The U.S. Federal Trade Commission has ordered Marriott and Starwood to implement a comprehensive information security program to settle charges related to multiple hacks and theft of customer data.
Marriott and Starwood were hacked multiple times, with the largest hack occurring in 2018 and involving 500 million customer records.
The FTC complaint accused Marriott and Starwood of misleading consumers by claiming to have sufficient data security measures.
Under the order, Marriott and Starwood must establish an information security program, retain personal information for a reasonable time period, and provide a process for customers to request data deletion.