the annual written reports for the Board of Directors. The employee must also prepare the specific incident reports required within 120 days of a covered event. The regulatory agencies hold this individual responsible for the execution of the tabletop exercises. The employee must verify that all franchised hotels comply with the 24 hour and five day reporting rules. This centralized accountability structure prevents the corporate diffusion of responsibility that plagued the company during the 2014 to 2020 breaches.
Third Party Assessment of the Incident Response Plan
The biennial third party assessments heavily scrutinize the incident response capabilities. The independent assessor must evaluate whether Marriott actually meets the 10 day Federal Trade Commission notification deadline during real incidents. The assessor review the communication logs between the franchised hotels and the corporate office. The audit verify if the local properties adhere to the 24 hour reporting rule for system compromises. The third party firm examine the post incident risk assessments. The assessor must confirm that Marriott adjusts its safeguards within the mandated 120 day window. The regulatory agencies retain the right to reject the chosen assessor. The assessment covers the period starting 60 days after the date of the settlement. The corporate security team must maintain pristine records of all incident response activities to pass these rigorous audits.
Federal Trade Commission Monitoring Methods and Reporting Obligations
The Federal Trade Commission finalized its consent order with Marriott International and Starwood Hotels on December 20, 2024. The mandate imposes a 20 year oversight period to correct security failures that exposed 344 million customer records. Regulators demand strict adherence to new reporting timelines and vendor oversight rules. Marriott faces a 180 day implementation deadline under the federal order. State attorneys general enforce a parallel settlement requiring full compliance by October 9, 2025.
| Investigative Query | Verified Metric |
|---|---|
| What is the duration of the federal consent order? | 20 years |
| When did regulators finalize the consent order? | December 20, 2024 |
| How customers were affected by the breaches? | 344 million |
| How frequently must Marriott conduct independent security assessments? | Every two years |
| Who must certify compliance to the federal regulator? | The Chief Executive Officer |
| How frequently must the chief executive officer certify compliance? | Annually |
| What is the deadline to notify regulators of a reportable incident? | 10 days |
| How quickly must Marriott detect network anomalies? | Within 24 hours |
| How quickly must Marriott investigate suspicious activity? | Within 24 hours |
| How frequently must Marriott conduct internal risk assessments? | Annually |
| What is the deadline to report a covered incident to the board? | 120 days |
| What specific vendor category requires enhanced rules? | Major IT Vendors |
| What is the federal implementation deadline? | 180 days |
| What is the state attorney general implementation deadline? | October 9, 2025 |
| How much did Marriott pay to settle with state regulators? | $52 million |
| How long did the 2014 Starwood breach go unnoticed? | Four years |
| What technology must Marriott use for loyalty accounts? | Multi factor authentication |
| What must Marriott do if loyalty points are stolen? | Restore them |
| How frequently must Marriott test its safeguards? | Annually |
| Who must receive the annual written report on the security program? | The Board of Directors |
Marriott must deploy continuous network monitoring systems. The federal mandate requires the company to detect network anomalies within 24 hours. Security teams must investigate suspicious activity within 24 hours of detection. The company must notify the Federal Trade Commission within 10 days of any legally mandated reportable incident. Marriott must conduct internal risk assessments annually and within 120 days of any covered cyber incident.
The Chief Executive Officer must submit a written certification of compliance to the federal regulator annually. The company must provide annual written reports on the information security program to its Board of Directors. An independent third party must assess the efficacy of the data security program once every two years. Marriott must cooperate fully with the assessor by providing access to all relevant information and material facts.
Mandated Reporting and Detection Timelines
Anomaly Detection
Incident Investigation
Federal Notification
Board Reporting
The settlement establishes strict rules for vendor oversight. Regulators hold Marriott accountable for developing written policies for all third party service providers. The state settlement creates a special category for major IT vendors that manage significant components of the security program or access company databases. Marriott must implement enhanced security rules for these major IT vendors. The requirements include specific contractual provisions, performance monitoring, and access limitations.
Marriott must evaluate the security posture of any newly acquired entity. The company must assess whether the acquired information security program complies with the federal order. The company must develop plans to address identified gaps during network integration. Marriott must contractually bind its franchisees to the terms of the consent order.
Budget Allocations for Cybersecurity Infrastructure Upgrades
20 Questions and Answers Regarding Cybersecurity Budget Allocations

| Question | Answer |
|---|---|
| What is Marriott’s total capital and technology expenditure for 2024? | Marriott allocated 750 million dollars for capital and technology expenditures in 2024. |
| What is the projected capital expenditure for 2025? | Marriott projects capital expenditures between 1. 0 billion and 1. 1 billion dollars for 2025. |
| How much did Marriott agree to pay to state attorneys general? | Marriott agreed to pay 52 million dollars to 49 states and the District of Columbia. |
| What was Marriott’s total revenue in 2024? | Marriott reported a total revenue of 25. 1 billion dollars in 2024. |
| What was Marriott’s net income in 2024? | The company reported a net income of 2. 375 billion dollars in 2024. |
| What was Marriott’s operating income in 2024? | Marriott reported an operating income of 3. 767 billion dollars in 2024. |
| How much did Marriott return to stockholders in 2024? | Marriott returned over 4. 4 billion dollars to stockholders through cash dividends and share repurchases. |
| What is the deadline for full implementation of the state attorney general settlement mandates? | Marriott must fully implement the mandated security program by October 9 2025. |
| How long does the Federal Trade Commission consent order last? | The consent order mandates compliance for 20 years. |
| How frequently must Marriott conduct independent third party security assessments? | The company must conduct these assessments every two years. |
| What specific security architecture must Marriott incorporate under the new mandates? | Marriott must incorporate zero trust principles into its network architecture. |
| How much does Marriott expect to save from its 2025 cost reduction program? | The company expects 80 million to 90 million dollars in annual general and administrative cost reductions starting in 2025. |
| How properties did Marriott operate at the end of 2024? | Marriott operated 9361 properties globally at the end of 2024. |
| How rooms were in the Marriott system at the end of 2024? | The system included 1706331 rooms. |
| How properties are in Marriott’s development pipeline? | Marriott has nearly 3800 hotels in its development pipeline. |
| How countries and territories does Marriott operate in? | The company operates in 144 countries and territories. |
| What specific authentication method is mandated by the settlement? | The settlement mandates multi factor authentication for all network access. |
| What was the global revenue per available room growth in 2024? | Global revenue per available room rose over 4 percent in 2024. |
| How members are in the Marriott Bonvoy loyalty program? | The program grew to nearly 228 million members globally by the end of 2024. |
| What specific vendor oversight is required by the settlement? | Marriott must conduct risk assessments for key information technology vendors and outline contracts with cloud providers. |
Capital and Technology Expenditure Trajectory
Marriott International reported 25. 10 billion dollars in total revenue for the fiscal year 2024. The company allocated 750 million dollars specifically for capital and technology expenditures during this period. This allocation funded technology systems transformation and hotel renovations. The Federal Trade Commission and 49 state attorneys general finalized a consent decree requiring Marriott to overhaul its information security program. The company must implement zero trust principles and multi factor authentication across its global network.
Executives project capital expenditures and other investments total between 1. 0 billion and 1. 1 billion dollars for 2025. This budget increase coincides with the October 9 2025 deadline to fully implement the security mandates required by the state attorneys general settlement. Marriott must fund independent third party security assessments every two years for the two decades. The company also agreed to pay a 52 million dollar penalty to the participating states.
Financial Performance and Cost Reduction Initiatives
Marriott reported an operating income of 3. 767 billion dollars and a net income of 2. 375 billion dollars in 2024. The company returned over 4. 4 billion dollars to stockholders through cash dividends and share repurchases. To offset the rising costs of technology upgrades and regulatory compliance, Marriott launched a broad cost reduction program. This program yields 80 million to 90 million dollars in annual general and administrative cost reductions starting in 2025.
The company operates 9361 properties with 1706331 rooms across 144 countries. Securing this infrastructure requires massive capital deployment. The settlement mandates strict vendor oversight. Marriott must conduct risk assessments for key information technology vendors and outline contracts with cloud providers. The company must also investigate suspicious network activity within 24 hours.
Budget Allocation Chart
Marriott Capital and Technology Expenditures
*Midpoint of $1. 0B to $1. 1B projection
Historical Breach Context and Financial
The regulatory actions from three major data breaches that occurred between 2014 and 2020. These intrusions compromised the personal information of more than 344 million customers worldwide. Hackers installed malware with keyloggers, remote access tools, and memory scrapers in more than 480 systems across 58 locations. The stolen data included passport numbers, payment card numbers, loyalty numbers, dates of birth, and email addresses. The United Kingdom Information Commissioner Office previously fined Marriott 18. 4 million pounds in 2020 for violating the General Data Protection Regulation.
The financial cost of these breaches exceeds the initial fines. Marriott must rebuild its entire security architecture to comply with the new mandates. The company failed to provide reasonable security for the personal information it collected. Investigators found that the company used weak password policies, allowing employees to use default or blank passwords. The company also failed to regularly update software patches and used outdated systems. These failures left the network exposed to attacks.
Information Security Program Mandates
The Federal Trade Commission finalized the consent order on December 20 2024. This order forces Marriott to establish a broad information security program. The company must incorporate zero trust principles into its network architecture. This requires strict access controls and continuous verification of all users and devices. The mandates also require regular security reporting to the highest levels within the company, including the Chief Executive Officer.
Marriott must enhance employee training on data handling and security. The company must provide annual role appropriate training for all employees who hold access to personal information. The settlement requires written documentation on the content, establishment, implementation, and maintenance of an incident response plan. This plan must protect against unauthorized access to personal information. The company must investigate suspicious activity within 24 hours. Marriott must provide assessments and reports for future data breaches within 120 days.
Data Minimization and Consumer Rights
The regulatory mandates force Marriott to implement strict data minimization and disposal requirements. This policy leads to less consumer data being collected and retained. The company must accurately inform its customers about how it handles personal information. Marriott must disclose how data is collected, stored, processed, deleted, and shared with others. The company must provide a clear link on its website for United States customers to request the deletion of their personal information.
The order also requires Marriott to review loyalty rewards accounts upon customer request. If the company determines that loyalty points were stolen through unauthorized access, it must restore those points. Customers can enable multi factor authentication on their Marriott Bonvoy accounts to add an extra of security. These consumer protection measures force major backend infrastructure upgrades. The 750 million dollar capital and technology expenditure in 2024 directly supports these necessary system upgrades.
Executive Oversight and Corporate Governance
The settlement terms are grounded in a well developed risk based method. Marriott must conduct an annual enterprise level risk assessment. The company must also perform risk analyses throughout the year for changes to security controls. These ongoing risk assessments must address the criteria of harm to others, which includes chance harm to consumers. The Board of Directors oversees the enterprise risk management process. Management created a global information security program with a dedicated global information security team.
The policies and procedures follow recognized frameworks established by the National Institute of Standards and Technology and the International Organization for Standardization. The incident response process focuses on preparation, detection, analysis, containment, eradication, recovery, and post incident remediation. The company maintains a Global Information Security and Privacy Incident Response Plan. This plan applies globally to information security incidents involving properties owned, leased, or managed by Marriott.
Future Acquisition Diligence
The settlement imposes strict requirements on future corporate acquisitions. If Marriott acquires another entity, it must assess the acquired company information security program. Marriott must develop plans to address identified security gaps before integrating the new network into its own system. This mandate directly addresses the failures that occurred during the 2016 acquisition of Starwood Hotels.
Marriott has nearly 3800 hotels in its development pipeline. The company must verify that all new properties comply with the mandated security standards. Franchisees must comply with brand standards relating to information security. They hold an obligation to report information security incidents to the corporate office. The global information security program follows frameworks established by the National Institute of Standards and Technology.
Employee Access Controls and Privilege Escalation Prevention
Investigative Matrix: Marriott Consent Decree Facts
| Query | Verified Data |
|---|---|
| What penalty did Marriott pay to the state coalition? | $52 million |
| How consumers were affected by the data breaches? | 344 million |
| When did the Federal Trade Commission finalize the consent agreement? | December 20 2024 |
| How long is the term of the FTC consent order? | 20 years |
| How frequently must Marriott undergo independent assessments? | Every two years |
| What specific authentication method did the FTC mandate? | Multifactor authentication |
| How unencrypted passport numbers were exposed? | 5. 25 million |
| When did Marriott acquire Starwood Hotels? | 2016 |
| What type of accounts did malicious actors target for fraud? | Loyalty rewards accounts |
| How guest records were accessed in the March 2020 breach? | 5. 2 million |
| What specific credential theft tool did attackers use in the 2018 breach? | Mimikatz |
| Within what timeframe must Marriott review logs for anomalous activity? | 24 hours |
| What principle must Marriott apply to employee data access? | Principle of least privilege |
| How states participated in the parallel settlement? | 49 states and the District of Columbia |
| What specific network control did Marriott fail to implement? | Network segmentation |
| How Starwood customers had payment card information exposed in the breach? | 40, 000 |
| What type of passwords did Marriott employees use before the FTC order? | Default blank or weak passwords |
| What must Marriott do if a consumer lost loyalty points due to unauthorized activity? | Restore the stolen points |
| How long must Marriott retain subsequent assessment reports? | Five years |
| Within how days must Marriott report a cyber incident to its governing body? | 120 days |
The Federal Trade Commission finalized a consent agreement with Marriott International and Starwood Hotels on December 20 2024. The order resolves allegations that the companies failed to deploy reasonable security measures. These failures resulted in three separate data breaches between 2014 and 2020. Malicious actors accessed the personal information of 344 million customers worldwide. Marriott agreed to pay a $52 million civil penalty to 49 states and the District of Columbia.
The FTC complaint detailed specific access control failures. Marriott employees used default blank or weak passwords. The company failed to deploy adequate multifactor authentication. Attackers exploited these vulnerabilities to gain remote access to the network. During the 2018 breach attackers used credential stealing tools like Mimikatz to capture passwords and escalate privileges. The intruders impersonated authorized users to query databases. In March 2020 malicious actors compromised the credentials of employees at a franchised property to access the corporate network. This specific intrusion exposed 5. 2 million guest records.
Breach Volume Metrics

| Breach Event | Records Exposed | Volume Visualization |
|---|---|---|
| 2014 Starwood Breach | 40, 000 | |
| 2018 Corporate Breach | 339, 000, 000 | |
| 2020 Franchise Breach | 5, 200, 000 |
The consent order mandates strict employee access controls. Marriott must implement multifactor authentication for all network logins. Employees and vendors accessing corporate assets remotely must use enhanced authentication measures. The company must enforce strong passwords and prevent the reuse of compromised credentials. Marriott must apply the principle of least privilege. This limits employee access to personal information to the absolute minimum required for their specific job functions.
Network segmentation is a central requirement of the new information security program. The FTC found that poor firewall controls allowed hackers to move laterally across connected devices. Marriott must establish appropriate network segmentation between hotel property systems and corporate databases. The company must restrict inbound and outbound connections to prevent unauthorized data exfiltration.
The order requires active logging and monitoring. Marriott must collect logs of events occurring on its information technology assets. Security teams must review these logs for anomalous activity within a 24 hour period. The company must configure monitoring services to identify security events and escalate them according to the incident response plan. Marriott must undergo an independent third party assessment every two years for the 20 years to verify compliance.
Vendor Risk Assessment Procedures and Contractual Obligations
20 Questions and Answers Regarding Vendor Risk Assessment Procedures
| Question | Answer |
|---|---|
| 1. What specific vendor management mandate does the Federal Trade Commission impose on Marriott? | The agency requires the company to select and retain only vendors capable of safeguarding customer data. |
| 2. How must Marriott enforce security standards with its third party service providers? | The company must contractually require all vendors to implement and maintain sufficient data safeguards. |
| 3. What special category of service providers does the state settlement designate? | The settlement designates a category for essential IT vendors that manage significant components of the security program. |
| 4. What specific technology providers fall under the essential IT vendor category? | Cloud computing providers fall under this specific vendor classification. |
| 5. What cybersecurity principle must Marriott enforce with its vendors where feasible? | The company must adopt zero trust cybersecurity principles across its vendor network. |
| 6. What does the zero trust model require for vendor access? | The model requires continuous verification before granting access to sensitive data or systems. |
| 7. How long does Marriott have to implement the Federal Trade Commission vendor oversight rules? | The company has 180 days from the December 20 2024 finalization date to implement the rules. |
| 8. What is the deadline for full implementation under the parallel state settlement? | The company must fully implement the state vendor requirements by October 9 2025. |
| 9. What documentation must Marriott maintain regarding its service providers? | The company must develop and maintain written policies and procedures for all vendor interactions. |
| 10. How frequently must Marriott assess the effectiveness of its vendor security program? | The company must undergo an independent assessment every two years. |
| 11. How long does the independent assessment mandate last? | The third party assessment requirement lasts for 20 years. |
| 12. What must Marriott do before signing contracts with new vendors? | The company must perform pre contract due diligence to evaluate the security posture of the vendor. |
| 13. What specific vendor security certifications should Marriott evaluate during due diligence? | The company evaluates certifications like ISO 27001 and SOC 2 during the assessment phase. |
| 14. What must Marriott include in vendor contracts regarding data termination? | Contracts must specify exact data return or destruction procedures when ending the business relationship. |
| 15. How does Marriott monitor ongoing vendor compliance? | The company requires annual compliance reports and uses third party risk monitoring services. |
| 16. What happens if a vendor experiences a security incident? | Marriott must test and monitor the effectiveness of its safeguards within 120 days following any reportable incident. |
| 17. Who must certify the company compliance with these vendor regulations annually? | The Chief Executive Officer must submit a written certification of compliance to the Federal Trade Commission. |
| 18. What financial penalty did Marriott pay alongside these vendor oversight mandates? | The company agreed to pay 52 million dollars to 49 states and the District of Columbia. |
| 19. What specific pre acquisition duty does the order impose on Marriott regarding vendors? | The company must conduct careful cybersecurity due diligence before acquiring any new entity and its vendor network. |
| 20. What must Marriott develop after acquiring a new company and its vendors? | The company must develop a post acquisition remediation plan to address any identified security gaps. |
The Federal Trade Commission finalized a consent order on December 20 2024 that forces Marriott International to overhaul its vendor risk assessment procedures. The regulatory action the exact supply chain flaws that allowed malicious actors to compromise hundreds of millions of guest records. Regulators mandate that the hotel chain select and retain only those service providers capable of safeguarding personal information. The company must contractually require these external partners to implement and maintain strict data safeguards.
State attorneys general from 49 states and the District of Columbia established parallel mandates that require full implementation by October 9 2025. The state agreement designates a specific classification for essential IT vendors. This category includes cloud computing providers and entities that manage significant components of the information security program. Marriott must enforce enhanced cybersecurity controls and adopt zero trust principles across this vendor network. The zero trust model demands continuous verification before any external provider receives access to sensitive corporate systems.
The regulatory framework eliminates superficial vendor onboarding methods. Marriott must execute thorough pre contract due diligence to evaluate the security posture of every prospective partner. This evaluation includes analyzing previous breach histories and verifying security certifications. The company must also establish clear exit provisions in all vendor agreements. These contractual clauses dictate the exact procedures for data return or destruction when a business relationship ends.
Oversight does not end at the contract signing phase. The Federal Trade Commission requires Marriott to maintain written policies and procedures for continuous vendor monitoring. The company uses third party risk monitoring services and demands annual compliance reports from its partners. To verify the effectiveness of these vendor management rules, the agency forces Marriott to undergo independent security assessments every two years for the two decades. The Chief Executive Officer must personally certify compliance with these vendor oversight regulations annually.
Vendor Risk Management Compliance Timeline
The regulatory focus on vendor risk management directly from the historical failures observed during the Starwood Hotels acquisition. Hackers installed memory scraping malware and remote access trojans across 480 systems in 58 Starwood locations. The intruders infiltrated the corporate network and customer contact centers because the company failed to execute proper pre acquisition due diligence on the existing vendor ecosystem. The Federal Trade Commission noted that the acquiring firm inherits the security flaws of its and their associated third party service providers. To prevent a repeat of this disaster, the consent order forces Marriott to develop a strict post acquisition remediation plan for any future corporate purchases.
The state settlement introduces strict requirements for essential IT vendors. Regulators define these entities as external partners that manage significant components of the information security program. Cloud service providers fall directly into this high risk category. Marriott must enforce zero trust cybersecurity principles across this specific vendor tier. The zero trust architecture operates on the assumption that threats exist both inside and outside the network boundaries. This model requires continuous identity verification and strict access controls before any vendor can interact with sensitive corporate databases.
Contractual obligations form the foundation of the new vendor oversight program. Marriott can no longer rely on verbal assurances or basic service level agreements. The company must insert specific security requirements into every vendor contract. These legal documents must mandate that service providers adopt and implement written information security standards. The contracts must also grant Marriott the authority to monitor the vendor and verify ongoing compliance. If a vendor fails to maintain sufficient safeguards, the contract must provide clear procedures for termination and secure data destruction.
The Federal Trade Commission requires Marriott to implement a threat management program that extends to its vendor network. The company must continually identify and assess security flaws introduced by third party software and services. This mandate includes running internal and external network threat scans at least quarterly. When reputable outside sources identify a new security flaw in a vendor product, Marriott must assign a risk ranking and perform rescans to ensure the vendor remediated the threat.
Financial penalties reinforce these vendor management mandates. Marriott agreed to pay 52 million dollars to resolve the parallel investigations conducted by state attorneys general. This financial settlement shows the severity of the regulatory action. The state agreement requires full implementation of the vendor oversight by October 9 2025. The Federal Trade Commission enforces a tighter timeline and demands compliance within 180 days of the December 20 2024 finalization date.
To guarantee long term compliance, the consent order establishes a 20 year oversight period. Marriott must hire an independent third party assessor to evaluate the effectiveness of its information security program every two years. This biennial audit specifically examines the vendor risk management procedures. The assessor verifies that Marriott actually enforces the contractual safeguards and conducts the required pre contract due diligence. The Chief Executive Officer of Marriott must review these audit results and submit an annual written certification of compliance directly to the Federal Trade Commission.
The Federal Trade Commission explicitly the data retention practices of third party service providers. Marriott must ensure that its vendors retain personal information only as long as reasonably necessary to fulfill the specific business purpose for which the data was collected. When a customer requests the deletion of their personal information through the newly mandated Marriott deletion portal, the company must cascade this deletion request down to its vendor network. Service providers can no longer hoard guest data indefinitely. The contracts must legally bind the vendors to execute these deletion requests promptly and provide confirmation back to the hotel chain.
The regulatory action also addresses the specific security weaknesses exposed during the Starwood integration. The Federal Trade Commission noted that Marriott had extensive visibility into the Starwood information security environment during the due diligence phase. The acquiring company failed to act on the obvious red flags regarding outdated software and poor vendor management. The new consent order forces Marriott to treat corporate acquisitions as high risk events. The company must deploy specialized vendor risk assessment teams to evaluate the target entity before finalizing any purchase.
State regulators demand that Marriott conduct an annual tabletop exercise to test its incident response capabilities. This exercise must actively involve scenarios where a primary IT vendor experiences a data breach. The simulation ensures that the company can quickly identify the compromised service provider, isolate the affected systems, and execute the required public notifications. The Federal Trade Commission requires Marriott to submit formal notifications within 10 days of any legally mandated reportable incident. This strict reporting window forces the company to maintain constant communication with its vendor network to detect intrusions early.
The financial sector provides a clear precedent for these strict vendor oversight rules. The Federal Trade Commission modeled several components of the Marriott consent order on the New York Department of Financial Services cybersecurity regulations. These regulations require a proactive and continuously adaptive method for third party governance. Marriott must abandon static security questionnaires and implement monitoring tools that track vendor compliance in real time. The company evaluates vendor reputation, financial health, and regulatory history as part of this continuous monitoring process.
The 52 million dollar penalty paid to the state attorneys general serves as a direct warning to other corporations regarding supply chain security. The state agreement requires Marriott to comply with the Payment Card Industry Data Security Standard across its entire vendor network. Service providers that process payment information must undergo rigorous technical audits to verify their encryption standards and access controls. The zero trust mandate further restricts lateral movement within the network if a vendor account becomes compromised.
Data Retention Policy Overhauls and Automated Purging Systems
20 Questions and Answers Regarding Data Retention and Purging Mandates
| Query | Verified Data |
|---|---|
| 1. What specific policy must Marriott implement regarding data retention? | The company must implement a data minimization policy. |
| 2. How long can Marriott retain personal information under the new order? | The company can retain data only as long as reasonably necessary to fulfill the collection purpose. |
| 3. What must Marriott document regarding stored data? | The company must document the specific business need for retaining the personal information. |
| 4. What new feature must Marriott add to its digital platforms? | The company must add a clear and conspicuous link for consumers to request data deletion. |
| 5. Which specific identifiers can consumers use to request data deletion? | Consumers can use their email addresses and loyalty rewards program account numbers. |
| 6. How days does Marriott have to verify receipt of a deletion request? | The company has 60 days to verify receipt. |
| 7. What must Marriott explain to consumers within that 60 day window? | The company must explain the exact process of data deletion. |
| 8. When did the Federal Trade Commission finalize the consent order? | The agency finalized the order on December 20 2024. |
| 9. By what date must Marriott fully implement the state settlement requirements? | The company must implement the requirements by October 9 2025. |
| 10. How states participated in the parallel settlement? | 49 states and the District of Columbia participated in the settlement. |
| 11. What financial penalty did Marriott pay to the states? | The company paid 52 million dollars to the states. |
| 12. What type of information must Marriott classify and inventory? | The company must inventory IT assets containing personal data. |
| 13. How long does the consent order remain in effect? | The order remains in effect for 20 years. |
| 14. What must Marriott do if a consumer requests a review of their loyalty account? | The company must review the account for unauthorized activity. |
| 15. What action must Marriott take if loyalty points were stolen? | The company must restore the stolen loyalty points. |
| 16. Does the deletion right apply to all United States customers? | Yes, the right applies regardless of state level privacy laws. |
| 17. What specific act did Marriott violate regarding data practices? | The company violated Section 5(a) of the Federal Trade Commission Act. |
| 18. How frequently must Marriott undergo third party assessments? | The company must undergo assessments every two years. |
| 19. How consumers were affected by the data breaches? | More than 344 million consumers were affected worldwide. |
| 20. What specific unencrypted data type was exposed during the breaches? | The breaches exposed 5. 25 million unencrypted passport numbers. |
Federal Trade Commission Data Minimization Directives
The Federal Trade Commission finalized a consent order against Marriott International on December 20 2024. Regulators mandate that the hotel chain implement strict data minimization policies across its global network. The company must retain personal information only as long as reasonably necessary to fulfill the specific purpose for which it was collected. Marriott must document the exact business need for keeping any consumer data. The agency prohibits the company from misrepresenting how it collects, maintains, uses, deletes, or discloses personal information.
The regulatory action addresses specific failures that led to massive data exposure. The federal complaint states Marriott and Starwood failed to deploy reasonable security to protect personal information. Hackers installed keyloggers, memory scraping malware, and remote access trojans in over 480 systems across 58 locations. The intruders accessed the corporate network, data centers, customer contact centers, and hotel properties. Because Marriott retained vast amounts of data indefinitely, the hackers exfiltrated 339 million Starwood guest records during the second breach. The new data minimization directives directly address this exact vulnerability. By forcing the company to delete data that serves no immediate business purpose, the agency limits the volume of information available to future intruders. Marriott must share the purpose behind collecting personal information in its privacy policy. The company must also disclose the specific business need for retaining the information.
The 60 Day Deletion Request Procedure
The deletion mandate represents a major shift in federal privacy enforcement. The agency uses this consent order to establish baseline consumer rights that extend beyond state borders. Customers in states without broad privacy laws possess the same deletion rights as residents of California or Colorado. Within 180 days of the order issuance, the company must provide a clear and conspicuous link on its website and mobile applications. This link directs United States consumers to an online portal where they can request the deletion of their personal information. Consumers can use their email addresses or loyalty rewards program account numbers to initiate these requests.
Marriott must verify the receipt of each request and explain the exact deletion process to the consumer within 60 days. The order specifies that Marriott must process requests linked to an email address or a Marriott Bonvoy loyalty account number. If a consumer suspects unauthorized activity, they can request a review of their loyalty account. Marriott must restore any loyalty points stolen by malicious actors. The 60 day window forces the company to maintain a responsive compliance department. Marriott must track the request, locate the associated data across its global network, execute the deletion, and confirm the action with the consumer. The agency requires the company to create and retain records demonstrating full compliance with these deletion requests for five years.
Automated Purging and Asset Inventory Requirements
To comply with the 20 year consent order, Marriott must overhaul its internal data storage architecture. The technical implementation requires Marriott to map its entire digital footprint. The company must inventory every server, database, and cloud storage instance that holds personal information. Once mapped, Marriott must classify the data based on its sensitivity and business purpose. Regulators require the hotel chain to implement data disposal policies that ensure less consumer data remains stored on corporate servers.
The company must deploy automated purging systems to remove data once the documented business purpose expires. These systems must scan databases and automatically delete records that exceed their authorized retention period. The agency mandates that Marriott encrypt any personal information contained on its IT assets or destroy the asset entirely. The order mandates that Marriott establish vulnerability and patch management policies to keep the software on these IT assets updated. The company must evaluate the impact of software updates on data security. If Marriott acquires another entity in the future, it must assess the acquired company information security program to identify vulnerabilities. Independent third party assessors evaluate these purging systems every two years to verify compliance. The assessors must verify that the company actually deletes the data it claims to purge.
State Attorney General Parallel Settlement Deadlines
A coalition of 49 states and the District of Columbia reached a parallel settlement with Marriott on October 9 2024. The states investigated the breaches in coordination with the federal agency. The company agreed to pay 52 million dollars to the participating states to resolve the data security allegations. The state agreement imposes a strict one year deadline for full implementation. Marriott must complete the rollout of its data minimization and disposal policies by October 9 2025. This deadline gives the company exactly one year to deploy the required systems across its network.
The state settlement requires the company to embrace zero trust architecture. This security model assumes that threats exist both inside and outside the network. Marriott must require enhanced cybersecurity controls for its essential IT vendors. The company must outline clear security expectations in its contracts with cloud computing providers. The North Carolina attorney general noted that companies should not store more consumer data than they need. The state settlement reinforces the federal mandate by requiring data disposal to ensure less consumer data is collected and retained.
Historical Context of the Data Hoarding Vulnerability
The regulatory mandates directly from the sheer volume of data Marriott stored without a defined business purpose. When hackers breached the Starwood network in July 2014, they found databases containing records dating back years. The intruders operated inside the network hidden from administrators until September 2018. During this 50 month period, the malicious actors exfiltrated 339 million guest records. The stolen data included 5. 25 million unencrypted passport numbers. The hackers also accessed payment card information, dates of birth, and loyalty account details.
If Marriott had deployed automated purging systems to delete older records, the scope of the breach would have been significantly smaller. The federal agency noted that the company failed to implement appropriate network segmentation. This architectural flaw allowed the attackers to move laterally across the network and access the central reservation database. The agency also faulted the company for failing to deploy adequate multi factor authentication and patch outdated software. The new data minimization rules force the company to correct these specific vulnerabilities.
Third Party Audits and Compliance Verification
The consent decree requires Marriott to submit to rigorous external oversight. The company must hire an independent third party assessor to evaluate its information security program every two years. This assessment covers the automated purging systems, the data minimization policies, and the 60 day deletion request procedure. The assessor must verify that the company accurately inventories its IT assets and classifies the personal data stored on them. Marriott must certify its compliance to the federal agency annually.
The order remains in effect for 20 years, ensuring long term regulatory supervision. The company must retain all records necessary to demonstrate full compliance with the order for five years. If the company experiences another covered security incident, it must report the breach to the agency within 10 days of notifying any other government entity. This rapid reporting requirement prevents the company from hiding future intrusions from federal regulators.
Data Retention Compliance Timeline
| Compliance Milestone | Deadline Date | Regulatory Authority | Status Requirement |
|---|---|---|---|
| State Settlement Finalized | October 9 2024 | 50 State Attorneys General | 52 Million Dollar Payment Executed |
| Federal Order Finalized | December 20 2024 | Federal Trade Commission | 20 Year Consent Decree Initiated |
| Deletion Link Deployment | June 18 2025 | Federal Trade Commission | 180 Days Post Order Issuance |
| Full State Implementation | October 9 2025 | 50 State Attorneys General | Zero Trust and Purging Active |
Marriott Bonvoy Application Security Audits and Vulnerability Patching

20 Questions and Answers Regarding Bonvoy Application Security and Patching
| Question | Answer |
|---|---|
| 1. What specific application requires new security audits under the Federal Trade Commission order? | The Marriott Bonvoy mobile application requires new security audits. |
| 2. When did the Federal Trade Commission finalize the consent order? | The agency finalized the order on December 20 2024. |
| 3. How long must Marriott submit to independent security assessments? | Marriott must submit to independent security assessments for 20 years. |
| 4. How frequently do third party auditors evaluate the Bonvoy application? | Auditors evaluate the application biennially. |
| 5. What specific patch management rules must Marriott adopt? | Marriott must adopt policies that account for the operational and security impact of software updates. |
| 6. What did the Federal Trade Commission allege regarding Marriott software patching? | The agency alleged Marriott failed to patch outdated software and systems. |
| 7. How consumers experienced data exposure between 2014 and 2020? | The breaches affected more than 344 million consumers worldwide. |
| 8. What specific function must the Bonvoy application include for data deletion? | The application must include a clear and conspicuous link for consumers to request personal data deletion. |
| 9. What authentication method must Marriott offer for Bonvoy accounts? | Marriott must offer Multi Factor Authentication for Bonvoy accounts. |
| 10. What action must Marriott take if malicious actors steal Bonvoy loyalty points? | Marriott must restore any loyalty points stolen by malicious actors. |
| 11. How much money did Marriott agree to pay to settle state investigations? | Marriott agreed to pay 52 million dollars to 49 states and the District of Columbia. |
| 12. What specific asset did the Federal Trade Commission recognize as personal property? | The agency recognized Bonvoy loyalty points as personal property. |
| 13. What timeline applies to verifying a data deletion request? | Marriott must verify the request and explain the deletion process within 60 days. |
| 14. What type of software did the Federal Trade Commission mandate Marriott to update? | The agency mandated Marriott to update software on all IT assets containing personal information. |
| 15. What specific access control flaw contributed to the Starwood breach? | Deficient firewalls and network segmentation contributed to the breach. |
| 16. How Starwood customers had payment card information exposed in the 2014 breach? | More than 40000 customers had payment card information exposed. |
| 17. What encryption standard did Starwood use for payment cards before the breach? | Starwood used AES 128 encryption for payment cards. |
| 18. How unencrypted passport numbers did the Starwood breach expose? | Malicious actors exposed 5 million unencrypted passport numbers. |
| 19. What specific reporting rule applies to future data breaches? | Marriott must report covered incidents to the Federal Trade Commission within 10 days of notifying other government entities. |
| 20. What specific security framework principle must Marriott incorporate? | Marriott must incorporate zero trust principles into its information security program. |
Federal Trade Commission Mandates for Vulnerability Management
The Federal Trade Commission finalized a consent agreement with Marriott International on December 20 2024. This regulatory action addresses severe data security failures that exposed the personal information of more than 344 million customers worldwide between 2014 and 2020. The agency specifically mandates strict vulnerability and patch management procedures to maintain and support software on all Marriott IT assets containing personal information.
Marriott must adopt governing policies that account for the operational and security impact of software updates. The company must allocate sufficient resources to maintain and update software in a timely manner. The Federal Trade Commission complaint noted that Marriott previously failed to patch outdated software and systems. This failure allowed malicious actors to exploit known software flaws and gain unauthorized access to the Starwood network.
The new patching mandates require Marriott to evaluate software updates based on data security impact and ongoing business needs. The company must implement processes to identify and remediate software flaws before malicious actors can exploit them.
Bonvoy Application Security Enhancements and Loyalty Point Protection
The Marriott Bonvoy application serves as a primary interface for millions of customers. The Federal Trade Commission order introduces specific security requirements for this mobile platform. Marriott must provide a clear and conspicuous link on its mobile applications directing United States consumers to an online process for personal data deletion. The company must verify receipt of each deletion request and explain the deletion process within 60 days.
The regulatory action explicitly recognizes Bonvoy loyalty points as personal assets. Marriott must provide a method for consumers to request a review of unauthorized activity in their Bonvoy accounts. If malicious actors steal loyalty points through unauthorized access, Marriott must restore the stolen points to the consumer.
To secure Bonvoy accounts, Marriott must offer Multi Factor Authentication to all users. This authentication method adds a necessary defense to prevent unauthorized account access. The agency noted that previous security failures included deficient multifactor authentication deployment.
Third Party Audits and Zero Trust Architecture Implementation
The consent order requires Marriott to undergo independent third party security assessments every two years. These audits evaluate the effectiveness of the information security program and verify compliance with the patching mandates. The auditing requirement remains in effect for 20 years.
Marriott must incorporate zero trust principles into its information security program. This architecture assumes that threats exist both inside and outside the network. The company must implement strict access controls and network segmentation to prevent lateral movement by malicious actors. The Federal Trade Commission previously observed that deficient network segmentation allowed intruders to access multiple systems and the core database without restriction.
The third party auditors evaluate the Bonvoy application to verify that Marriott applies security patches promptly. The auditors also review the data minimization practices to confirm that Marriott only retains personal information for as long as reasonably necessary.
Historical Patching Failures and Regulatory Correction
The 52 million dollar settlement with 49 states and the District of Columbia reinforces the federal mandates. The investigations revealed that the Starwood breach began in June 2014 and remained unnoticed for 14 months. Malicious actors accessed the payment card information of more than 40000 customers during this period.
A subsequent breach exposed 5 million unencrypted passport numbers. The intruders exploited outdated software and deficient firewall controls. Starwood stored payment card numbers using AES 128 encryption. The encryption keys remained on the same network, allowing the attackers to access the payment data in usable form.
The regulatory correction forces Marriott to abandon poor security practices. The company must report any covered security incidents to the Federal Trade Commission within 10 days of notifying other government entities. This reporting rule guarantees that federal regulators maintain visibility into the Marriott security posture.
Breach Timeline and Exposed Records
| Breach Period | Compromised Data Type | Exposed Records Count | Detection Delay |
|---|---|---|---|
| June 2014 to November 2015 | Payment Card Information | 40000 | 14 Months |
| July 2014 to September 2018 | Guest Accounts and Passports | 339 Million | 4 Years |
| September 2018 to February 2020 | Guest Records | 5. 2 Million | 17 Months |
Data Minimization and Application Logging Requirements
The Federal Trade Commission explicitly the excessive retention of consumer data. Marriott must implement a strict data minimization policy across all platforms, including the Bonvoy application. The company must document specific business justifications for retaining any personal data. The rules dictate that Marriott can only collect and keep personal information if a legitimate business need exists. Once that need expires, Marriott must delete the collected information.
Also, the consent order prohibits Marriott from using personal information for marketing purposes if a consumer previously requested the deletion of that data. The agency found that Marriott previously misrepresented its data protection practices to consumers. The new rules prohibit the company from making false claims about how it collects, maintains, uses, deletes, or discloses personal information.
Application logging serves as a primary defense against unauthorized access. The Federal Trade Commission complaint highlighted that Marriott failed to adequately log and monitor network environments. This failure prevented the company from detecting intruders in the network for several years. Marriott must deploy active network monitoring and logging tools to identify suspicious activity within the Bonvoy application and the broader corporate network.
Franchise Oversight and Acquisition Diligence
Marriott manages and franchises more than 7000 properties across more than 130 countries. The sheer size of this network complicates vulnerability patching and application security. The state settlement requires Marriott to increase oversight of its vendors and franchisees. The company must verify that franchised properties adhere to the same strict security standards applied to corporate locations.
The 2016 acquisition of Starwood for 12. 2 billion dollars introduced massive security liabilities to the Marriott network. Consumers received notification of the Starwood breach in 2015, just four days after Marriott announced the acquisition. The state attorneys general mandate improved diligence in relation to future acquisitions. Marriott must conduct deep security assessments of any acquired company to prevent the integration of compromised networks into the Marriott infrastructure.
In early 2020, Marriott discovered that malicious actors accessed guest information using the login credentials of two employees at a franchised property. This incident exposed the personal data of 5. 2 million guests. The breach demonstrates the severe risks associated with franchised property access to the central Bonvoy database. The new mandates force Marriott to implement strict access controls and Multi Factor Authentication to prevent similar credential abuse.
State Attorney General Parallel Settlements and State Level Enforcement
State Attorney General Parallel Settlements and State Level Enforcement
On October 9 2024 50 state attorneys general announced a 52 million dollar multistate settlement with Marriott International. The agreement resolves investigations into a multi year data breach of the Starwood guest reservation database. Intruders accessed the system in July 2014 and remained until September 2018. The breach exposed 131. 5 million guest records containing contact details, gender, dates of birth, legacy Starwood Preferred Guest information, and unencrypted passport numbers. The state level enforcement actions run parallel to the Federal Trade Commission consent decree.
Connecticut Attorney General William Tong co led the multistate coalition. The attorneys general determined that the corporation violated state consumer protection laws, personal information protection laws, and breach notification laws. The joint investigation revealed that hackers installed keyloggers, memory scraping malware, and remote access trojans on more than 480 systems across 58 locations within the Starwood network. New York Attorney General Letitia James noted the severity of the corporate negligence.
Marriott let cybercriminals live in its database for years and millions of people had their information stolen as a result. Protecting customers private information should be a top priority, not a last resort, for all companies.
20 Questions and Answers Regarding State Level Enforcement
| Query | Verified Data |
|---|---|
| What total financial penalty did Marriott agree to pay the state attorneys general? | 52 million dollars. |
| How state attorneys general participated in the multistate settlement? | 50 attorneys general. |
| When did the state attorneys general announce the settlement? | October 9 2024. |
| How much money does New York receive from the settlement? | 2. 29 million dollars. |
| What is the exact payout allocated to the state of Texas? | 3. 5 million dollars. |
| How much compensation does Connecticut receive? | 1, 992, 130 dollars. |
| What is the financial allocation for the state of Ohio? | 1. 5 million dollars. |
| How much money does Minnesota collect from the agreement? | 814, 847 dollars. |
| What specific payout amount goes to Iowa? | 594, 105 dollars. |
| What specific consumer protection right must Marriott offer under the state settlement? | A data deletion option. |
| Does the data deletion mandate apply even if a state absence a specific privacy law? | Yes. |
| What cybersecurity architecture principle must Marriott incorporate under the agreement? | Zero trust principles. |
| Who must receive regular security reports within the Marriott corporate structure? | The Chief Executive Officer. |
| What specific criteria must ongoing risk assessments address? | The criteria of harm to others. |
| What must Marriott do regarding future corporate acquisitions? | Assess the security practices of the new entity and address any weaknesses. |
| How long did the intruders remain in the Starwood system according to the state investigations? | From July 2014 until September 2018. |
| How guest records were exposed in the breach? | 131. 5 million records. |
| What specific loyalty program data was compromised in the breach? | Legacy Starwood Preferred Guest information. |
| What specific state laws did the attorneys general allege Marriott violated? | State consumer protection laws, personal information protection laws, and breach notification laws. |
| Does Marriott admit liability in the settlement agreement? | No. |
Multistate Financial Penalties and Specific State Allocations
The 52 million dollar penalty is distributed among the participating states based on the number of affected residents and specific state consumer protection laws. Texas receives 3. 5 million dollars from the settlement. New York collects 2. 29 million dollars. Connecticut secures 1, 992, 130 dollars. Ohio obtains 1. 5 million dollars. Minnesota gets 814, 847 dollars. Iowa receives 594, 105 dollars. The financial penalties hold the corporation accountable for failing to implement reasonable security measures. The corporation makes no admission of liability in the agreement. Ohio Attorney General Dave Yost summarized the regulatory position.
Marriott was supposed to be a trusted gatekeeper of millions of people’s personal information, it failed. We are holding the company accountable and ensuring they have the tools in place to prevent a repeat performance.
Specific Security Failures Identified by State Investigators
State investigators identified multiple specific security failures that allowed the breach to continue for four years. The forensic examination of the Starwood systems revealed insufficient firewall controls across the network. The corporation stored unencrypted payment card information outside of the secure cardholder data environment. The network operated without multi factor authentication for administrative access. The investigators also found insufficient monitoring and logging practices. These failures allowed the intruders to install keyloggers and memory scraping malware without triggering security alerts. The attackers compromised the external facing webserver and used remote access trojans to move laterally through the corporate network.
The breach exposed unencrypted passport numbers belonging to more than five million people. The stolen records also included email addresses, phone numbers, and loyalty account information. The state attorneys general argued that the corporation misrepresented its data security practices to consumers. The corporation claimed to have strong privacy protections in place while failing to implement basic data security controls. The settlement requires the corporation to cease misrepresenting its data collection and storage practices. The corporation must document its justifications for retaining specific types of consumer data.
State Mandated Cybersecurity Overhauls and Zero Trust Architecture
The state settlement imposes strict injunctive terms to force a complete overhaul of corporate data security practices. The agreement mandates the implementation of an extensive Information Security Program. This program must incorporate zero trust principles across the corporate network. Zero trust architecture requires strict identity verification for every person and device attempting to access resources on a private network. The settlement also requires regular security reporting to the highest levels within the company. The Chief Executive Officer must receive these security reports directly. The corporation must enhance employee training on data handling and security.
The attorneys general require the corporation to adopt a continuous risk based method for cybersecurity. The corporation must conduct an annual enterprise level risk assessment. The security team must also perform risk analyses throughout the year for any changes to security controls. These ongoing risk assessments must specifically address the criteria of harm to others. This requirement ensures the corporation evaluates chance harm to consumers rather than just financial risk to the business. The settlement mandates increased vendor and franchisee oversight to prevent third party vulnerabilities. The corporation must emphasize risk assessments for primary information technology vendors and outline contracts with cloud providers.
Consumer Data Deletion Rights and Acquisition Security
The state level agreement provides consumers with specific protections regarding their personal information. Marriott must offer a data deletion option to all United States customers. Consumers can request the deletion of personal information associated with their email address or loyalty rewards number. The corporation must honor these deletion requests even if the consumer resides in a state that does not currently guarantee that right under state law. The settlement enforces strict data minimization and disposal requirements. The corporation must limit the collection and retention of personal information to reduce risk.
The attorneys general established specific security for future corporate acquisitions. The Starwood breach originated from an acquired network. The settlement requires Marriott to assess the security practices of any newly acquired entity. The corporation must identify and address any security weaknesses before integrating the new network into the primary corporate infrastructure. The corporation must undergo independent third party evaluations of its security program every two years for the two decades. The corporation must also offer multi factor authentication to customers for their loyalty rewards accounts and conduct reviews of those accounts to ensure there is no suspicious activity.
Franchise Network Security and Vendor Oversight Mandates
The state settlement extends security requirements to the franchise network. Marriott must develop and maintain written policies requiring franchised hotels to implement appropriate safeguards for personal information. Franchised locations must notify the corporate office within twenty four hours of any system compromise that affects corporate assets. The franchise operators must also notify the corporate office within five business days of terminating any employee or contractor who had access to corporate systems. This requirement aims to prevent unauthorized access by former employees.
The agreement defines strict rules for primary information technology vendors. A primary vendor is any third party providing managed services that form a significant component of the information security program. These vendors frequently have direct access to covered databases or corporate assets. The corporation must conduct thorough risk assessments for these vendors and establish outlined contracts with cloud service providers. The independent third party assessor evaluates these vendor relationships during the biennial security audits. The state courts maintain jurisdiction to enforce the terms of the consent judgment.
Verified State Payout Allocations
The chart details the specific financial allocations for six states that publicly disclosed their settlement amounts.
Verified State Settlement Payouts (USD)
Customer Compensation Claims and Credit Monitoring Distribution
20 Questions and Answers Regarding Customer Compensation and Credit Monitoring
| Question | Answer |
|---|---|
| 1. What is the total financial penalty Marriott agreed to pay the states? | 52 million dollars. |
| 2. Did the 52 million dollar settlement create a direct cash fund for consumers? | No, the funds were distributed to 49 states and the District of Columbia. |
| 3. What agency finalized the consent order in December 2024? | The Federal Trade Commission. |
| 4. What specific consumer right does the FTC mandate regarding personal data? | Marriott must provide United States customers a way to request deletion of their personal information. |
| 5. What must Marriott do regarding stolen loyalty points? | Marriott must review accounts upon request and restore stolen loyalty points. |
| 6. What security feature must Marriott offer for loyalty accounts? | Multi Factor Authentication. |
| 7. What identity monitoring service did Marriott offer after the 2018 breach discovery? | WebWatchers. |
| 8. How long was the free identity monitoring service provided? | One year. |
| 9. What travel document replacement cost did Marriott agree to reimburse? | Passport replacement costs. |
| 10. How much is the standard United States passport replacement fee that Marriott offered to cover? | 110 dollars. |
| 11. What condition must guests meet to get passport reimbursement? | They must prove they experienced fraud as a result of the breach. |
| 12. How unencrypted passport numbers were exposed in the Starwood breach? | 5. 25 million. |
| 13. How encrypted passport numbers were acquired in the breach? | 20 million. |
| 14. When did the FTC finalize the consent order? | December 20 2024. |
| 15. How states participated in the 52 million dollar settlement? | 49 states. |
| 16. What loyalty program is specifically targeted for the new security upgrades? | Marriott Bonvoy. |
| 17. How total guest records were exposed in the initial Starwood breach? | 339 million worldwide. |
| 18. What specific encryption standard did Marriott use for credit cards? | Advanced Encryption Standard 128. |
| 19. How encrypted credit card numbers were stolen? | 8. 6 million. |
| 20. What is the duration of the information security program mandated by the FTC? | 20 years. |
State Settlement Allocation Versus Direct Consumer Relief
The October 2024 agreement between Marriott International and 49 state attorneys general mandates a 52 million dollar payment. The Federal Trade Commission does not possess the legal authority to obtain civil penalties in this specific case. The 52 million dollar sum goes directly to the participating states and the District of Columbia. The settlement does not establish a direct cash compensation fund for individual data breach victims. Consumers seeking direct financial damages must navigate the ongoing multidistrict class action litigation.
The Federal Trade Commission consent decree finalized on December 20 2024 focuses entirely on injunctive relief and specific consumer remediation methods. The regulatory framework forces Marriott to provide non monetary compensation and security upgrades to affected guests. The mandates include loyalty point restoration and personal data deletion rights.
Credit Monitoring and Identity Protection Distribution
Following the public disclosure of the Starwood database intrusion in November 2018, Marriott initiated a credit monitoring distribution program. The company partnered with WebWatchers to provide identity theft protection services. Marriott offered this service at no cost to affected guests for a duration of one year. The WebWatchers platform monitors internet sites where personal information is shared and alerts users if their data appears in unauthorized locations.
The breach exposed 5. 25 million unencrypted passport numbers and 20 million encrypted passport numbers. The exposure of highly sensitive travel documents prompted demands for passport replacement compensation. Marriott agreed to reimburse the 110 dollar fee for a new United States passport. Guests must prove they experienced actual fraud resulting directly from the passport data exposure to qualify for the reimbursement. The company established a dedicated process to evaluate these specific fraud claims.
Multidistrict Class Action Litigation Status
The 52 million dollar state settlement resolves regulatory investigations leaves individual consumer compensation to the federal courts. Consumers filed numerous class action lawsuits against Marriott following the 2018 breach disclosure. The Judicial Panel on Multidistrict Litigation consolidated these cases into a single docket in the District of Maryland. The consolidated case is known as Multidistrict Litigation 2879.
In February 2020 a federal judge ruled that Marriott must face the multidistrict litigation. The plaintiffs successfully stated they face an imminent risk of injury and identity theft. The court documents indicate consumers spend time and money protecting against identity theft. The plaintiffs also claim they lost property value in their personal information and suffered a loss of the benefit of their agreement with Marriott regarding data privacy.
The class action lawsuit holds the hotel chain liable under theories of tort, contract, and breach of statutory duties. The plaintiffs allege Marriott failed to take reasonable steps to protect personal information against a foreseeable cyber attack. The litigation remains a primary avenue for consumers seeking direct financial compensation for out of pocket expenses, lost time, and emotional distress caused by the data exposure.
The Passport Data Threat and Reimbursement Obstacles
The Starwood database intrusion exposed 5. 25 million unencrypted passport numbers and 20 million encrypted passport numbers. Passport information represents a highly sensitive data category. Cybersecurity experts note that hacking organizations specifically target large pools of passport data because the information holds significant value on digital black markets. Passport numbers serve as foundational identity documents, making them prime for sophisticated identity theft operations.
Marriott faced intense public pressure regarding the exposed travel documents. United States Senator Chuck Schumer publicly demanded the company cover the 110 dollar replacement fee for any customer whose passport number was stolen. Marriott subsequently agreed to reimburse the costs associated with getting a new passport. The company attached a strict condition to this reimbursement offer. Guests must prove they experienced actual fraud as a direct result of their passport information being involved in the incident.
This proof of fraud requirement created a high barrier for consumer claims. The United States State Department advised travelers not to report their passport numbers stolen unless they lost the physical document. This federal guidance complicated the process for consumers attempting to justify a passport replacement based solely on the digital data breach. Marriott established a dedicated process to evaluate these fraud claims, the strict eligibility criteria limited the number of successful reimbursements.
Mechanics of Personal Data Deletion Requests
The December 2024 Federal Trade Commission consent order introduces a mandatory data deletion process for all United States customers. Prior to this regulatory action, data deletion rights depended heavily on state specific privacy laws. The federal mandate standardizes this consumer right across the entire country for Marriott guests.
Marriott must provide a clear and accessible method for consumers to request the removal of their personal information. The deletion applies to data associated with a specific email address or a Marriott Bonvoy account number. The company must execute these requests promptly and confirm the removal of the data from its active databases. This requirement forces Marriott to maintain an accurate data inventory to ensure all instances of a customer record are identified and purged upon request.
The data deletion mandate directly addresses the root cause of the prolonged Starwood breach. The intruders remained in the system for four years, accessing legacy data that the company retained without a strict business need. By allowing consumers to force data deletion, the Federal Trade Commission reduces the volume of sensitive information stored on Marriott servers. This data minimization strategy limits the possible damage of future network intrusions.
Loyalty Point Restoration Rules
The Marriott Bonvoy program holds significant financial value for frequent travelers. Hackers target these accounts to steal accumulated points and redeem them for free hotel stays or gift cards. The 2024 regulatory settlement acknowledges the financial damage of loyalty point theft. The state attorneys general and the Federal Trade Commission mandate that Marriott implement a formal review process for suspicious account activity.
Consumers can request an investigation into unauthorized point redemptions. Marriott must review the account history and identify fraudulent transactions. If the investigation confirms that unauthorized access led to the loss of points, the company must restore the stolen balance in full. This provision ensures that consumers do not lose the earned value of their loyalty rewards due to corporate security failures.
To prevent future point theft, the settlement requires Marriott to deploy Multi Factor Authentication across the loyalty platform. This security rule requires users to provide two or more verification factors to access their accounts. The implementation of Multi Factor Authentication adds a necessary level of security, blocking automated credential stuffing attacks and unauthorized access attempts using stolen passwords.
Consumer Relief Methods and Eligibility Metrics
| Relief Method | Value or Duration | Eligibility Requirement | Regulatory Driver |
|---|---|---|---|
| WebWatchers Identity Monitoring | 1 Year | Affected Starwood Guests | Voluntary Corporate Action 2018 |
| Passport Replacement Reimbursement | 110 Dollars | Documented Fraud Linked to Breach | Voluntary Corporate Action 2018 |
| Loyalty Point Restoration | Full Stolen Balance | Confirmed Unauthorized Account Access | Federal Trade Commission Order 2024 |
| Personal Data Deletion | Permanent Removal | All United States Customers | Federal Trade Commission Order 2024 |
| Multi Factor Authentication | Ongoing Security Feature | All Marriott Bonvoy Members | State Attorneys General Settlement 2024 |
Cloud Storage Configuration Audits and Misconfiguration Remediation
20 Questions and Answers Regarding Cloud Storage Audits
| Question | Answer |
|---|---|
| 1. What exact date did the Federal Trade Commission finalize the Marriott consent order? | The agency finalized the order on December 20 2024. |
| 2. How long does the Federal Trade Commission mandate independent security assessments for Marriott? | The mandate lasts for 20 years. |
| 3. How frequently must Marriott obtain a third party information security assessment? | The company must obtain an assessment every two years. |
| 4. What specific cloud storage platform was involved in the Otelier breach affecting Marriott? | The breach involved Amazon Web Services S3 buckets. |
| 5. How much data did attackers download during the Otelier breach? | Attackers downloaded 7. 8 terabytes of data. |
| 6. When did the unauthorized access to Otelier systems begin? | The intrusion started in July 2024. |
| 7. When did Otelier terminate the unauthorized access? | The company terminated the access in October 2024. |
| 8. How unique customer email addresses were exposed in the Otelier breach? | The breach exposed 437, 000 unique customer email addresses. |
| 9. What type of malware did attackers use to steal Otelier employee credentials? | Attackers used information stealing malware. |
| 10. Which specific server did attackers access during the Otelier breach? | Attackers accessed an Atlassian server. |
| 11. What action did Marriott take regarding Otelier after discovering the breach? | Marriott suspended automated services with the vendor. |
| 12. What specific configuration standard does the Federal Trade Commission require Marriott to develop? | The agency requires Marriott to develop component hardening standards. |
| 13. What must Marriott do with operating systems and network devices under the new order? | Marriott must harden these assets against known threats. |
| 14. What specific inventory requirement does the consent order impose on Marriott? | Marriott must regularly inventory and classify all corporate IT assets. |
| 15. What must Marriott do before approving new software or hardware? | Marriott must perform a risk analysis on any new asset. |
| 16. How quickly must Marriott investigate suspicious network activity under the settlement? | Marriott must investigate suspicious activity within 24 hours. |
| 17. What specific security rule must Marriott enforce for cloud service providers? | Marriott must outline security responsibilities in written contracts. |
| 18. What financial penalty did Marriott agree to pay to state attorneys general? | Marriott agreed to pay 52 million dollars. |
| 19. What specific testing program must Marriott implement for its databases? | Marriott must implement a risk based penetration testing program. |
| 20. How frequently must Marriott conduct penetration testing on its assets? | Marriott must conduct these tests at least annually. |
Federal Trade Commission Mandates for Cloud Storage
The Federal Trade Commission finalized a consent order against Marriott International on December 20 2024. The agency requires the hotel chain to overhaul its information security program. The mandate cloud storage misconfigurations and third party vendor oversight. Marriott must enforce strict configuration standards for all operating systems and network devices. The agency calls this process component hardening. The company must harden all assets against known threats. The order applies to internal servers and external cloud environments.
Marriott must maintain a written inventory of all corporate IT assets. The company must classify these assets based on sensitivity. The Federal Trade Commission requires Marriott to use scanning tools to locate unmanaged cloud instances. The agency mandates a risk analysis before Marriott approves any new software or hardware. The company must outline security responsibilities in written contracts with all cloud service providers. The order forces Marriott to monitor all connections to third party vendors.
The Federal Trade Commission order forces Marriott to establish formal policies for logging and monitoring all IT assets. The company must track the movement of files and users within the network. The agency mandates strict user access controls. Marriott must annually review a sampling of user accounts. The company must verify that access privileges remain appropriate. The order requires Marriott to terminate unnecessary access immediately. The agency forces Marriott to implement a data minimization policy. The company must document justifications for retaining any personal data. Marriott must provide United States customers with a method to request the deletion of personal information. The company must link this deletion request to the customer email address or loyalty rewards number. Marriott must review loyalty rewards accounts upon customer request. The company must restore any stolen loyalty points.
The Otelier Amazon Web Services Breach
A third party vendor breach in 2024 exposed the exact vulnerabilities the Federal Trade Commission order. Otelier operates as a cloud based software provider for over 10, 000 hotel properties worldwide. The vendor stores massive amounts of sensitive guest data in Amazon Web Services S3 buckets. Attackers breached the Otelier Atlassian server using credentials stolen via information stealing malware. The attackers scraped internal tickets to find access keys for the S3 buckets. The intrusion began in July 2024. The attackers maintained access until October 2024.
The attackers downloaded 7. 8 terabytes of data during this three month period. The stolen files contained millions of guest records from Marriott, Hilton, and Hyatt. The data security website HaveIBeenPwned added 437, 000 unique customer email addresses from the breach to its database. The exposed data included physical addresses, phone numbers, travel booking details, and partial credit card numbers. The attackers attempted to extort Marriott directly. They left ransom notes demanding cryptocurrency payments. The attackers mistakenly believed the S3 buckets belonged directly to Marriott. The hotel chain confirmed its systems remained secure. Marriott suspended automated services with Otelier to stop further data exposure.
Misconfiguration Remediation and Biennial Audits
The Federal Trade Commission requires Marriott to perform detailed after action reports following any future data breaches. The company must submit these assessments within 120 days of a breach involving personal data. The agency mandates strict rules for hardware removal. Marriott must remove or encrypt all personal information on any IT asset before taking the device offline. The company must apply these rules to all cloud storage instances and physical servers. The order requires Marriott to conduct data security training for all IT personnel. The company must also train all employees who handle sensitive customer data.
Marriott must implement a risk based testing program. The company must identify and assess security vulnerabilities across all databases. The mandate includes internal and external penetration testing. Marriott must conduct web application penetration testing at least annually. The company must perform retests to confirm appropriate remediation. The agency requires Marriott to investigate any suspicious network activity within 24 hours.
Marriott must obtain an independent third party information security assessment every two years. The mandate lasts for 20 years. The company must submit the initial assessment to the Federal Trade Commission. Marriott must retain subsequent assessments for five years. The agency can request these documents at any time. The company must cooperate fully with the independent assessor. Marriott must provide access to all relevant IT assets and material facts. The order holds Marriott accountable for the security practices of its cloud vendors. Marriott must obtain approval from the Federal Trade Commission before hiring an independent assessor. The initial assessment period begins 60 days after the date of the order. The assessment period ends 365 days later. The company must repeat this process every two years. The agency holds the power to reject any proposed assessor.
Financial Penalties and Remediation Costs
The financial penalties extend beyond the Federal Trade Commission order. Marriott agreed to pay 52 million dollars to resolve parallel investigations by 49 state attorneys general and the District of Columbia. The state settlement forces Marriott to adopt zero trust cybersecurity principles. The company must require continuous verification before granting access to sensitive data or systems. The state agreement mirrors the federal requirement for strict vendor oversight. Marriott must strengthen its contractual obligations with all cloud service providers. The company must enforce these rules across its entire corporate network.
The United Kingdom Information Commissioner Office previously fined Marriott 23. 8 million dollars in 2020. The fine penalized the company for failing to secure legacy systems after acquiring Starwood Hotels. Marriott spent over 70 million dollars on remedial measures by the quarter of 2019. The company faces ongoing costs to maintain the mandated information security program. The 20 year duration of the federal order guarantees continuous compliance expenses.
Marriott Security Incident Costs (Millions USD)
Long Term Compliance Viability and Future Regulatory Exposure
Long Term Compliance Viability and Future Regulatory Exposure
The Federal Trade Commission finalized its consent order against Marriott International on December 20, 2024. This regulatory action binds the hospitality corporation to a strict compliance timeline that extends through the year 2044. Marriott faces severe financial exposure if it fails to meet the mandated security requirements over the two decades. January 17, 2025, the maximum civil penalty for violating a Federal Trade Commission order increased to 53, 088 dollars per violation. Regulators calculate these penalties on a per-day basis for ongoing infractions. A single unpatched vulnerability left open for 90 days can trigger millions in federal fines.
20 Questions and Answers Regarding Future Regulatory Exposure
| Question | Answer |
|---|---|
| 1. What is the exact duration of the Federal Trade Commission consent order against Marriott International? | The federal agency mandates a 20-year compliance period that requires continuous security monitoring and reporting through the year 2044. |
| 2. When does the 20-year compliance clock officially begin for the hospitality corporation? | The regulatory timeline officially commenced on December 20, 2024, when the federal agency finalized the consent agreement. |
| 3. What is the maximum civil penalty per violation the Federal Trade Commission can levy in 2025? | The agency can impose a maximum civil penalty of 53, 088 dollars per violation. |
| 4. On what exact date did the 2025 federal penalty increase take effect? | The inflation-adjusted penalty increase officially took effect on January 17, 2025. |
| 5. How does the federal government calculate penalties for ongoing security violations? | Regulators treat each day of non-compliance and each separate occurrence as a distinct violation subject to the maximum fine. |
| 6. How quickly must Marriott report new covered incidents to the federal government? | The corporation must submit a formal report to the Federal Trade Commission within 10 days of notifying any other government entity. |
| 7. Which international regulator previously fined Marriott for the Starwood network breach? | The United Kingdom Information Commissioner’s Office penalized the corporation for the intrusion. |
| 8. What was the final penalty amount issued by the United Kingdom Information Commissioner’s Office in 2020? | The foreign regulator issued a fine of 18. 4 million pounds on October 30, 2020. |
| 9. Under which specific law did the United Kingdom penalize Marriott? | The regulator enforced the penalty under the General Data Protection Regulation. |
| 10. How frequently must Marriott submit independent security assessments to federal regulators? | The consent order requires the corporation to undergo and submit a third-party assessment every two years. |
| 11. How frequently must Marriott executives certify their information security program compliance? | Corporate officers must submit a formal compliance certification to the federal agency annually. |
| 12. Which specific statutory section governs the civil penalties for consent order violations? | Section 5(l) of the Federal Trade Commission Act dictates the penalty structure for order violations. |
| 13. Does the federal consent order shield Marriott from future state-level enforcement actions? | No, state attorneys general retain independent legal authority to investigate and penalize the corporation for future security failures. |
| 14. What happens if Marriott acquires another hotel chain during the 20-year order? | The acquired entity’s digital systems immediately fall under the strict mandates of the federal consent order. |
| 15. Can individual consumers sue Marriott for future breaches under the federal order? | The federal order does not grant a private right of action, yet consumers can file separate civil lawsuits under other statutes. |
| 16. What specific compliance framework did the United Kingdom regulator cite during its 2020 enforcement? | The foreign regulator the National Institute of Standards and Technology framework to evaluate the security failures. |
| 17. How long did the initial Starwood breach go before regulatory scrutiny began? | The intrusion remained for four years, spanning from 2014 to 2018. |
| 18. What is the primary financial risk of failing a biennial third-party assessment? | A failed audit gives the federal agency immediate grounds to initiate enforcement actions and trigger per-day financial penalties. |
| 19. Which federal statute mandates the annual inflation adjustment for civil penalties? | The Federal Civil Penalties Inflation Adjustment Act Improvements Act of 2015 requires the annual increase. |
| 20. Does Marriott admit liability for the allegations detailed in the federal consent order? | No, the corporation agreed to the settlement terms without an official admission of liability for the alleged violations. |
The 20-Year Mandate and Structural Overhaul
The Federal Trade Commission finalized the consent agreement on December 20, 2024, locking Marriott into a two-decade regulatory framework. This timeline requires the corporation to maintain an extensive information security program through 2044. The company must fund continuous vendor audits, mandatory multi-factor authentication deployments, and strict data minimization. Executives must certify compliance annually. False certifications expose corporate officers to direct legal liability. The federal agency designed this 20-year window to force permanent structural changes within the corporate hierarchy. The mandate leaves no room for temporary fixes or superficial security patches.
The Financial Mathematics of Non-Compliance
Future regulatory exposure carries severe financial consequences. The federal government adjusted the maximum civil penalty for violating a Federal Trade Commission order to 53, 088 dollars per violation, January 17, 2025. Regulators calculate these fines aggressively. The agency treats each day of non-compliance as a separate violation. If Marriott fails to patch a known vulnerability for 30 days, the theoretical maximum penalty exceeds 1. 5 million dollars for that single infraction. If the failure affects multiple systems or involves multiple distinct security rules, the financial exposure multiplies rapidly. The corporation must allocate massive capital reserves to guarantee continuous compliance and avoid these penalties.
Maximum FTC Civil Penalty Per Violation (2023-2025)
2023
2024
2025
Data Source: Federal Register Inflation Adjustments
The 10-Day Government Notification Rule
The consent decree includes a strict rapid reporting method. Marriott must submit a formal report to the Federal Trade Commission within 10 days of notifying any other United States federal, state, or local government entity about a covered incident. This rule prevents the corporation from hiding future intrusions or delaying federal oversight. During the original Starwood breach, the intrusion remained from 2014 until 2018. The new 10-day mandate forces immediate transparency. Any delay in reporting a new breach directly violates the consent order and triggers the 53, 088 dollar per-day penalty structure.
International Regulatory Precedent and the UK ICO
Global regulatory exposure remains a serious threat to Marriott. The United Kingdom Information Commissioner’s Office previously fined the corporation 18. 4 million pounds on October 30, 2020. The foreign regulator issued this penalty for General Data Protection Regulation violations connected to the Starwood database compromise. This prior enforcement establishes a clear precedent for international action. Foreign regulators monitor the company closely. If Marriott suffers another data exposure affecting European citizens, the General Data Protection Regulation allows fines up to 4 percent of global annual revenue. The corporation must maintain security standards that satisfy both United States federal mandates and strict European privacy laws.
State-Level Enforcement and the 49-State Coalition
The federal consent order does not preempt state-level legal authority. In October 2024, Marriott agreed to pay 52 million dollars to 49 states and the District of Columbia to resolve parallel investigations into the historic breaches. These state attorneys general retain full authority to investigate and penalize the corporation for future security failures. State laws frequently carry separate penalty structures and distinct notification timelines. A single future breach could trigger simultaneous investigations by the Federal Trade Commission, foreign data protection authorities, and dozens of state attorneys general. This multi-jurisdictional exposure requires Marriott to execute a flawless compliance strategy.
The Biennial Third-Party Assessment Trap
The consent order forces Marriott to undergo an independent security assessment every two years. The corporation cannot use internal auditors to satisfy this requirement. The third-party assessor must evaluate the effectiveness of the mandated information security program and submit findings directly to the federal government. A negative assessment gives the Federal Trade Commission immediate grounds to initiate enforcement actions. The auditors test multi-factor authentication deployments, data deletion, and vendor oversight method. Any documented failure in these areas directly into consent decree violations. The corporation must treat every biennial audit as a high- regulatory examination.
Long-Term Viability and Corporate Resource Allocation
Sustaining compliance over a 20-year period requires massive resource allocation. Marriott must fund continuous network monitoring, regular penetration testing, and extensive employee training programs. The corporation must also police its third-party vendors and franchised properties. The consent order requires Marriott to develop a risk-based audit program to review compliance at franchised hotels. The company must retain contractual rights to enforce security standards across its entire franchise network. This requirement shifts the financial load of oversight directly onto corporate headquarters. The long-term viability of Marriott depends entirely on its ability to execute these security mandates without fail through the year 2044.


































