The industry is robust, companies just refuse to spend money on security because the risks aren’t all that great to them and insurance policies are paid out regardless.
According to their 2017 annual report [1], Marriot had $22.9bn in worldwide revenue. A 4% penalty on that would be $900M.
[1] https://marriott.gcs-web.com/static-files/057a8e1a-a5c5-4c20...
The question is probably if it is state of the art to encrypt passport numbers. If yes, then Marriot could be fine with a similiar argument of "the company knowingly violated its duty to ensure data security".
the grace period started two years ago until may 2018...
people seem to forget that the GDPR was technically already a law in 2016, it was just not enforced.