Considering recent guest information privacy policy violations by
the staff members at Padgett-Beale, Chief Privacy Officer has
asked to for improvements in staff awareness and training, so
that privacy violations do not reoccur in the future. All employees
will understand personally identifiable information, privacy by
design, and acceptable use policy from the updated training. The
internal training program should address the seriousness of the
violations of guest’s personally identifiable information It should
cover possible consequences, not limited to suspension and
termination of the guilty party, but also include the legal
ramifications from the victim(s), the organization, and/or the state
and local governments. By updating the training to include
personally identifiable information, privacy by design, and
acceptable use policy with outline of punishment, all employees at
Padgett-Beale should understand the magnitude of protecting
customer information.
The employees must first understand what
personally identifiable information, otherwise known as PII, is.
According to Bernstein (2021), PII is “any data that could
potentially identify a specific individual”. This include, but not
limited to, name, address, email, telephone number, date of birth,
credit or debit card, and any other information about the
customer that is collected at Padgett-Beale properties that can
identify a customer. At Padgett-Beale, PII information is handled
at point of sales, reception, and by our cooks, and should be
limited to those who require such information to conduct
business behalf of Pagett-Beale as guest service. Employees
should be aware, like others in the industry, Padgett-Beale does
not collect information of children under the age of 16 (The
Leading Hotels of the World, 2021). All employees should
understand the protection of guest PII is responsibility of all
personnel at Padgett-Beale, and the consequences for violators
should be outlined in PII training, as well as in acceptable use
policy. In protecting PII, the organization should state its
adherence to Privacy by Design principles.
Padgett-Beale protects customer PII by adhering to
Privacy by Design. According to Kroener and Wright (2014),
Privacy by Design Principles was pioneered by Commissioner Ann
Cavoukian at Ontario Information and Privacy, advocating
proactiveness in protecting privacy. Not only is IT infrastructure
important in protecting customer privacy from outside threats, but
it is also important that privacy taken seriously from point of
sales to data retention. The employees handling PII, needs to
understand that they are a part of the Privacy by Design at
Padgett-Beale, and it involves all employees in proactively
protecting customer PII. Privacy and protection of information is
the responsibility of entirety of the organization, and
consequences should also be highlighted in the training.
Padgett-Beale, in it’s revamped training, needs to
include acceptable use policy for all employees. This should cover
what information is privileged information, and who has access to
this information, as well as the consequences of violating the
policy. AUL, should clearly outline the responsibilities of those
who handle PII, and types of behaviors that are discouraged in
handling sensitive information. It should also outline what data is
protected by the organization and subject to suspension or
termination, and data that is protected by law and subject to
prosecution. The AUP should be signed by all employees and
included in their employee file as part of their training and
employment requirement (BioMelbourne Network, 2020).
With the revamped Padgett-Beale employee
training, all employees should understand the importance and the
consequences of violating privacy policies of the organization.
They should be aware of the terms such as PII, Privacy by
Design, and Acceptable Use Policy of the organization. -Beale
management team will see the reduction in the violation of
customer privacy as all employees become familiarized with the
consequences of their actions.
References
Bernstein, C. (2021, September 24).
personally identifiable
information (PII)
. Tech Target.
https://www.techtarget.com/searchsecurity/definition/personally-
identifiable-information-
PII#:%7E:text=Personally%20identifiable%20information%20(PII)%2
0is,anonymous%20data%20is%20considered%20PII.
BioMelbourne Network. (2020, January 27).
Importance of
acceptable use policy – IT Systems & Services
.
https://biomelbourne.org/importance-of-acceptable-use-policy-it-
systems-
services/#:%7E:text=An%20acceptable%20use%20policy%20(AUP,b
eing%20granted%20a%20network%20ID.
Kroener, I., & Wright, D. (2014). A Strategy for Operationalizing
Privacy by Design.
Information Society
,
30
(5), 1.
https://doi.org/10.1080/01972243.2014.944730
The Leading Hotels of the World. (2021, May).
The Leading
Hotels of the World Privacy Policy
. https://www.lhw.com/Privacy-
Policy