The U.K.’s data regulator on Friday fined hotel group Marriott International £18.4 million (U.S. $23.8 million) under the EU’s data protection rules for failing to keep millions of customers’ personal data secure. The fine is less than 20 percent of the original number the regulator proposed, the second time this month the Information Commissioner’s Office (ICO) drastically reduced a penalty for a violation of the General Data Protection Regulation (GDPR).

Neil Hodge is a freelance business journalist and photographer based in Nottingham, United Kingdom. He writes on insurance and risk management, corporate governance, internal audit, compliance, and legal...