☰
✕


HOTEL BUSINESS REVIEW

DECEMBER FOCUS: Hotel Law

 

Strategies for Global Brands in Navigating Data Localization Requirements

By Wendy Hansen Counsel, Eversheds Sutherland | December 2023

Co-authored by Michael Bahar, Partner, Rhys McWhirter, Partner, Andrew Garbett, Principal Associate, Jamie Leung, Associate,  & Lucrezia Berto, Legal Officer, Eversheds Sutherland

It is a well-known fact that hotels collect tremendous amounts of data and the value of that data is only increasing.

Guest data ranges from basic contact information to fulfill a room reservation to sensitive information related to age, gender and food allergies.

Beyond the front desk, data is collected and processed in managing hotel staff and contracting with service providers.

Increasingly, however, governments are implementing data localization requirements that present substantial challenges to a global, "one brand" approach to hotel operations. If guest histories and preferences cannot be transferred cross-border, it may be difficult to deliver on a brand promise of personalized service. It can also be challenging for the human resources department to manage career progressions or implement diversity, equity and inclusion initiatives if employee data cannot be transferred cross-border. Implementing advanced technologies like facial recognition and other uses of Artificial Intelligence and biometrics may also face obstacles with the restriction on the free-flow of data. Service providers may also be unwilling or unable to offer localized solutions due to these requirements.

How can global brands best manage these requirements from a practical perspective? This article will give an overview of data localization, including summaries of key data transfer requirements in the European Union and the United Kingdom, Mainland China and the Middle East, and it will conclude with three strategies for global brands to address such requirements - (1) map it, tag it and track it; (2) aim for a globalized, risk-based approach; and (3) increase the use of clear, affirmative consents. The strategies can also help as other countries move to adopt their own data sovereignty laws.

Data Localization

What is data localization? Data localization refers to the concept that any data collected within a country must be collected, processed and stored locally or "in country," and restrictions may apply to any transfer of such data outside the country. The often-stated purpose of data localization laws is to protect the privacy of individuals within the country, although there are elements of trade protectionism in the practice. For example, requiring a company to store data locally or use local suppliers helps develop the local economy, and the underlying data itself is an increasingly valuable asset, particularly to fuel Artificial Intelligence capabilities and even for national security purposes.

European Union and the United Kingdom

The adoption of the General Data Protection Regulation (GDPR) in the European Union has impacted how companies do business and share data worldwide. The GDPR applies to businesses and other entities established in the EU and, in certain circumstances, to entities in foreign countries that process the data of individuals in the EU. It sets out principles and rules that must be followed in order to avoid sanctions and fines, which can reach €20 million or 4% of worldwide annual turnover.

Transfers of personal data to countries outside the European Economic Area are allowed only if the recipient country is recognized as providing "adequate" protection or if another safeguard set out in the regulation applies. The list of so-called adequate countries is currently limited to fewer than 20 nations, including Argentina, Japan and Switzerland, and it does not include the United States. Relying on the consent of the individual affected is often not an appropriate safeguard, and in practice, many transfers to non-adequate countries are based on a contract between the entities involved, under which the recipient agrees to comply with the GDPR. The existence of that contract - typically the Standard Contractual Clauses (SCCs) - does not alleviate the data protection responsibilities of the exporting entity, as it still must assess the impact of the transfer on the data and periodically review the recipient's compliance with the agreement.

The process for transfers of data from the EU to the US has recently been simplified with the creation of the Data Privacy Framework (DPF), the successor to the overturned Privacy Shield, to which US companies can now certify in order to enable the freer flow of personal data. Not all US companies participate in the framework, and the list should be checked before any personal data is transferred. 

After Brexit, the UK incorporated the GDPR into UK law, with little change to the original principles, rights and obligations. The rules about cross-border transfers of personal data are substantially similar to those set out in the GDPR, and the DPF with the US has been extended to meet the UK standards for data transfers as well.

The regime applicable to international transfers affects how hotels established in the EU and UK can share their guests' and employees' personal data with their suppliers and group companies. The relationship with foreign suppliers involving transfers of personal data must be carefully analyzed and based on adequate safeguards, and assessments of the impact of the transfer on the personal data affected must be performed prior to engaging the supplier and periodically during the provision of the services.

Since the DPF is likely to face its own challenges in the EU courts, relying on both the SCCs and the DPF may be the safest long-term solution for multinational hotel chains. They can also consider creating "binding corporate rules" as an alternative to intragroup data agreements. Binding corporate rules are a mechanism providing appropriate safeguards for cross-border transfers of data within a group of companies, provided that they meet the requirements of the GDPR and are approved by a competent supervisory authority. For this reason, they must be carefully drafted and submitted for approval.

Mainland China

Under Mainland China data protection laws, certain data including personal data of Mainland China individuals must be stored in Mainland China unless it is exported to other countries in accordance with laws and regulations. Notably, offshore remote access to data stored in Mainland China is also caught under cross-border data transfer.

More specifically, there are three main mechanisms, collectively the Cross-Border Data Transfer Requirements, to lawfully facilitate cross-border personal data transfer under the Personal Information Protection Law:

(1)  Passing the security assessment (CAC Security Assessment) carried out by the Cyberspace Administration of China (CAC).

(2)  Obtaining certification from CAC-accredited professional institutions.

(3)  Entering the China standard contractual clauses with overseas data recipients (PRC SCCs).

Currently, a data controller will be required to undertake the CAC Security Assessment if it meets any of the following thresholds:

(i)   A data controller transfers any "important data" (generally referring to any data that once tampered with, damaged, leaked, or illegally obtained or used may endanger national security or public interest) outside Mainland China.

(ii)  A critical information infrastructure operator or a data controller processing personal data of more than 1 million Mainland China individuals transfers personal data outside Mainland China.

(iii) Personal data of more than 100,000 individuals has been exported outside Mainland China since January 1 of the previous calendar year.

(iv) Sensitive personal data of more than 10,000 individuals has been exported outside Mainland China since January 1 of the previous calendar year

A data controller may only leverage the PRC SCCs or certification from CAC-accredited agencies to transfer personal data outside Mainland China if it does not meet any of the above thresholds. Given the personal data and sensitive personal data collected from hotel guests and employees, it is very likely that international hotel companies will exceed the thresholds above and be required to pass the CAC Security Assessment.

Separately, the Personal Information Protection Law also requires data controllers to obtain "separate consent" from Mainland China individuals for exporting their personal data outside Mainland China. As market practice, organizations typically do so by implementing an individual consent "checkbox" for transferring personal data overseas. This checkbox is to be separated from other items of consent for data processing. Deemed or "bundled" consent is unlikely to be sufficient.

On September 28, 2023, however, the CAC released the Consultation Draft of the Regulations on Standardization and Promotion of Cross-border Data Flow (the Draft Regulations), which propose new exemptions to the Cross-Border Data Transfer Requirements. It should be noted that the Draft Regulations are not final and may be subject to further change. It is generally expected that the Regulations will be published in final form and become effective before December 2023. (Note that this article was submitted for publication prior to December 2023.)

It is proposed that entities be exempt from all Cross-Border Data Transfer Requirements in any of the following cases:

(1)  Personal data is collected and generated outside Mainland China and then transferred outside Mainland China.

(2)  The export of personal data is necessary for the conclusion and performance of a contract to which the data subject is a party, such as cross-border purchases, cross-border remittance, flight and hotel bookings, and visa applications.

(3)  The export of internal staff's personal data is necessary for an entity's human resource management implemented in accordance with lawfully established labor rules and regulations and collective bargaining contracts.

(4)  The export of personal data is necessary for protecting the life, health, property, safety, etc. of natural persons in emergency situations.

(5)  Personal data of fewer than 10,000 individuals is expected to be transferred outside Mainland China by an entity within a year.

(6)  For entities registered in free-trade zones, the export of the types of personal data that are not listed on the "negative list" formulated by the relevant free-trade zone and approved by the CAC.

Separately, it is proposed that an entity is exempt from the CAC Security Assessment if personal data of more than 10,000 but fewer than 1 million individuals is expected to be transferred outside Mainland China by the entity within a year and the entity has filed the executed SCC with the CAC or obtained certification from CAC-accredited agencies.

While the Draft Regulations would help facilitate the types of data hotel companies need to transfer cross-border, it is important to note there remain areas of uncertainty in the proposed law. For example, it is unclear what the regulators will consider "necessary" with respect to exemptions (2) – (4) above.

As a reminder, the proposed exemptions in the Draft Regulations are also subject to carve-outs; e.g. they may not apply to the export of personal data or important data by government bodies or critical information infrastructure operators, or the export of sensitive data or sensitive personal data relating to Mainland China's political party, the government, the military or a classified agency.

Middle East

Several countries in the Middle East have recently enacted data protection laws. Given the lack of previous specific data protection regimes in those countries, this has significantly changed the position when it comes to the treatment of information about individual guests, employees, etc. In addition to the restrictions on international transfers of personal data set out in those laws, there has also been a trend in the region toward "data sovereignty" more generally.

The United Arab Emirates (UAE), which includes Dubai, is a major center for the hotel industry in the Middle East. In 2021, it enacted its first national law for the protection of personal data. In many ways, this law reflects the concepts underlying the EU's GDPR, although inevitably with differences that reflect local culture. It applies to businesses and other entities established in the UAE and to entities outside the UAE that process data about individuals in the UAE. The law is not yet being actively enforced, pending the issue of its executive regulations, but strictly speaking, compliance is already required and, in any event, individuals are likely to expect the businesses they deal with to comply with high standards in handling their personal data.

The UAE law prohibits the transfer of personal data out of the UAE to another country unless the data controller either has the consent of the data subject or can show that one of several other conditions applies. These include the recipient country having an adequate data protection regime, that the transfer is "necessary" to enter into or perform a contract with the data subject and that the recipient enters into a contract agreeing to comply with the UAE data protection law.

Clearly, there are potential problems with relying on these other grounds, so in practice, obtaining clear and freely given consent from the data subject is usually the best course. That is all the more important, as there are other laws, such as the Penal Code and the Cybercrimes Law, which prohibit the disclosure of "confidential" information without consent unless there is some other lawful authority, which is undefined and therefore difficult to rely on.

Saudi Arabia also restricts the transfer of personal data out of the country. Under its new data protection law, transfers of personal data will be permitted only to countries on the "Approved List," which is to be - but has not yet been - issued by the Saudi data protection regulator. In addition, the transfer must be for one of a limited number of purposes, including that it is "necessary" for fulfilling an obligation to which the data subject is a party. Any transfer of personal data out of Saudi Arabia therefore faces significant hurdles.

As a result, it is not straightforward for hotels in the Middle East to share data about their guests or employees with companies in other countries, even if those companies are in the same business group. It can therefore be difficult to operate hotels in the Middle East as part of a seamless global business and to serve guests as they move around that business's hotels in other parts of the world.

Strategies for Global Brands

As noted above, data localization requirements present real challenges to hotel operations. Three strategies for global hotel companies to navigate these varying and rapidly developing requirements are set out below:

1. Map it, tag it and track it. It is increasingly essential to know your data and to be nimble and agile in handling it. Hotel companies would do well to understand the origin, type, volume and purposes of personal data collected and processed by each group entity. They may want to "map it, tag it and track it" from cradle to grave, and they should consider separating that which needs to flow across borders and that which can remain local. Having this deep, pragmatic understanding and agility is key to assessing whether and how data transfer requirements apply, whether exemptions are available, and whether it makes business sense to transfer the data across borders.

2. Take a globalized approach. Aim for a globalized, risk-based approach to implementing requirements. It can be overwhelming to focus on the differences in regulations among jurisdictions. Instead, seek commonalities in privacy and data rules, and focus on where they are the same, while taking into consideration the risk of regulatory enforcement. As volatile as the global privacy field is, there is a strong degree of regulatory convergence, which multinational hotels can leverage to create more globalized, streamlined and future-proofed data-sharing arrangements.

3. Increase the use of consent. Obtaining the data subject's clear, unambiguous and affirmative consent to transfer their data cross-border, where appropriate, can go a long way to meeting requirements. In considering global consent strategies, hotel companies should evaluate whether separate consents are required. In particular, "separate consent" is required not only for transferring personal data outside Mainland China but also for processing sensitive personal data and sharing personal data with third-party data controllers, etc.

Data localization requirements are part of an ever-evolving data privacy landscape. We encourage our clients to closely monitor the development of the law and be prepared to respond to any new change in the cross-border data transfer requirements.

This article was co-authored by the following:

Michael Bahar Partner, Co-Lead of Global Cybersecurity and Data Privacy, Eversheds Sutherland

Mr. Bahar is a Partner and Co-Lead of Global Cybersecurity and Data Privacy at Eversheds Sutherland. He sits in the Washington, DC office. He provides highly-responsive, pragmatic and comprehensive cybersecurity and privacy law advice to some of the world's largest companies. He has particular experience in helping businesses across industries efficiently navigate the rapidly evolving threat, regulatory and litigation environments. His business-focused legal advice is designed to mitigate risk and maximize opportunities, especially when looking to enter new markets, develop or adopt revolutionary technologies and products, monetize data and transfer data across borders. Leading a team of over 160 cybersecurity and data privacy lawyers across 35 countries, Mr. Bahar provides holistic and proactive advice to protect against, prepare for and effectively respond to cyber incidents. He provides calm and clear support during breaches, providing global teams with coordinated and consistent legal advice around the clock.

Rhys McWhirter, Partner, Head of Technology (Asia), Eversheds Sutherland

Mr. McWhirter is a Partner in the Eversheds Sutherland Hong Kong office and leads the Technology and Commercial Practice in Hong Kong. He has extensive experience in drafting and negotiating high-value and strategic commercial contracts and has acted for both government and private sector clients, particularly financial institutions throughout APAC on complex commercial and digital transformation projects. He has significant experience in advising leading financial services, mining and aviation multi-national companies in APAC on various strategic commercial and TMT related transactions, including infrastructure (private and public cloud), contact centre services, core-banking, telecommunications, enterprise software, data centre, facilities management and application outsourcing arrangements.

Andrew Garbett, Principal Associate, Eversheds Sutherland

Mr. Garbett is a principal associate in the Eversheds Sutherland commercial practice and is based in the Abu Dhabi office. He focuses on TMT matters across the MENA region, in particular on contractual and regulatory matters. Andrew has over 15 years' experience of commercial work, including contractual and transactional work on major projects for regional and global clients. Typical areas of work include advising on and drafting procurement and supply contracts, data protection issues, agency and distribution arrangements, commercialization agreements, and IP and IT matters.

Jamie Leung, Associate, Eversheds Sutherland

Ms. Leung is an Associate in the Technology and Commercial Practice in the Eversheds Sutherland Hong Kong office. She has a wide range of experience in data privacy, cybersecurity, payments, technology outsourcing and other regulatory matters. In respect of data privacy matters, she is particularly experienced in handling data protection requirements as part of commercial transactions, and advising MNCs on compliance with multi-jurisdiction data protection and transfer requirements. Most recently, Ms. Leung has advised regional and global clients in the hospitality sector on the complete revamp of their global data management and protection policies and the launch of a global loyalty programme.

Lucrezia Berto, Legal Officer, Eversheds Sutherland

Ms. Berto is a Legal Officer based in the Eversheds Sutherland Abu Dhabi office. She specialises in intellectual property, IT and data privacy non-contentious matters, advising regional and international companies across various sectors. Typical areas of work include IT contracts, commercialisation agreements, trademark and software licenses, personal data protection compliance, regulatory advice and IP/IT due diligences on software and OSS.

Choose a Social Network!

The social network you are looking for is not available.

Close

Terms & Conditions

The following are terms of a legal agreement ("Agreement") between you and HotelExecutive. By accessing, browsing and/or otherwise using this web site, HotelExecutive, you acknowledge that you have read, understood and agreed to be bound by these terms and conditions, and to comply with all applicable laws and regulations, including U.S. export and re-export control laws and regulations. If you do not agree to all of these terms and conditions, you may not access, browse and/or use HotelExecutive. The material provided on HotelExecutive is protected by law, including, but not limited to, United States copyright law and international treaties.

These terms of access apply to your access to and use of HotelExecutive and do not alter in any way the terms and conditions of any other agreement you may have with HotelExecutive for products, software, services or otherwise, unless otherwise directed by HotelExecutive. If you breach any of these terms and conditions, your authorization to use HotelExecutive automatically terminates and you must immediately destroy any downloaded or printed materials and discontinue use of any hyperlinks to HotelExecutive.

1. USE RESTRICTIONS

Copyright. All Site materials, including, without limitation, text, pictures, graphics and other files and the selection and arrangement thereof are copyrighted materials of HotelExecutive © 1996-2016, ALL RIGHTS RESERVED, or by the original creator of the material. Permission is granted to display and use the materials on HotelExecutive for private individual, educational and noncommercial use only, provided you do not modify the materials and that you retain all copyright and other proprietary notices contained in the materials. You may not, however, distribute, copy, reproduce, display, republish, download, or transmit any material on HotelExecutive for commercial use without prior written approval from HotelExecutive. You may not "mirror" any material contained on HotelExecutive on any other server without prior written permission from HotelExecutive. Any unauthorized use of any material contained on HotelExecutive may violate copyright laws, trademark laws, the laws of privacy and publicity and communications regulations and statutes.

Trademarks

The trademarks, service marks, trade names and logos (the "Trademarks") used and displayed on HotelExecutive are registered and unregistered Trademarks of HotelExecutive. In addition, all page headers, custom graphics, icons and scripts are service marks, trademarks and/or trade dress of HotelExecutive, and may not be copied, imitated or used, in whole or in part, without the prior written permission of HotelExecutive. You acknowledge that the Trademarks used and displayed on HotelExecutive are and shall remain the sole property of HotelExecutive or the Trademark owner. Nothing in this Agreement shall confer any right of ownership of any of the Trademarks in you. Further, nothing in HotelExecutive shall be construed as granting, by implication, estoppel or otherwise any license or right to use any Trademark used or displayed on HotelExecutive, without the express written permission of HotelExecutive or the Trademark owner. The misuse of the trademarks displayed on HotelExecutive, or any other Content on HotelExecutive, is strictly prohibited.

Hyperlinks

You are granted a limited, nonexclusive right to create a hypertext link to HotelExecutive provided that such link is to the entry page of HotelExecutive and does not portray HotelExecutive or any of its products or services in a false, misleading, derogatory, or otherwise defamatory manner. This limited right may be revoked at any time for any reason whatsoever. You may not use framing techniques to enclose any Company trademark, logo or trade name or other proprietary information including the images found at HotelExecutive, the Content of any text or the layout/design of any page or any form contained on a page without HotelExecutive's express written consent. Links to third party sites on HotelExecutive are provided solely as convenience to you. If you use these links, you will leave HotelExecutive. HotelExecutive has not reviewed all of these third party sites and does not control and is not responsible for any of these sites, their Content or their policies, including, without limitation, privacy policies or lack thereof. HotelExecutive does not endorse or make any representations about third party sites or any information, software or other products or materials found there, or any results that may be obtained from using them. If you decide to access any of the third party sites linked to HotelExecutive, you do so entirely at your own risk. You acknowledge and agree that HotelExecutive shall not be responsible or liable, directly or indirectly, for any damage or loss caused or alleged to be caused by, or in connection with the use of or reliance on any such third party sites.

Downloadable Materials

Any software, including codes or other materials that are made available to download from HotelExecutive, is the copyrighted work of HotelExecutive and/or its suppliers and affiliates. If you download software from HotelExecutive, use of the software is subject to the license terms in the software license agreement that accompanies or is provided with the software. You may not download or install the software until you have read and accepted the terms of the applicable software license agreement. Without limiting the foregoing, copying or reproduction of the software to any other server or location for further reproduction or redistribution is expressly prohibited unless otherwise provided for in the applicable software license agreement in the case of software, or the express written consent of HotelExecutive in the case of codes or other downloadable materials.

Limited Access

Except as otherwise expressly permitted by HotelExecutive, any access or attempt to access other areas of HotelExecutive computer system or other information contained on the system for any purposes is strictly prohibited. You agree that you will not use any robot, spider, other automatic device, or manual process to "screen scrape," monitor, "mine," or copy the Web pages on HotelExecutive or the Content contained therein without HotelExecutive's prior, express, and written permission. You will not spam or send unsolicited e-mail to any other user of HotelExecutive for any reason. You agree that you will not use any device, software or routine to interfere or attempt to interfere with the proper working of HotelExecutive. You agree that you will not take any action that imposes an unreasonable or disproportionately large load on HotelExecutive's infrastructure.

Additional Use Restrictions

You shall not post, transmit, e-mail, re-transmit or store material on or through any of the services provided by HotelExecutive (the "Services") which, in the sole judgment of HotelExecutive: (i) is in violation of any local, state, federal or non-United States law or regulation, (ii) is threatening, obscene, indecent, defamatory or that otherwise could adversely affect any individual, group or entity (collectively, "Persons") or (iii) violates the rights of any person, including rights protected by copyright, trade secret, patent or other intellectual property or similar laws or regulations including, but not limited to, the installation or distribution of "pirated" or other unauthorized photos or software products that are not appropriately licensed for use by you. You shall be responsible for determining what laws or regulations are applicable to its use of the Services. In addition, you may only use the Services in a manner that, in HotelExecutive's sole judgment, is consistent with the purposes of such Services. If you are unsure of whether any contemplated use or action is permitted, please contact HotelExecutive at editor@HotelExecutive By way of example, and not limitation, the following uses described below of the Services are expressly prohibited:

A. upload, post, e-mail or otherwise transmit any information, data, text, software, music, sound, photographs, graphics, video, messages or other materials (collectively, "Content") that is unlawful, harmful, threatening, abusive, harassing, tortious, defamatory, vulgar, obscene, libelous, invasive of another's privacy, hateful, sexually intolerant or racially, ethnically or otherwise objectionable;

B. impersonate any person or entity, including, but not limited to, a Company official, forum leader, guide or host, or falsely state or otherwise misrepresent your affiliation with a person or entity;

C. forge headers or otherwise manipulate identifiers in order to disguise the origin of any Content transmitted through the Services or develop restricted or password-only access pages, or hidden pages or images (those not linked to from another accessible page);

D. upload, post, e-mail or otherwise transmit any Content that you do not have a right to transmit under any law or under contractual or fiduciary relationships such as inside information, proprietary and confidential information learned or disclosed as part of employment relationships or under nondisclosure agreements;

E. upload, post, e-mail or otherwise transmit any Content that infringes any patent, trademark, trade secret, copyright or other proprietary rights of any party;

F. upload, post, e-mail or otherwise transmit any unsolicited or unauthorized advertising, promotional materials, "junk mail," "spam," "chain letters," "pyramid schemes" or any other form of solicitation;

G. upload, post, e-mail or otherwise transmit any material that contains software viruses, worms or any other computer code, files or programs designed to interrupt, destroy or limit the functionality of any computer software or hardware or telecommunications equipment;

H. interfere with or disrupt the Services or servers or networks connected to the Services, or disobey any requirements, procedures, policies or regulations of networks connected to the Services;

I. intentionally or unintentionally violate any applicable local, state, national or international law, including, but not limited to, regulations promulgated by the U.S. Securities and Exchange Commission, any rules of any national or other securities exchange, including, without limitation, the New York Stock Exchange, the American Stock Exchange or the NASDAQ, and any regulations having the force of law;

J. 'stalk' or otherwise harass another user of HotelExecutive or Company employee or official;

K. promote or provide instructional information about illegal activities, promote physical harm or injury against any group or individual, or promote any act of cruelty to animals. This may include, but is not limited to, providing instructions on how to assemble bombs, grenades and other weapons, and creating "Crush" sites; and

L. effecting security breaches or disruptions of Internet communication. Security breaches include, but are not limited to, accessing data of which you are not an intended recipient or logging into a server or account that you are not expressly authorized to access.

M. advertising to, or soliciting any user of HotelExecutive to buy or sell any products or services through the unauthorized or impermissible use of the Services. You may not transmit any junk email or chain letters to other users. If you breach this Agreement and send unsolicited bulk email, instant messages or other unauthorized commercial communications of any kind through the Services, you acknowledge that you will have caused substantial harm to HotelExecutive, but that the amount of such harm would be extremely difficult to ascertain. As a reasonable estimation of such harm, you agree to pay HotelExecutive $500 for each such unsolicited email or other unauthorized commercial communication you send to each user through the Services.

2. DISCLAIMER WARRANTY

HotelExecutive, including all software, functions, materials, and information is provided "as is" without warranties of any kind, either express or implied. HotelExecutive disclaims all warranties, express or implied, including, but not limited to, warranties of non-infringement and implied warranties of merchantability, fitness for a particular purpose, non-infringement, title, merchantability of computer programs, data accuracy, system integration, and informational Content. HotelExecutive does not warrant or make any representations regarding the operation of HotelExecutive, the use, validity, accuracy or reliability of, or the results of the use of the materials on HotelExecutive or any other sites linked to HotelExecutive. The materials of HotelExecutive may be out of date, and HotelExecutive makes no commitment to update the materials at HotelExecutive. HotelExecutive does not and cannot guarantee or warrant that the files available for downloading from HotelExecutive, if any, will be free from infection, viruses, worms, Trojan horses, or other code that manifest contaminating or destructive properties. HotelExecutive does not warrant that HotelExecutive, software, materials, products, or services will be uninterrupted or error-free or that any defects in HotelExecutive, software, materials, products, or services will be corrected.

3. LIMITATION OF LIABILITY

In no event will HotelExecutive, its suppliers or other third parties mentioned at or in HotelExecutive be liable for any damages, including, without limitation direct, indirect, special, incidental, or consequential damages, damages resulting from lost profits, lost data or business interruption arising out of relating to the use, inability to use, or resulting from the use of HotelExecutive, any web sites linked to HotelExecutive, the materials, software or other information contained in any or all such sites, whether based on warranty, contracts, statutes, regulations, tort (including but not limited to, negligence) or any other legal theory and whether or not advised of the possibility of such damages. If your use of the materials or information from HotelExecutive results in the need for servicing, repair or correction of equipment or data, you assume all costs thereof.

4. REVISIONS TO THIS AGREEMENT

HotelExecutive may revise this Agreement at any time without notice by updating this posting. By using HotelExecutive you agree to be bound by any such revisions and should therefore periodically visit HotelExecutive and page to determine the then current Terms of Access and Use conditions of use to which you are bound.

5. TRANSMISSIONS

Any idea you transmit to or post on HotelExecutive by any means will be treated as non-confidential and non-proprietary and may be disseminated or used by HotelExecutive or its affiliates for any purpose whatsoever, including, but not limited to, developing and marketing products. You are prohibited from posting or transmitting to or from HotelExecutive any unlawful, threatening, libelous, defamatory, obscene, scandalous, inflammatory, pornographic, profane material or any other material, including but not limited to any material that could give rise to any civil or criminal liability under both domestic and international law.

6. YOUR WARRANTIES

You warrant to HotelExecutive that:

You are the sole owner of all rights in the materials posted or uploaded by you (including all related copyrights) or that you have the absolute right to license their use as provided in this section. While you will retain ownership of the copyright in the materials posted or uploaded by you, you agree that all materials posted or uploaded by you shall become part of a database, and that HotelExecutive will own the compilation copyright in that database. In addition, you hereby grant HotelExecutive a perpetual, worldwide, irrevocable license to use, reproduce, modify, publish, publicly perform, publically display and distribute such materials, and portions of such materials and any derivative works created from such materials, in print, electronic and other media, by any means now known or developed in the future. We may sublicense all of our rights and licenses or assign them to third parties. Neither HotelExecutive nor any third party using the materials in accordance with this section will be obligated to pay you any royalties or other compensation for use of the materials.

You will comply with these Terms of Access and Use including, without limitation, the USE RESTRICTIONS set out in Section 3 above;

You agree to indemnify and hold HotelExecutive harmless from any claim or damages (including any legal fees in relation to same) made by a third party in respect of any matter in relation to or arising from your use and/or membership arising from any breach or suspected breach of these Terms of Access and Use by you or your violation of any law or the rights of any third party.

7. ACTIONS WE MAY TAKE AT OUR SOLE DISCRETION

HotelExecutive may take any or all of the following actions at our sole discretion:

Remove any member profile (including photographs) or other material that, in our sole discretion may be inappropriate or we suspect to be illegal, subject us to liability or which may violate these Terms of Access and Use or where required to do so by law;

Issue members with verbal or written warnings and may take such further action as we deem appropriate if such warnings are not heeded;

Suspend or terminate a member's access to the members's area of HotelExecutive or a member's account without notice at any time;

Inform the appropriate authorities and provide them with information regarding any suspected illegal activity; or bring legal action against a member or other user of HotelExecutive in relation to any breach of these Terms of Access and Use or any illegal or suspected illegal activity.

8. GOOD SAMARITAN CONTENT AND COMPLAINT PROCEDURES POLICY

A. Policy

We have provided opportunities for you to contribute Content to our Site. It is our policy, however, not to allow any Content which may constitute intellectual property infringement; violations of federal, state, or local law; obscene or defamatory material, or may otherwise be unacceptable or inappropriate. Upon learning of such Content, we will attempt, and you hereby give HotelExecutive the right, to delete, edit, remove, disable, change, or restrict access to or the availability of the Content, which in our sole discretion, is otherwise unacceptable or objectionable. We may or may not notify you about what action we take with respect to the disputed Content. The provisions of this section are intended to implement this policy but are not in any way intended to impose a contractual obligation upon us to undertake, or refrain from undertaking, any particular course of conduct.

B. Complaint Procedures

If you believe that another user or other third party has posted Content which violates this policy or specifically the USE RESTRICTIONS in Section 3 above, you may notify HotelExecutive via e-mail at editor@HotelExecutive . In order to allow HotelExecutive to respond effectively, please provide HotelExecutive with as much information as possible in your correspondence, including: (1) the nature of the right infringed or violated (including any applicable registration numbers of the federally-registered intellectual property allegedly infringed), if applicable, or the unacceptable or inappropriate Content; (2) all facts which lead you to believe that a right has been violated or infringed, if applicable; (3) the precise location where the offending Content is located; (4) any grounds to believe that the party or user which posted the Content was not authorized to do so or did not have a valid defense (including the defense of fair use), if applicable; (5) if known, the identity of the party or user who posted the infringing, offending, or inappropriate Content; and (6) in the case of alleged copyright infringement claims, information sufficient to identify the work and your claims to ownership.

C. Indemnification/Waiver of Certain Rights

By contacting HotelExecutive and complaining of an alleged violation, you agree that the substance of your complaint shall constitute a representation made under the pains and penalties of perjury pursuant to the laws of the State of California. In addition, you agree, at your own expense, to defend and indemnify HotelExecutive and hold HotelExecutive harmless against all claims which may be asserted against HotelExecutive, and all losses incurred, as a result of your complaint and/or our response to it.

D. Waiver of Claims and Remedies

We expect all users of our Site to take responsibility for their own actions and cannot and do not assume liability for any acts of third parties which take place at our Site. By utilizing the Good Samaritan procedures set forth herein, you waive any and all claims or remedies which you might otherwise be able to assert against hotelexecutive under any theory of law (including, but not limited to, intellectual property laws) that arise out of or relate in any way to the content at hotelexecutive or our response, or failure to respond, to a complaint.

E. Investigation/Liability Limitation

You agree that we have the right, but not the obligation, to investigate any complaint received. By reserving this right, we do not undertake any responsibility in fact to investigate complaints or to remove, edit, disable or restrict access to or the availability of Content. We will not act on complaints that we believe, in our sole discretion, to be deficient, incomplete, or otherwise questionable. If you believe that Content remains on HotelExecutive which violates your rights, Your sole and exclusive remedy shall be against the user or other party responsible for said content, not against HotelExecutive. your sole and exclusive remedy against HotelExecutive shall be to terminate your use of HotelExecutive and service.

Digital Millennium Copyright Act Compliance. As set forth in Subsection (b), you must contact our agent if you believe that a work protected by a U.S. Copyright which you own has been posted on our Site without authorization or that our Site, in some material way, contributes to its infringement. It is our policy in appropriate circumstances, if possible, to terminate the access rights of repeat infringers and other users who use HotelExecutive in an inappropriate or objectionable manner.

9. COOPERATION WITH LAW ENFORCEMENT

HotelExecutive reserves the right to fully cooperate with any law enforcement authorities or court order requesting or directing HotelExecutive to disclose the identity or other information regarding any user or member alleged by any governmental entity to be using HotelExecutive or any Content or materials available in, at, through or in association with HotelExecutive in violation of any law or regulation, or in violation of this Agreement, including, without limitation, the posting of e-mail messages, or publishing or otherwise making available any such materials. By accepting this agreement you waive and hold harmless HotelExecutive from any claims resulting from any action by HotelExecutive during, or as a result of, its investigations, and from any actions taken as a consequence of investigations by either HotelExecutive or law enforcement authorities

10. APPLICABLE LAWS, VENUE, JURISDICTION & MANDATORY ARBITRATION

If any provision(s) of this Agreement is held by a court of competent jurisdiction to be contrary to law, then such provision(s) shall be construed, as nearly as possible, to reflect the intentions of the parties with the other provisions remaining in full force and effect. HotelExecutive's failure to exercise or enforce any right or provision of this Agreement shall not constitute a waiver of such right or provision unless acknowledged and agreed to by HotelExecutive in writing. The section titles in this Agreement are solely used for the convenience of the parties and have no legal or contractual significance. This Agreement may be assigned in whole or in part by HotelExecutive. This Agreement may not be assigned in any manner by you without the express, prior written permission of HotelExecutive.

Any and all disputes or controversies of any kind, including but not limited to any performance, duty, obligation or liability arising under or related to this Agreement which are not first resolved informally, shall be determined by binding arbitration in San Francisco, California, in accordance with the rules of the American Arbitration Association. The final award in any such arbitration proceeding shall be subject to entry as a judgment by any court or competent jurisdiction, provided that such judgment does not conflict with the terms and provisions hereof. The jurisdiction of the arbiter (or arbiters) with respect to legal matters shall be limited only by the statutory and common law of the State of California and the United States.

Notwithstanding the foregoing, any and all disputes, which the parties cannot informally resolve, regarding the scope of issues or matter with the jurisdiction of the arbitrator, shall be resolved by a separate dispute resolution process whereby HotelExecutive, in its sole discretion shall elect the dispute to be resolved by either (1) a court of competent jurisdiction in the State of California or (2) a panel of three new arbitrators.

This Agreement shall be governed by and construed in accordance with the laws of the State of California notwithstanding any conflict of laws provisions. You and HotelExecutive agree that the venue for all legal disputes, controversies, actions of any kind arising under or related to this Agreement shall be San Francisco, California. You and HotelExecutive further agree that in case of any litigation regarding this Agreement, you irrevocably and unconditionally (i) consent to submit to the exclusive jurisdiction of the state and federal courts in the County of San Francisco, California for any litigation or dispute arising out of or relating to this Agreement, (ii) agree not to commence any litigation arising out of or relating to this Agreement except in the California Courts, (iii) agree not to plead or claim that such litigation brought therein has been brought in an inconvenient forum, and (iv) agree the California Courts represent the exclusive jurisdiction for all litigation relating to this Agreement.

11. MEMBERSHIP FEES

Hotel Business Review Subscriptions

If you choose to purchase a subscription, member subscription payments can be made in U.S. Dollars, as well as a variety of international currencies. Membership terms are Annual Recurring, and Monthly Recurring. The Annual Recurring subscription is an annual commitment and subscribers will be charged each consecutive billing cycle. Annual Recurring subscriptions can be cancelled after the first billing cycle and within 30-days of the billing date for a full refund. Monthly Recurring subscriptions are ongoing and subscribers will be charged each consecutive monthly billing cycle. Monthly Recurring subscriptions can be cancelled after the first month and within 7 days of the monthly billing cycle for a full refund.

12. PAYMENT AUTHORIZATION

Payment for the services provided to you in, at, through or in association with HotelExecutive may be made by automatic credit card, debit card, direct debit, bankwire or Paypal and other approved payment means offered in, at, through or in association with HotelExecutive, and you hereby authorize HotelExecutive and its agents to transact such payments on your behalf.

You hereby authorize HotelExecutive's Internet Payment Service Provider to charge your credit card to pay for your membership to HotelExecutive. You further authorize HotelExecutive's Internet Payment Service Provider to charge your credit card for any and all purchases of products, services in association with HotelExecutive. You agree to be personally liable for all charges incurred by you in association with your access or other use of any content provided by HotelExecutive or any third party in association with HotelExecutive. You acknowledge and agree that your liability for all such charges shall continue after termination of your access or any type of membership arrangement with HotelExecutive.

In the event that you have chosen to have your membership automatically rebilled, unless and until you notify HotelExecutive that you wish to cancel or terminate your membership to HotelExecutive, you hereby agree and authorize HotelExecutive's Internet Payment Service Provider to automatically renew your membership to HotelExecutive on a continuing basis and to charge your credit card (or other payment means you have selected) to pay for the ongoing cost of your membership. You hereby further authorize HotelExecutive's Internet Payment Service Provider to charge your credit card (or other approved payment means you have selected) for any and all purchases of products, services and entertainment provided to in, at, through or in association with HotelExecutive.

13. PRIVACY POLICY

The following is the Privacy Policy for HotelExecutive

We can be reached via telephone, email, or online at our contact page. When you visit our site we do not log any information regarding your domain or email address. Information Sharing: We do not share user information with any third parties other than via press release distribution as described below.

Hotel Newswire is a newswire service that distributes press releases on behalf of our users. If you decide to submit a press release for distribution through our system we will transmit your entire press release including any personal information therein contained to our media contacts and online distribution points including search engines. This is the only redistribution of your information that we engage in. Your submission of press releases through our system indicates consent with this policy. The information we collect during your registration process is used to notify users about updates to our service and inform users of any special events hosted by Hotel Newswire. This information is not shared with other organizations for commercial or non-commercial purposes.

Cookies: Our system requires the use of cookies to enable the user to log back into our website to access information from the newswire, without having to log in each time using the required username and password.

If you do not want to receive email from us in the future, please let us know by following instructions included in our communication with you. Users who supply us with telephone numbers online may receive telephone contact from us regarding their account, or informing them of new products and services available on the HotelExecutive website. If you do not wish to receive such telephone calls, please edit your account and remove your phone number from your account profile. This can be done from your user account menu.

Ad Servers: We do not partner with or have any relationship with any ad server companies. From time to time, we may use customer information for new uses not previously disclosed in our privacy notice. If our information practices change at any time, we will post the policy changes to our website to notify you of these changes and provide you with the ability to opt out of these new uses. If you are concerned about how your information is used, you should check back at our website periodically.

Upon request we provide site visitors with access to all information (including proprietary information) that we maintain about them. Users can access this information by logging in to their account.

Security: We always use industry-standard encryption technologies while transferring and receiving user data exchanged with our site. We have appropriate security measures in place in our physical facilities to protect against the loss, misuse, or alteration of information that we have collected from you on our site. We do not store credit card information in our systems.

If you feel that this site is not following its stated information policy, you may contact us.

Amy Draheim Scrolling to Selling: A Hotel Social Media Playbook
    READ MORE
Kasia Russell The Benefits of a Small Hotel Management Company
    READ MORE
Scott Bent A Visitor's Guide to Hospitality REITs
    READ MORE
Laszlo Puczko From Magpies to Babysitters: Cheat Sheet to Wellness Innovation in Hospitality
    READ MORE
Michael Klein Top Ways AI Is Elevating The Guest Experience from Search to Stay
    READ MORE
Mary Barker The Future of Digital Experiences in Hospitality for 2024
    READ MORE
Stephen Wittman Hotel Food and Beverage Thrives on People, Who are the Best Investment
    READ MORE
Coming up in March 1970...