factual

Regarding public statements about a data breach, what must a Bft franchisee do?

Bft Franchise · 2025 FDD

Answer from 2025 FDD Document

If Franchisee becomes aware of a suspected or actual breach of security or unauthorized access involving Personal Information, Franchisee will notify Franchisor immediately and specify the extent to which Personal Information was compromised or disclosed. Franchisee also agrees to fully cooperate, at its own expense, with any investigation Franchisor, or its designees, conducts related to the suspected or actual breach. Franchisee also agrees to follow Franchisor's instructions regarding curative actions and public statements relating to the breach. Franchisee also agrees to comply with applicable law regarding notice of the breach (either to the affected individuals and/or applicable governmental officials). To the extent permitted under Applicable Law, Franchisee will provide Franchisor with a copy of the form of breach notice as soon as practical in advance of providing such notice to the affected data subjects and/or governmental official. Franchisor reserves the right to conduct a data security and privacy audit of any of the Studio and computer system at any time, from time to time, to ensure that Franchisee is complying with Franchisor's requirements. Franchisee must promptly notify Franchisor if it receives any complaint, notice, or communication, whether from a governmental agency, customer or other person, relating to any Personal Information, or Franchisee's compliance with Franchisee's obligations relating to Personal Information under this Agreement, and/or if Franchisee has any reason to believe that it will not be able to satisfy any of its obligations relating to Personal Information under this Agreement.

Source: Item 23 — RECEIPTS (FDD pages 79–265)

What This Means (2025 FDD)

According to Bft's 2025 Franchise Disclosure Document, a franchisee who becomes aware of a data breach involving personal information must take specific actions. The franchisee is required to immediately notify Bft and provide details on the extent to which personal information was compromised or disclosed.

Furthermore, the franchisee must fully cooperate, at their own expense, with any investigation conducted by Bft or its representatives regarding the breach. This cooperation includes following Bft's instructions on curative actions and, crucially, any public statements related to the breach. The franchisee must also comply with all applicable laws regarding breach notification, both to affected individuals and relevant government officials.

To the extent permitted by law, the franchisee is obligated to provide Bft with a copy of the breach notice before it is sent to the affected parties or government officials. This ensures that Bft maintains control over the messaging and response to the data breach, protecting the brand's reputation and ensuring consistent communication. Bft also retains the right to conduct data security and privacy audits of the studio's computer systems to ensure compliance with their requirements.

Disclaimer: This information is extracted from the 2025 Franchise Disclosure Document and is provided for research purposes only. It does not constitute legal or financial advice. Consult with a franchise attorney before making any investment decisions.