Customer data in franchising: preparing your business in Croatia
Before expanding your franchise network, establish who can access customer data, define partners’ responsibilities and set rules for shared digital tools.
Published

When turning an existing business into a franchise, your customer database is more than a sales asset. Bookings, orders, complaints and loyalty schemes contain personal data, so you must clearly establish who may use it and why. Before bringing the first partner into your franchise network, put clear arrangements in place for data flows: a shared name and the same software do not mean everyone should be able to see everything.
1. Map your data before choosing a shared system
Start with how your existing outlet actually operates, rather than a legal document template. Follow the customer journey from the first enquiry to completion of the service. Record where customers provide data, who can see it and whether it is sent outside the outlet.
Create a simple table with these columns:
- Data: for example, a name, contact details, order history or the content of a complaint.
- Purpose: booking an appointment, fulfilling an order or sending offers.
- Access: outlet staff, the franchisee, the franchisor or an external service provider.
- Storage location: the till system, email, a paper form or a shared application.
- Retention period: a period justified by the purpose and applicable legal obligations.
Include informal channels too: employees’ personal phones, shared passwords and spreadsheets sent by email. These habits can easily carry over into a new outlet. Before expanding, decide which to eliminate and which to replace with a controlled process.
2. Assign roles according to who actually makes the decisions
Croatia has no specific franchise law and no general requirement to register a franchise in a dedicated state register. Franchise relationships are governed by the Croatian Obligations Act and other applicable general legislation. For personal data, the key legislation is the General Data Protection Regulation, or GDPR, and Croatia’s Act on the Implementation of the General Data Protection Regulation. The supervisory authority is the Croatian Personal Data Protection Agency, known as AZOP.
Roles depend not on who owns the brand, but on who determines the purposes and means of processing. Consider each activity separately:
- Independent controllers: a franchisee may independently process the data needed for its own orders and complaints. The franchisor has no automatic right to access the franchisee’s entire database.
- Joint controllers: if the franchisor and franchisee jointly determine the purposes and means of a shared loyalty scheme, they need an arrangement under Article 26 of the GDPR. The essence of that arrangement must be made available to data subjects.
- Controller and processor: where one party processes data solely on behalf of the other and under its instructions, the relationship must be governed in accordance with Article 28 of the GDPR.
The same company can have different roles for different activities. A single contractual clause stating that the franchisee is “responsible for GDPR compliance” is therefore not enough.
3. Limit the shared database to justified needs
Before buying or customising software, decide whether the franchisor needs to see customers’ identities at all. Aggregated, genuinely anonymous data is often sufficient to compare turnover, complaint numbers or repeat purchase rates. Pseudonymised data that can be linked back to an individual remains personal data.
For every transfer between partners, establish the purpose and an appropriate lawful basis. Data collected to fulfil an order is not automatically available for joint marketing campaigns. For electronic marketing messages, you must also check the rules under Croatia’s Electronic Communications Act; consent is not the only possible basis in every circumstance, but exceptions are subject to conditions.
Clearly explain to customers which legal entity processes their data, why, to whom it discloses the data and how they can exercise their rights. A notice that gives only the brand name may be insufficient where different businesses operate the outlets.
Set up separate user accounts, permissions based on job responsibilities and access logging. Staff at one outlet should not be able to browse another outlet’s customer records simply because they use the same software.
4. Prepare the documents and an incident response procedure
Alongside the franchise agreement, prepare documents that reflect the roles you have identified: a data processing agreement or joint controller arrangement where required, customer privacy notices, and access and retention rules. Also check the software supplier, its sub-processors and any potential data transfers outside the European Economic Area.
Decide who receives customer requests for access, rectification or erasure, and how those requests are passed to the person responsible. Erasure is not an unconditional right: some data must be retained to meet legal obligations.
Put specific reporting procedures in place for lost devices, misdirected messages and unauthorised access. A processor must notify the controller without undue delay. Where the conditions under the GDPR are met, the controller must report the breach to AZOP without undue delay and, where feasible, no later than 72 hours after becoming aware of it. Your internal procedure must therefore allow for a prompt assessment, rather than waiting for a routine meeting.
5. Test the settings before bringing a partner on board
Run a short test using fictional customer data. Can an employee see another outlet’s records? Who responds to a request from a customer who has shopped at several locations? Can you immediately revoke access for someone who is leaving?
Record the results and assign someone to address each issue. Grant access to real data only after checking permissions and documentation. Seek specialist legal advice where roles are unclear or sensitive data is involved.
Practical takeaway: before expanding your franchise network, map your data, assign responsibilities and test access in practice. A shared brand should connect outlets, but it does not justify unrestricted sharing of customer data.
Sources
- Kako pretvoriti svoj posao u franšizu u šest koraka
- 101 Sažetak Razvoj globalnog gospodarstva dokazuje ...
- Franchising kao poduzetnička strategija
- [PDF] FRANŠIZNO POSLOVANJE - STANJE U HRVATSKOJ
- 598
- PRAVNI OSVRT NA UGOVOR O FRANCHISINGU
- Pokretanje poslovanja u Hrvatskoj - gov.hr - e-Građani
- Usporedba franšiznog poslovanja u Hrvatskoj i



