U.S. should take note of EU's data-privacy rules: Travel Weekly

In last week's column, you noted that there are no U.S. government restraints on the ability of any travel supplier or travel agency to disseminate travel data in any way that it wishes. Shouldn't there be a law making such disclosure illegal unless the traveler consents?

A: There ought to be a law protecting the privacy of travel records, just as there is a law protecting your health records. There also ought to be a federal government agency that enforces the law.

Such laws and enforcement agencies exist in every European Union country and Canada. The basic principles of these laws are the right of the consumer to know where data originated and where it will be going; the right to have data rectified; the right to sue for unauthorized disclosure; and the right to withhold permission to disclose data to any third party, except for national security purposes.

These principles go far beyond the weak "privacy policies" on e-commerce Web sites. More importantly, the biggest commercial data gatherers of all, the GDS vendors, have no privacy policies that affect agency bookings.

So, why doesn't the U.S. have a data protection law like the EU and Canada?

Companies, such as major travel suppliers, have successfully argued to Congress that voluntary efforts are sufficient because there have been almost no major leaks of personal travel data.

Further, U.S. travel suppliers that do business with clients in the EU must adhere to a set of principles that mirror the EU laws, in part.

However, all these voluntary promises are empty because there are no meaningful consequences for violations.

As Edward Hasbrouck, author of "The Practical Nomad" books and advocate of travel privacy laws, puts it, "Imagine timeshare salespeople to whom your travel data was sold showing up at your hotel to sell you a local property." You have no legal right to prevent the sale of such data now.

Until a law is enacted, corporations that don't want their employees' travel data sold for commercial-espionage purposes need to try to make sure their contracts with suppliers and travel agencies contain detailed nondisclosure clauses.

Large travel suppliers and GDSs probably would balk at such a request, citing their own allegedly rigorous policies, which, as you now know, are almost worthless.

On the other hand, travel agencies should have no problem promising to safeguard corporate data, as long as corporations understand that agencies have no control over what GDSs and suppliers do with it.

Mark Pestronk is a Fairfax, Va.-based attorney specializing in travel law. He answers your questions in the TravelWeekly.com Legal Ease forum. To contact Mark directly, e-mail him at [email protected].

From Our Partners


From Our Partners

GTM West Supplier Spotlight 2026 Part Two
GTM West Supplier Spotlight 2026 Part Two
Register Now
Revenue, Retention and Risk: The Business Case for Integrated Travel Insurance Technology
Revenue, Retention and Risk: The Business Case for Integrated Travel Insurance Technology
Read More
The Art of Destination Recommendation: Alternative Destination Strategies for Travel Advisors
The Art of Destination Recommendation: Alternative Destination Strategies for Travel Advisors
Register Now

JDS Travel News JDS Viewpoints JDS Africa/MI