Who assumes responsibility for providing notices of breach or compromise concerning customers of a Carvel franchise?
Carvel Franchise · 2025 FDDAnswer from 2025 FDD Document
In the event of an actual or suspected Data Breach, you grant us and our designees and agents the right, exercisable in our sole and absolute discretion, to conduct an investigation of the incident and to install, run, and maintain any hardware, software, or code on your Computer System or in your computer network necessary or advisable to facilitate the investigation and to contain and remediate the incident, and you agree to cooperate with us and to provide us with any access and information we may reasonably request for those purposes.
Nothing in the preceding sentence shall relieve you of your obligation to comply with applicable laws, regulations, rules, standards or any equivalent thereof concerning an actual or suspected Data Breach.
You are responsible for any costs or financial losses you incur or remedial actions that you must take as a result of an actual or suspected Data Breach.
Source: Item 23 — Receipts (FDD pages 100–353)
What This Means (2025 FDD)
According to Carvel's 2025 Franchise Disclosure Document, the franchisee is responsible for complying with laws and standards related to data breaches. In the event of an actual or suspected data breach, the franchisee grants Carvel the right to investigate the incident and implement necessary measures on the franchisee's computer system.
However, this does not relieve the franchisee of their obligation to comply with applicable laws and regulations concerning data breaches. The franchisee is responsible for any costs or financial losses incurred, as well as any remedial actions that must be taken due to an actual or suspected data breach.
This means that if a Carvel franchise experiences a data breach, the franchisee is ultimately accountable for addressing the situation, including covering any associated expenses and ensuring compliance with legal requirements. While Carvel has the right to investigate and intervene, the franchisee bears the primary responsibility for managing the consequences of the breach.