Cybersecurity and data protection · Third party data security and vendors
We utilize and interact with the IT of third parties for many aspects of our business, including related to our customers, franchisees and service providers such as cloud service providers and third-party delivery service providers. These third parties have access to information we maintain about our company, operations, customers, employees and vendors, or operating systems that are critical to or can significantly impact our business operations.
Technology infrastructure · Technology systems and infrastructure failure
We rely on information technology networks and systems and other operational technologies to operate our business, including the internet and internally developed systems and applications, as well as certain technology systems from third-party vendors. For example, we rely on IT to receive package level information in advance of the physical receipt of packages, move and track packages through our operations, efficiently plan deliveries, execute billing processes.
Cybersecurity and data protection · Insider threats and access controls
IT (ours, as well as those of our franchisees, acquired businesses, and third-party service providers) have been and will continue to be susceptible to damage, disruptions and shutdowns due to programming errors, defects or other vulnerabilities, power outages, hardware failures, misconfigurations, computer viruses, cyber-attacks, encryption caused by ransomware or malware attacks, exfiltration of data, attacks by foreign governments, state-sponsored actors, or criminal groups, theft, misconduct by employees or other insiders.
Information management · Technology vendor dependence
We utilize and interact with the IT of third parties for many aspects of our business, including related to our customers, franchisees and service providers such as cloud service providers and third-party delivery service providers.
Cybersecurity and data protection · Data breaches and cyber attacks
IT (ours, as well as those of our franchisees, acquired businesses, and third-party service providers) have been and will continue to be susceptible to damage, disruptions and shutdowns due to programming errors, defects or other vulnerabilities, power outages, hardware failures, misconfigurations, computer viruses, cyber-attacks, encryption caused by ransomware or malware attacks, exfiltration of data, attacks by foreign governments, state-sponsored actors, or criminal groups.
Cybersecurity and data protection · Data privacy and protection regulations
In addition, there has recently been heightened regulatory and enforcement focus relating to the collection, use, retention, transfer, and processing of personal data in the U.S. (at both the state and federal level) and internationally. This includes the EU's General Data Protection Regulation, the California Privacy Rights Act, the Virginia Consumer Data Protection Act, and other similar laws.