Franchising your business

Customer data when franchising a business in Colombia

Before sharing a customer database with franchisees, define permissions, responsibilities and controls to protect personal data.

Published

Customer data when franchising a business in Colombia

When franchising an existing business, sharing the customer database may seem as simple as setting up a user account in the sales system. It is not: consent obtained by the original business does not necessarily allow another company to use that data for its own campaigns. To build a responsible franchise network, plan how information will be processed before connecting the first franchised outlet.

1. Identify what information will be shared and why

Start with a specific inventory, not a generic clause. Review the data collected through invoices, bookings, deliveries, loyalty programmes, web forms and customer service conversations. Include spreadsheets and staff phones too: they often contain information that does not appear in the central system.

For each data flow, document:

  • Source: who collects the information and through which channel.
  • Purpose: fulfilling an order, handling a warranty claim or sending marketing material, for example.
  • Recipient: which company needs access and why.
  • Scope: which fields it needs and for how long.
  • Evidence: where consent is recorded, where required.

Separate information needed to run the business from information that is merely useful for analysis. To compare outlets, the franchisor may need aggregated sales figures without customers’ names, telephone numbers or addresses.

If a purpose can be achieved using effectively anonymised information, avoid sharing identifiable data. Removing a name is not enough if the remaining fields allow the person to be identified.

2. Apply the relevant Colombian rules

In Colombia, franchise agreements are not a specifically regulated category of contract: there is no comprehensive, franchise-specific framework that replaces general contract law. The Commercial Code and, where relevant, the Civil Code apply, alongside the mandatory rules governing each activity. Freedom of contract does not allow the parties to remove data subjects’ rights.

The key provisions in this area are Law 1581 of 2012, on personal data protection, and its implementing regulations, consolidated in Decree 1074 of 2015. Among other matters, these rules govern consent, the duties of controllers and processors, data processing policies, and the handling of enquiries and complaints. The Superintendence of Industry and Commerce oversees compliance in this area.

Distinguish between two roles: the controller makes decisions about the database or its processing; the processor processes information on the controller’s behalf. These roles depend on what each company actually does, not the label used in the franchise agreement.

Do not confuse the different registers either. The National Database Register is not a franchise register. Whether registration is mandatory depends on the legal criteria applicable to each organisation; being exempt from registration does not remove other data protection duties.

Proposed franchise regulations must not be presented as current law. In particular, proposals for an offering circular or specific disclosure deadlines do not, in themselves, create enforceable obligations.

3. Review consent before granting access

Imagine that your business runs a loyalty programme and you want to let a new franchisee contact everyone enrolled. Before importing the database, check who is named as the controller, which purposes customers were told about and what the existing consent covers.

Using the same brand does not make two companies a single entity. If the franchisee intends to use the data for its own purposes, simply describing it as a technology provider or processor is not enough. Assess whether this constitutes a data transfer and which requirements apply. If it acts solely on the controller’s instructions, examine the rules on data transmission to a processor and the agreement required.

Updating the policy published on your website does not automatically replace any consent required for a new use. Where there is insufficient evidence of valid consent, obtain the necessary consent before starting that processing.

Also check where the system provider hosts the data and who can access it from other countries. International data transfers and transmissions are subject to different rules; do not assume the matter is settled simply because the application is marketed in Colombia.

4. Turn decisions into verifiable controls

Prepare a data processing addendum that reflects how the business actually operates. Identify each party’s role, the authorised purposes, instructions, permitted access and the procedure for handling requests from data subjects. Include arrangements for reporting incidents and managing technology providers, data retention, and the return or deletion of information.

Set up individual user accounts and role-based permissions. Someone arranging a delivery may need an address, but not the ability to download the entire customer database. Avoid shared passwords and unrestricted data exports.

Before opening, run a test: simulate a data access or deletion request and check who receives it, who responds and how it is recorded. Any deletion must take account of applicable statutory retention requirements.

Practical conclusion: before sharing data with a franchisee, verify three deliverables: an inventory of data flows, a documented legal basis for each use and correctly configured technical permissions. If any are missing, delay access—not customer protection.

Sources

Free guide

Get the free guide to franchising your business

Enter your details and we'll email you the guide. You can also download it straight away.

We use your details to send the guide and to understand interest in franchising. You can unsubscribe at any time.

Latest articles