The issue of privacy must be an essential aspect to look into in many
companies and most important companies such as a hotel that deals
with people's personal information such as phone numbers, names,
and identification numbers. I have been invited by the Chief Privacy
Officer (CPO) to assist in identifying a set of appropriate and
relevant updates to the company's internal training program for staff
members with access to guest information. Based on the
background information, it has been reported that anonymous staff
has been posting guest information under the "Humor" section of
employee bulletin boards in the Resort Operations staff locker
rooms. These behaviors are considered unprofessional and a leak of
privacy. Therefore, my responsibility is to bring some updates on
privacy training in order for you to understand the importance of
maintaining guess privacy and the consequences that will be
imposed on staff who are found violating these policies.
First, I recommend that Padgett-Beale's privacy policies must be
visible. A company privacy policy must not be difficult to find, let the
policy page be open to employees or staff. When this is done,
everyone will be aware of what to do and what not to do. Better
Business Bureau proposed that “at a minimum, your privacy policy
should be linked to from your homepage and any other pages where
data is collected (Bureau, 2020).” Also, the policy should be linked to
the company’s homepage for it to be more visible. Another policy
recommendation is that policies should be kept simple for them to
be well understood by staff members. When understanding a policy
is complicated, its application of it also becomes difficult. BBB made
it clear that “Your privacy policy should be clear, concise and written
in plain language so that your customers can readily understand how
you’re handling their information (Bureau, 2020).”
Further, it is by law that people's private information should be
protected. The fourth amendment talks about protecting people's
information. It declares that “The right of the people to be secure in
their persons, houses, papers, and effects, against unreasonable
searches and seizures, shall not be violated, and no Warrants shall
issue, but upon probable cause, supported by oath or affirmation,
and particularly describing the place to be searched, and the persons
or things to be seized (U.S Constitution).” So, if a guess's information
is not protected and it happens that their information is out there to
the bad guys, the guess might sue the company for exposing their
privacy. Therefore, it is recommended that Padgett-Beale must
protect safeguard the company’s data to avoid a breach of data.
Identity management and access control is another recommendation
that Padgett-Beale's must consider in protecting its data. IAM is a
technology that helps to protect personal information from
unauthorized users. IAM technology includes authentication
mechanisms, data and resource access controls, provisioning
systems, and user account management. This technology allows staff
members to double authenticate before they are given access to a
guess database. The ISACA journal outline in its document that
“from a compliance perspective, IAM capabilities enable an
organization to accurately track and enforce user permissions across
the enterprise (ARCHIVES, 2010).”
Last, I recommend that Padgett-Beale use encryption technology to
encrypt customers' personal information. Hotels mostly deal with
customers' personal data the protection of this information is crucial.
When data is encrypted, the access to that data will not be simple
and before anyone can get into that specific data, they must access
the code for decrypting the data. Intersoft Consulting in its
document said, “Encryption is the best way to protect data during
transfer and one way to secure stored personal data(inter soft
consulting).” When guess information is encrypted, it becomes
inaccessible unless you have the key decrypt and get access to the
data.
ARCHIVES, I. J. (2010). Data Governance for Privacy,
Confidentiality, and Compliance: A Holistic
Approach.https://www.isaca.org/resources/isaca-journal/past-
issues/2010/data-governance-for-privacy-confidentiality-and-
compliance-a-holistic-approach
Bureau, B. B. (2020). Writing an Effective Privacy Policy for Your
Business' Website.
Better Business Bureau
.
https://www.bbb.org/article/news-releases/21390-bbb-tip-writing-
an-effective-privacy-policy-for-your-small-business-website
https://gdpr-info.eu/issues/encryption/