4 ms·
I'm ever so slightly optimistic in this regard. As soon as we see a few GDPR-related penalties assessed, the risk-reward calculation will change drastically. A
by jlgray 8y ago
I'm ever so slightly optimistic in this regard. As soon as we see a few GDPR-related penalties assessed, the risk-reward calculation will change drastically.
According to their 2017 annual report [1], Marriot had $22.9bn in worldwide revenue. A 4% penalty on that would be $900M.
[1] https://marriott.gcs-web.com/static-files/057a8e1a-a5c5-4c20-a51c-0b20bf8a0bc1 https://marriott.gcs-web.com/static-files/057a8e1a-a5c5-4c20...
- reaperducer 8y agoI read that there was some kind of grace period involving GDPR penalties. Has the EU handed out any fines yet, or is it still letting companies adjust?
- qznc 8y agoYes, the first case is done: https://www.welivesecurity.com/2018/11/27/german-chat-site-faces-fine-gdpr/ https://www.welivesecurity.com/2018/11/27/german-chat-site-f... The question is probably if it is state of the art to encrypt passport numbers. If yes, then Marriot could be fine with a similiar argument of "the company knowingly violated its duty to ensure data security".
- kazen44 8y ago> I read that there was some kind of grace period involving GDPR penalties. the grace period started two years ago until may 2018... people seem to forget that the GDPR was technically already a law in 2016, it was just not enforced.
- gamma-male 8y agoI've seen employees demonstrating every day for months in front of the Marriott in San Francisco. Didn't think they were doing that good.