Buying a franchise

Buying a franchise: Get to grips with customer data and GDPR

Who can use customer data in your franchise network? Clarify responsibilities, access and GDPR compliance before signing the franchise agreement.

Published

Buying a franchise: Get to grips with customer data and GDPR

When you buy a franchise, it often comes with a shared booking system, loyalty scheme or customer database. This can make day-to-day operations easier, but it can also create dependency: can you contact your own customers, handle a complaint and provide evidence of consent without help from head office? Before joining a franchise network, you should investigate both practical access to customer data and legal responsibility for it.

1. Map the customer journey through the systems

Start by asking the franchisor to demonstrate a typical customer journey. Follow the information from the first booking or purchase through to payment, marketing and eventual deletion. A demonstration often tells you more than a general assurance that the system is secure.

Create a simple overview covering these points for each system:

  • What personal data is collected, and for what purpose?
  • Which business collects the data?
  • Who has access: you, head office, other franchisees or external suppliers?
  • How long is the data retained?
  • Can you retrieve the information you need for your own operations and record-keeping?

In particular, check whether customers are doing business with your company or with the franchisor. This affects the information you need, but does not, on its own, determine how responsibilities are allocated under the GDPR. Nor does a shared logo mean that everyone in the network is free to share customer data.

Ask to see how access controls work in practice. If another franchisee can view your customers’ purchase histories without a legitimate need, this requires an explanation and possibly a change.

2. Allocate responsibility according to the actual activities

Denmark has no specific franchise law, no franchise-specific registration scheme and no statutory standard disclosure package that must be provided before an agreement is signed. General principles of contract law may, however, impose a duty to disclose material information. Franchise agreements are governed, among other legislation, by the Danish Contracts Act, while the processing of personal data is subject to the GDPR and the supplementary Danish Data Protection Act.

The data controller determines the purposes and essential means of processing. A data processor processes data on the controller’s behalf and in accordance with its instructions. If you and the franchisor jointly determine the purposes and essential means, you may be joint controllers.

Roles can vary between activities. For example, you may be an independent controller for local customer service, while a shared loyalty scheme requires a separate assessment. The label used in the contract does not determine the role; the actual circumstances do.

You should therefore ask for a written allocation of roles for each activity. A controller–processor relationship requires a data processing agreement under Article 28 of the GDPR. Joint controllers must set out their respective responsibilities in an arrangement under Article 26. A data processing agreement is not automatically the right solution between all members of the network.

3. Check the basis for the loyalty scheme and marketing

Access to a customer list is not the same as permission to use it for any purpose. Nor can the agreement give you a general right of ‘ownership’ that overrides customers’ rights.

Ask to see the privacy information customers receive, along with the wording of, and evidence for, any marketing consents. Check which businesses, channels and purposes those consents cover. Do not assume that consent given to one business also covers your business or the entire chain.

For electronic marketing, the rules in the Danish Marketing Practices Act apply alongside the GDPR. Prior consent is generally required, although there is a narrow exception, subject to specific conditions, for marketing a business’s own similar products to existing customers.

Ask specifically how an unsubscribe request is reflected in both local and central systems. If you are taking over an existing franchise outlet, the transfer and continued use of customer data must be assessed separately. A customer list does not become freely usable simply because it is included in the purchase price.

4. Make data access and security explicit contractual terms

Have the agreement specify which data you can access and export, in what format and subject to which restrictions. This right should be tied to lawful purposes and necessary information, rather than unrestricted copying of the entire chain’s database.

Also clarify these practical points:

  • Who creates and revokes employee access?
  • Who handles customers’ requests for access to or erasure of their data?
  • Who investigates data breaches and informs the other parties?
  • Which subcontractors are used, and is data transferred outside the EU/EEA?
  • How will you obtain the records you need if your access to the system ends?

Certain breaches must be reported to the Danish Data Protection Agency (Datatilsynet) within 72 hours of the controller becoming aware of them. Internal notification must therefore be swift, with clear responsibility assigned.

Practical takeaway: Before signing, obtain a system demonstration, an activity-by-activity allocation of roles and the relevant data protection agreements. Ask an adviser to check that your contractual rights align with your actual responsibilities and access to the systems.

Sources

Free guide

Get the free guide to buying a franchise

Enter your details and we'll email you the guide. You can also download it straight away.

We use your details to send the guide and to understand interest in franchising. You can unsubscribe at any time.

Latest articles