Marriott International says a breach may have compromised the personal data of 5.2 million customers, the second significant data breach for the hotel chain in less than two years.

A significant penalty under the EU’s General Data Protection Regulation (GDPR) after the first breach in November 2018 still hangs over Marriott in the United Kingdom. The company said in a press release Tuesday that it has begun sending emails about the latest incident to potentially affected customers.

Aaron Nicodemus is the Editor-in-Chief of Compliance Week. He previously worked as a reporter for Bloomberg Law and as business editor at the Telegram & Gazette in Worcester, Mass. Email: aaron.nicodemus@complianceweek.com LinkedIn:...