To: Chief Privacy Officer
Introduction
Padgett-Beale had made extraordinary progress on the privacy and
security of our guest’s data. The company has analyzed what data is
collected, how it is being collected, and what we are doing with the
data. From this information gathered we have created detailed
technology solutions and data management policies. Although all
these processes were much needed and effective, the company did
not place the proper attention and focus on the employees that
would be handling this data. The recent incident involving
customer’s personal data to the employee bulletin boards is
unacceptable and action must be taken. Employee training in
concern to guest privacy and security is a weak link in the company’s
security policy, and it is suggested that we implement three training
courses in sequence to all employees who have access to guest data.
Recommendation 1
The first recommended training course will be composed of two
themes or focuses. First portion of the training will outline in detail
to all staff exactly how Padgett-Beale goes to extraordinary lengths
to protect customer data and why the company must uphold
rigorous attention to detail in relation to customer data security. The
second portion of the training will be focused on directing how each
staff member plays an extremely important role in this security and
what exactly is expected of them.
Recommendation 2
The second recommendation is the implementation of a training
course for all guest relations employees, and it will be focused on
dealing with ‘out of the ordinary’ or even outrageous guest requests.
During this training session employees will be taught conflict
negotiation skills. The goal of the training is to empower employees
with the ability to deal with clients in a pressure filled situation and
leave that experience in an emotional state that will not result in
untoward behavior.
Recommendation 3
The third recommendation is an all-company online training seminar
that explains Padgett-Beale’s new extended consequences for
violations of the guest relations privacy policy. The employees will
be made aware that the previous policy of consequences that would
start at two-week suspension is no longer in places. Any violations
to the security policies will result in immediate termination. This
adoption of a zero-tolerance policy will require all employees with
access to customer data to sign a legally binding non-disclosure
agreement (NDA). Employees will be adequately informed that
future policy violations could result in legal action against them in
addition to employment termination.
Summary
This sequenced three step approach to employee training will result
in employees first fully understanding what is expected of them in
relation to securing employ data and why it is important. The next
step will tell them how to approach and deal with the situations
involving difficult guests. The last step of training will explain the full
consequences of not following the directives outlined by the two
previous training sessions. Padgett-Beale has made incredible
progress with concern towards guest privacy and security. These
training sessions will complete the process by adequately training
those who represent Padgett-Beale as the face of the company.
References
Shonk, Katie. (2020, December 31).
How to Deal with Difficult
Customers
. Harvard Law School Program on Negotiation. Retrieved
from https://www.pon.harvard.edu/daily/dealing-with-difficult-
people-daily/deal-with-difficult-customers/
Better Business Bureau. (2020, January 28).
BBB Tip: Writing an
Effective Privacy Policy for Your Business' Website
. Better Business
Bureau. Retrieved from https://www.bbb.org/article/news-
releases/21390-bbb-tip-writing-an-effective-privacy-policy-for-
your-small-business-website