Brazil’s LGPD: prepare your data before expanding through franchising
Set access permissions, responsibilities and data protection rules before connecting your business to its first franchised outlets in Brazil.
Published

Turning a business into a franchise means deciding who will be able to access customer, applicant and employee data. A shared spreadsheet without access controls may work in the original shop, but create risks once independent business owners become involved. Before expanding your franchise network, organise how information will be collected, used, protected and deleted — and translate those decisions into system settings and clear responsibilities.
1. Map the data that will flow between businesses
Start with the business’s actual activities, rather than a generic privacy policy template. Follow a sale, a registration, a promotional campaign and an after-sales enquiry. At each stage, record which personal data is involved and where it goes next.
Create a table containing the following information:
- Activity: appointment booking, delivery, a loyalty programme or another specific purpose.
- Data used: name, telephone number, address, purchase history and any other necessary information.
- Participants: franchised outlet, franchisor and technology suppliers.
- Access: who can view, edit, export or delete records.
- Retention: how long the data is needed and the justification for keeping it.
Include informal tools, such as messaging apps, personal mobile phones and copies of spreadsheets. These channels are often overlooked during planning, even though they hold important information.
Do not automatically replicate everything head office collects. If a performance report can use aggregated figures, the franchisor may not need customers’ names and telephone numbers. Reducing the flow of data limits exposure and makes it easier to manage.
2. Assign responsibilities based on how the business operates
Brazil’s General Personal Data Protection Law, Law No. 13,709/2018 (LGPD), applies to the processing of personal data under the conditions set out in the legislation. It operates alongside Law No. 13,966/2019, Brazil’s Franchise Law, which governs franchise relationships in Brazil. Complying with one does not replace compliance with the other.
Under the LGPD, the controller makes decisions about processing, while the processor handles data on the controller’s behalf. These roles depend on the activities actually carried out, not simply on the labels assigned to the businesses in a contract.
For example, an outlet may decide how to process its own employees’ data, while the franchisor determines the purposes of a centralised customer relationship programme. A platform supplier may act as a processor for certain activities, depending on what it actually does.
Avoid, therefore, declaring that the franchisee will always act as the franchisor’s processor. Review each data flow with legal support and document:
- who determines the purpose and the data required;
- which legal basis permits the processing;
- who informs data subjects and handles their requests;
- who oversees suppliers and responds to incidents.
Consent is not the only legal basis available under the LGPD, nor should it be used as blanket permission for any purpose. Each use needs an appropriate justification. Sensitive data, such as health information, requires a specific assessment.
3. Configure systems to separate and protect access
Before committing to a platform for your future franchise network, check whether it can keep each outlet’s data separate. A system that works well for several company-owned shops may not provide the controls needed for legally independent businesses.
Ask for a practical demonstration. Create user profiles for frontline staff, outlet managers and the franchisor’s team. Check that each profile can see only what it needs and that relevant actions are logged.
Use individual accounts, multi-factor authentication where available, and a procedure for revoking access when staff leave. Shared passwords make it harder to identify who is responsible and stop unauthorised access.
Also check:
- whether exports of customer records can be restricted;
- whether backups and restoration tests are in place;
- the terms for returning or deleting data when the service ends;
- the supplier’s use of other service providers;
- any international data transfers and the requirements that apply.
Test how data subject requests will be handled before expanding. Can the team locate a record, correct information and assess a request for deletion? Deletion should not be automatic where there is a legitimate basis for retention, such as a legal obligation. The response must take the specific circumstances into account.
4. Align your documents and prepare an incident response
Decisions about data should be reflected consistently in contracts, operating guidance and privacy notices. Specify access permissions, data sharing, security duties, cooperation in handling data subject requests and procedures following the end of the relationship.
Where systems are mandatory and carry associated charges, these conditions should also be properly reflected in the franchise disclosure document, known in Brazil as the Circular de Oferta de Franquia (COF). Law No. 13,966/2019 requires clear information about recurring charges and mandatory suppliers. In a standard private franchise offering, the COF must be provided at least ten days before the contract or preliminary agreement is signed, or before any fee is paid to the franchisor or a person or business connected with it.
Also prepare a response plan for lost equipment, unauthorised access or records sent to the wrong recipient. Identify the responsible contact and set out procedures for preserving evidence, containing the incident and assessing any legally required notifications to Brazil’s National Data Protection Authority (ANPD) and data subjects. Not every incident requires external notification, but every incident needs to be assessed.
Putting this into practice: before connecting the first outlet, validate a data map, a responsibility matrix and an access test. Share records only once the purpose, safeguards and responsible parties have been established.
Sources
- L13966 - Planalto
- Lei de Franquias (13.966/2019) para franqueadoras
- MEI pode abrir uma franquia?
- Parceria Sebrae e ABF
- Como funciona uma franquia
- Franquia pode ser opção para pequenos negócios que desejam ...
- Franquia - Portal Gov.br
- pt.wikipedia.org › wiki › FranquiaFranquia – Wikipédia, a enciclopédia livre



