Q: When our agency sells the
products of a supplier such as a hotel chain, cruise line or
all-inclusive resort chain, the supplier accumulates data that we
consider highly confidential, such as our total sales of that
supplier's products and sales by each of our branch offices, hosted
agencies and at-home agents. We would not like the supplier to use
such data for unauthorized purposes, such as soliciting our hosted
agents directly. We also would not like the supplier to disseminate
such data to third parties such as our former consortium, which
wants to accumulate data on all recently resigned members. Do we
have the legal right to stop the supplier from using our data in
these unauthorized ways?
A:
No, you don't. Although you call the information "our data," and
its use "unauthorized," it is really the supplier's data. The
supplier can do whatever it wishes with the data, in the absence of
an agreement or understanding between you and the supplier
restricting the supplier's use of the data.
I have always found
it odd that in the travel business, every provider of data seems to
believe that it has an inherent, proprietary right to the
information and can somehow direct or limit its dissemination by
the receiving party. For example, corporate travel managers seem to
believe that the information in the travel agency's profiles
belongs to the corporation, not the travel agency.
Similarly, agencies
sometimes claim that they have the right to stop a consortium's use
of agency sales data to set up override programs that may undermine
the agency's own supplier deals.
However, none of
this is true. The general legal rule is that the recipient of data
can use, give or sell it in any way that it wishes. Another way of
saying it is that the possessor of data is its owner. There are
three exceptions to the general rule.
First, of course, a
contract between the disclosing party and the receiving party can
restrict the latter's use of the data. For example, your contract
with a supplier can provide that the supplier will not use your
data to solicit your hosted agents or disclose the data to third
parties without your consent.
Second, you can try
to protect your data as a trade secret within the meaning of the
Uniform Trade Secrets Act, which is in effect in almost every
state. To protect it, there must be "reasonable efforts to maintain
its secrecy," which means at least telling the recipient that your
data is confidential and having the recipient agree to treat it as
such. This is practical only if the recipient acknowledges its
responsibilities in writing, so this exception is like the first
one, except that the written acknowledgement can be in a letter or
e-mail in addition to a contract.
Third, there are
federal and state laws that restrict a recipient's use of data, but
none of them applies to the travel business. Examples are health,
bank, library and movie-rental records.
So if you want a
hotel chain to agree not to solicit your hosted agents for direct
deals or sell your data to third parties without restrictions, you
will need a contract clause, letter or e-mail that says so. Most
suppliers won't agree, but you may at least be able to get them to
articulate their current data policies, and you can try to put
those in a contract.
Mark Pestronk
is a Washington-based attorney specializing in travel
law.