Because Booking.com is a Dutch company, and the EU has GDPR, the incident cannot legally repeat itself. This was 2016 incident and GDPR become effective 2018.
As the article noted the company operates on a “if we don’t see it and it doesn’t hurt us we don’t care” principle. Even with the GDPR, the company can still chose to not give a fuck. It just becomes a more risky gamble assuming anyone ever finds out.