The Federal Trade Commission issued a consent order against Marriott in August 2024 following a series of data breaches affecting customer personal information. The order imposed specific, enforceable requirements on data minimization, access controls and retention practices that extend beyond the organization's immediate remediation obligations.

For chief executives, chief privacy officers, general counsel and IT leadership at organizations handling large volumes of customer data, the order signals a clear shift in regulatory expectations: security controls must be governed from the top, documented systematically, and auditable. The question is no longer whether to implement data retention limits or role-based access controls, but who inside the organization is accountable for the strategy, risk decisions and reporting that demonstrate compliance.

Why This Matters to the Business

The FTC enforces Section 5 of the FTC Act, which prohibits unfair and deceptive acts or practices. When an organization makes privacy promises—expressly or by implication—the Act requires it to honor those claims. Even without specific promises, organizations have an obligation to maintain security appropriate to the nature of the data they possess.

The Marriott order represents a practical application of this standard. Repeated breaches demonstrate that technical controls alone are insufficient. The FTC expects leadership accountability: policies that define what data is collected and why, retention schedules that limit exposure, access controls that restrict who can reach sensitive information, and governance that ensures these practices are followed and verified.

The business consequence is direct. Without documented governance, retention schedules and access control frameworks, leadership cannot demonstrate that security practices are adequate. This creates liability during regulatory review, increases breach notification obligations when incidents occur, and complicates insurance claims and contractual indemnification disputes.

What the Order Requires

While the specific terms of the Marriott order are not publicly detailed in the supplied sources, FTC enforcement actions in privacy and data security cases typically address three categories of control: data minimization, access limitation and retention management.

Data minimization requires organizations to collect only the personal information necessary for a specified business purpose and to justify retention beyond that purpose. Access limitation means restricting access to sensitive data based on role, enforcing the principle of least privilege. Retention management involves establishing and enforcing schedules that define how long data is kept and when it must be securely disposed of.

These are not one-time technical implementations. They require policy decisions, risk assessment, cross-functional coordination and ongoing verification. The FTC's approach reflects this: consent orders typically mandate not just the installation of controls, but the documentation of governance, periodic assessment and executive certification.

The Accountability Gap

The central problem for leadership is that regulatory obligations create accountability for a security outcome without a clear internal owner, implementation sequence or measurement framework. IT teams implement controls. Legal counsel interprets regulatory text. Compliance functions track obligations. Privacy officers manage consent and disclosure. But who owns the strategy that connects these efforts? Who makes the risk decisions that balance security, usability and cost? Who reports to the board on whether the program is adequate?

In organizations without dedicated security leadership, these responsibilities fragment. Access control policies may exist in IT documentation but remain disconnected from retention schedules managed by legal or records management. Data inventories maintained for privacy compliance may not inform security architecture. Audit findings accumulate without a clear prioritization framework or remediation roadmap.

The result is that leadership is accountable for demonstrating adequate security governance without the internal structure to produce it. A [virtual CISO](/vciso/) provides the executive ownership that closes this gap: defining the security strategy, making risk decisions within business context, establishing governance that coordinates across functions, and reporting to leadership on the state of controls.

Vendor, MSP and Third-Party Oversight

Data retention and access controls extend beyond the organization's direct infrastructure. Customer data processed by vendors, stored by cloud providers and accessed through third-party applications must be governed with the same rigor as internal systems.

Managed service providers (MSPs) and technology vendors perform essential functions, but they do not own the organization's regulatory obligations. Contracts must specify retention requirements, access limitations and audit rights. Vendor assessments must verify that controls are in place and operating as expected. Incident response protocols must define notification obligations and coordination procedures.

This coordination requires security governance. Someone must define the vendor risk framework, translate regulatory requirements into contract terms, conduct due diligence reviews and monitor ongoing compliance. In the absence of dedicated security leadership, vendor oversight often remains checklist-driven rather than risk-informed, creating gaps that surface only during audits or incidents.

Practical Next Steps for Leadership

If your organization handles customer personal data at scale, three questions clarify the path forward:

  • Can leadership produce a current inventory of what personal data is collected, where it is stored, who has access and how long it is retained?
  • Are retention schedules documented, justified by business purpose and enforced through technical or administrative controls?
  • Is there a single executive accountable for security strategy, risk decisions and reporting to the board on the adequacy of controls?

If the answer to any of these is uncertain, the priority is governance before additional tooling. Begin with a scoped assessment: inventory personal data across systems and vendors, document current retention practices and access controls, and identify gaps between documented policy and operational reality. This produces the foundation for informed risk decisions.

The NIST Cybersecurity Framework provides a structured approach to understanding and improving cybersecurity risk management. The NIST Privacy Framework offers a complementary tool for identifying and managing privacy risk through enterprise risk management. Both frameworks emphasize governance, risk assessment and continuous improvement rather than prescriptive technical controls.

Leadership should clarify internal accountability. If security governance is distributed across IT, legal, compliance and privacy functions without a coordinating executive, decisions will remain reactive and reporting will stay fragmented. A virtual CISO establishes the executive ownership that regulatory expectations assume: someone who translates business objectives into security strategy, makes risk decisions within budget and operational constraints, coordinates across internal functions and vendors, and reports to leadership on the state of controls with specificity.

Heights Consulting Group provides virtual CISO leadership for organizations facing this accountability gap. If your leadership team is responsible for demonstrating adequate data governance without dedicated security executive capacity, a confidential consultation can clarify what adequate ownership looks like in your specific context and how to establish it without expanding headcount.

Sources

  1. Cybersecurity Framework | NIST , www.nist.gov
  2. Privacy and Security | Federal Trade Commission , www.ftc.gov
  3. Privacy Framework | NIST , www.nist.gov

Related service: Vendor, MSP and Third-Party Oversight

Clear accountability for the security work your providers perform: defined expectations, stated evidence requirements, and a review process that holds over the life of the contract.

Read about Vendor, MSP and Third-Party Oversight