factual

What security standards must a Carls franchisee comply with at all times?

Carls Franchise · 2024 FDD

Answer from 2024 FDD Document

** add memory, ports and other accessories or peripheral equipment or additional, new or substitute software to the original computer system purchased by Franchisee; and (B) replace or upgrade the entire computer system with a larger system capable of assuming and discharging the computer-related tasks and functions specified by CJR. Franchisee also acknowledges that computer designs and functions change periodically and that CJR may

desire to make substantial modifications to its computer specifications or to require installation of entirely different systems during the term of this Agreement or upon renewal of this Agreement.

To ensure full operational efficiency and communication capability between CJR's computers and those of all Carl's Jr. Restaurants, Franchisee agrees, at its expense, to keep its computer system in good maintenance and repair and to make additions, changes, modifications, substitutions and replacements to its computer hardware, software, telephone and power lines and other computer-related facilities as directed by CJR, and on the dates and within the times specified by CJR in its sole discretion. Upon termination or expiration of this Agreement, all computer software, disks, tapes and other magnetic storage media shall be returned to CJR in good operating condition, excepting normal wear and tear.

Franchisee agrees to utilize administrative, physical, and technical safeguards designed to protect systems and data from unauthorized access, disclosure, acquisition, destruction, use, or modification that are consistent with industry standards and best practices. Franchisee further agrees to adhere to any applicable law relating to data security. In the event of a suspected or actual data breach, Franchisee will notify CJR within 24 hours of becoming aware of the actual or suspected data breach and provide timely updates and information when requested by CJR. Franchisee will comply with industry standards and best practices regarding breach reporting and notification obligations and take all necessary and appropriate corrective action to remedy the data breach, prevent a recurrence of such a breach, and avoid and/or prevent any further loss or damage arising from the data breach.

F. Upkeep of the Franchised Restaurant

Franchisee shall constantly maintain and continuously operate the Franchised Restaurant and all furniture, fixtures, equipment, furnishings, floor coverings, interior and exterior signage, the building interior and exterior, interior and exterior lighting, landscaping and parking lot surfaces in first-class condition and repair in accordance with the requirements of the System, including all ongoing necessary remodeling, redecorating, refurbishing and repairs. In addition, Franchisee shall promptly and diligently perform all necessary maintenance, repairs and replacements to the Franchised Restaurant as CJR may prescribe from time to time including periodic interior and exterior painting; resurfacing of the parking lot; roof repairs;

Source: Item 22 — CONTRACTS (FDD page 80)

What This Means (2024 FDD)

According to the 2024 Carls Franchise Disclosure Document, franchisees must adhere to specific security standards to protect systems and data. These standards include utilizing administrative, physical, and technical safeguards designed to prevent unauthorized access, disclosure, acquisition, destruction, use, or modification of data. These safeguards must align with industry standards and best practices, ensuring a robust security posture. Franchisees must also comply with all applicable laws related to data security.

In the event of a suspected or actual data breach, a Carls franchisee is required to notify Carls within 24 hours of becoming aware of the breach. They must provide timely updates and information as requested by Carls. Furthermore, franchisees are obligated to follow industry standards and best practices for breach reporting and notification, taking all necessary corrective actions to remedy the breach, prevent its recurrence, and avoid further loss or damage.

Carls also mandates that franchisees comply with all laws and regulations pertaining to data protection, privacy, and security, including data breach response requirements, as well as any data privacy and security policies, procedures, and other requirements that Carls may periodically establish. Franchisees must maintain reasonable, appropriate, and effective security controls to preserve the security, integrity, availability, confidentiality, and resilience of consumer information. Franchisees are responsible for any financial losses incurred or remedial actions required due to security breaches or unauthorized access to consumer information under their control.

Disclaimer: This information is extracted from the 2024 Franchise Disclosure Document and is provided for research purposes only. It does not constitute legal or financial advice. Consult with a franchise attorney before making any investment decisions.