Does Learningrx require franchisees to limit employee access to Customer Data?
Learningrx Franchise · 2025 FDDAnswer from 2025 FDD Document
regarding Customer Data received by the Franchisee from a "consumer" as defined by applicable Privacy Laws;
- (h) adopt policies, procedures, and controls, including those set out in the Operations Manual, if any, that enable Franchisee to respond, and to cause its agents and employees to respond, promptly to any rights request made pursuant to applicable Privacy Laws, including any disclosure request, deletion request, or opt-out request;
- (i) adopt policies, procedures, and controls, including those set out in the Operations Manual, if any, that limit access to Customer Data to only those employees that have a need-to-know basis based on specific job function or role.
Source: Item 23 — RECEIPT (FDD pages 54–209)
What This Means (2025 FDD)
According to Learningrx's 2025 Franchise Disclosure Document, franchisees are required to limit employee access to customer data. Specifically, Learningrx mandates that franchisees adopt policies, procedures, and controls that limit access to Customer Data to only those employees that have a need-to-know based on specific job function or role. These policies and procedures may be detailed in the Learningrx Operations Manual.
This requirement ensures that sensitive customer information is protected and accessed only by authorized personnel. Franchisees must also provide data privacy and security training to employees who have access to Customer Data or who operate or have access to system controls. Employees must adhere to data confidentiality terms, further safeguarding Customer Data as per the Franchise Agreement and Operations Manual.
In the event of a security incident, such as unauthorized access to Customer Data, the franchisee is obligated to promptly notify Learningrx and cooperate in the investigation. Franchisees must also take steps to remedy any noncompliance with privacy laws, the Franchise Agreement, or the Operations Manual, as determined by Learningrx. This includes granting Learningrx the ability to delete, access, or copy Customer Data in the franchisee's possession or control and notifying Learningrx of any requests regarding Customer Data received from a consumer as defined by applicable Privacy Laws.