Franchising your business

Franchising your business: managing customer data

Customer databases, shared software and loyalty schemes: define responsibilities and access rights before bringing your first franchisees on board.

Published

Franchising your business: managing customer data

Turning an existing business into a franchise network changes how you manage customer data. A database previously used by just one company may become accessible to several independent businesses. Before rolling out your point-of-sale software, online booking system or loyalty scheme, clarify who uses which data, for what purpose and under whose responsibility.

1. Map out data uses before sharing the database

Start with your existing business practices, rather than assuming they can be replicated unchanged by every franchisee. List the points at which you collect data: purchases, quotations, appointments, forms, complaints, newsletter sign-ups and loyalty accounts.

For each use, prepare a simple record setting out:

  • the data that is genuinely needed;
  • the business collecting it and those with access to it;
  • the intended purpose and proposed lawful basis;
  • the retention period or the criteria for determining it;
  • the software and service providers involved.

A shared tool does not justify giving everyone access to all the data. A franchisee may need their own customers’ order histories without needing to see those of every other outlet. The franchisor can often monitor performance using aggregated figures, without receiving customers’ names and contact details.

Also identify any older databases whose origins or collection conditions are unclear. Simply holding them within your business does not authorise their use for new network-wide campaigns.

2. Allocate responsibilities according to actual use

In France, personal data is governed in particular by the General Data Protection Regulation, or GDPR, and the French Data Protection Act, known as the Loi Informatique et Libertés. The CNIL, France’s data protection authority, oversees compliance. Franchising has no exemption: each business must assess its role in every processing activity.

The controller determines the purposes and essential means of processing. A processor acts on the controller’s behalf and under its instructions. Where several businesses jointly determine these elements, they may be joint controllers.

For example, a franchisee independently managing its quotations and local customer relationships will generally be the controller for those activities. A loyalty scheme designed and managed jointly may require a different assessment. The fact that a franchisor requires franchisees to use particular software does not, on its own, settle the question.

Have the roles assessed for each processing activity. Depending on the outcome, put in place a data processing agreement that complies with Article 28 of the GDPR or a joint controller arrangement that complies with Article 26. A clause stating that ‘the franchisee is solely responsible for all data’ does not remove the franchisor’s actual responsibilities.

For electronic direct marketing to individuals, also check the rules in the French Postal and Electronic Communications Code. Prior consent is generally required, subject to statutory exceptions. Consent given to one outlet does not automatically cover marketing from every business in the network.

3. Reflect your decisions in the contractual documents

French law does not provide a single, comprehensive legal framework specifically governing franchise agreements. General contract law, competition law and intellectual property law apply, alongside personal data protection rules.

Pre-contractual disclosure is governed in particular by Articles L. 330-3 and R. 330-1 of the French Commercial Code, under the framework commonly known as the Doubin Law. Where the relevant conditions are met, notably where a trade name, trade mark or other distinctive sign is made available in return for an exclusive or near-exclusive commitment in relation to the business activity, the pre-contractual disclosure document (DIP) and draft agreement must be supplied at least twenty days before signing or, where applicable, before any advance payment.

Without turning the DIP into a technical manual, clearly explain the commitments associated with mandatory tools and their costs. In the agreement and its schedules, specify access rights, permitted uses, service providers, security obligations and arrangements for handling individuals’ data protection requests.

Avoid reducing the issue to ‘ownership of the database’. That phrase resolves neither customers’ rights nor whether particular uses are lawful. Distinguish between rights in the tool itself, the conditions for accessing information and responsibility for processing it.

4. Test procedures before the first franchise outlet opens

Use your existing outlet to test the procedures with separate user accounts. Check that a local user cannot export the entire database and that an employee who has left genuinely loses access.

Prepare for three scenarios: a customer requests access to their data, a campaign is sent to the wrong recipients, and a computer containing customer information goes missing. For each, identify a point of contact, an escalation process and a way to keep an audit trail.

A personal data breach may need to be reported to the CNIL within seventy-two hours of the controller becoming aware of it, unless it is unlikely to pose a risk to individuals. Internal reporting must therefore be swift.

Key takeaway: before connecting your first franchisee, make sure you have mapped out data uses, documented responsibilities and tested access controls. Shared software should support the network, not lead to uncontrolled data sharing.

Sources

Free guide

Get the free guide to franchising your business

Enter your details and we'll email you the guide. You can also download it straight away.

We use your details to send the guide and to understand interest in franchising. You can unsubscribe at any time.

Latest articles