factual

What laws must a Cicis franchisee comply with regarding the collection, storage, and processing of personal information?

Cicis Franchise · 2025 FDD

Answer from 2025 FDD Document

You are responsible, at your expense, to comply with all Laws related to the collection (including with respect to permissions to do so), storage and processing of information that you collect, store or process and that can be used to identify an individual, including names, addresses, telephone numbers, e-mail addresses, employee identification numbers, signatures, passwords, financial information, credit card information, biometric or health data, government-issued identification numbers and credit report information ("Personal Information").

You must implement all administrative, physical and technical safeguards necessary to protect and appropriately dispose of any Personal Information that you have collected or stored in accordance with all applicable Laws and industry best practices.

If you become aware of a suspected or actual breach of security or unauthorized access involving Personal Information, you will notify us immediately of the breach

Source: Item 22 — CONTRACTS (FDD pages 64–65)

What This Means (2025 FDD)

According to Cicis's 2025 Franchise Disclosure Document, franchisees are responsible for complying with all laws related to the collection, storage, and processing of personal information. This includes obtaining necessary permissions for collecting such data. Personal information is defined as data that can be used to identify an individual, such as names, addresses, telephone numbers, email addresses, employee identification numbers, signatures, passwords, financial information, credit card information, biometric or health data, government-issued identification numbers, and credit report information.

Cicis franchisees must implement administrative, physical, and technical safeguards to protect and appropriately dispose of any personal information they collect or store. These safeguards must align with all applicable laws and industry best practices. This means franchisees need to establish and maintain a secure system that prevents unauthorized access, use, or disclosure of personal information, and they must properly dispose of such information when it is no longer needed.

Furthermore, the FDD states that franchisees must immediately notify Cicis of any suspected or actual breach of security or unauthorized access involving personal information. This immediate notification is crucial for Cicis to take appropriate steps to mitigate any potential damage and ensure compliance with data protection laws. The franchisee bears the expense of adhering to these information security requirements.

Disclaimer: This information is extracted from the 2025 Franchise Disclosure Document and is provided for research purposes only. It does not constitute legal or financial advice. Consult with a franchise attorney before making any investment decisions.