In last week's column, you noted that there are no
U.S. government restraints on the ability of any travel supplier or
travel agency to disseminate travel data in any way that it wishes.
Shouldn't there be a law making such disclosure illegal unless the
traveler consents?
A: There ought to be a law protecting the
privacy of travel records, just as there is a law protecting your
health records. There also ought to be a federal government agency
that enforces the law.
Such laws and enforcement agencies exist in every European Union
country and Canada. The basic principles of these laws are the
right of the consumer to know where data originated and where it
will be going; the right to have data rectified; the right to sue
for unauthorized disclosure; and the right to withhold permission
to disclose data to any third party, except for national security
purposes.
These principles go far beyond the weak "privacy policies" on
e-commerce Web sites. More importantly, the biggest commercial data
gatherers of all, the GDS vendors, have no privacy policies that
affect agency bookings.
So, why doesn't the U.S. have a data protection law like the EU
and Canada?
Companies, such as major travel suppliers, have successfully
argued to Congress that voluntary efforts are sufficient because
there have been almost no major leaks of personal travel data.
Further, U.S. travel suppliers that do business with clients in
the EU must adhere to a set of principles that mirror the EU laws,
in part.
However, all these voluntary promises are empty because there
are no meaningful consequences for violations.
As Edward Hasbrouck, author of "The Practical Nomad" books and
advocate of travel privacy laws, puts it, "Imagine timeshare
salespeople to whom your travel data was sold showing up at your
hotel to sell you a local property." You have no legal right to
prevent the sale of such data now.
Until a law is enacted, corporations that don't want their
employees' travel data sold for commercial-espionage purposes need
to try to make sure their contracts with suppliers and travel
agencies contain detailed nondisclosure clauses.
Large travel suppliers and GDSs probably would balk at such a
request, citing their own allegedly rigorous policies, which, as
you now know, are almost worthless.
On the other hand, travel agencies should have no problem
promising to safeguard corporate data, as long as corporations
understand that agencies have no control over what GDSs and
suppliers do with it.
Mark Pestronk is a Fairfax, Va.-based attorney specializing
in travel law. He answers your questions in the TravelWeekly.com
Legal Ease forum. To contact Mark directly, e-mail him at [email protected].