Hotel Online
News for the Hospitality Executive


advertisement
.


Hotel Liability for Guest Information -
What you need to know and how to avoid liability.


 
By Jim Butler and the Global Hospitality Group®
Hotel Lawyers
| Authors of www.HotelLawBlog.com
October 9, 2012

Hotel Lawyer on hotels' liability for failure to protect hotel guests personal identities

My partner Robert Braun advises hotel owners in a wide range of operational issues, including information management. Because of the ubiquitous use of credit cards by hotel guests during a stay, as well as the growing demand for WiFi availability, hotels have been increasingly targeted by identity thieves. In his article below, Bob explains how hotels' liability for this new type of guest security has grown and what hotels can do to protect their guests' identities.

Hotel Liability for Guest Information and Identity
What you need to know
by
Robert E. Braun | Hotel Lawyer

A version of this article was first published in the September 21, 2012 issue of Hotel Business and is reprinted with permission.

Not too long ago, keeping guest information safe was a fairly straightforward process - perhaps the most innovative development was providing an in-room safe for valuables. This approach made sense at the time, when guest security was a matter of securing people and their physical possessions.

The industry now recognizes that hotel guests have valuables to protect that go far beyond watches and wallets, or even laptops and iPads - - perhaps the most valuable information a hotel guest has is his or her identity, and unless a hotel actively safeguards it, those valuables are at risk. The ubiquity of credit card, wireless internet and other options, while essential to hotel operations, is also a source of insecurity.

Hotels are Targets
Hotels are obvious targets for identity and financial theft for many reasons. Hotels transact business through credit cards, and those credit cards are kept on file and can be accessed multiple times during a guest's stay. The possibility that a credit card charge will be recorded occurs with each night's room charge, room service, bar or restaurant bill, spa charge, and so on. Every charge is another opportunity for an identity thief to access the information using sophisticated computer hacks and other malicious software, generally without the hotel's knowledge.

The need to respond to guest demands is another source of insecurity. The Identity Theft Resource Center noted, "The ability to connect to the Internet is an integral part of many individuals daily life. This has led to the increased demand for public WiFi." As a result, hotels find themselves compelled to offer wireless internet, and that service is almost always unsecured. But an unsecured wireless network is "just as dangerous as leaving files of your most important personal documents on a street curb for all to see. Hackers can easily get into an unsecured wireless network and get financial information, business records or sensitive e-mails." (PC World, "Got Wireless Security", http://www.pcworld.com/article/125040/got_wireless_security.html). At the same time, hotels have little say in the matter. Guests demand wireless internet service.

Finally, hotels have employees -- lots of employees -- and many of them have access to the credit card and other personal information of guests. No matter how well trained and supervised, more personnel correlates to greater risk. The fact that low-level employees typically have access to key guest information, and that there is, historically, a high turnover in hotel employees, exacerbates the problem.

Some security researchers have described a wave of attacks against the hospitality industry. In 2010, the cybersecurity consultant Trustwave found that in 38% of its investigations, hotels and resorts were the victims of successful cyber intrusions, despite those firms only representing 3% of its customers. Hotels represent a disproportionate number of security breaches.

The Wyndham Case
In June 2012, the Federal Trade Commission filed a lawsuit against Wyndham hotels, claiming Wyndham misrepresented its security measures to prevent intrusions by computer hackers. In its press release, the FTC claimed Wyndham had subjected consumers' data to an "unfair and deceptive" lack of protection that led to a series of breaches of Wyndham hotels and those of three subsidiaries. The lawsuit describes three attacks on the hotel chain and its franchisees beginning in 2008 that first compromised 500,000 credit card numbers stored by the firm, followed by attacks that breached another 50,000 and 69,000 accounts at other locations.

Key to the FTC complaint is its claim Wyndham failed to take common and well-known security measures. The FTC noted that Wyndham failed to require complex passwords, implemented a network setup that did not separate corporate and hotel systems, and used "improper software configurations" that led to sensitive payment card information being stored without encryption. The FTC complaint compared those failures to Wyndham's privacy policy, which said that Wyndham strove to "recognize the importance of protecting the privacy of individual-specific (personally identifiable) information collected about guests, callers to our central reservation centers, visitors to our Web sites, and members participating in our Loyalty Programs," and promised the use of strong encryption and firewalls.

While Wyndham plans to fight the FTC's suit, a highly-publicized claim like this puts a hotel firm at a competitive disadvantage. If a hotel chain were known to have faulty locks or in-room safes, guests would think twice before making a reservation. A hotel chain that cannot safeguard the financial and personal information of guests is just as vulnerable.

Beyond Guest Information
While the security of guest information is a key concern, and its breach garners adverse and unwanted publicity, hotel owners and operators should be aware that there is other, valuable information that needs protection. The hospitality industry is a highly competitive environment, and hotel owners and operators need to take steps to protect their own business information and trade secrets. This information can include pricing strategies and revenue management policies; marketing plans; menus and other food and beverage operations; and perhaps most sensitive of all, employee information. The inadvertent disclosure of this information can cause irreparable harm to a hotel or operator, and steps need to be taken to safeguard competitive and confidential matters.

Another area of potential liability, often overlooked by hotel operators, is the impact of social media. Postings on Facebook, Twitter, Tripadvisor and other social media sites are often treated as less serious than "formal" communications. However, hotels can be held responsible for postings, both those that a firm makes intentionally - for example, in response to a customer review - and those made without clear authorization, like postings by a hotel employee.

What do I do now?
Securing guest and corporate information is a key task, and the steps necessary to implement a secure environment are unique to each organization. However, there are some general considerations that all firms should be aware of that are essential to securing information:
  • Hotels operators should inventory potentially sensitive information and document on which computers, servers and laptops it's stored.
  • Operators and owners should keep sensitive information on the fewest number of computers or servers, and be sure to segregate it -- the fewer copies of data you have, the easier it is to protect.
  • Utilize encryption for storing, and secure connections for receiving or transmitting, credit card information and other sensitive data.
  • One of the key claims in the FTC's case against Wyndham was that Wyndham claimed to have effective privacy measures; in response, firms should design, institute and follow an effective privacy policy, including policies for using social media, and should be careful not to overstate the effectiveness of their measures. Remember - no system is completely safe.
  • When implementing a wireless system, use a good firewall and a secure wireless connection.
  • For internal communications and information, protect sensitive data with strong passwords and change passwords on a regular basis.
  • Since much, if not most, of computer systems and services are handled by vendors, check their security practices.
  • Most of all, hotel companies need to make a commitment to secure the sensitive information of their companies and their guests, and to seek out informed consultants and advisors. Information security is a relatively new and rapidly changing area, and requires specialized knowledge; the investment today can protect a hotel from being front page news - for the wrong reasons - later.
Robert E. Braun is a senior member of the Global Hospitality Group® at JMBM. Mr. Braun advises hospitality clients with respect to management agreements, franchise agreements and spa agreements. He also advises on business formation, financing, mergers and acquisitions, venture capital financing and joint ventures, telecommunications, software, Internet, e-commerce, data processing and outsourcing agreements for the hospitality industry. Contact him at (310) 785-5331 or rbraun@jmbm.com.

This is Jim Butler, author of www.HotelLawBlog.com and hotel lawyer, signing off. We've done more than $60 billion of hotel transactions and have developed innovative solutions to unlock value from hotels. Who's your hotel lawyer?
__________________________

Our Perspective
. We represent hotel lenders, owners and investors. We have helped our clients find business and legal solutions for more than $60 billion of hotel transactions, involving more than 1,300 properties all over the world. For more information, please contact Jim Butler at jbutler@jmbm.com or +1 (310) 201-3526.
 
Jim Butler is a founding partner of JMBM, and Chairman of its Global Hospitality Group® and Chinese Investment Group™. Jim is one of the top hospitality attorneys in the world. GOOGLE "hotel lawyer" and you will see why.

Jim and his team are more than "just" great hotel lawyers. They are also hospitality consultants and business advisors. They are deal makers. They can help find the right operator or capital provider. They know who to call and how to reach them.

 

Contact:

Jim Butler
jbutler@jmbm.com
310.201.3526


.
Receive Your Hospitality Industry Headlines via Email for Free! Subscribe Here

To Learn More About Your News Being Published on Hotel-Online Inquire Here
.
Also See: JMBM's Global Hospitality Group® releases 2nd Edition of The HMA Handbook, Hotel Management Agreements for hotel owners, developers, investors and lenders / Jim Butler / September 2012

Finally, Some GOOD NEWS from Washington, DC / Jim Butler, Catherine Holmes and Victor T. Shum / September 2012

EB-5 Financing for Hotels is Now Mainstream Institutional / Jim Butler / September 2012

JMBM's Chinese Investment Group Happenings and Events / Jim Butler / August 2012

Dodd-Frank Act Presents Hotels with Decisions on Credit and Debit Card Charges / Jim Butler & Robert Braun / August 2012

Hotel Restructuring, Workouts, Receiverships and Bankruptcy. The Art of Heavy Lifting. / Jim Butler / August 2012

How to Buy a Hotel Handbook: Franchise issues in hotel purchase and sale transactions / Jim Butler / August 2012

Hotel Lawyer: Experts Share Top 5 Tips on Picking the Right Hotel Operator and Brand for Your Hotel / Jim Butler & Robert Braun / July 2012

Losing the Expectation of Privacy bit by bit, byte by byte / Jim Butler and Mark Adams / July 2012

How to Buy a Hotel Handbook: Labor and Employment Tips; Buying a hotel - the Hotel Purchase Agreement documentation and process / Jim Butler, Catherine DeBono Holmes and Marta M. Fernandez / July 2012

How to Terminate a Hotel Management Agreement: A Tale of Two Hotels - Marriott's Edition Waikiki and Fairmont's Turnberry Isle Resort; Two owners terminate long-term hotel management agreements, seize control of their hotels from branded operators, and then settle their litigation / July 2012

EB-5 Lawyer Alert #3: Update on California TEA designation procedure. What's the problem in California! / Jim Butler, Catherine DeBono Holmes and Victor T. Shum / June 2012

How to Finance Hotel Development in 2012....Alternate financing for new hotel construction in a brave new world / Jim Butler / June 2012

'Cyber Accessibility' is the New Frontier for ADA Lawsuits. Your Next DOJ Investigation or ADA Class Action Could be Just a Mouse Click Away! / Jim Butler / June 2012

ADA Compliance and Defense Lawyer: ADA Experts Discuss Hottest Issues Facing the Hotel Industry Today / Jim Butler / May 2012

HotelLawyer.com Launches; Portal to Knowledge for the Hospitality Industry; JMBM's Global Hospitality Group® of Hotel Lawyers Provide Comprehensive Hospitality Resource / May 2012

Update on California's EB-5 Policy Regarding Designation of Targeted Employment Areas or TEAs / Jim Butler / May 2012

Successful Joint Ventures for Hotel Development, Acquisition and Financing / Jim Butler / May 2012

Hotel Lawyer: Clarification on the DOJ's Amendment to the Pool Lift Extension / Jim Butler / May 2012

Hotel Lawyer from Meet the Money® - Lodging Industry Investment Council (LIIC) Announces its Top 10 Challenges for Hotel Industry in 2012 / Jim Butler / May 2012

Meet the Money® Conference Talks about Hotel Loans and Equity Investment, Creating Value with Hotel Value-add and Repositioning, Hotel Opportunistic Investment, Deal Making and Much More / Jim Butler / May 2012

ADA Compliance and Defense Lawyer Alert: Charles Schwab settles claim over website accessibility / Jim Butler / May 2012

EB-5 ALERT: California's New TEA Approach will Discourage EB-5 Investment in California / Jim Butler / May 2012

JMBM is One of 20 Hottest Law Firms in the U.S. Per the National Law Journal's Latest List / April 2012

Hotel Labor Lawyer: California Supreme Court Finally Gives Employers Some Good News in Brinker Restaurant Corporation v. Superior Court / Jim Butler & Travis Gemoets / April 2012

How to Negotiate a Hotel Management Agreement. 10 Tips for a Smoother Process / Jim Butler / March 2012

ADA Defense Lawyer: What does the ADA pool lift compliance extension mean to you? / Jim Butler / March 2012

DOJ Turnabout: Pool lift compliance deadline extended to May 15 / Jim Butler / March 2012

5 Things to Remember when Buying Hotel Notes / Jim Butler / March 2012

ADA Defense and Compliance Lawyer: More clarification or confusion on March 15 ADA standards? / Jim Butler / March 2012

ADA ALERT - A Call to Action Before the March 15, 2012 ADA Deadline / Jim Butler / February 2012

GlobeSt.com Interviews JMBM's ADA Defense and Compliance Lawyers: Hotels Handle Pool Lift Regulations / Jim Butler / February 2012

FBI Tips for Hotels; How to spot terrorists and what to do. / Jim Butler / February 2012

ADA Defense and Compliance Lawyer Advisory: DOJ Clarifies March 15, 2012 Mandatory Pool Lift Requirement! (Uh-oh!) / Jim Butler & Martin Orlick / February 2012

Quick! Can You Pass This 3-Question ADA Pop Quiz? / Jim Butler / January 2012

Hotel Lawyer in Los Angeles: ALIS - What's the commotion all about? Closing the conference hotel to outsiders. / Jim Butler / January 2012

Hotel Management Contract Disputes: Importance of 'Fiduciary' Duties in Owner-Operator Lawsuits / Jim Butler / January 2012

Litigation and Disputes Between Hotel Owners and Operators are on the Rise? Why? / Jim Butler / January 2012

ADA Defense Lawyer: New ADA Regulations Kick in Soon. Say goodbye to 'grandfathering' under the ADA / Jim Butler / November 2011

Hotel Lawyer in Washington D.C. - Why the Lodging Industry Will Continue to Do Well Despite Bumpy Markets and More / Jim Butler / November 2011

Chinese Investment in U.S. Hotels: What the Real Estate Professionals Want to Know / Jim Butler / October 2011

Hotel Lawyer in Dallas Listening to the Special Servicers / Jim Butler / October 2011

Hotel Lawyer with Optimism for the Hotel Industry from the Dallas Lenders Conference, Fishing for Solutions 2011 / Jim Butler / October 2011

Updating Service Animal Policies of Your Hotel or Other 'Place of Lodging' / Jim Butler, Martin Orlick and David Sudeck / October 2011

Hotel Industry Alert: Some things to feel (very) good about! / Jim Butler / September 2011

Hotel Lawyers in Phoenix: It's not just me. The market has changed in just the last 60 days! / Jim Butler / September 2011

Hotel Labor and Employment Lawyer Update: Controversial Union Rights Notice Subject to Legal Challenge - Employers Should Not Rush To Post It / Jim Butler & Scott Brink / September 2011

Hotel Franchise Lawyer: Hotel Franchise Agreements and the 5 Biggest Mistakes a Hotel Owner Can Make / Jim Butler & Robert Braun / September 2011

Hotel Labor and Employment Lawyer Alert: The NLRB is making it harder to stay union free / Jim Butler & Scott Brink / September 2011

Tips from Hotel Franchise and Management Lawyers: Beware the Trap of Changing Brand Standards / Jim Butler & Robert Braun / September 2011

Labor and Employment Alert: New Law Requires Employers to Post Employee Rights Notice by November 14, 2011; NLRB Publishes Final Rule for Notification of Employee Rights / Scott Brink , JMBM / September 2011

Hotel Lending Lawyer: What every hotel lender needs to know about hotel due diligence / Jim Butler & Guy Maisnik / September 2011

Hotel Lending Lawyer: What every hotel lender needs to know about Cash Controls / Jim Butler & Guy Maisnik / August 2011

Hotel Lawyers on Terminating Hotel Operators: M Edition Lawsuit Against Marriott Has a New Twist Marriott is Replaced Overnight / Jim Butler / August 2011

Hotel Lawyers on Terminating Hotel Operators: Turnberry Resort Drops Fairmont Flag / Jim Butler / August 2011

Hotel Lending Lawyer: What every hotel lender needs to know about SNDA's / Jim Butler & Guy Maisnik / August 2011

Hotel Lending Lawyer: What every hotel lender needs to know about HMAs and hotel franchise agreements / Jim Butler & Guy Maisnik / August 2011

Hotel Lawyer on the Importance of Brands - Intellectual Property Rights and What They Mean: Family Suites Resorts v. Viacom International d/b/a MTV Networks - a Suit Over Branding / Jim Butler / August 2011

Hotel Lawyer on the Fiduciary, Contractual and Agency Duties of Hotel Brokers - Host Hotels & Resorts LP v. Molinaro Koger Litigation / Jim Butler / August 2011

M Waikiki's Edition Lawsuit Against Marriott International and Ian Schrager - an Owner's HMA Dispute with Marriott and What it All Means / Jim Butler / August 2011

Hotel Investment: Why Asian investors are targeting U.S. hotels for purchase and investment, and what could it mean for you? / Jim Butler / August 2011

Hotel Developers: Why a "regional center" may be the key to financing your next hotel development or expansion. And what you need to know... / Jim Butler / July 2011

How to use the EB-5 Immigrant Investor Visa Program for financing / Jim Butler / July 2011

JMBM Announces Formation of the Chinese Investment Group™ - Hotels, Real Estate, EB-5 Immigrant Investor Visas / July 2011

Hotel Lawyer: How do you know when you should set up a captive insurance company for your hotel? Take our "litmus test". / Jim Butler & Gordon Schaller / July 2011

Hotel Lawyer: What you need to know about the "ancillary benefits" of setting up a captive insurance company / Jim Butler & Gordon Schaller / June 2011

Hotel Lawyer: Are you thinking about setting up a captive insurance company? Maybe you should be. . . / Jim Butler & Gordon Schaller / June 2011

Hotel Lawyer in New York with pre-NYU industry forecast: Sunny with occasional clouds and NO storms on the horizon / Jim Butler / June 2011

Hotel Lawyer with the Executive Roundtable Results; Debt is returning, equity is out looking, and we've passed the bottom of the trough. Why now is the time to purchase a hotel. / Jim Butler / June 2011

ADA Defense Lawyer: How to Quickly Lose Business. (No ADA-Compliant Reservation System) / Jim Butler & David Sudeck / May 2011

Hotel Lawyer with Fresh Perspectives on the Hotel Industry from Smith Travel / Jim Butler / May 2011

Hospitality Lawyers with PKF and Mark Woodworth's Lodging Overview / Jim Butler / May 2011

Hotel Lawyers' Updates on Capital and Debt Markets for Hotels, Transaction Sales Data and Financings / Jim Butler / May 2011

Hotel Lawyer with Updates on Hotel Cap Rates, Values and Transactions / Jim Butler / May 2011

Hotel Lawyer with nuggets from JMBM's Meet the Money® 2011 / Jim Butler / May 2011

Hotel Lawyer: The hotel transaction market is heating up! / Jim Butler / April 2011

Hotel Lawyer with good news! A new federal court decision upholds condo hotel structure. No "securities" involved as structured. Disgruntled condo hotel unit purchaser lawsuit dismissed. / Jim Butler / April 2011

Meet the Money®: Hotel Financing Renaissance is Underway! / Jim Butler / April 2011

JMBM’s Global Hospitality Group® announces publication of The HMA Handbook, a FREE practical guide for negotiating Hotel Management Agreements for Hotel Owners, Developers, Investors and Lenders / March 2011

Buying a Hotel? Don't Buy an ADA Lawsuit or DOJ Investigation / Jim Butler / March 2011

Hotel Lawyer on Hotel Management Agreements: Exculpation Clauses for Protecting the Owner's Assets / Jim Butler / February 2011

ADA Defense Lawyer: How to handle an ADA lawsuit....and How not to do it / Jim Butler / February 2011

Hotel Lawyer: 5 Key Elements for Good Hotel Management Agreement Budget Provisions / Jim Butler / February 2011

How improving fundamentals make 2011 the year of "Great Expectations" for the Hotel Industry / Jim Butler / February 2011

Ask the Hotel Lawyer: 2011 is starting as the year of "Great Expectations" for the hotel industry! / Jim Butler / January 2011

Hotel ADA Defense Lawyer: How a recent ADA case affects all hotels but particularly conference centers and meeting hotels / Jim Butler / January 2011

Hotel Lawyer: So, You Think You Want to Buy a Hotel? For savvy investors, the time could be right / Jim Butler / January 2011

Sheraton Universal Hotel Sale Facilitated by JMBM's Global Hospitality Group® / Jim Butler / January 2011

.


To search Hotel Online data base of News and Trends Go to Hotel.OnlineSearch

Home | Welcome | Hospitality News
| Industry Resources

Please contact Hotel.Online with your comments and suggestions.