Cybersecurity and Data Privacy Implications When a Services Partner Fails By: David Wheeler and Josh Altman November 20 , 2025 Background On November 10, 2025, Sonder Holdings Inc. (“Sonder”), a company operating apartment‑style and boutique hotel accommodations, announced termination of its licensing agreement with Marriott International, Inc. due to Sonder’s financial default, followed immediately by Sonder’s decision to wind down operations and initiate Chapter 7 liquidation in the U.S. (with insolvency planning abroad). While much commentary has focused on stranded guests and lodging contracts, the collapse raises significant cybersecurity and data‑privacy risks for hospitality operators, brands, and associated parties. This alert addresses key risk exposures, lessons, and recommended steps. Key Risk Areas
CLIENT ALERT
Sonder’s shutdown raises critical questions around guest data (including personally identifiable information), payment data, loyalty data, and vendor credentials. Sudden loss of access or unmanaged retention/disposal can trigger GDPR, CCPA/CPRA, and state‑law exposure. Sonder’s collapse followed significant delays in systems integration. Hospitality operators, depending on shared digital platforms, must prepare for vendor distress scenarios, including data‑access loss and support abandonment. Guest trust, notification obligations, system failures, inaccessible reservations, and orphaned guest profiles can lead to consumer-protection scrutiny and reputational damage. Reported Marriott/Sonder systems integration challenges highlight the importance of contractual data‑transition, portability, and exit clauses. Liquidation often results in degraded security controls and uncertain data handling. Further, guests or operational data may become part of a bankruptcy estate. Sonder operated internationally, increasing data‑sovereignty and transfer risks in insolvency scenarios. Potential Sale of Data When a partner files Chapter 7 liquidation or Chapter 11 reorganization proceedings, any guest data, loyalty-program data, and other consumer records owned or licensed by the debtor are potentially valuable assets that the debtor may seek to sell to increase recovery for creditors. Section 363(b)(1) of the bankruptcy code allows a debtor, subject to notice, a hearing, and court approval, to sell or lease such assets in a manner that is consistent with the applicable privacy policy in place on the date of the bankruptcy filing. But if the debtor wants to sell or lease such assets in a manner inconsistent with the existing policy, the debtor can seek to do so. The bankruptcy court may, after notice and a hearing, approve such a sale after (a) considering the findings of a consumer privacy ombudsman appointed under section 332 of the bankruptcy code to evaluate the impact of the sale on consumer privacy, among other factors, and (b) ensuring compliance with non-bankruptcy law. Thus, it is important to regularly update license agreements and privacy policies (in accordance with applicable law) to protect applicable data in the event of a bankruptcy filing and regularly monitor and participate in bankruptcy cases if you have concerns about the sale or use of consumer data.
Neal, Gerber & Eisenberg LLP | 225 W. Randolph St. Chicago, IL 60606 | 312.269.8000 | www.nge.com