XML 24 R13.htm IDEA: XBRL DOCUMENT v3.20.2
Commitments and Contingencies
9 Months Ended
Sep. 30, 2020
Commitments and Contingencies Disclosure [Abstract]  
Commitments and Contingencies COMMITMENTS AND CONTINGENCIES
Guarantees
We present the maximum potential amount of our future guarantee fundings and the carrying amount of our liability for our debt service, operating profit, and other guarantees (excluding contingent purchase obligations) for which we are the primary obligor at September 30, 2020 in the following table:
($ in millions)
Guarantee Type
Maximum Potential Amount of Future FundingsRecorded Liability for Guarantees
Debt service$53 $
Operating profit183 107 
Other18 
$254 $117 

Our maximum potential guarantees listed in the preceding table include $79 million of guarantees that will not be in effect until the underlying properties open and we begin to operate the properties or certain other events occur.
Contingent Purchase Obligation
Sheraton Grand Chicago. We granted the owner a one-time right, exercisable in 2022, to require us to purchase the leasehold interest in the land and the hotel for $300 million in cash (the “put option”). If the owner exercises the put option, we have the option to purchase, at the same time the put transaction closes, the fee simple interest in the underlying land for an additional $200 million in cash. We accounted for the put option as a guarantee, and our recorded liability at September 30, 2020 was $57 million.
Starwood Data Security Incident
Description of Event
On November 30, 2018, we announced a data security incident involving unauthorized access to the Starwood reservations database (the “Data Security Incident”). Working with leading security experts, we determined that there was unauthorized access to the Starwood network since 2014 and that an unauthorized party had copied information from the Starwood reservations database and taken steps towards removing it. The Starwood reservations database is no longer used for business operations.
Expenses and Insurance Recoveries
In the 2020 third quarter, we recorded a $35 million net reversal of expenses and $4 million of accrued insurance recoveries, and in the 2019 third quarter, we recorded $6 million of expenses and $9 million of accrued insurance recoveries, related to the Data Security Incident. In the 2020 first three quarters, we recorded a $17 million net reversal of expenses and $24 million of accrued insurance recoveries, and in the 2019 first three quarters, we recorded $198 million of expenses and $77 million of accrued insurance recoveries, related to the Data Security Incident. We received insurance recoveries of $1 million in the 2020 third quarter, $6 million in the 2019 third quarter, $45 million in the 2020 first three quarters, and $58 million in the 2019 first three quarters. The net reversal of expenses for the 2020 third quarter and year-to-date is primarily due to the reduction of the accrual for the ICO fine further described below. We recognize insurance recoveries when they are probable of receipt and present them in our Income Statements in the same caption as the related expense, up to the amount of total expense incurred in prior and current periods. We present expenses and insurance recoveries related to the Data Security Incident in either the “Reimbursed expenses” or “Restructuring and merger-related charges” captions of our Income Statements.
Litigation, Claims, and Government Investigations
Following our announcement of the Data Security Incident, approximately 100 lawsuits were filed by consumers and others against us in U.S. federal, U.S. state and Canadian courts related to the incident. All but one of the U.S. cases were consolidated and transferred to the U.S. District Court for the District of Maryland, pursuant to orders of the U.S. Judicial Panel on Multidistrict Litigation (the “MDL”). The plaintiffs in the U.S. and Canadian cases, who generally purport to represent various classes of consumers, generally claim to have been harmed by alleged actions and/or omissions by the Company in connection with the Data Security Incident and assert a variety of common law and statutory claims seeking monetary damages, injunctive relief, costs and attorneys’ fees, and other related relief. Among the U.S. cases consolidated in the MDL proceeding is a putative class action lawsuit that was filed against us and certain of our current officers and directors on December 1, 2018, alleging violations of the federal securities laws in connection with statements regarding our cybersecurity systems and controls, and seeking certification of a class of affected persons, unspecified monetary damages, costs and attorneys’ fees, and other related relief. The MDL proceeding also includes two shareholder derivative complaints that were filed on February 26, 2019 and March 15, 2019, respectively, against the Company, certain of its officers and certain current and former members of our Board of Directors, alleging, among other claims, breach of fiduciary duty, corporate waste, unjust enrichment, mismanagement and violations of the federal securities laws, and seeking unspecified monetary damages and restitution, changes to the Company’s corporate governance and internal procedures, costs and attorneys’ fees, and other related relief. A separate shareholder derivative complaint was filed in the Delaware Court of Chancery on December 3, 2019 against the Company and certain of its officers and certain current and former members of our Board of Directors, alleging claims and seeking relief generally similar to the claims made and relief sought in the other two derivative cases. This case will not be consolidated with the MDL proceeding. We dispute the allegations in the lawsuits described above and are vigorously defending against such claims. We have filed motions to dismiss in each of these cases, some of which have been denied, but the cases generally remain at an early stage. There has been some consolidation of the Canadian cases, with five cases now pending across five provinces, and we expect there could be further consolidation in the future. In April 2019, we received a letter purportedly on behalf of a shareholder of the Company (also one of the named plaintiffs in the putative securities class action described above) demanding that our Board of Directors take action against the Company’s current and certain former officers and directors to recover damages for alleged breaches of fiduciary duties and related claims
arising from the Data Security Incident. The Board of Directors has constituted a demand review committee to investigate the claims made in the demand letter, and the committee has retained independent counsel to assist with the investigation. The committee’s investigation is ongoing. In addition, on August 18, 2020, a purported representative action was brought against us in the High Court of Justice for England and Wales on behalf of an alleged claimant class of English and Welsh residents alleging breaches of the General Data Protection Regulation and/or the U.K. Data Protection Act 2018 (the “U.K. DPA”) in connection with the Data Security Incident. We dispute all of the allegations in this purported action and will vigorously defend against any such claims. On November 5, 2020, the court issued an order with the consent of all parties staying this action pending resolution of another case raising similar issues, but not involving the Company, that is pending before the U.K. Supreme Court.
In addition, numerous U.S. federal, U.S. state and foreign governmental authorities made inquiries, opened investigations, or requested information and/or documents related to the Data Security Incident and related matters, including Attorneys General offices from all 50 states and the District of Columbia, the Federal Trade Commission, the Securities and Exchange Commission, certain committees of the U.S. Senate and House of Representatives, the Information Commissioner’s Office in the United Kingdom (the “ICO”) as lead supervisory authority in the European Economic Area, and regulatory authorities in various other jurisdictions. With the exception of the ICO proceeding, these matters generally remain open. In July 2019, the ICO issued a formal notice of intent under the U.K. DPA proposing a fine in the amount of £99 million against the Company in relation to the Data Security Incident. We submitted written responses to the ICO vigorously defending our position and have engaged with the ICO regarding the Data Security Incident and proposed fine. We mutually agreed with the ICO to an extension of the regulatory process until October 30, 2020, and on October 30, 2020 the ICO issued a final decision under the U.K. DPA. The decision includes a fine of £18.4 million. The Company does not intend to appeal the ICO’s decision, but has made no admission of liability in relation to the decision or the underlying allegations. Our accrual for this loss contingency, which we present in the “Accrued expenses and other” caption of our Balance Sheets, was $65 million at December 31, 2019, and $23 million at September 30, 2020.
While we believe it is reasonably possible that we may incur additional losses associated with the above described proceedings and investigations related to the Data Security Incident, it is not possible to estimate the amount of loss or range of loss, if any, in excess of the amounts already incurred that might result from adverse judgments, settlements, fines, penalties, or other resolution of these proceedings and investigations based on the current stage of these proceedings and investigations, the absence of specific allegations as to alleged damages, the uncertainty as to the certification of a class or classes and the size of any certified class, if applicable, and/or the lack of resolution of significant factual and legal issues.