Data last synced:
Last updated:
Expedia Group, Inc., on behalf of itself and its subsidiaries worldwide, settled potential civil liability for apparent violations of the Cuban Assets Control Regulations, agreeing to pay $325,406. The apparent violations arose from assisting 2,221 persons with Cuba-related travel services prior to agency notice.
Penalty Amount
$325,406.00
Enforcement Date
June 13, 2019
Rank in Top Penalties
#167
Between on or about April 22, 2011 and on or about October 16, 2014, Expedia dealt in property or interests in property of Cuba or Cuban nationals by assisting 2,221 persons β some of whom were Cuban nationals β with travel or travel-related services for travel within Cuba or between Cuba and locations outside the United States, in apparent violation of the Cuban Assets Control Regulations, 31 C.F.R. part 515 (CACR).
The apparent violations occurred because certain Expedia foreign subsidiaries lacked an understanding of and familiarity with U.S. economic sanctions laws and Expedia employees overlooked particular aspects of Expedia's business that presented risks of noncompliance with sanctions. Electronically booked travel resulted from failures or gaps in Expedia's technical implementations and other measures to avoid such apparent violations. With respect to at least one foreign subsidiary, Expedia failed to inform the subsidiary until approximately 15 months after Expedia acquired the subsidiary that it was subject to U.S. jurisdiction and law. Expedia was slow to integrate the subsidiary into the Expedia corporate family, including with respect to compliance with U.S. sanctions, and the subsidiary continued operating independently during the integration period.
OFAC determined that Expedia voluntarily self-disclosed the apparent violations and that the apparent violations occurred prior to agency notice. Under the Cuba Penalty Schedule, 68 Fed. Reg. 4429 (Jan. 29, 2003), the base penalty for the apparent violations is $556,250. The settlement amount of $325,406 reflects OFAC's consideration of the aggravating and mitigating factors described below, pursuant to the General Factors under OFAC's Economic Sanctions Enforcement Guidelines, 31 C.F.R. part 501, app. A.
Consistent with the settlement agreement, Expedia committed to enhancing its compliance procedures by ensuring that Expedia: (1) has a management team in place that is committed to compliance; (2) conducts regular risk assessments to ensure that Expedia's internal controls appropriately mitigate its sanctions-related risks; (3) conducts regular testing and audits; and (4) provides ongoing sanctions compliance training throughout the Expedia corporate family. Expedia also steadily increased its resources dedicated to compliance with U.S. sanctions, resulting in substantially more robust staffing and resources corporate-wide, and took measures to increase compliance with U.S. sanctions, including enhanced screening methods and implementation of automated software restrictions.
This case illustrates the benefits persons subject to the jurisdiction of the United States β including, with respect to OFAC's Cuba sanctions, entities owned or controlled by U.S. persons β can realize by implementing corporate-wide compliance measures commensurate with their sanctions risks. U.S. companies can mitigate risk by conducting sanctions-related due diligence both prior and subsequent to mergers and acquisitions, and taking appropriate steps to audit, monitor, train, and verify newly acquired subsidiaries for OFAC compliance. U.S. foreign subsidiaries are subject to the CACR, and U.S. person parent companies may face potential exposure to civil monetary penalties vis-Γ -vis the actions of their foreign subsidiaries. Foreign acquisitions can pose unique sanctions risks, to which a U.S. person parent company should be alert at all stages of its relationship with the subsidiary.
This page summarizes an OFAC enforcement case based on the document archived below. SanctionsLookup assumes no liability for errors, omissions, or inaccuracies in the original documents, this summary, or any changes made to the source documents at any time.
Provided for informational purposes only and does not constitute legal or compliance advice. Always consult the source document directly rather than relying on this summary.
Archived on June 13, 2026
SHA-256: 44ff73cfcf1cc6667c30681f5e0bcdb4dc6d47e6e53b39d57cf7492de0a8fa33