Consumers Affected
344,000,000
The FTC finalized an order against Marriott International and Starwood Hotels for failing to implement reasonable data security, which led to three data breaches affecting over 344 million customers. The companies must implement a comprehensive security program, delete unnecessary personal information, allow U.S. customers to request deletion, and restore stolen loyalty points. They are also prohibited from misrepresenting their data security practices.
Marriott and Starwood must establish a comprehensive information security program, implement a data retention policy to keep personal information only as long as necessary, provide a website link for U.S. customers to request deletion of personal information, review and restore stolen loyalty points upon request, and are prohibited from misrepresenting their data collection, use, and security practices.
In-house legal teams should review all customer-facing agreements (e.g., hotel registration terms, loyalty program terms), vendor agreements (particularly those involving data processing or access to personal information), and any data processing addendums. Specific clauses to scrutinize include: (1) data security standards and representations, ensuring they align with 'reasonable' practices and do not overstate security; (2) data retention and deletion provisions, confirming they allow for deletion upon customer request and comply with data minimization principles; (3) breach notification obligations, verifying timely and comprehensive notification requirements; and (4) loyalty program data handling terms. Changes may be needed to add explicit customer deletion rights, tighten data retention limits, strengthen security requirement language, and correct any misleading security assurances.
Entity
Marriott International, Inc. and its subsidiary Starwood Hotels & Resorts Worldwide LLC
Also known as: Marriott
Industry
OtherOfficial Press Release
https://www.ftc.gov/news-events/news/press-releases/2024/12/ftc-finalizes-order-marriott-starwood-requiring-them-implement-robust-data-security-program-address
1923022marriottfinalorder
https://www.ftc.gov/system/files/ftc_gov/pdf/1923022marriottfinalorder.pdf
Federal Trade Commission Enforcement Page
https://www.ftc.gov/enforcement
"Marriott International, Inc. and its subsidiary Starwood Hotels & Resorts Worldwide LLC"
"failed to deploy reasonable security to protect consumers’ personal information"
The FTC, Utah, and Nevada sued Lens.com Inc., alleging that it advertised artificially low contact lens prices while hiding mandatory checkout charges and misleading consumers about its AutoRefill subscription. The complaint seeks to stop the alleged practices; the court has not yet decided the case, and no penalty or remedy has been imposed.
The FTC issued an advance notice of proposed rulemaking seeking public comment on whether ad-optimization tools offered by online platforms may help scammers impersonate businesses and government agencies. This is a proposed regulatory inquiry, not an enforcement action against a named company; no penalty or remedy was imposed.
$2.5B
A federal court approved a revised order in the FTC's Amazon Prime case under which Amazon will accelerate and expand redress payments under the September 2025 $2.5 billion settlement, which resolved allegations that Amazon enrolled millions of consumers in Prime subscriptions without their consent and knowingly made cancellation difficult. More consumers now qualify for refunds, the maximum payment cap rises from $51 to $200, and all future payments will be distributed automatically starting October 1, 2026, with potential supplemental $149 payments by April 2027. Amazon has already issued more than $845 million in redress payments as of September 2026.
$225.0M
The FTC and the state of Washington filed a joint complaint and proposed stipulated order requiring Amway Corp. and two affiliates—World Wide Group, L.L.C. (WWG) and Leadership Team Development Inc. (LTD)—to pay a $225 million judgment, the largest monetary recovery ever obtained from an MLM in an FTC action, over allegations that they used deceptive earnings claims and unfair tactics to recruit Independent Business Owners. The complaint alleges the companies falsely promised substantial income and recruitment success, pressured IBOs to buy products they could not resell, and instructed IBOs to falsely report sales. Nearly all of the judgment will be used as redress for IBOs who lost money, and the proposed order imposes structural reforms including a 70% resale requirement, independent audits of sales records, and a ban on approved providers charging new IBOs for first-year training.
$100.0M
FleetCor Technologies Inc. (now Corpay Inc.) and its CEO Ronald Clarke agreed to pay $100 million to settle an FTC administrative action alleging the company charged small business customers hidden and unauthorized fees for fuel cards and misrepresented gas savings, fraud-control features, and fees. A federal district court granted the FTC summary judgment on all counts in 2023, and a federal appeals court upheld that judgment and the permanent injunction in 2026. The settlement funds will be used to provide redress to harmed business customers.
FTC staff published FAQs on price transparency to help the automobile industry comply with the FTC Act, reiterating that an advertised vehicle price must be the actual price any consumer can pay, excluding only government-required charges. The guidance follows warning letters the FTC sent to 97 auto dealership groups earlier in 2026 and signals continued litigation against dealers that advertise one price but charge more through undisclosed fees. No specific entity was charged and no penalty was imposed.