Securing your Brand’s Digital Presence
By Jason Brisebois – Senior Franchise Associate, Sotos LLP
The emergence of COVID-19 has fundamentally changed the way franchisors and their franchisees do business. It would have been unimaginable a year and a half ago that patrons would soon be required to provide a name and phone number to dine at a restaurant, or that patio dining in mid-November would be desirable. While many had spent the last number of years bidding farewell to drive-thrus, meanwhile, the concept is now back with a vengeance.
Although we yearn to get back to a sense of normalcy, there can be no denying that COVID-19 has significantly accelerated a variety of trends that were already transforming the franchising industry. Perhaps chief among these trends is the urgency to take brands online.
As concepts fight to remain relevant in the minds of customers with whom they have limited direct interaction with at present, businesses are increasingly turning to digital initiatives to build and sustain customer interest. A heightened emphasis on simplifying e-commerce, creating new customer rewards programs, and unveiling interactive and gamified smartphone apps, are just a few of the ways that brands are effectively building a report with current and future customers in these trying times.
In their continued transition towards the digital sphere, businesses are collecting more data about their customers than ever before, allowing them to more effectively connect with, and market to, potential consumers. But this newfound treasure trove of customer data, and the potential opportunities it can generate, brings with it its own significant hurdles and obligations. Failure to properly collect, use, and safeguard this data can lead to severe adverse financial, legal, and reputational consequences for franchisors and franchisees alike.
What are my System’s Obligations?
The media has been abuzz in previous years regarding companies misusing, or failing to properly protect, the personal information of their customers. Perhaps the highest profile example in recent memory was the 2017 Equifax data beach, in which hackers capitalized on lax cybersecurity procedures to steal the personal information of hundreds of millions of customers. In addition to countless investigations, fines, and lawsuits faced by Equifax for failing to take proper precautions against this occurrence, even more severe has been the damage to the company’s reputation, and ultimately, its bottom line.
Although many franchisors will assume that the Equifax example is something that could never happen to them, franchisors (and their franchisees) are prime candidates for a cyberattack or accidental data leak. Franchise systems are, by their nature, a dispersed network of loosely related businesses. As franchisors and their franchisees are growing increasingly interconnected, including through system-wide intranet and point-of-sale systems, there are a growing number of access points through which malicious actors may purposefully enter, or through which company data may accidentally be disclosed to the public.
Businesses’ obligations with respect to collecting, using, and safeguarding customer data is multifaceted and complex. One of the primary sources of such obligations is Canada’s Personal Information Protection and Electronic Documents Act (“PIPEDA”), or in certain provinces, the applicable provincial privacy act. One of the core elements of PIPEDA is the requirement that customers meaningfully understand, and ultimately consent to, which of their personal information is being collected, who this information will be shared with, and how this information will be used. PIPEDA also requires that all data under an organization’s control be adequately protected from malicious actors and accidental disclosures.
Moreover, in November 2020, the federal government announced that it would substantially transfer the national privacy and data security landscape in Canada, including making substantial changes to PIPEDA. While the changes proposed by the Digital Charter Implementation Act (“DCIA”) are numerous, it proposes expanding the financial penalties non-compliant companies can face for misusing or failing to protect customer data, and expanding the rights afforded to customers and potential customers of businesses. While commentators await further details regarding the changes DCIA will usher in, there’s no doubt it will heighten the obligations on franchisors and strengthen punishments for non-compliance.
Best Practices to Protect Your System
While businesses’ privacy law requirements, including under PIPEDA and beyond, cannot be explained in a single article, there are a wide variety of steps franchisors can take immediately to begin securing their data, including:
Update Franchise Agreement Terms: Many legacy franchise agreements do not specifically address the topics of data security and privacy. Franchisors should ensure that its franchisees are required to comply with all relevant data security and privacy laws (including PIPEDA and the DCIA, when implemented), the terms of the franchisor’s privacy policy (as discussed below), and implement adequate measures to safeguard and properly use customer data. Franchisors should ensure they’re reserving themselves the flexibility to adapt to new threats, but also to ensure they can capitalize on new channels of commerce. As an example, how does the franchise agreement in question address the topic of e-commerce and internet sales, or does it permit the rollout of a system-wide digital rewards and loyalty program?
Ensure both Franchisor and its Franchisees each have a Privacy Policy: Privacy law requires businesses to build a privacy policy that explains to customers how their information will be collected, used, stored, shared, and ultimately disposed of. Franchisors should critically assess its data collection and security processes and design a privacy policy that allows users to understand and meaningfully consent to the business’ policies and procedures with respect to their personal information. Franchisors should also be sure to require its franchisees to each adopt a privacy policy that reflects the specifics of the franchisee’s operations. Franchisees and franchisors rely on the data each other party collects to optimize their respective business activities; as such, its crucial all parties are working jointly to inform customers and protect personal information.
Monitor Franchisee Compliance with the System’s Information Technology Requirements: Much like consistency lies at the heart of every franchise system’s “secret sauce”, franchisors should mandate a consistent approach to data privacy and security amongst all of its franchisee. The system’s operations manual should clearly set out all technology, safeguards, and software that a franchisee should implement to protect the system. Such safeguards can include causing data to be secured virtually (including through the use of anti-virus software) and also physically (including through the guarding of who may physically access the franchise system’s computer hardware and networks). For any such requirements to be effective, franchisors will need to devote themselves to continually monitoring franchisees to confirm ongoing compliance with system requirements.
Ensure Franchisees (and their Employees) Understand the Issues: While franchisor policies are essential, the system’s franchisees must also understand the risks they are attempting to guard against. Franchisors should ensure that they are building a cybersecurity element into their initial and ongoing training programs for franchisees, and enabling franchisees to spot potential issues in order to act as a first line of defense. While franchisors should proceed cautiously with providing any such training directly to franchisee employees (due to the risk of being deemed a joint-employer of such employees), franchisors should require that franchisees regularly train their relevant employees on such matters.
Plan Ahead: Security incidents and accidental data leaks can happen without warning. Franchisors should take the time to put in place a Written Information Security Program (WISP) to memorialize the specific security measures the system will follow to guard against accidental and malicious data breaches. Considering the speed at which any business must respond to a potential data breach or accidental disclosure, franchisors should also ensure they have a crisis management plan in place, addressing how the franchisor business will react in the event the unthinkable happens, and address how to mitigate any further harm.
Data privacy and security has never been more important, especially for customer-facing businesses like franchise systems. More so than ever, franchisors will need to harness customer information, and build virtual brands, to remain competitive. With great opportunity, however, comes significant risks. Franchisors would be best served to invest time at the beginning of such digitization to ensure they’re ready to quickly and effectively respond to challenges that the digital economy will bring. With the DCIA expected to come into force in the coming year, there has never been a better time for franchisors to revisit their data security and privacy infrastructure and procedures.
Jason Brisebois is a senior franchise associate with Sotos LLP in Toronto, Canada’s largest franchise law firm. He is head of the firm’s personal services franchise practice area, and practices business law with a focus on franchising, distribution, and licensing. He is admitted to practice law in both the Province of Ontario and State of New York. Jason has been recognized as a “Legal Eagle” by Franchise Times Magazine as a leading Canadian franchise law practitioner. Jason can be reached directly at 416-572-7323 or jbrisebois@sotosllp.com.
