What is the Camp Margaritaville franchisee's obligation regarding the destruction of information related to a security incident?
Camp_Margaritaville Franchise · 2025 FDDAnswer from 2025 FDD Document
- (iv) All information relating to the Security Incident must be retained by Franchisee until Franchisor has consented in writing to its destruction.
If requested by Franchisor and subject to Franchisor's confidentiality obligations, Franchisee shall permit Franchisor and its agents to access Franchisee's facilities and/or the affected hardware or software, as applicable, to conduct a forensic analysis of such Security Incident.
Source: Item 23 — RECEIPTS (FDD pages 72–406)
What This Means (2025 FDD)
According to Camp Margaritaville's 2025 Franchise Disclosure Document, a franchisee must retain all information relating to a security incident until the franchisor has provided written consent for its destruction. A 'Security Incident' is defined as any suspected or actual unauthorized access, acquisition, disclosure, or use of Guest Profile Data or Confidential Information. This includes incidents that compromise the security, confidentiality, availability, or integrity of such data, whether accidental or intentional. It also encompasses unlawful or unauthorized intrusions into the franchisee's information systems or networks that could compromise Guest Profile Data or Confidential Information, result in unauthorized access, or threaten the availability of the franchisee's systems.
This requirement ensures that Camp Margaritaville maintains control over the handling of sensitive data breach information, allowing them to conduct thorough investigations and implement necessary corrective measures. The franchisor's right to access the franchisee's facilities and systems for forensic analysis further underscores the importance of preserving all related information. The franchisee is obligated to permit Camp Margaritaville and its agents to access facilities and affected hardware or software to conduct a forensic analysis of a security incident, if requested.
For a prospective Camp Margaritaville franchisee, this means that in the event of a security incident, they must prioritize the preservation of all related data and documentation. Premature destruction of information could hinder investigations, potentially leading to legal or financial repercussions. Franchisees should establish clear protocols for data retention in the event of a security incident and ensure that their systems are capable of preserving the necessary information. Franchisees must also obtain cyber security insurance in the amounts required by Camp Margaritaville and provide a Certificate of Insurance naming Camp Margaritaville as an additional insured.
This requirement is more stringent than simply following standard data retention policies, as it mandates explicit written consent from Camp Margaritaville before any destruction of security incident-related information. This provision highlights the critical importance Camp Margaritaville places on data security and its potential impact on the brand's reputation and customer trust. Franchisees should factor in the potential costs and operational challenges associated with this requirement when evaluating the franchise opportunity.