Delaware Court of Chancery Dismisses Caremark Claim Arising From Marriott Cybersecurity Breach

Morris James LLP
Contact

Previously published on Business Law Today

Fire Ret. Sys. of St. Louis v. Sorenson, et al., 2021 WL 4593777 (Del. Ch. Oct. 5, 2021).

The Delaware Court of Chancery dismissed pursuant to Rule 23.1 derivative claims arising from the hack of roughly 500 million users’ personal data following Marriott’s 2016 acquisition of Starwood Hotels and Resorts – one of the largest hacks ever, an event that spawned lawsuits and governmental investigations. Among other things, the stockholder-plaintiff failed to allege with particularity facts showing that a majority of the board of directors consciously disregarded “red flags” showing alleged non-compliance data privacy norms. While “[w]ith hindsight knowledge of the extent of the data breach,” the board’s remediation plan was implemented “probably too slow.” Id. at *16. But, the court reasoned, “the difference between a flawed effort and a deliberate failure to act is one of extent and intent. A Caremark violation requires the plaintiff to demonstrate the latter.” Id. at *19. Accordingly, the court dismissed the plaintiff’s complaint.

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© Morris James LLP | Attorney Advertising

Written by:

Morris James LLP
Contact
more
less

Morris James LLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide