Hotel Online Special Report



.
The Personal Data Privacy & Security Act
.
Is Your Hotel Ready?
This article is from the Fall 2006 issue of Hospitality Upgrade magazine.To view more articles covering technology for the hospitality industry please visit the Hospitality Upgrade Web site or to request a free publication please call (678) 802-5307 or e-mail.
.
By Rick Warner, October 2006

Due to the number of high-visibility customer data thefts and losses that have occurred over the past couple of years, Congress has been under increasing pressure to enact protective legislation. 

In response, Senators Arlen Specter (R-Pa.) and Patrick Leahy (D-Vt.) introduced the �Personal Data Privacy and Security Act� in late 2005.  This legislation is intended to assist consumers to better protect the privacy of their personal information in the face of recurrent data security breaches across the country.  It is still in Committee right now (S.1789), but when this legislation is eventually brought before Congress for a vote, it is expected to pass into law.  Once that occurs, it will have a profound impact on the way that customer data will be handled going forward�especially in the hospitality industry.

The legislation states that affected business entities must be able to prove that they are doing the following: 

  • Regularly assess, manage and control risks to data privacy and security consistent with the size, complexity and scope of its business 
  • Publish or otherwise make available the terms of its program to the extent that such terms do not reveal information that comprise data security or privacy
  • Provide employee training to implement its data privacy and security program; 
  • Conduct tests to identify system vulnerabilities 
  • Ensure that if service providers not also subject to these laws are retained, those service providers are capable of maintaining appropriate safeguards for personally identifiable information and are subject to contract requirements consistent with the legislation
  • Periodically assess its data privacy and security program to ensure that the program addresses current threats, and  
  • Implement a data privacy and security program no later than one year after the date of enactment 
When the pending legislation was first announced, Senator Leahy, the Chairman of the Senate Judiciary Committee, said, �Our laws need to keep pace with technology.  Insecure databases have become low-hanging fruit for hackers looking to steal identities and commit fraud during a time when we are seeing a troubling rise in organized rings that target personal data to sell in online, virtual bazaars.�

The Specter-Leahy legislation is largely based on similar laws that have been passed in the State of California, which is generally thought to be the most proactive state when it comes to consumer protection. One of the key features of the legislation is a requirement that any business engaging in interstate commerce that involves collecting, accessing, transmitting, using, storing or disposing of �personally identifiable� information in electronic or digital form on 10,000 or more U.S. persons to apply rigorous data privacy and security safeguards. This is a big change from the past when bona-fide data brokers such as ChoicePoint were the only companies held to such a high standard.

Companies that knowingly or unknowingly violate the data privacy and security program requirements, or those that cannot produce supporting evidence to the contrary, are subject to civil penalties of up to $5,000 per violation per day while such violations persist.  In addition, the U.S. Attorney General can bring civil action in U.S. district court on behalf of the residents of that state.  Recently, the Federal Trade Commission forced ChoicePoint to pay a $10 million fine, the largest civil penalty ever levied, as part of the settlement of an investigation into their security practices.

This legislation will impact virtually all hotel chains and most large independent operators because they conduct interstate commerce, and store personally identifiable information (e.g., credit card numbers) on at least 10,000 customers.  At a minimum, hospitality companies will be held accountable for documenting and maintaining all data security procedures that are in place to protect guest information from identity thieves.

You may think that since your property management system vendor handles all of your customer data, you can�t be held accountable for whether they safeguard it or not.  However, provision No. 5 above clearly states that you are in fact responsible for the actions of your service providers as well.

Beside the legal dimension, there are two other significant exposures.  First, individual consumers can initiate civil lawsuits with large potential penalties if lost or stolen customer data ultimately results in the theft of their identity.  Second, the national media has been quick to seize upon any customer data loss news.  Consequently, you might find yourself on the front page of the Wall Street Journal�and not in a good way.  The bad publicity alone could be very costly.

Hackers are everywhere, and they are constantly looking for new and creative ways to access customer data.  Yours has probably already been attacked multiple times without your knowledge.  To make matters worse, if any security weaknesses are eventually found and exploited, word of this will spread, and you will become an on-going target for other hackers�perhaps even more dangerous than the ones who came before.

The bottom line is this: if it is unclear as to whether the proper controls and procedures currently exist at your company, a complete review of the way your guest data is handled is highly advisable before it is too late.  There are a number of relatively simple things that can be done to not only lessen the likelihood that you will be attacked in the first place, but also demonstrate good-faith efforts to mitigate risk.  This becomes important if an incident does occur, and auditors later ask, �What did you do to prevent this?�

Your first step should be to conduct a compliance assessment, which is effectively a gap analysis intended to ascertain and document where your organization stands today relative to the �Interagency Guidelines Establishing Standards for Safeguarding Customer Information,� the benchmark the federal government is using to measure compliance.  The assessment is not a formal audit where the results are shared with any outside entities. The findings are yours to keep and act upon as you see fit.  Once this has been done, a custom program can be developed intended to address all seven of the key areas of focus set forth in the legislation. Considering what�s at stake, this is relatively inexpensive insurance.
.


Rick Warner is Thoughtmill's vice president of Travel Services. A 20+ year industry veteran of world-class organizations like Disney and Marriott, he has successfully implemented large-scale projects all over the world. He can be reached at [email protected].
.
�©Hospitality Upgrade, 2006. No reproduction or transmission without written permission.�

###

Contact:

Geneva Rinehart 
Managing Editor 
Hospitality Upgrade magazine 
and the Hospitality Upgrade.com website
http://www.hospitalityupgrade.com
[email protected]

.

Also See: Hospitality Loyalty Programs; Strategies for Points-based, Recognition-based Programs / Mark Haley / October 2006
What's New in the Hotel Guestroom? Digital, HD or IP Televisions / Ashok Kumar / June 2006
A Future Vision for Hotel Revenue Management / Caryl Helsel and Kathleen Cullen / June 2006
Marketing to the Next Generation of Buyers; Scoring Your Hotel Reservations System / Debra Kristopson / June 2006
Consortia-Corporate-Group Best Available Rate (BAR): Good or Bad for Hotels? / Caryl Helsel / October 2005
Check In Kiosks: Coming to a Hotel Lobby Near You? / Jerry W. Sheldon / October 2005
Moving into Compliance Mode; Realizing the Benefits, Cutting the Costs / Dorian Cougias / March 2005
What Hoteliers Need to Know About Flat Panel and HDTVs / Jake Buckstead / March 2005
10 Trends Affecting Hospitality IT in 2005 / Bradford Iverson / March 2005
Searching for Bookings? Optimize / Dr. Matthew Dunn / August 2004
Instant Messaging: Age Is Everything - Expectations of Immediacy, Productivy and the Rise of IM / Elizabeth L. Ivey / August 2004
Baby It's Cold Outside the Firewall / Michael Schubach / April 2004
High Wired: The Hotel Room of the Future / Kelly Stanford / April 2004
We're Not In Kansas Anymore; Differentiating your hotel through technology / Mark Haley / January 2004
Understanding the Power of Customer Relationship Management / Neil Holm / Hospitality Upgrade Magazine / November 2003
The Case for Self Service in Hospitality / Marvin Erdly and Amitava Chatterjee / Hospitality Upgrade Magazine / October 2003
Five Questions to Ask Online Distributors / Michelle Peluso / Hospitality Upgrade Magazine / October 2003
Surf's Up - Internet Marketing for Destination Properties / Marvin Erdly and Amitava Chatterjee / Debra Kristopson / Hospitality Upgrade Magazine / October 2003
Wireless Changes Everything; So, do ya want a latte with that or what? / Jocelyn Valley / Hospitality Upgrade Magazine / June 2003
Customer Awareness or Customer Beware? Data Security in a CRM-Obsessed Industry / Elizabeth Ivey / Hospitality Upgrade Magazine / June 2003
Your Magnificent Selling Machine Would you Prefer Your Hotel to Get: the Web Hit or the Phone Call? / Robert Camastro / Hospitality Upgrade Magazine / June 2003
Tradeshows & Economic Soldiers / Dan Phillips / Hospitality Upgrade Magazine / April 2003
Hotel Telecommunications in the 21st Century / Geoff Griswold / Hospitality Upgrade Magazine / March 2003
The ABCs of CRM  / Mark Haley & Bill Watson / Hospitality Upgrade Magazine / March 2003
Getting the Most out of Your IT Investment / By: Clay B. Dickinson / Hospitality Upgrade Magazine / Fall 2002
The Role of Paper in a Digital World / By: Bill Fitzpatrick / Hospitality Upgrade Magazine / Fall 2002
The Rotten Pineapple (international symbol of hospitality) / By: Steve D'Erasmo / Hospitality Upgrade Magazine / Fall  2002
Focusing on Labor Can Improve More Than Just Cost / Hospitality Upgrade Magazine / Summer 2002
Attention Hotels - An Ounce of Prevention is Worth a Pound of Cure / Elizabeth Lauer Ivey / Hospitality Upgrade Magazine / May 2002 
HOSTEC - EURHOTEC 2002 - Room for Improvement / Christel Dietzsch / Hospitality Upgrade Magazine / Feb 2002 
Technology and the Human Touch / Dan Phillips / Hospitality Upgrade Magazine / Spring 2002
Wireless Technology:  Where We Have Been, Where Are we Going? / Geneva Rinehart / Hospitality Upgrade Magazine / Spring 2002
Effective Customer Relationship Management (CRM) Implementations / John Schweisberger and Amitava Chatterjee, CHTP / Hospitality Upgrade Magazine / Fall 2001 
What's Up With Call Accounting Systems (CAS) / Dan Phillips / Hospitality Upgrade Magazine / Fall 2001
Technology Dilemmas: What have IT investments done for you lately? / Elizabeth Lauer / Hospitality Upgrade Magazine / Summer 2001
Full Circle from Centralized to ASP - The Resurrection of Old Themes and a Payment Solution / Gary Eng / Hospitality Upgrade Magazine / Summer 2001 
A High Roller in the Game of System Integration / Elizabeth Lauer / Hospitality Upgrade Magazine / Spring 2001 
CAVEAT EMPTOR! Simple Steps to Selecting an E-procurement Solution / Mark Haley / Hospitality Upgrade Magazine / Spring 2001 
Your Bartender is Jessie James and He Needs to Pay for College / Beverly McCay / Hospitality Upgrade Magazine / Fall 2000 
Choosing a Reservation Representation Company / John Burns / Hospitality Upgrade Magazine / Spring 2001 
Understanding and Maximizing a Hotel�s Electronic Distribution Options / by John Burns / Hospitality Upgrade Magazine / Fall 2000 
The Future of Electronic Payments - From Paper to Plastic and Beyond / J. David Oder /  Hospitality Upgrade Magazine / Summer 2000
Timeshare Technology Steps Up / by Elizabeth Lauer / Hospitality Upgrade Magazine / July 2000 
Biometric Payment: The New Age of Currency / by Geneva Rinehart / Hospitality Upgrade Magazine / Mar 2000 

 


To search Hotel Online data base of News and Trends Go to Hotel.Online Search

Home | Welcome! | Hospitality News | Classifieds | Catalogs & Pricing | Viewpoint Forum | Ideas/Trends
Please contact Hotel.Online with your comments and suggestions.