Marriott International, Inc.
The Marriott International, Inc., Customer Data Security Breach litigation was centralized before Judge John P. Bailey in the District of Maryland in February 2019, consolidating claims arising from a data security breach affecting Marriott's Starwood guest reservation database, disclosed in late 2018 after the underlying unauthorized access reportedly went undetected for an extended period. This remains one of the largest hospitality-sector data-breach MDLs by scale of affected records, and the docket still carries 73 pending actions seven years after centralization.
What drives duration and resolution risk in a large-scale data-breach docket like this one is a fairly consistent structural pattern across the category: early motion practice on Article III standing and the sufficiency of alleged harm, followed by class-certification proceedings, and — where the parties reach a negotiated resolution — a settlement-fund and claims-administration process that can itself take years to fully distribute and close out. A docket carrying pending actions this long after centralization is often working through that later administrative phase rather than a still-open liability fight.
Data-breach MDLs of this scale provide a useful structural template for understanding how large consumer-data litigation typically resolves: an initial phase focused on standing and certification, followed by an extended settlement-administration tail that can keep a docket technically active for years after the core legal questions are resolved. Criterica Intelligence's platform tracks this phase progression — distinguishing an open certification fight from a settlement-administration tail — across every active data-breach MDL, providing a calibrated read on where a given docket sits in that lifecycle. A companion capital brief on this docket is available through Criterica Capital.
Claims from customers affected by the Marriott/Starwood data breach raised common factual questions about the scope of unauthorized access and the adequacy of Marriott's data-security practices, warranting coordinated pretrial proceedings.
Large-scale data-breach MDLs typically move through an early standing-and-certification phase followed by an extended settlement-administration process, and a docket at this age is often working through that later administrative tail.
Not primarily — the core certification and damages-methodology questions common to this category of litigation have been substantially developed, so remaining activity likely reflects claims administration more than open liability uncertainty.
It illustrates the typical phase progression for large consumer-data litigation — standing and certification followed by a multi-year settlement-administration tail — a pattern Criterica Intelligence tracks across the data-breach MDL category.
Statistics shown reflect historical or illustrative model outputs derived from real case data. They are not predictions or guarantees of any individual outcome. Litigation results depend on facts, jurisdiction, judge, and counsel, and vary case by case. Model accuracy is subject to selection effects and changing legal dynamics.