Franchising your business

Customer data in a franchise network: agree responsibilities before expanding

A shared customer management system does not make customer data shared property. Define data protection responsibilities before your first franchisee joins.

Published

Customer data in a franchise network: agree responsibilities before expanding

When you expand your existing business into a franchise network, the way you process customer data changes. A booking system, online shop or customer loyalty database used by one company starts serving independent businesses. Before your first franchisee joins, you need to establish who decides how the data is used, who can access it and what customers are told. Simply buying a shared system does not settle these responsibilities.

1. Map customer data flows before choosing a system

Start with your existing business. Record where customers’ personal data is collected: through online forms, at the till, when booking appointments, during customer service interactions or when signing up for marketing. Also establish where the data goes and who uses it. Personal data includes not only names and contact details, but also purchases and service notes linked to an identifiable customer.

Create a simple table with a separate row for each purpose for which data is used. Record:

  • what data is collected and why
  • which company needs the data to carry out its work
  • which system holds the data
  • who receives it or can view it
  • when it is deleted or anonymised.

Distinguish between fulfilling a customer’s order and marketing across the network. The same contact details may be used for both, but the purpose and lawful basis for processing must be assessed separately. Being a customer at one outlet does not, in itself, entitle every business in the network to use that customer’s data for its own campaigns.

Pay particular attention to your existing customer database. Giving new franchisees access to it is not merely a technical change to access permissions. First establish whether the planned processing is lawful and consistent with the information given to customers. If necessary, keep the existing data outside the new shared system.

2. Identify the controller based on who actually makes the decisions

Finland has no separate franchising act, statutory franchise register or franchise-specific pre-contractual disclosure law. Franchise relationships are governed by general legislation, including the Contracts Act, the Unfair Business Practices Act and the Competition Act. Customer data processing is governed primarily by the EU General Data Protection Regulation, or GDPR, and Finland’s supplementary Data Protection Act. Electronic direct marketing is also subject to requirements under the Act on Electronic Communications Services.

The Finnish Franchising Association’s Code of Ethics is a form of self-regulation, not legislation or official authorisation. It does not replace compliance with data protection obligations.

Data protection roles depend on what actually happens in practice. A label in a contract does not settle the matter if decision-making authority lies elsewhere.

Separate controllers: Each franchisee may independently decide how personal data is processed for its own customer service activities. In that case, sharing data with another franchisee or the franchisor requires an appropriate lawful basis.

Data processor: For some activities, the franchisor may process data on behalf of a franchisee, following the franchisee’s documented instructions. This requires a data processing agreement under Article 28 of the GDPR. However, providing the system does not automatically make the franchisor a processor.

Joint controllers: If the franchisor and franchisee jointly determine the purposes and means of processing, they may be joint controllers. Their responsibilities must then be allocated through an arrangement under Article 26 of the GDPR, with the essence of that arrangement made available to customers.

Assess these roles separately for each processing purpose. The same company may be a controller for one activity and a processor for another. For example, fulfilling a local order and running a network-wide loyalty programme may require different arrangements.

3. Turn responsibilities into contracts and access permissions

Include a clear description of the customer data processing arrangements, together with the necessary data protection agreements, as part of the franchise agreement. Avoid relying on a simple statement that the customer database belongs to the network. An ownership clause does not determine whether personal data can lawfully be used.

Agree, at a minimum, how access rights will be granted and revoked, how subcontractors will be used, how data breaches will be reported and how customer requests will be handled. Also specify who is responsible for keeping privacy information up to date and how changes will be communicated to franchisees.

Set up role-based access permissions in the system. A local employee will not usually need to see customer data from every outlet. Developing the network may often require only aggregated data from which individual customers cannot be identified. If data is merely pseudonymised, it remains personal data.

Check the system supplier’s contract for data locations, sub-processors and any transfers outside the European Economic Area. Also make sure that data can be retrieved, corrected, deleted and, where necessary, exported from the system. Check these capabilities before committing to a long-term service contract.

Set retention periods for each processing purpose. The statutory obligation to retain accounting records does not automatically justify keeping every part of a customer profile for the same length of time. At the same time, decide how termination of the franchise agreement will affect access rights and data retention in each company.

4. Test a customer request and a data security incident

Before a new franchisee opens for business, rehearse a common scenario: a customer asks to see all the data held about them. Who receives the request, verifies their identity and compiles the response? Under the GDPR, requests must generally be answered within one month. Unclear internal responsibilities do not remove this obligation.

Also rehearse what happens if a customer list is sent to the wrong recipient. Employees must have an easy-to-find reporting channel. A processor must notify the controller of a personal data breach without undue delay. The controller assesses the next steps: where notification to the supervisory authority is required, it must be made within 72 hours of becoming aware of the breach. In high-risk cases, affected customers must also be informed without undue delay.

Document any shortcomings identified during the exercise and assign responsibility for fixing them. Make sure the agreed procedures also work in the evenings and when the person responsible is absent.

Practical checklist: Before your first franchisee joins, finalise your data flow map, allocation of roles, necessary agreements and restricted access permissions. Then test one customer request and one data security incident. This ensures that customer data management across the franchise network rests on working practices, not assumptions.

Sources

Free guide

Get the free guide to franchising your business

Enter your details and we'll email you the guide. You can also download it straight away.

We use your details to send the guide and to understand interest in franchising. You can unsubscribe at any time.

Latest articles