
PIPEDA Findings #2022-005: Hotel chain discovers breach of customer database following acquisition of a competitor
On November 30, 2018, Marriott International, Inc. announced a data security breach involving unauthorized access to a Starwood Hotels database, which it had acquired in 2016. The breach, spanning over four years, affected up to 12.8 million Canadian records, including passport and payment card details. The OPC launched an investigation into Luxury Hotels Canada, Marriott's Canadian operating company, following eleven complaints. The investigation found Marriott's security safeguards, accountability measures, and information retention practices to be inadequate, contravening PIPEDA Principles 4.7, 4.1.4, and 4.5. Specifically, Marriott failed to detect the breach sooner due to insufficient logging, monitoring, and multi-factor authentication, and retained personal information longer than necessary. While Marriott's notification to affected individuals was deemed adequate, the OPC had outstanding concerns regarding remote access, unencrypted data storage, and retention periods. The findings are well-founded and conditionally resolved, as Marriott committed to implementing the OPC's recommendations, including engaging an external assessor and reviewing its privacy framework.
- 1Whether personal information held by Marriott was protected by security safeguards appropriate to the sensitivity of the information as required by Principle 4.7 (Safeguards).
- 2Whether Marriott demonstrated due diligence and took steps to fulfil its responsibilities to implement policies and practices to protect personal information under Principle 4.1.4 (Accountability) when acquiring control of the Starwood network.
- 3Whether Marriott retained personal information for longer than necessary, relevant to Principle 4.5 (Limiting use, disclosure and retention).
- 4Whether the mitigation measures offered by Marriott to affected individuals were adequate to protect their personal information from unauthorized use, such as future identity theft, in accordance with Principle 4.7 (Safeguards).
- Security safeguards: Found inadequate
- Accountability measures: Found inadequate
- Information retention: Found inadequate
- Breach detection: Found inadequate
- Notification to individuals: Found adequate
- Resolution of concerns: Conditionally resolved
Complaint well-founded and conditionally resolved
The OPC found Marriott's security safeguards, accountability for acquired systems, and information retention practices to be deficient, leading to a prolonged and extensive data breach. The findings are conditionally resolved because Marriott agreed to implement the OPC's recommendations to address these systemic issues and enhance its privacy framework.
The Commissioner recommended that Marriott retain an experienced independent external assessor to evaluate its security enhancements and submit a report to the OPC within nine months, and review its organizational and governance measures for ongoing assessment of its privacy framework, also submitting a report within nine months.
- Principle 4.7 PIPEDA
- Principle 4.1.4 PIPEDA
- Principle 4.5 PIPEDA
This summary is for informational purposes only and does not constitute legal advice.
Related by meaning
Decisions with similar reasoning and facts — found by AI across statutes and jurisdictions, not just keywords.
Coverage — 13 of 14 jurisdictions searchable
Fully searchable: Ontario, British Columbia, Alberta, Saskatchewan, Newfoundland and Labrador, Northwest Territories, New Brunswick, Manitoba.
Partial (recent decisions only): Federal (Canada) (651 of 1,631), Nova Scotia (49 of 472), Quebec (6 of 7,090), Prince Edward Island (2 of 279), Yukon (1 of 75).
Coming soon: Nunavut — being re-processed for AI search.
Find decisions like this one — by meaning, not keywords.
Related by meaning is a Pro feature. Upgrade to surface conceptually similar decisions across the corpus, powered by AI.
Upgrade to Pro